DuxoraDuxoraWorkforce

Privacy Policy

Last updated: October 10, 2026

This Privacy Policy explains how Saachi LLC, d/b/a Duxora ("Duxora," "we," "us," or "our") collects, uses, and protects information when you use our employee scheduling platform, including our website, mobile applications, and related services (collectively, the "Service").

Saachi LLC, d/b/a Duxora, is a North Carolina limited liability company. If you have questions about this policy, contact us at [email protected].

Pilot Scope: The Service is currently offered only to Employers and Employees located in North Carolina, as part of a limited six-month pilot program. This Privacy Policy is written accordingly and does not address requirements applicable to other jurisdictions (e.g., GDPR, CCPA). We will update this policy if and when the Service expands beyond North Carolina.

1.Who This Policy Covers

Duxora is used by two types of users:

  • Business Customers ("Employers") — organizations that sign up for Duxora to schedule their workforce.
  • End Users ("Employees") — individuals added by an Employer to use the Service for clocking in/out, viewing shifts, requesting time off, and related tasks.

If you are an Employee using Duxora through your employer, your employer is the data controller of your information, and Duxora acts as a data processor on their behalf. Questions about how your data is used should generally be directed to your employer first.

2.Information We Collect

Account & Profile Information

  • Name, email address, phone number
  • Job title, location assignment, role/permissions
  • Login credentials

Scheduling & Work Data

  • Shift schedules, availability, confirmations, swaps
  • Time-off requests
  • Clock-in/clock-out timestamps and task completion records

Biometric Data

If you enable Face ID or Touch ID unlock, we (or your device operating system) process biometric identifiers to authenticate your login.

  • We do not store raw biometric images or templates on our servers. Biometric authentication is handled locally by your device's operating system (Apple/Google), which returns only a confirmation of identity to our app — not the underlying biometric data.
  • You may disable biometric unlock at any time in your device or app settings and use a password instead.
  • We retain any biometric-related authentication logs only as long as necessary to operate the feature, and delete them upon request or account deletion, consistent with applicable law (e.g., Illinois BIPA, Texas CUBI, Washington biometric privacy laws).

Device & Usage Information

  • IP address, device type, operating system, browser type
  • App usage and interaction data, log data, crash reports

Payment Information

Billing details are processed by our third-party payment processor. We do not store full payment card numbers.

Trial Access Requests

If you request trial access through our website, we collect your name, email address, company name, industry, and — if you choose to share them — your number of locations, team size, and any notes you provide. We also record how you found us (for example, a campaign link or referring website). We use this information only to evaluate and respond to your request for access to the Service; it is not added to a marketing list.

3.How We Use Information

We use collected information to:

  • Provide, operate, and maintain the Service (scheduling, shift management, clock-in/out, notifications)
  • Authenticate users and secure accounts, including biometric login where enabled
  • Communicate with you about your account, updates, and support requests
  • Improve and develop new features, including the AI Store Manager scheduling tool
  • Comply with legal obligations
  • Detect and prevent fraud, abuse, or security incidents

4.How We Share Information

We do not sell personal information. We may share information with:

  • Your Employer — Employee data (shifts, clock-in/out, time-off requests) is visible to the Employer that added you to the Service.
  • Service Providers — third parties who help us operate the Service (hosting, analytics, payment processing, customer support), bound by confidentiality and data protection obligations.
  • Legal Requirements — where required by law, subpoena, or to protect rights, safety, or property.
  • Business Transfers — in connection with a merger, acquisition, or sale of assets, subject to standard confidentiality protections.

5.Data Retention

We keep personal information only as long as needed to provide the Service, meet legal obligations, resolve disputes, and enforce our agreements. The periods below are the longest we keep each type of data; we may delete it sooner when it is no longer needed.

  • Active accounts. Account, profile, location, schedule, and settings data are kept while the Employer's subscription is active.
  • Time and payroll records. Shifts, clock-in/clock-out events, and closed pay-period summaries are kept for 3 years from the date of the record, then deleted.
  • Quick notes and photos. Notes, replies, reactions, and attached photos are kept for 12 months from when they were posted, then permanently deleted. A note or reply that is deleted in the app is permanently removed within 30 days. Photo uploads that are never attached to a note are removed within 7 days.
  • Notifications and technical records. In-app notifications are kept for up to 180 days. Sign-in sessions, one-time verification codes, invitation links, and device push tokens are deleted within 90 days after they expire or are revoked; a device push token that has not been used for a year is also deleted.
  • Closed accounts. When an Employer's subscription is canceled or its trial ends without a paid subscription, the account is closed. For 30 days after closure the Employer may request an export of its organization's data (see our Terms of Service). Organization data, including Employee profiles that are not part of another active Employer's account, is permanently deleted within 90 days after closure. Copies in our backups are overwritten within a further 35 days.
  • Records we keep for legal reasons. Records of SMS consent and opt-outs, Terms acceptances, and payment authorizations are kept for up to 5 years after the account closes, even after other data is deleted, so we can meet our legal obligations and resolve disputes.
  • Location. We never store your raw GPS coordinates. For geofenced clock-ins we keep only whether the punch was inside the allowed area, the distance from the location, and the reported accuracy, as part of the time record above.
  • Trial access requests. Requests that are declined or identified as spam are deleted within 12 months; requests that lead to an invitation are kept alongside that invitation. You can ask us to delete a trial access request at any time by writing to [email protected].

Employers may request deletion of their organization's data at any time. Employees may request deletion by contacting their Employer or us directly at [email protected]. We may keep data longer than stated above where the law requires it or to respond to a pending legal claim.

6.Your Rights

Depending on your location, you may have rights to:

  • Access, correct, or delete your personal information
  • Object to or restrict certain processing
  • Data portability
  • Withdraw consent for biometric data collection (where applicable)
  • Lodge a complaint with a supervisory authority (EU/UK users)

To exercise these rights, contact [email protected]. We will respond consistent with applicable law (e.g., GDPR, CCPA/CPRA, and state biometric privacy statutes).

7.International Data Transfers

If you access the Service from outside the United States, your information may be transferred to and processed in the United States. We take steps to ensure appropriate safeguards are in place for such transfers where required by law.

8.Data Security

We use commercially reasonable administrative, technical, and physical safeguards designed to protect personal information. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

9.Children's Privacy

The Service is not directed to individuals under 16. We do not knowingly collect personal information from children.

10.Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via a notice within the Service. Continued use of the Service after changes take effect constitutes acceptance.

11.Contact Us

Saachi LLC

[email protected]