1. Who we are and our role regarding information
The service and the website are operated by RayClock Ltd., company number 517398269, of 140 Derech Akko, Kiryat Bialik, Israel ("RayClock" or "we"). RayClock operates an attendance and human resources management system for employers. It is important to distinguish between two types of information:
- Information about the customer's employees — attendance data, absences, documents and forms. The employer owns this information and decides what is collected and why. We hold and process it on the employer's behalf only, under our agreement with it, and do not use it for purposes of our own.
- Information collected on this website — details you choose to leave in the contact and signup forms. Here we are the owner of the information.
2. What information is collected
In forms on the website: name, email address, phone number, company name, and the content of the message you wrote.
When signing up for a trial: in addition to the above — the company name, and the company number if you chose to provide it.
When using the system: login and activity data needed for security and operation, as well as information the employer enters or that is created by employees' use of the system — attendance clock-ins, location at the time of clocking in when the employer has enabled location checks, absence requests, signed documents and forms.
We do not collect sensitive information beyond what is needed to operate the service, and we do not sell information to third parties.
3. What the information is used for
- Providing the service and operating the system.
- Responding to inquiries and quote requests.
- Securing the system, preventing misuse and logging actions.
- Meeting legal obligations that apply to us or to the employer.
We will not send you marketing emails without your consent, and any such email will include an option to unsubscribe.
4. Signing in with Google or Microsoft
On the system website (app.rayclock.co.il) and in the RayClock apps for iPhone and Android, you can sign in with a Google account or a Microsoft account instead of a password.
What information we receive: when you sign in, Google or Microsoft sends us an identity token that includes the account's email address, and also the name and profile picture, if they exist. We do not request access to your mailbox, calendar, contacts, files or any other information in the account.
What it is used for: the email address is used solely to verify your identity and connect you to the RayClock account your employer has already opened for you. Such a sign-in does not create a new account: if there is no account in the system with the same email address, the sign-in is rejected.
What is stored: we do not store the identity token, the name or the profile picture received from Google or Microsoft. Only the time of the sign-in is recorded, together with the fact that the email address was verified.
Sharing: we do not sell, share or transfer to third parties information received from Google or Microsoft, and we do not use it for advertising or for training artificial intelligence models. Our use of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.
Revoking access: you can disconnect RayClock from your Google account at any time through your Google account settings, and from your Microsoft account through Microsoft permissions management (for a work account, through your organization's system administrator). After disconnecting, you can still sign in to your RayClock account with email and password, and anyone who has not set a password can create one through "Forgot password".
5. Connecting AI assistants (ChatGPT, Claude)
A RayClock user can connect RayClock to an AI assistant they use, such as OpenAI's ChatGPT or Anthropic's Claude, through the MCP protocol. No connection exists by default: one is created only when the user explicitly approves it on RayClock's connection screen. By default, only an admin at the employer can create a connection. The admin can also allow managers, employees or both to create connections (two separate settings, off by default), and turning a setting off stops that group's connections immediately.
What information is passed on: when a user asks the assistant a question, the assistant requests the data it needs from RayClock, and we send it only that, and only within that user's permissions. An admin's assistant may receive: attendance status and clock-in and clock-out times, basic employee details (name, employee number, email, phone, role, department and start date), absences (type, dates, status and note), and profile change requests (who asked, which field and the status), and monthly hour summaries (hours worked, expected hours, shortage and overtime) and month-end status, as well as the shift schedule in companies that use shift management.
Managers' and employees' assistants: a manager's assistant receives only information about the departments that manager manages, and acts only within their permissions in RayClock. An employee's assistant receives only that employee's own information — their punches, their monthly hours and days, their leave balances and absences — and never information about other employees.
Actions and reports: on the connection screen the user chooses whether the connection is read-only or also allows changes. With a connection that allows changes, the assistant can act on the user's behalf in ways the system allows them — for example adding punches and correcting the time of an existing punch, approving or rejecting requests, recording absences, locking a month, adding and updating employees, scheduling shifts and sending announcements to employees for an admin, or requesting an absence for an employee — only after the user confirms, and under the same rules that apply in the system. Every action is recorded in the activity log and the attendance change log, marked as made by the assistant. The assistant cannot delete punches, reopen a locked month, or change an employee's role, email or pay. Reports produced through the assistant are downloaded directly to the user's browser through a one-time link, and their contents are not passed to the assistant.
What is never passed on: ID numbers, bank account details, salary and employer cost, the values requested in profile change requests, documents and Form 101.
At the assistant's provider: information sent to the assistant is processed by its provider (for example OpenAI or Anthropic) under the account of the employer or of the user who connected the assistant, and under that provider's terms and privacy policy. The decision to allow assistant connections, the choice of provider and the account settings there are the employer's, as the owner of the information. We do not use this information to train models.
What we keep: the connection details (who approved it, when, for which assistant and when it was last used), access tokens in hashed form only, and an activity-log entry for each request the assistant makes. We do not keep the conversation with the assistant.
Disconnecting: every user can see and disconnect their own connections at any time, and any admin at the employer can disconnect any connection on the "AI assistants" screen. Disconnecting takes effect immediately. A connection also stops when the admin turns off assistant connections for managers or employees, if the user who approved it no longer has a role allowed to connect or is deactivated, or if the employer's account is closed or suspended.
6. Where the information is stored
The information is stored on an external provider’s cloud infrastructure, within the European Union. Information is transferred over encrypted connections.
7. Disclosure to third parties
We disclose information only when this is required to provide the service or by law:
- Cloud infrastructure and hosting providers.
- An email service provider, for sending system messages.
- An approved provider for signing Form 101, when the customer has chosen to use this feature — and only for the information required for that submission.
- A competent authority, when there is a legal obligation to disclose.
8. Retention and deletion
Information about a customer's employees is kept for as long as the agreement with the employer is in force, and afterwards for the period the employer is required to keep it by law. Requests to delete an employee's information should be directed to the employer, who owns the information. Information submitted through the website forms is kept for as long as it is needed to handle the inquiry.
9. Your rights
Under the Protection of Privacy Law, 5741-1981, you may review the information kept about you, request that it be corrected if it is not accurate, complete or up to date, and request its deletion, subject to retention obligations that apply to us. For requests on this matter: privacy@rayclock.co.il.
10. Cookies and usage measurement
The marketing website uses Google Analytics for statistical measurement of website usage — how many visitors come in, to which pages and from which sources. The tool uses Google cookies, and the data collected is statistical and is not used by us to personally identify visitors. You can block these cookies in your browser settings or with the Google Analytics opt-out browser add-on. The website does not use third-party advertising tools or marketing networks. The system itself uses local browser storage only to keep you signed in and to save display preferences.
11. Information security
We take accepted security measures, including encryption in transit, separation between the data of different companies, role-based permissions and logging of actions in an activity log. No system is completely immune, and we work to improve continuously.
12. Changes to this policy
We will update this policy from time to time. The date of the latest update appears at the top of the page, and material changes will be brought to customers' attention.
13. Contact
For privacy questions: privacy@rayclock.co.il or info@rayclock.co.il.