FirmClock Privacy Notice

Founder-approved publication candidate. Counsel review remains pending.

Proposed publication URL: https://www.firmclock.com/legal/privacy

Effective date: September 24, 2026

This Privacy Notice explains how FIRMCLOCK LLC, a New Jersey limited liability company (“FirmClock,” “we,” “us,” or “our”), collects, uses, discloses, retains, and otherwise handles personal information through the FirmClock website, accounts, workspaces, support communications, and related services (collectively, the “Service”).

FirmClock provides timekeeping, team invitations, CSV imports, workspace setup, review, reporting, accounting exports, and workspace portability tools. FirmClock may also offer migration assistance requested and authorized by Customer after its secure transfer and operational controls are activated. A Customer that controls a FirmClock workspace decides who may use it and what information its users enter or transfer. Depending on the Customer, workspace information may include employee or contractor information, client names, engagement or matter labels, time descriptions, import records, and migration source information.

1. Scope and our role

This Notice covers personal information FirmClock handles for account administration, security, future billing, support, and operation of the Service. It also describes how FirmClock handles personal information entered into a workspace on behalf of the Customer that controls that workspace.

For most personal information in a workspace (“Workspace Data”), the Customer determines why and how the information is used and FirmClock processes it to provide the Service under the Customer’s instructions. The Customer generally acts as the controller or business and FirmClock acts as its processor or service provider. A request about Workspace Data may therefore need to be directed to the Customer.

FirmClock separately determines how it handles information for account administration, security, legal compliance, support, communications, and, if activated, billing. This Notice does not apply to a Customer’s practices outside the Service or to a third-party website or service with its own privacy notice.

The current beta is free. Public self-service registration, checkout, billing, and live charges remain disabled until separately activated. Existing beta workspaces will not be charged unless an owner affirmatively starts a paid checkout and consents to the displayed paid terms.

2. Personal information we collect

The FirmClock application does not itself persist IP addresses or browser or device details. Depending on the hosting and network configuration that is activated, service providers may process connection information such as IP address, browser or device details, and request logs. FirmClock will keep this Notice accurate as that configuration changes.

If Stripe-hosted checkout and billing are activated and FirmClock requires a payment method, Stripe will collect and process payment-card information on its hosted surface. FirmClock may receive subscription and payment-provider identifiers, whether a payment method is on file, and transaction status. The FirmClock application will not receive or store card data or invoice details. Do not send passwords, recovery links, payment-card numbers, or full workspace exports in a support or privacy request.

The current self-service CSV import processes an uploaded file to validate and normalize it but does not retain the raw CSV. It retains normalized preview rows, mappings, validation issues, hashes, and import receipts as needed to complete the import, prevent duplicates, and preserve audit evidence. Concierge migration file transfer, scanning, operator transport, importer execution, and deletion execution remain inactive until their provider and operational controls are separately verified and activated.

3. How we use personal information

We use personal information to:

FirmClock does not sell personal information, share it for cross-context behavioral advertising, use it for targeted advertising, or use Workspace Data to train artificial-intelligence models. FirmClock does not profile individuals to make decisions that produce legal or similarly significant effects.

4. Workspace access and professional information

Users may access Workspace Data according to Customer membership and role. Current roles include owner, administrator, reviewer, employee, and read-only roles with different permissions. Owners and administrators can manage portions of the workspace, reviewers can review team time, employees can use their own time workflows, and read-only users have limited reporting access. The Service enforces the permissions applicable to each role.

Customer controls its workspace and is responsible for managing membership, assigning roles, reviewing access, and deciding what information its users enter. If an employer, firm, or other organization provides your account, that organization may administer it and, according to role, access, correct, and export Workspace Data using available features.

The current product does not provide an in-product workspace-deletion or closure control. A workspace owner may request closure by emailing [email protected] from the owner’s account email. FirmClock will verify identity and owner authority before acting.

Client and matter information can be especially sensitive. A law firm may enter information that it considers confidential or legally privileged. FirmClock provides technical processing and does not determine whether a record is protected by attorney-client privilege, work-product protection, professional secrecy, or another legal rule. This Notice does not promise that using FirmClock creates, preserves, or waives any privilege. Customer must decide whether the Service is appropriate for the information it submits and whether additional contractual, ethical, or technical safeguards are required.

5. When we disclose personal information

We may disclose personal information to the following categories of recipients for the stated purposes:

Service providers may process information only for the services FirmClock asks them to perform or as otherwise permitted by contract and law. FirmClock will not authorize them to use Workspace Data for targeted advertising or artificial-intelligence model training.

6. Cookies and similar technologies

The current Service uses cookies necessary for authentication and security, including an HTTP-only session cookie and a cookie used to help prevent cross-site request forgery. These cookies support sign-in, maintain a secure session, and help verify that state-changing requests came from the Service.

The current application does not use advertising cookies, advertising trackers, or product analytics. We will update this Notice and provide any legally required choice before using nonessential analytics or advertising technology.

Browser settings may allow you to block cookies, but blocking necessary cookies can prevent sign-in or other Service functions.

7. Retention, closure, and deletion

We retain personal information only for as long as reasonably necessary for the purposes described in this Notice, subject to the following policy:

A legal hold, dispute, security investigation, or legal obligation may require longer retention. When that happens, FirmClock will limit the retained information and use it only for the applicable purpose. When retention ends, FirmClock will delete or de-identify the information using its approved process.

For 30 days after a verified workspace closure, the owner may request an export or ask FirmClock to reverse the closure if deletion has not begun. Customer remains responsible for exporting records it must retain for employment, payroll, tax, client, matter, ethical, or professional purposes.

8. Support and operational access

FirmClock does not provide a support-impersonation feature. Operational access to Workspace Data is permitted only for documented support requested by Customer, maintenance necessary to provide the Service, security or abuse investigation, an emergency threatening the Service or its users, or legal compliance.

Customer approval is required for routine support access when reasonably practicable. Emergency, security, abuse, and legally compelled access may occur without prior approval when delay could cause harm or violate law. Access must be approved for a specific purpose, limited to authorized personnel and the minimum necessary information, expire when the task is complete and no later than 24 hours unless reapproved, and be logged. Security personnel must review emergency access after the event and review operational access records at least monthly.

If concierge migration is activated, an operator may access a migration case only after the workspace owner gives the required case consent and the operator receives an exact firm-scoped assignment. The current candidate limits an assignment to eight hours, requires a separate operator for final execution, and does not permit operators to impersonate Customer users or browse other workspaces. These controls require hosted verification before the feature handles Customer files.

9. Privacy rights and choices

Depending on where you live and the law that applies, you may have rights to:

FirmClock does not sell personal information, use it for targeted advertising, or conduct profiling that produces legal or similarly significant effects. Accordingly, FirmClock does not currently offer a separate opt-out control for those activities.

To submit a request or appeal, email [email protected]. You do not need to create a new account to make a request, but we may require use of an existing account or other information reasonably needed to verify identity and authority. An authorized agent may submit a request where applicable law permits, subject to verification of the agent’s authority.

We will respond to a verified request within 45 days. We may extend that period once by up to 45 additional days when reasonably necessary and will explain the extension during the initial period. If we deny a request, we will explain why and how to appeal. We will respond to an appeal in writing within 45 days. If an appeal is denied and applicable law requires it, we will explain how to contact the appropriate regulator. Requests are free at least once in any 12-month period; we may charge a reasonable fee or decline manifestly unfounded, excessive, or repetitive requests where applicable law permits.

If a request concerns Workspace Data controlled by a Customer, we may direct the requester to that Customer or work with the Customer to respond. Rights are subject to applicable exceptions, including legal retention duties, security needs, the rights of others, and information FirmClock processes solely on a Customer’s instructions.

Do not include credentials, verification or recovery links, payment-card numbers, or full exports in a privacy request.

10. Security

FirmClock uses measures designed to protect personal information, including account verification, authentication and session controls, role-based authorization, workspace separation, audit records, restricted exports, and safeguards for the systems used to provide the Service. We review and adjust safeguards as the Service changes.

If FirmClock determines that a security incident involving personal information requires notice, FirmClock will provide notice as required by applicable law.

No internet service can guarantee absolute security. FirmClock does not promise client-side encryption, end-to-end encryption, zero-knowledge storage, or a particular compliance certification. Customers should use available access controls, promptly remove access that is no longer needed, and avoid entering information unnecessary for timekeeping and related workflows.

11. Processing location

FirmClock offers the Service only to users in the United States. Personal information may be processed in the United States and in other jurisdictions where an activated service provider operates or provides support. Privacy protections and government-access rules may differ by location.

12. Children

The Service is for people age 18 or older and is not directed to children. FirmClock does not knowingly collect personal information directly from anyone under 18. If we learn that a person under 18 created an account, we will close the account and address the associated information under this Notice.

13. Changes to this Notice

We may update this Notice to reflect changes in the Service, our practices, or legal requirements. We will post the updated Notice with a new effective date. We will provide at least 30 days’ advance notice of a material change by email, through the Service, or by another reasonable method, except when a shorter period is required by law or reasonably necessary for urgent security reasons.

14. Contact us

FIRMCLOCK LLC
1600 NJ-70
Lakewood, NJ 08701
United States

Privacy requests and appeals: [email protected]
Legal notices: [email protected]