Privacy Policy
Last Updated: January 27, 2026
1. Introduction
Welcome to Peoplora. We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Human Resource Management System (HRMS) platform and services ("Services").
Peoplora is a Software-as-a-Service (SaaS) platform designed to help organizations manage their human resources operations, including employee lifecycle management, attendance tracking, payroll processing, performance management, and AI-powered insights.
2. Information We Collect
2.1 Information You Provide
When you use Peoplora, we collect:
- Account Information: Company name, email address, password, phone number, and billing address when you register for an account
- Employee Data: Information about your employees including names, contact details, job titles, department, employment status, attendance records, leave requests, performance reviews, payroll information, and any other HR-related data you choose to input
- User Communications: Messages, support tickets, and feedback you send through our platform
- Payment Information: Billing details and payment information processed through our secure payment processor (Stripe). We do not store complete credit card numbers on our servers
- Documents and Files: Any documents, images, or files you upload to the platform including employee documents, contracts, policies, and knowledge base materials
2.2 Information Collected Automatically
- Usage Data: Information about how you interact with our Services, including features accessed, pages viewed, time spent on pages, and click data
- Device Information: IP address, browser type, operating system, device type, and unique device identifiers
- Location Data: General location information derived from IP addresses for security and service optimization
- Precise Geolocation Data: With your explicit consent, we collect precise GPS-based location data through our mobile application and web app for features including attendance clock-in/clock-out verification, remote work location tracking, and geofence-based presence confirmation. This data includes latitude, longitude, and timestamp information
- Cookies and Tracking: We use cookies and similar technologies to maintain sessions, remember preferences, and analyze usage patterns
- Log Data: Server logs containing access times, error messages, and system activity for security and troubleshooting
2.3 Information from Third Parties
- Authentication Services: We use Stytch for authentication. When you sign in, we receive basic profile information
- Payment Processors: Stripe processes payments on our behalf and shares transaction status and billing information with us
- AI Services: Our AI-powered features use OpenAI for processing queries, which may involve sharing relevant data to provide intelligent responses
3. How We Use Your Information
We use collected information to:
- Provide Services: Operate and maintain the Peoplora platform, process transactions, and deliver requested features
- Account Management: Create and manage your account, authenticate users, and manage subscriptions
- Communication: Send service-related notifications, updates, security alerts, and respond to your inquiries
- Improve Services: Analyze usage patterns, conduct research, and develop new features and enhancements
- Security: Detect, prevent, and address technical issues, fraud, and security threats
- Compliance: Comply with legal obligations and enforce our terms of service
- AI Features: Process and analyze data to provide AI-powered insights, recommendations, and automated responses through our knowledge base and support systems
- Analytics: Monitor usage metrics, generate reports, and improve platform performance
- Marketing: Send promotional communications about new features, updates, and offers (with your consent)
- Geolocation Services: Verify employee attendance clock-in/clock-out locations, enable geofence-based presence tracking, support remote work location verification, and provide location-aware HR features as configured by your organization
4. Data Sharing and Disclosure
4.1 Service Providers
We share information with trusted third-party service providers who assist us in operating our platform:
- Stytch: Authentication and identity management
- Stripe: Payment processing and subscription management
- OpenAI: AI-powered features including document Q&A and automated responses
- Cloud Hosting: Infrastructure providers for secure data storage and processing
- Email Services: Transactional and notification email delivery
- Analytics: Usage analytics and performance monitoring
These service providers are bound by confidentiality agreements and are only permitted to use your information to provide services to us.
4.2 Within Your Organization
In our multi-tenant architecture, data is strictly isolated by company. Employee data is accessible to authorized users within your organization based on role-based access controls:
- Company Administrators: Full access to all company data
- HR Administrators: Access to HR-related data and employee information
- Employees: Access to their own data and limited company information
4.3 Legal Requirements
We may disclose your information if required by law or in response to:
- Legal process or government requests
- Protection of rights, property, or safety of Peoplora, our users, or the public
- Detection and prevention of fraud, security issues, or technical problems
- Enforcement of our Terms of Service
4.4 Business Transfers
If Peoplora is involved in a merger, acquisition, or sale of assets, your information may be transferred. We will notify you via email and/or prominent notice on our platform before your information becomes subject to a different privacy policy.
5. Data Security
We implement industry-standard security measures to protect your information:
- Encryption: Data in transit is encrypted using TLS/SSL. Sensitive data at rest is encrypted using AES-256
- Access Controls: Role-based access control (RBAC) ensures users only access data they're authorized to view
- Authentication: Multi-factor authentication available for all accounts. Passwords are hashed using bcrypt
- Network Security: Firewalls, intrusion detection, and DDoS protection
- Regular Audits: Security assessments, penetration testing, and vulnerability scanning
- Data Isolation: Multi-tenant architecture with strict data segregation between companies
- Monitoring: 24/7 system monitoring and logging for security incidents
- Backup: Regular automated backups with secure storage and disaster recovery procedures
While we strive to protect your information, no security system is impenetrable. We cannot guarantee absolute security of your data.
6. Data Retention
We retain your information for as long as necessary to provide Services and fulfill the purposes outlined in this Privacy Policy:
- Active Accounts: Data is retained while your account is active
- Account Deletion: After account deletion, most data is permanently deleted within 90 days
- Legal Obligations: Some data may be retained longer to comply with legal, tax, or accounting requirements
- Backup Systems: Deleted data may persist in backups for up to 180 days before permanent deletion
- Aggregated Data: De-identified and aggregated data may be retained indefinitely for analytics and service improvement
7. Your Rights and Choices
Depending on your location, you may have the following rights:
7.1 Access and Portability
You can access, review, and export your personal information through your account settings or by contacting us.
7.2 Correction and Update
You can update your account information and employee data directly through the platform.
7.3 Deletion
You can request deletion of your account and associated data. Please note that some information may be retained for legal compliance.
7.4 Opt-Out of Marketing
You can opt out of marketing communications by clicking "unsubscribe" in emails or updating your notification preferences.
7.5 Cookie Preferences
You can control cookies through your browser settings. Note that disabling cookies may affect platform functionality.
7.6 Geolocation Controls
You can control geolocation data collection through:
- Your device's location settings (disable location services for the Peoplora app)
- Browser permissions (deny location access for the web app)
- In-app settings to manage location sharing preferences
Note: Disabling geolocation may limit certain features like attendance verification and geofence-based clock-in/clock-out functionality. Your organization's policies may require location data for specific HR functions.
7.7 Data Processing Objection
You may object to certain data processing activities. We will evaluate such requests based on legal grounds.
To exercise these rights, contact us at privacy@peoplora.com. We will respond within 30 days.
8. International Data Transfers
Peoplora is operated by Automate Control Mondial Inc., a company based in Canada. Your information may be transferred to and processed in countries other than your own, including Canada and the United States. These countries may have different data protection laws.
When we transfer data internationally, we implement appropriate safeguards, including:
- Standard Contractual Clauses approved by the EU Commission
- Data Processing Agreements with third-party processors
- Adherence to recognized data protection frameworks
- Technical and organizational security measures
9. Geolocation Data
Peoplora collects precise geolocation data through our mobile application and web app to provide location-based HR features. This section explains how we handle your location information.
9.1 What Geolocation Data We Collect
- GPS Coordinates: Precise latitude and longitude when you clock in/out or use location-based features
- Timestamp: Date and time associated with location data points
- Location Accuracy: Information about the precision of collected location data
- Device Location Settings: Whether location services are enabled on your device
9.2 How We Use Geolocation Data
- Attendance Verification: Verify employee presence at designated work locations during clock-in/clock-out
- Geofence Monitoring: Enable automatic presence detection when employees enter or exit defined geographic areas
- Remote Work Tracking: Support organizations in verifying remote work locations as configured by your employer
- Compliance: Help organizations meet regulatory requirements for workforce location tracking
9.3 Consent and Control
Explicit Consent Required: We only collect precise geolocation data with your explicit permission. You will be prompted to grant location access the first time you use location-based features.
Organizational Settings: Your employer configures which location features are enabled. Some organizations may require location data for specific functions like attendance tracking.
Background Location: The mobile app may request background location access for geofence features. You can control this through your device settings at any time.
9.4 Data Retention for Geolocation
Geolocation data is retained according to your organization's data retention policies and applicable labor laws. Typically:
- Attendance location data is retained for the duration required by your organization's HR policies
- Real-time location data is not stored beyond what is necessary for the immediate function
- Historical location records may be retained for compliance and audit purposes
9.5 Third-Party Access
Your geolocation data is only accessible to authorized users within your organization (such as HR administrators and managers) based on role-based permissions. We do not sell or share your location data with third parties for advertising or marketing purposes.
10. Children's Privacy
Peoplora is designed for business use and is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If we become aware that we have collected information from a child under 18, we will take steps to delete it promptly.
11. Third-Party Links and Services
Our Services may contain links to third-party websites or integrations. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies.
12. California Privacy Rights (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
- Right to know what personal information is collected
- Right to know if personal information is sold or disclosed
- Right to opt-out of the sale of personal information
- Right to request deletion of personal information
- Right to non-discrimination for exercising CCPA rights
Note: Peoplora does not sell personal information to third parties.
13. GDPR Compliance (European Users)
If you are in the European Economic Area (EEA), United Kingdom, or Switzerland, you have rights under the General Data Protection Regulation (GDPR):
- Legal Basis for Processing: We process data based on contract performance, legitimate interests, legal obligations, and consent
- Data Controller: Your organization is the data controller for employee data; Peoplora acts as a data processor
- Data Protection Officer: Contact our DPO at dpo@peoplora.com
- Supervisory Authority: You have the right to lodge a complaint with your local data protection authority
14. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our practices or legal requirements. We will notify you of material changes by:
- Posting the updated policy with a new "Last Updated" date
- Sending email notification to your registered email address
- Displaying a prominent notice on our platform
Continued use of our Services after changes become effective constitutes acceptance of the updated Privacy Policy.
15. Security & Trust
For how we host Peoplora, protect data in transit and at rest, control access, work with vendors, and our roadmap for formal certifications, see our dedicated overview.
Written for security, IT, and procurement teams—plain language, no certifications we have not earned.
16. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Peoplora
A product of Automate Control Mondial Inc.
- Email:
- privacy@peoplora.com
- Support:
- support@peoplora.com
- Data Protection Officer:
- dpo@peoplora.com
We will respond to your inquiry within 30 days or as required by applicable law.
Acknowledgment
By using Peoplora, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with this Privacy Policy, please do not use our Services.