Privacy policy

Last updated: September 29, 2026

dastur.io is a time clock: employees clock in and out on their own phones, and the app checks that they are at their workplace when they do. This policy explains what data that involves, what we do with it, and the choices you have.

Who we are

dastur.io is operated by SANAM APP LLC ("we"). For any question about your data, write to support@dastur.io.

Companies use dastur to record their employees’ working time. For the data about their employees (names, phone numbers, clock-ins, locations), the employer decides what is collected and why: the employer is responsible for that data, and we process it on their behalf and on their instructions. For admin accounts, messages sent through our contact form, and visits to our website, we are responsible.

What we collect

  • Admin accounts: your name, work email, company name and job title, the time zone of your browser, and your password (stored only as a secure hash by our sign-in provider). If you sign in with Google or Microsoft, we receive your name, email address and the basic profile details that service shares; we never see your Google or Microsoft password.
  • Employees (entered by their employer): name, phone number, role, assigned workplace and weekly schedule.
  • Clock-ins and clock-outs: the time, the phone’s GPS position and its accuracy at that moment, the distance from the workplace, and whether the punch was on time, late or early. When an admin corrects a record, we keep the change, the reason given and who made it.
  • Paired phones: a random code saved on the employee’s phone so it is recognised next time (we keep only a scrambled version of it), the phone’s browser type, and where the phone was when it was paired.
  • Workplaces: names, addresses, map positions and the size of the check-in zone.
  • Contact form: your name, email, company (optional), your message and the language you were browsing in.
  • Technical data: our hosting and database providers keep standard server logs, including IP addresses, for security and troubleshooting.

We don’t use analytics, advertising or tracking tools, and we don’t sell data.

Location data

dastur reads a phone’s location only at the moment someone clocks in, clocks out or pairs the phone, and only while the dastur page is open. It does not track anyone in between, in the background, or outside working time.

The precise coordinates are kept for 90 days, long enough to settle a disputed punch, and are then erased automatically. What payroll needs stays: the times, the distance from the workplace, the status and any corrections.

How we use it

  • to run the service: recording working time, checking that clock-ins happen at the workplace, and showing employers their reports;
  • to create and secure accounts, sign you in, and send account emails such as confirmations and password resets;
  • to answer messages sent through our contact form;
  • to keep the service secure and working, and to prevent abuse.

We use data about employees only to provide the service to their employer, not for our own purposes. We rely on our contract with the employer, our legitimate interest in running a secure service, and, where needed, legal obligations. Employers are responsible for having a lawful basis for recording their employees’ working time and for informing them.

Services we rely on

We share data only with the providers that run parts of dastur for us, and only what each one needs:

  • Supabase: database and sign-in.
  • Railway: hosting of the website and app.
  • Google and Microsoft: only if you choose to sign in with them.
  • OpenStreetMap: map images in the admin area. Your browser loads them directly, which shares your IP address with the map server.
  • Photon (Komoot): address search when an admin adds a workplace. The search text and your IP address go to that service.
  • Our email provider: to deliver account emails.

Some of these providers store or process data outside Georgia. We may also disclose data when the law requires it.

How long we keep it

  • Precise clock-in, clock-out and pairing locations: 90 days.
  • Phones that were unpaired: deleted 90 days later.
  • One-time pairing PINs: deleted a day after they expire or are used.
  • Admin invitations: deleted 30 days after they are used or expire.
  • Time records, employees and workplaces: for as long as the employer’s account is open, or until the employer deletes them.
  • Contact form messages: for as long as we need them to handle your request.

When an employer closes their account, we delete their company’s data.

Cookies and storage on your device

dastur only uses what it needs to work:

  • sign-in cookies that keep admins logged in;
  • a cookie that remembers the language you chose;
  • on an employee’s phone, the pairing code kept in the browser’s storage, and saved app files so the time clock opens quickly.

There are no advertising or tracking cookies, so we don’t ask for cookie consent.

Security

All connections are encrypted (HTTPS). Passwords, pairing PINs and phone codes are stored only in scrambled (hashed) form. Each company can see only its own data, and this is enforced by the database itself, not just the app.

Your rights

You can ask to see the data we hold about you, to correct it, to delete it, or to object to how it is used. Write to support@dastur.io.

If you are an employee, your employer controls your data in dastur, so please ask them first; we will help them answer you. If you are unhappy with how your data is handled, you can complain to the Personal Data Protection Service of Georgia.

Children

dastur is a service for businesses and is not meant for children.

Changes to this policy

When we change this policy, we update the date at the top. If a change is significant, we tell admins by email before it takes effect.