Mintage Payroll

Mintage Pulse Privacy Policy

Last updated: October 8, 2026

Mintage Pulse is a workplace attendance kiosk provided by Invernisoft LLC. This policy explains how Pulse and its connected Mintage attendance service handle information about employees using the kiosk. Your employer manages employee enrollment, attendance records, and the clocking methods available at its workplace. Invernisoft processes that information to provide the service.

1. Face data we collect

We collect facial photographs during employee enrollment and when facial recognition or a clock-photo requirement is enabled. The service derives mathematical representations of faces, called facial templates or face vectors, to match a person at the kiosk to an enrolled employee.

Face data includes enrollment photographs and templates, photographs submitted for recognition, photographs attached to clock events, and scan-audit photographs from successful matches, rejected clock actions, failed verification, or unrecognized scans. We also process matching results and related attendance details, such as the employee identifier when known, kiosk identifier, and time of the attempt.

The iOS app processes camera frames on the device to detect a face and check for signs of a live person. Selected still images are uploaded to the attendance service for enrollment, recognition, and attendance records. Pulse does not record and upload a continuous video of the workplace. It does not access Apple's Face ID enrollment data or TrueDepth facial maps.

2. How we use face data

We use face data to enroll employees, recognize or verify the person clocking in or out, check liveness, prevent attendance impersonation, and allow authorized employer staff to review attendance photos and failed recognition attempts. Facial recognition can identify an enrolled employee without that employee first selecting a name on the kiosk.

Invernisoft does not sell face data or use it for advertising, marketing, tracking across other apps or websites, or inferring unrelated personal characteristics. Face processing within the Mintage attendance service is limited to the purposes described in this policy.

3. Storage and sharing of face data

Facial photographs and associated TimeKeeper records are stored using DigitalOcean infrastructure in the United States. Amazon Web Services (AWS) receives enrollment and recognition images through Amazon Rekognition to perform facial matching. Rekognition stores face vectors and associated identifiers in an AWS collection in the United States. DigitalOcean and AWS are service providers involved in storing or processing face data.

Your employer's authorized administrators can access enrollment information, attendance photos, and scan-audit records through TimeKeeper. Where your employer connects Mintage Workforce, enrollment photographs can be synchronized from Workforce to TimeKeeper for attendance recognition.

The iOS app holds captured images temporarily in memory for capture, review, recognition, and upload. It does not maintain a persistent local enrollment database. Removing Pulse from a device does not delete photographs or templates already stored by the connected services.

AWS documents that images submitted to Rekognition may be retained and used to improve its services unless an applicable AI-services opt-out is enabled. The 90-day TimeKeeper cleanup described below does not control those AWS-managed copies. See AWS's information about Rekognition data handling and contact us to confirm the settings applicable to your employer's service.

4. Face-data retention and deletion

Enrollment photographs and facial templates are kept to support the employee's active face enrollment. They have no automatic 90-day expiry; an employer must remove enrollment when it is no longer required. Changing an employee's active status does not by itself delete enrollment photographs or Amazon Rekognition face vectors.

In TimeKeeper, photographs attached to clock events and face scan audit photographs and records are retained for 90 days from the clock event or scan, then automatically deleted by the next hourly cleanup. This includes successful matches, rejected clock actions, failed verification, and unrecognized scans. A service or storage outage can delay deletion until a successful cleanup run. Deleting these photographs does not delete the underlying non-biometric attendance entry, such as the employee identifier, clock time, and clock action.

Enrollment removal includes the enrollment photographs held by the attendance service and the corresponding face vectors in its Amazon Rekognition collection. Deletion requests should cover both copies. Removing enrollment does not by itself erase attendance photographs, which have the separate retention period described above.

The 90-day automatic cleanup applies to TimeKeeper's live scan records and the photo objects referenced by its scan and attendance records. It does not erase backups, retained cloud-object versions, unreferenced photo objects, or copies stored independently in Workforce or by a service provider. We do not represent that all of those copies are erased by the TimeKeeper cleanup. Contact your employer or support@invernisoft.com for the retention and deletion arrangements applicable to those copies and for assistance with a deletion request.

5. Your choices and deletion requests

Contact your employer to ask about face enrollment, request access to or deletion of your face data, or arrange an alternative attendance method. Pulse supports other clocking methods, including PIN, profile selection, and QR codes, depending on your employer's configuration. PIN or profile clocking may still require a photo when that setting is enabled; ask your employer for a method that does not collect face data if you need one.

You may also send a face-data access or deletion request to support@invernisoft.com. Identify your employer and the employee record concerned so we can coordinate the request with the employer. Do not email a face photograph or biometric template with your initial request.

6. Other information collected by Pulse

Pulse processes employee names and identifiers, configured profile photos, clock actions and times, and kiosk identifiers to record attendance. With location permission, Pulse can attach the device's location to a clock event. The updated iOS implementation requests approximate location; earlier versions may attach precise coordinates when permission allows. Location is optional and is requested while the app is in use. Pulse does not continuously collect background location.

7. Contact and policy updates

Contact Invernisoft LLC at support@invernisoft.com with questions about this policy. Changes to this policy will be published on this page with an updated effective date.

Invernisoft Logo

Invernisoft, Inc. delivers innovative cloud solutions to empower businesses.
Our platform simplifies workflows, boosts productivity, and scales with your needs.
All rights reserved.

Made in GuyanaLocal Content
© 2025 Invernisoft, Inc.