Back
NuvoWork
Privacy & Security

Privacy-first workforce management.

NuvoWork was built to help businesses manage their teams without sacrificing employee privacy. We do not sell user data. We do not use workforce information for advertising. Workforce data belongs to the company and its employees — and we believe both deserve transparency and control.

This page is maintained by the NuvoWork team to answer common security and privacy questions in plain language. It describes the controls the product actually has — it is not an independent audit or certification.

Secure password encryption

Passwords are stored as one-way cryptographic hashes. They are never viewable — not by NuvoWork, not by your admin, not by developers, and not through database queries.

Encrypted connections (HTTPS)

All traffic between your device and NuvoWork is encrypted in transit using industry-standard TLS. Sensitive information is never transmitted over unsecured connections.

Company data isolation

Every request is checked against your company, your authenticated user, and your role. No employee or admin can access another company's employees, messages, calendar, hours, work categories, or settings — even through direct URLs or manipulated requests.

Role-based permissions

Employees see only their own hours, and pay rates are restricted at the database level so coworkers cannot read each other's compensation. Company Admins manage only their own company. NuvoWork platform administrator access is limited to authorized support and security personnel, and is used only for account administration, support, and troubleshooting — never to browse business data casually.

No selling, no ads, no tracking

NuvoWork does not sell or share personal information, does not run advertising, and does not use third-party analytics or tracking cookies. There is no Google Analytics, no ad pixels, and no cross-site tracking. The only browser storage we use keeps you signed in and remembers your location preference.

Location verification, not surveillance

GPS is used only to verify where clock-ins and clock-outs happen, and only while an employee is on the clock with the app open. It is never used for off-duty tracking: no background tracking, no location after clock-out, and nothing recorded on days off. Only authorized company admins can view it — and if your employer changes the GPS policy, every employee is notified inside the app.

Security audit logs

Administrative actions — invitations, role changes, hour adjustments, company settings changes, deletions — are recorded to an append-only audit log that no one can edit or remove. Settings changes record who made the change, the field, the previous value, and the new value.

Regular platform updates

NuvoWork is updated regularly with security improvements, dependency patches, and hardened defaults so your data stays protected as the security landscape evolves.

Privacy first

NuvoWork is designed to help businesses run efficiently while respecting the people who use it. We prioritize:

  • We never sell or share your personal information — no advertising, no data brokers, no cross-context behavioral advertising
  • No analytics or tracking cookies — we do not follow you around the web or profile your usage
  • GPS is never used for off-duty tracking — location is captured only during an active shift, in the foreground
  • Data privacy for both companies and their employees
  • Business confidentiality between organizations
  • Secure access controls at every layer of the app
  • Responsible handling of customer information

How GPS verification works

Location is only collected when required for clock-in or clock-out verification. NuvoWork does not track anyone's location when they are off the clock.

  • Off by default — a company admin must enable GPS verification, and each employee sees a clear Active / Inactive status in their own settings.
  • Only at approved moments — a clock-in, a clock-out, or, if a company explicitly enables route verification, occasional checkpoints during an active shift.
  • Foreground only — nothing is collected while the app is closed or in the background, after clock-out, or on days off. There is no background location service.
  • Limited visibility — an employee always sees their own records; only admins at that same company can view their team's.

Role-based access

  • Employee — their own hours, timesheets, time-off balances, profile and personal settings.
  • Manager (planned) — team-level visibility and approvals, without company billing or settings access.
  • Owner / Admin — their own company's team, hours, payroll, settings and billing. Never another company's.

Roles are stored and enforced on the server, not in the browser, so they cannot be changed by editing the app on a device.

Third-party services we use

We keep this list short on purpose. Each service below is used to operate the product — none of them receive data for advertising, profiling, or resale.

  • Cloud hosting & database — runs the application and stores your company's data.
  • Transactional email — sends invitations, password resets and account notices. No marketing lists.
  • Stripe — processes subscription payments. Card details go directly to Stripe; NuvoWork never sees or stores them.
  • Map address lookup — when GPS verification is on, coordinates are converted into a readable street address for the clock record.
  • Push delivery — if you opt in on your phone, notifications are delivered through your browser's push service.

There is no advertising network, no data broker, and no third-party analytics or tracking SDK in NuvoWork. Product usage information we keep is limited to what is needed to operate and support the app.

See the full subprocessor list — purpose, data shared and reason →

Honest limits

No online service can promise perfect security. NuvoWork does not currently hold SOC 2, ISO 27001, HIPAA, or PCI certification, and this page is not an independent audit or certification — it is a plain-language description of the controls we actually have in place. What we can commit to is transparent, professional handling of your data, continuous investment in security, and clear communication if something ever goes wrong.

Things we do not offer yet, so you are not surprised: two-factor authentication, remote sign-out of other devices, customer-managed encryption keys, and a formal bug-bounty program. Company audit log viewing is available on the Pro plan.

Trust Center·Privacy Policy·Subprocessors·Terms·About NuvoWork