Dayflow

Privacy Policy

Last updated August 22, 2026

This is a placeholder privacy policy for the Dayflow hackathon build. Replace it with your organization's actual policy before handling real employee data.

What we store

Company and employee profile details, attendance records, leave requests, and salary structure — scoped to your company's workspace only. Passwords are never stored in plain text; they are hashed with bcrypt before being written to the database.

Sessions

Signing in sets a single, signed, HTTP-only cookie used to identify your session. It is not readable by client-side JavaScript and is cleared when you sign out.

Sharing

Employee payroll and personal data are visible only to that employee and to your company's Admin/HR accounts. Dayflow does not sell or share workspace data with third parties.