§ Law & obligations · 6 min read
GPS when clocking in/out: what is stored, who sees it, when it is gone
What this is about
A drywall installer clocks in in the morning at the construction site in Neuss, not at the office. The business wants to be able to prove that the clock-in took place where the work was done. That is what GPS clocking is for: when clocking in and out in the mobile app, the location is stored once along with the entry.
That is all. Zeitflex does not locate anyone between clock-ins, does not check a radius around the site and does not record a route. This article explains exactly what happens — for management, who flip the switch, and for employees, whose location is concerned.
Two switches, both must be on
- The plan. GPS clocking is only included in the Pro plan (also during the trial). On the Free and Starter plans the switch is greyed out, and the app does not request the location at all.
- The business’s decision. Open Settings → GPS & privacy and switch on Turn on GPS tracking for the business. The owner and management may do this.
The switch is off in every new business. No industry template presets it — not even trades or building cleaning; there it is at most marked as “recommended” in the module list, but not switched on. The “GPS at clock-in” entry in the module list under Business also exists; what counts for the app is solely the switch under GPS & privacy.
If the Pro plan ends, the app no longer records a location — the switch remains saved but has no effect. Zeitflex points this out to you before the change. See Changing your plan.
What exactly is stored
The time entry holds at most four numbers: latitude and longitude at clock-in, latitude and longitude at clock-out. Nothing else — no address, no series of timestamps, no accuracy value.
- Only the mobile app provides the location. The time clock in the browser and the wall terminal never send coordinates, even if the switch is on.
- The app asks the phone for its position once at the moment of clocking in/out. Nothing runs between two clock-ins.
- If the person refuses location permission on the phone or the device does not provide a position, the clock-in still happens — the entry simply has no location. Clocking in/out never fails because of GPS.
- Entries created or corrected afterwards do not get a location; with a correction, the originally recorded point stays on the entry.
What Zeitflex does not do: check a radius around a site, generate an “outside the site” warning, build a movement history or display a map.
The same switch applies to photos in the photo documentation: only if it is on is a location point stored for an uploaded photo, and the app additionally asks for each photo whether the location should be included. Unlike with the time entry, this point is displayed in the document preview — see Filing documents and records.
Who sees the coordinates
| Who | What | Where |
|---|---|---|
| Person concerned | the stored coordinates of their own entries | in their own data access report |
| Owner and management | in everyday use only the “Location recorded” label on running entries; the coordinates themselves only via a data access report for the person | Dashboard; Employees → Data report |
| Colleagues | nothing | — |
| Tax adviser | nothing — location data is blocked without exception for the tax adviser | — |
Zeitflex does not display the coordinates of clock-ins anywhere in the interface — neither in the timesheet nor in the app, not even to management. They are stored on the time entry and appear only in the data access report under Art. 15 GDPR (see What Zeitflex stores about me). The person requests it themselves; the owner and management can also create it for a person — this is recorded in the change log, and the person is notified about it.
When they are gone
The location is not part of the statutory working-time record: § 16 (2) ArbZG (German Working Hours Act) and § 17 MiLoG (German Minimum Wage Act) require start, end and duration — not a place. That is why a separate, short period applies to the coordinates:
- Six months after the time of clocking, a daily deletion run removes the four numbers from the time entry. The entry itself, with clock-in, clock-out and duration, remains for as long as the working-time data must be retained.
- The period is not configurable and cannot be extended.
- If someone leaves the business, their location points are deleted along with the anonymisation of the person.
- The explanation box below the switch in the settings currently still states “2 years” and includes a note about the timesheet. That is an old text; what counts is the deletion run with six months, and no coordinates appear in the timesheet.
What the business must clarify beforehand
The legal basis for recording is the legitimate interest in being able to prove the place of work (Art. 6 (1) (f) GDPR). This only holds if the intrusion remains as small as it is built here — one point per clock-in, a short period, no profile. Three obligations remain with the business:
- Inform (Art. 13 GDPR): employees must know before switching on what is recorded, for what purpose and for how long.
- Co-determination: if there is a works council, introducing it requires co-determination under § 87 (1) no. 6 BetrVG (German Works Constitution Act) — see Works council and co-determination.
- Weigh up: anyone who can prove the place of work without coordinates — for example via the site assignment on the entry — does not need GPS.
For employees: what you can see and do yourself
- In the app, the Transparency page shows whether your business has switched on the GPS snapshot or not.
- You decide on your phone whether the app may access the location. If you decline, you can still clock in/out — without a location. Whether that is acceptable under employment law is up to your business, not the software.
- Your data access report lists every stored location point. You request it yourself, without going through the business.
- Direct objections or questions to your business — it is the controller of the data.
Still stuck?
If the switch is greyed out, it is due to the plan; the support team can help with everything else. How the three ways of clocking in/out work together is explained under Clocking in/out by phone, tablet or browser, and what belongs in a works agreement, under Works council and co-determination.
Last checked on . We check every article against the application — if something no longer matches, that is a bug and not a difference of opinion.
Was this helpful?
Related articles
- Clocking in and out by phone, tablet or browserThree routes, one record: when each route is the right one, what each can do, which PIN rules apply at the terminal and what happens without a connection.
- Works council and co-determinationWhy time tracking requires co-determination under § 87 BetrVG, what belongs in a works agreement, which modules you should agree on beforehand and which data Zeitflex processes.
- Retention periodsHow long working-time data, sick notes and payroll records must be kept, which periods Zeitflex has set for each type of data, and what the nightly deletion run does.