OpslyIQ Back

Privacy Policy

Last updated September 1, 2026

OpslyIQ Provider: itecbrains llc, a Georgia limited liability company, d/b/a OpslyIQ

Effective: September 1, 2026

1. Who this policy is for, and the distinction that governs it

OpslyIQ is used by two different groups of people, and their rights are different. Read § 1.2 before anything else if you are an employee.

1.1 If you are a restaurant owner, operator or manager

who signs up, pays for and administers an OpslyIQ account, you are our Customer. We deal with you directly. This policy describes how we handle your information, and you exercise your rights with us.

1.2 If you are an employee of a business that uses OpslyIQ

, your employer — not OpslyIQ — decides what information about you is collected, how it is used, and how long it is kept. In legal terms your employer is the controller (under the California Consumer Privacy Act, the business) and OpslyIQ is the processor (the service provider). We handle your information only on your employer's instructions and for the purposes they set.

This means that if you want to see, correct or delete your information, you should ask your employer. We cannot honour those requests on our own, because doing so would alter your employer's own records — records they are frequently required by law to keep, such as Form I-9 and wage records. When you contact us, we will refer you to your employer and assist them in responding. § 11 explains this in full.

1.3 Scope

This policy covers the OpslyIQ platform, our websites, and our communications. It does not cover any third-party service you or your employer connects.

2. What we collect

2.1 Account and organization information

Name, email address, telephone number, business name and address, Locations, role and permissions, and authentication data including multi-factor authentication settings.

2.2 Workforce information

— collected on the instruction of the employer:

- Identifiers: name, email address, telephone number, postal address. - Date of birth, used to derive minor status and apply hours restrictions. - Government identifiers: Social Security number or ITIN. Stored as an encrypted reference; only the last four digits appear in our database tables. - Financial account information: bank routing and account number for direct deposit. Stored as an encrypted reference; only the last four digits appear in our database tables. - Employment records: time entries, schedules, wages, tips, overtime, payroll inputs and estimates, role and pay rate, employment status. - Employment documents: Form I-9 and supporting documents, Form W-4, signed offer letters and handbook acknowledgments. - Expense receipts submitted through the Service.

2.3 Clock-in capture

— collected only for Locations where the employer has enabled the feature:

- A photograph of the employee taken at the moment of the punch. This is a photograph. We do not perform facial recognition, do not extract facial geometry, and do not generate or store any biometric template or faceprint. The photograph is used solely for a human manager's visual review of a time entry. § 3 explains this further. - Precise geographic coordinates at the moment of the punch. These are precise — accurate to within a few metres or better — not approximate. They are used solely to verify that the punch occurred at the work site and to enforce a geofence the employer configures. A punch may be rejected or flagged for review based on distance from the work site.

2.4 Operational data from connected services

Where the Customer connects a point-of-sale system, banking provider or other integration, we receive the data that integration supplies — for example sales, voids, discounts, tips, and point-of-sale employee references — together with the credentials needed to maintain the connection.

2.5 Technical data

IP address, device and browser characteristics, timestamps, pages and features used, and error and performance telemetry.

2.6 Billing data

Our payments processor handles payment card details; we do not store full card numbers. We retain the organization identifier, billing email, Location count, and subscription and consent records.

2.7 What we do not collect

We do not collect biometric templates. We do not collect health information, precise location outside a clock-in event, or information about anyone under thirteen.

3. The clock-in photograph — a specific statement

We describe this separately because it is the item people most often ask about, and because being precise matters more than being reassuring.

What we do. We store a photograph taken at the punch, in a private storage bucket, accessible only through a short-lived signed link to authorized users of the employer's organization.

What we do not do. We do not run facial recognition. We do not measure or record facial geometry. We do not create a faceprint or template. We do not compare one photograph to another. We do not use any photograph to identify anyone. We do not use photographs to train any model, and we do not sell or share them.

A feature we have not built. Our system contains a per-employee consent flag reserved for an optional face-matching feature that does not exist today. If we ever build it, it will be off by default and will remain off for any individual for whom the employer has not first obtained a written release that complies with the biometric privacy law of that individual's jurisdiction. The flag exists so that the feature cannot be switched on without that release.

Retention. Clock-in photographs are deleted 90 days after capture. See § 6.

4. How we use information

We use information to: provide, operate, secure and support the Service; authenticate users and enforce permissions; produce schedules, time records, labor analytics, payroll estimates and compliance readings; maintain integrations the Customer connects; detect and investigate security incidents, fraud and misuse; communicate about the Service, including billing, renewal and service notices; comply with law; and enforce our agreements.

Automated analysis. The Service produces analytics that flag individual time entries for manager review and that rank employees by a composite operational score. These outputs are decision support for a human reviewer. No employment decision — discipline, termination, change in hours or change in pay — is made by the Service. Under our Terms of Service the employer must independently review the underlying evidence and give the affected individual an opportunity to respond before taking any action.

Operational text analytics. Where the Customer uses our assistant features, operational text is sent to a third-party analytics provider to generate the response. Social Security numbers, bank and routing numbers, card numbers, employer identification numbers and personal names are removed before the text leaves our systems, and the same removal is applied before anything is written to our logs. Under our configuration, that provider does not use the content to train its models.

We do not sell personal information, and we do not share it for cross-context behavioural advertising. We have not done so in the preceding twelve months.

5. Who we disclose information to

RecipientPurposeWhat they receive
SupabaseHosting, database, storage and authenticationApplication data
StripeSubscription billingOrganization identifier, billing email, Location count. No workforce data.
Clover, SquarePoint-of-sale integrationMerchant credentials outbound; sales, voids, tips and point-of-sale employee references inbound
PlaidBank connection for the Customer's own business accountsBusiness banking credentials. Not employee bank accounts.
Anthropic, PBCOperational text analytics for assistant featuresOperational text with identifiers removed before transmission
Google Maps PlatformBusiness address lookup at onboardingAddress text. No personal information.
ResendTransactional and digest emailRecipient email address and message content
SentryError and performance telemetryDiagnostic data, with secrets scrubbed

We also disclose information: to the Customer whose account the data belongs to; to professional advisers under confidentiality; in connection with a merger or sale of assets, subject to this policy; and where required by law or to protect rights and safety. We will notify the affected Customer of a compelled disclosure where we are lawfully able to.

A current list of sub-processors is maintained at the URL identified in the Data Processing Addendum. We give Customers thirty (30) days' notice before adding a sub-processor that processes workforce data.

6. How long we keep information

CategoryRetention
Clock-in photographs90 days from capture
Precise clock-in coordinates13 months from capture
Time entries, schedules, wage and tip records4 years from creation
Form I-9 and supporting documents3 years from hire or 1 year from end of employment, whichever is later
Form W-4 and payroll tax records4 years after the tax is due or paid
Other employment documents4 years after end of employment
Expense receipts4 years
Account, subscription, consent and billing records7 years
Security and audit logs2 years
Technical and error telemetry90 days

We may retain information longer where required by law, or where necessary to resolve a dispute or enforce our agreements, and will delete it when that need ends. Deletion is performed on a schedule and recorded. Backups are overwritten in the ordinary course.

Employment records of former employees are deliberately retained for the periods above. Payroll and tax records must survive the end of employment, and archiving rather than deleting an employee is how the Service preserves them. Archived employees are excluded from the Location count and carry no fee.

7. Security

Sensitive values — Social Security numbers, bank account details and integration credentials — are held encrypted at rest in a secrets vault and are readable only server-side by a privileged service role. They are never returned to a browser. Where the plaintext is never needed, values are stored as one-way hashes.

Separation between organizations is enforced at the database layer, not by application code, so one organization's records are unreadable by another organization's users regardless of how a request is made. Within an organization, access is further narrowed by role and by position in the Location hierarchy.

All file storage is private and reached through short-lived signed links. Authentication supports time-based one-time-password multi-factor authentication, enforced-MFA policy, single sign-on and SCIM provisioning. Every sensitive change writes an audit record capturing the before and after state.

No system is perfectly secure. We will notify affected Customers without undue delay after becoming aware of a breach affecting their data, and will provide the information they need to meet their own notification obligations.

8. Where information is held

We process and store information in the United States. If you access the Service from outside the United States, you understand that your information will be transferred to and processed in the United States.

9. Cookies

We use cookies and similar technologies that are strictly necessary to operate the Service — session management, authentication and security — and a limited set for measuring product usage. We do not use advertising cookies and we do not participate in cross-context behavioural advertising. Where a browser transmits a Global Privacy Control signal, we treat it as a valid opt-out request under the state laws that require it.

10. Children and young workers

The Service is not directed to children. We do not knowingly collect personal information from anyone under thirteen (13). If we learn that we have, we will delete it and notify the Customer.

Our Customers may lawfully employ minors, and the Service supports that: date of birth is collected so that hours and scheduling restrictions applicable to minors can be applied. Authorized Users enrolled by a Customer must be at least fourteen (14) years of age. A minor employee does not contract with us — the employer is the contracting party — and a minor's information is processed on the employer's instruction like any other employee's.

11. Your rights

11.1 If you are an employee

Direct requests to see, correct, delete, or obtain a copy of your information to your employer. Your employer controls the record. On receiving a request from an employee we will identify the employer and assist them in responding within the time their law allows. We will not delete or alter an employee record on the employee's own request, because doing so could destroy records the employer is legally required to keep. Nothing here limits any right you have directly against your employer.

11.2 If you are a Customer

Contact us at privacy@opslyiq.com. Depending on where you live you may have the right to know what we hold, to obtain a copy in a portable format, to correct it, to delete it, to opt out of sale or sharing (we do neither), to limit the use of sensitive information, to opt out of profiling with legal or similarly significant effects, and not to be discriminated against for exercising a right.

11.3 How to exercise

Email privacy@opslyiq.com or write to the address in § 14. We will verify your identity against information already in your account. An authorized agent may act for you with written permission. We respond within the period the applicable law allows — generally 45 days, extendable once.

11.4 Appeal

If we decline a request, you may appeal by replying to our response. We will decide within the period your state's law requires — generally 45 or 60 days — and if we decline the appeal we will tell you how to complain to your state attorney general.

11.5 California

California is the only state whose comprehensive privacy law applies to employment information. If you are a California resident, the categories in § 2, the purposes in § 4, the recipients in § 5 and the retention periods in § 6 constitute our notice at collection. Precise geolocation, and your Social Security number and financial account details, are "sensitive personal information." We use them only for the purposes described in § 4 and for no purpose requiring an option to limit under Civil Code § 1798.121. We do not sell or share personal information. Where you are an employee of a Customer, your employer is the business and the routing in § 11.1 applies.

11.6 Shine the Light

California Civil Code § 1798.83 permits residents to request information about disclosures for third-party direct marketing. We make no such disclosures.

12. Changes

We will post a revised policy with a new effective date and, where the change is material, notify Customers by email at least thirty (30) days before it takes effect.

13. Data Processing Addendum

Annex 1 forms part of this policy and of our Terms of Service and governs our processing of workforce information on a Customer's behalf.

14. Contact

itecbrains llc d/b/a OpslyIQ, 5354 McGinnis Ferry Rd, Suite 224, Johns Creek, Georgia 30005. privacy@opslyiq.com

Annex 1 — Data Processing Addendum

A1. Roles

You are the controller and business; we are the processor and service provider. You determine the purposes and means of processing. We process only on your documented instructions, which consist of this Addendum, the Terms of Service, and your configuration of the Service.

A2. Our undertakings

We will:

(a) Process Personal Information only for the specific business purposes of providing the Service, and not retain, use or disclose it for any other purpose, or outside our direct business relationship with you, or for any commercial purpose of our own.

(b) Not sell or share Personal Information, as those terms are defined by applicable law.

(c) Not combine Personal Information received from you with information received from another source, except as permitted for a service provider.

(d) Comply with the obligations applicable to a service provider and processor and provide the same level of protection the applicable law requires.

(e) Notify you promptly, and in any case within five (5) business days, if we determine that we can no longer meet our obligations, and cease or remediate on your instruction.

(f) Permit you to take reasonable and appropriate steps to stop and remediate unauthorized use.

(g) Ensure personnel with access are bound by confidentiality and are trained.

(h) Maintain the safeguards described in § 7 of the Privacy Policy, appropriate to the nature of the information.

(i) Notify you without undue delay after becoming aware of a breach of security leading to accidental or unlawful destruction, loss, alteration or unauthorized disclosure of Personal Information, and provide the information reasonably necessary for your own notifications.

(j) Assist you in responding to requests from individuals, in your security and breach-notification obligations, and by providing the information necessary for your data protection assessments.

(k) Delete or return Personal Information at the end of the Subscription Term as provided in the Terms of Service § 4.4 and § 4.5.

(l) Make available the information necessary to demonstrate compliance and, on reasonable notice and not more than once annually, allow you or an independent assessor to review it. We may satisfy this by providing a current third-party report.

A3. Sub-processors

You authorize the sub-processors listed in Privacy Policy § 5 and any successor list we publish. We impose obligations on each sub-processor no less protective than this Addendum, and we remain responsible for their performance. We will give thirty (30) days' notice before adding a sub-processor that processes workforce information. If you reasonably object on data-protection grounds within that period, we will work with you in good faith, and if we cannot resolve it you may terminate the affected subscription without penalty and receive a refund of prepaid unused fees.

A4. Your undertakings

You represent and warrant that:

(a) You have provided all notices and obtained all consents, authorizations and releases required by law to collect the Personal Information you submit or instruct us to collect and to have us process it — including any notice or consent required for photograph capture at clock-in, precise geolocation capture, geofence enforcement, and electronic monitoring of employees.

(b) You have complied with any statute requiring advance notice of electronic monitoring, including New York Civil Rights Law § 52-c and Conn. Gen. Stat. § 31-48d, before enabling any capture feature for an Authorized User in such a jurisdiction.

(c) Your instructions comply with applicable law and do not cause us to violate it.

(d) You will respond to requests from your workforce concerning their information, and will not direct them to us as the responder.

(e) Where you use analytics that flag or rank individuals, you will comply with the law applicable to the use of automated systems in employment decisions in your jurisdiction, including any notice, notice- to-employee, impact-assessment or recordkeeping obligation, and will conduct the independent human review required by Terms of Service § 6.6.

A5. Details of processing

Subject matter: provision of the Service. Duration: the Subscription Term plus the retention periods in Privacy Policy § 6. Nature and purpose: hosting, storage, computation, analytics, transmission to sub-processors and integrations you connect, and deletion. Categories of individuals: your owners, managers, employees and contractors. Categories of Personal Information: as set out in Privacy Policy § 2. Sensitive information: Social Security number or ITIN, financial account details, precise geolocation, photographs, date of birth.

A6. Precedence

In the event of conflict, this Addendum controls over the Terms of Service and the Privacy Policy as to its subject matter.

*End of Exhibit B.*