Legal
Attendance extension privacy
Last updated 7 June 2026.
What the extension handles
| Data | Why | Where it goes |
|---|---|---|
| Work email & one-time login code | To sign you in to your Wurxa account (passwordless login). | Sent to api.wurxa.com. The email address is also stored on your device so you stay signed in. |
| Selfie photo (optional) | To attach a photo to the punch so your employer can verify attendance. | Captured by your camera and sent to api.wurxa.com with the punch. You can skip the photo on any punch, or turn it off in Settings. |
| Location (optional) | To record where a punch was made, if your employer requires it. | Coordinates are sent to api.wurxa.com with the punch and, to show a readable place name, to the OpenStreetMap Nominatim service. You can turn location off in Settings. |
| Preferences & session | To remember your signed-in email, photo/location choices, and reminder settings. | Stored only on your device using the browser’s local extension storage. Not transmitted to us. |
Permissions the extension requests
- Storage — remembers your signed-in email and preferences on your device.
- Alarms — schedules the optional daily clock-in / clock-out reminders.
- Notifications — shows those reminders.
- Access to api.wurxa.com — sends your punch to your Wurxa workspace.
- Location (optional) — records where a punch was made; requested only when enabled.
- Camera — captures the selfie attached to a punch; requested only when you take a photo.
Who controls your data
Your employer is the controller of the attendance data you submit through the extension. Wurxa processes that data on your employer’s behalf as a service provider. Questions about how your employer uses your attendance, photos, or location should be directed to your employer. We will action verified requests in line with our agreement with them.
Retention
Attendance records, photos, and location attached to punches are retained in your employer’s Wurxa workspace for as long as your employer keeps them. Data stored locally by the extension (email, preferences) is removed when you sign out or remove the extension.
Security
Traffic between the extension and Wurxa is encrypted over HTTPS. Your login uses a short-lived, single-use code rather than a stored password, and the session credential is kept in a secure, HTTP-only cookie.
Children
The extension is for use by employees in a workplace and is not directed to children.
Changes
If this policy changes materially, we will update the date above and, where appropriate, notify your employer.
Contact
WebWurx — hi@wurxa.com. For privacy-specific requests, write to privacy@wurxa.com.
Questions about this document? Email hello@wurxa.com.