Effective date: 1 July 2026 · Last updated: 30 August 2026 (sections 2, 5, 7, 8, 9 and 10 updated)
ProofClock is a Ring Appstore application operated by Erbacci LLC (Wyoming, USA), which is the data controller for the personal data described here. Your ProofClock plan is handled entirely by the Ring Billing System. You can contact us for any privacy request at info@erbacciltd.com.
To deliver proof-of-attendance, ProofClock accesses, through the Ring Partner API and only with your authorization at account linking:
ProofClock does not access Live Video, media clips, image snapshots, or audio. Because it receives no images or video from your camera, there is nothing for a privacy zone to apply to: it cannot see anything a privacy zone hides, and it performs no masking of its own.
From those timestamps, ProofClock derives and stores only the minimal data needed for the service: your sites and schedules, your device list and status, the motion-event timestamps, and the computed attendance verdicts (Verified / Short / No-show / Unverifiable) for each expected window. It also stores your session, the email addresses of people you invite, and an access log of sign-ins and data views.
We use this data solely to provide the feature you enabled: showing when scheduled crews arrived, how long they stayed, and whether they met the service window, and producing reports you can use for billing. We do not use Ring data for advertising, marketing, profiling of individuals, resale, or any purpose beyond delivering the service.
No AI training. ProofClock uses no AI or machine-learning models, and no Ring data is ever used to train, fine-tune, or improve any model.
ProofClock sends only account and service email — never marketing:
The account owner can turn service notices and the weekly digest on or off at any time in Settings → Email preferences; the digest stays off unless the owner turns it on, and invited members are not sent service notices or the digest. We do not send promotional or marketing email, and — as stated in section 4 — we never use Ring data for advertising or marketing.
ProofClock is a consensual employer attendance tool. If you use it to monitor staff or crews, you (the employer/account owner) are responsible for giving those individuals notice and obtaining any consent required by your local law. The account owner confirms this in-app before use, and ProofClock keeps an access log so account owners can see who accessed the data. ProofClock is not intended for covert surveillance of individuals.
Raw motion-event rows are retained for approximately 90 days and then expire automatically. Two of those timestamps — the first and last motion of a visit, shown as its arrival and departure — are copied onto the computed verdict for that visit and follow the retention of that verdict. Access-log entries are retained for approximately 1 year. Sites, schedules, devices and computed verdicts do not expire on their own: they are retained until you delete them, unlink the integration, or request deletion, after which they are removed.
ProofClock shares data only with the processors strictly necessary to run the service:
Our web pages load two typefaces from Google Fonts (fonts.googleapis.com, fonts.gstatic.com), so Google receives the IP address and browser user-agent of the device rendering the page. No Ring data, account data or attendance data is sent to Google.
We do not sell your data and have no law-enforcement integration or data-sharing with law enforcement.
You can delete your account and all associated data at any time from Settings → Delete account in the app, or by unlinking ProofClock from the Ring app. Either way we permanently delete your stored data — sites, schedules, devices, motion events, verdicts, team memberships, sessions and access logs. Deleting in the app does not by itself unlink the integration, so if you want all processing to stop, also remove ProofClock in the Ring app (Menu → My Apps → ProofClock); that unlink (the app_integration_removed event) triggers the same deletion and ends further collection. Deleted data is removed from our databases immediately; operational server logs, which may contain event timestamps and device identifiers, expire automatically within 30 days. If the same email address also owns or belongs to another ProofClock account, we keep the sign-in identity for that address so the other account continues to work. You can also exercise your data-protection rights wherever you are — including US state-law rights (such as the CCPA/CPRA) and, where they apply to you, your rights under the GDPR and UK GDPR — by emailing info@erbacciltd.com.
Data is encrypted in transit (TLS/HTTPS; plain HTTP is redirected to HTTPS) and at rest — Amazon S3 with SSE-S3 (AES-256) default encryption and public access blocked, and Amazon DynamoDB with its always-on server-side encryption. Your Ring account-linking tokens are held in DynamoDB under that encryption; they are never returned to any client, never rendered in the dashboard, and never included in any API response. The functions that process Ring data run under dedicated AWS IAM execution roles scoped to the specific tables, bucket and secret they need, and administrative access is limited to a small number of authorised people. Application activity is logged to Amazon CloudWatch Logs, retained for 30 days and reviewed by us; we do not currently run automated anomaly detection.
ProofClock is a business tool for adults. It is not directed to children under 13 and contains no child-oriented content.
We may update this policy; material changes will be reflected here with a new effective date and, where appropriate, communicated in-app.
Erbacci LLC (Wyoming, USA) · Contact: info@erbacciltd.com · ProofClock · Powered by Ring