본문으로 건너뛰기 / Skip to content

ONTIME 근태관리

개인정보 처리방침Privacy Policy

시행일: 2026년 8월 4일Effective: August 4, 2026

1. 서비스 개요

ONTIME 근태관리(이하 “서비스”)는 사업장이 직원의 출퇴근을 기록하고 근무시간과 급여를 산정하기 위해 사용하는 기업용(B2B) 앱입니다. 서비스는 일반 소비자를 대상으로 한 회원가입을 제공하지 않으며, 직원 계정은 해당 직원이 소속된 사업장의 관리자가 발급합니다.

이용자 역할은 다음 두 가지입니다.

  • 직원(WORKER) — 본인의 출퇴근 기록, 근무 일정, 시급 및 예상 급여만 조회할 수 있습니다.
  • 사업장 관리자(ADMIN) — 소속 사업장의 직원 정보, 지점, 근태 및 급여 집계를 관리합니다.

2. 운영자 및 문의처

서비스 운영자: Valo digital (운영자: NAM IRINA) (대한민국)
문의: valo.digital6988@gmail.com

개인정보 관련 문의, 열람·정정·삭제 요청은 위 이메일로 접수하며, 접수 사실과 처리 결과를 회신합니다.

3. 계정 생성 방식

  • 사업장 관리자가 직원의 이름과 이메일 주소를 입력해 계정을 생성하고, 6자리 활성화 코드를 발급합니다.
  • 직원은 앱에서 활성화 코드를 입력한 뒤 비밀번호를 직접 설정합니다. 운영자는 비밀번호 원문을 보관하지 않습니다.
  • 서비스에는 공개 회원가입 절차가 없습니다.

4. 처리하는 개인정보 항목

서비스는 아래 항목만 처리합니다.

  • 계정 정보 — 이메일 주소, 이름, 역할(직원/관리자), 계정 식별자, 소속 사업장 및 지점 식별자, 계정 활성화 정보.
  • 근무 조건 정보 — 배정 지점, 예정 출퇴근 시각, 시급 및 연장근로 시급.
  • 근태 정보 — 출근·퇴근 시각, 근무 상태, 근무 시간, 기간별 근태 이력.
  • 급여 산정 정보 — 정규 및 연장 근무시간, 이를 바탕으로 계산된 예상 급여액.
  • 위치정보 — 출퇴근 기록 시점의 정확한 GPS 좌표(위도·경도), 그리고 관리자가 지점을 등록할 때 지정하는 지점 좌표와 반경. 자세한 내용은 5항을 참고하십시오.

서비스는 전화번호를 수집하지 않습니다. 또한 광고 식별자, 연락처, 사진, 통화·문자 기록, 캘린더, 기기 내 파일을 수집하지 않으며, 분석(Analytics)·광고·크래시 리포트 SDK를 탑재하고 있지 않습니다.

5. 위치정보의 처리

  • 직원이 앱에서 출근 또는 퇴근 버튼을 누른 그 순간에만 기기의 위치를 1회 확인합니다. 상시 추적이나 백그라운드 위치 수집은 하지 않습니다.
  • 앱은 전경(앱 사용 중) 권한만 요청합니다. 백그라운드 위치 권한은 요청하지 않습니다.
  • 수집한 좌표는 출퇴근 요청과 함께 서버로 전송되며, 서버가 해당 좌표를 관리자가 설정한 지점 반경과 대조해 출퇴근 인정 여부를 판단합니다. 판단은 서버가 수행합니다.
  • 사업장 관리자는 지점을 등록·수정할 때 지점의 좌표와 허용 반경(geofence)을 지정합니다. 이때 기기의 현재 위치를 지점 좌표로 사용할 수 있습니다.
  • 위치 권한을 허용하지 않으면 출퇴근 기록 기능을 사용할 수 없습니다. 권한은 기기 설정에서 언제든지 철회할 수 있습니다.

6. 이용 목적

  • 계정 생성, 인증 및 유지
  • 출퇴근 기록 및 근무시간 산정
  • 지정된 사업장 반경 내에서 출퇴근이 이루어졌는지 확인
  • 근무시간에 따른 급여 산정 및 근태·급여 보고서 제공
  • 이용자 문의 및 요청 처리
  • 서비스의 보안 유지, 오류 대응, 법령상 의무 이행

서비스는 개인정보를 광고, 마케팅, 프로파일링, 행태정보 분석에 이용하지 않으며 판매하지 않습니다.

7. 제3자 제공 및 처리위탁

  • 직원의 근태 및 급여 정보는 해당 직원이 소속된 사업장의 관리자에게 표시됩니다. 이는 서비스의 본질적 기능이며, 사업장은 사용자(고용주)로서 해당 정보를 처리합니다.
  • 지점 지도 화면은 운영체제의 지도 기능(Android의 Google Maps, iOS의 Apple 지도)을 사용합니다. 지도 화면에 표시되는 좌표는 해당 지도 제공자에게 전달되며, 그 처리에는 각 제공자의 약관과 방침이 적용됩니다.
  • 관리자가 지점 주소를 검색하면, 입력한 문자열이 좌표로 변환되기 위해 운영체제의 주소 검색(지오코딩) 기능에 전달됩니다. 해당 기능의 제공자는 기기와 플랫폼 서비스에 따라 다르며, 그 처리에는 제공자의 약관과 방침이 적용됩니다. 서비스는 입력한 문자열을 저장하지 않으며, 관리자가 확정한 좌표와 반경만 저장합니다.
  • 그 밖에 개인정보를 제3자에게 판매하거나 마케팅 목적으로 제공하지 않습니다.
  • 법령에 따른 요청이 있거나 법적 의무 이행, 권리 보호, 이용자 및 공중의 안전 보호를 위해 필요한 경우에는 관계 법령이 정한 범위에서 제공될 수 있습니다.

8. 보관 기간 및 파기

  • 계정 정보 — 계정이 유지되는 기간 동안 보관하며, 계정 종료 후에는 분쟁 대응 등을 위해 최대 24개월까지 보관할 수 있습니다.
  • 문의 및 응대 기록 — 접수일로부터 최대 24개월.
  • 접속 기록(서버 로그) — 보안 및 장애 대응 목적으로 최대 24개월.
  • 근태 및 급여 기록 — 근로·회계·세무 관련 법령이나 계약상 의무가 요구하는 기간 동안 보관합니다. 이 기간은 계정 삭제 요청과 무관하게 적용될 수 있습니다.
  • 위치정보(출퇴근 좌표) — 출퇴근 인정 여부 확인이라는 목적에 더 이상 필요하지 않게 되면, 별도의 법적 보관 근거가 없는 한 삭제하거나 개인을 식별할 수 없도록 처리합니다.

보관 기간이 지난 개인정보는 지체 없이 삭제하거나 익명 처리합니다. 백업본에 남아 있는 사본은 운영자의 백업 보관 주기에 따라 순차적으로 삭제되며, 그 전까지는 복구·보안·법령 준수 목적 외에는 이용되지 않습니다.

9. 안전성 확보조치

  • 앱과 서버 사이의 모든 통신은 HTTPS로 암호화됩니다.
  • 로그인 토큰은 기기의 보안 저장소(iOS 키체인 / Android 키스토어)에 저장되며, 로그아웃하거나 인증이 만료되면 삭제됩니다.
  • 비밀번호는 원문으로 저장하지 않습니다.
  • 다만 인터넷을 통한 전송이나 전자적 저장 방식 중 100% 안전한 방법은 존재하지 않으므로, 절대적인 안전성을 보장할 수는 없습니다.

10. 이용자의 권리

이용자는 자신의 개인정보에 대해 열람, 정정, 삭제, 처리정지를 요청할 수 있습니다. 요청은 valo.digital6988@gmail.com로 접수하며, 본인 확인 절차를 거친 후 처리합니다.

계정 삭제는 별도 안내 페이지의 양식으로 직접 요청할 수 있습니다. 해당 페이지에는 삭제되는 정보와 법령에 따라 보관되는 정보가 정리되어 있습니다.

계정 삭제 요청 안내 →

11. 만 16세 미만 아동

서비스는 만 16세 미만을 대상으로 하지 않으며, 만 16세 미만 아동의 개인정보를 고의로 수집하지 않습니다. 만 16세 미만 아동의 정보가 수집된 사실을 알게 된 경우 지체 없이 삭제합니다.

12. 국외 이전

개인정보는 운영자와 그 수탁자가 서비스를 운영하는 지역의 서버에서 처리되며, 이용자의 거주 국가 밖에 위치할 수 있습니다. 이 경우 관계 법령이 요구하는 보호조치를 적용합니다.

13. 처리방침의 변경

본 처리방침이 변경되는 경우 변경된 내용을 이 페이지에 게시하고 시행일을 갱신합니다. 중요한 변경은 시행 전에 이메일 또는 앱 내 공지로 안내합니다.

1. About this service

ONTIME (“the Service”) is a business-to-business attendance app used by workplaces to record employee check-in and check-out, calculate working hours and estimate pay. The Service has no consumer sign-up: an employee account is created by an administrator at the workplace that employs them.

There are two user roles:

  • Worker — sees only their own attendance records, schedule, hourly rate and estimated pay.
  • Business administrator — manages the employees, branches, attendance and payroll summaries of their own workplace.

2. Operator and contact

Operator: Valo digital (operator: NAM IRINA) (South Korea)
Contact: valo.digital6988@gmail.com

Privacy questions and requests for access, correction or deletion are received at that address; we confirm receipt and reply with the outcome.

3. How accounts are created

  • A business administrator creates the account by entering the employee’s name and email address, and the Service issues a 6-digit activation code.
  • The employee enters that code in the app and chooses their own password. We do not store the password in readable form.
  • There is no public self-service registration.

4. Personal data we process

The Service processes only the following:

  • Account data — email address, full name, role (worker or administrator), account identifier, organization and branch identifiers, account activation data.
  • Employment terms — assigned branch, expected start and end of shift, hourly rate and overtime hourly rate.
  • Attendance data — check-in and check-out times, shift status, worked minutes, attendance history for a selected period.
  • Payroll calculations — regular and overtime minutes and the estimated pay derived from them.
  • Location data — the precise GPS coordinates (latitude and longitude) captured at the moment of a check-in or check-out, and the branch coordinates and radius an administrator sets when configuring a branch. See section 5.

The Service does not collect a phone number. It also does not collect advertising identifiers, contacts, photos, call or SMS logs, calendar entries or files on your device, and it contains no analytics, advertising or crash-reporting SDK.

5. How location is used

  • The device location is read once, at the moment the employee presses check-in or check-out. There is no continuous tracking and no background location collection.
  • The app requests foreground (“while using the app”) location permission only. It never requests background location permission.
  • The captured coordinates are sent with the check-in or check-out request. The server compares them against the branch radius configured by the administrator and decides whether the check-in is accepted; that decision is made on the server.
  • A business administrator sets a branch’s coordinates and permitted radius (geofence) when creating or editing the branch, optionally using the current device location as the branch point.
  • Without location permission the attendance feature cannot be used. Permission can be withdrawn at any time in the device settings.

6. Purposes of processing

  • Creating, authenticating and maintaining accounts
  • Recording attendance and calculating working time
  • Verifying that a check-in or check-out happened within the configured branch radius
  • Calculating pay from working time and producing attendance and payroll reports
  • Handling user enquiries and requests
  • Keeping the Service secure, diagnosing faults, and meeting legal obligations

We do not use personal data for advertising, marketing, profiling or behavioural analysis, and we do not sell it.

7. Disclosure and third parties

  • An employee’s attendance and payroll data is visible to the administrators of the workplace that employs them. This is inherent to the Service; the workplace processes that data as the employer.
  • Branch map screens use the operating system’s map component (Google Maps on Android, Apple Maps on iOS). Coordinates displayed on the map are passed to that map provider and are subject to the provider’s own terms and privacy policy.
  • When an administrator searches for a branch address, the text they type is passed to the operating system’s address lookup (geocoding) function so that it can be converted into coordinates. The provider of that function depends on the device and its platform services, and the processing is subject to that provider’s own terms and privacy policy. We do not store the text that was typed — only the coordinates and radius the administrator confirms.
  • We do not otherwise sell personal data or disclose it for marketing purposes.
  • We may disclose personal data where required by law, or where necessary to meet a legal obligation, protect rights, or protect the safety of users or the public, within the limits the applicable law allows.

8. Retention and deletion

  • Account data — kept for the duration of the account relationship, and for up to 24 months after closure to resolve any post-termination issues or disputes.
  • Support correspondence — up to 24 months from receipt.
  • Server logs — up to 24 months for security monitoring and troubleshooting.
  • Attendance and payroll records — kept for as long as required by applicable labour, accounting, tax or contractual obligations. This period can apply independently of an account deletion request.
  • Check-in location coordinates — deleted or anonymized once they are no longer needed for the presence check, unless a separate legal basis requires keeping them.

When a retention period ends, the data is deleted or anonymized without undue delay. Residual copies in backups are removed on the operator’s ordinary backup cycle and are not used before then for anything other than recovery, security or legal compliance.

9. Security

  • All traffic between the app and the server is encrypted with HTTPS.
  • The login token is held in the device’s secure storage (iOS Keychain / Android Keystore) and is erased on logout or when the session is rejected.
  • Passwords are not stored in readable form.
  • No method of transmission over the internet or of electronic storage is completely secure, so absolute security cannot be guaranteed.

10. Your rights

You may request access to, correction of, deletion of, or restriction of processing of your personal data. Send the request to valo.digital6988@gmail.com; we process it after verifying your identity.

You can request account deletion yourself using the form on a separate page, which also lists what is deleted and what must be retained by law.

Request account deletion →

11. Children under 16

The Service is not directed to anyone under the age of 16 and we do not knowingly collect personal data from them. If we learn that we hold such data, we delete it without undue delay.

12. International transfers

Personal data is processed on servers operated by the operator and its processors, which may be located outside your country of residence. Where that happens, we apply the safeguards required by applicable law.

13. Changes to this policy

If this policy changes, the new version is published on this page and the effective date is updated. We announce material changes by email or in-app notice before they take effect.