Legal
Privacy Policy
We take your privacy seriously. This policy explains what data we collect, why we collect it, and how we protect it.
Contents
Summary: We collect only the data necessary to run the HR and payroll system. We do not sell your data, and we apply industry-standard security measures to keep it safe.
Introduction
This Privacy Policy describes how CreativeNook HR ("we", "us", or "our") collects, uses, stores, and protects personal information when you use the CreativeNook HR HR Management and Payroll System (the "System").
We are committed to protecting your personal information and being transparent about how it is used. This policy applies to all users of the System, including administrators, employees, and clients.
Information We Collect
We collect information that is necessary to provide HR and payroll services. The types of data we process include:
| Category | Examples | Purpose |
|---|---|---|
| Identity | Full name, email address | Account creation & authentication |
| Employment | Job title, department, compensation | Payroll and HR operations |
| Time & Attendance | Hours worked, leave records | Payroll calculation, compliance |
| Google Account | Email, name, profile picture | OAuth sign-in (if used) |
| Usage Data | Login timestamps, audit logs | Security monitoring |
How We Use Your Data
We use your personal data only for the purposes described below. We do not use your data for advertising or sell it to third parties.
Core Operations
- Processing payroll and calculating compensation
- Managing time logs, leave, and schedules
- Generating invoices and payment records
- Providing HR reporting for administrators
Security & Compliance
- Authenticating and verifying user identity
- Detecting and preventing unauthorized access
- Maintaining audit logs for accountability
- Complying with applicable legal obligations
Data Sharing
We do not sell, trade, or rent your personal information to third parties. We may share data only in the following limited circumstances:
- With your organization's authorized administrators, as necessary for HR operations
- With service providers who process data on our behalf (e.g., cloud hosting, email delivery) under strict data processing agreements
- When required by law, court order, or regulatory authority
- In the event of a business transfer, with appropriate notice to users
Data Security
We implement a range of technical and organizational security measures to protect your personal information from unauthorized access, disclosure, alteration, or destruction.
- Encryption of sensitive data at rest and in transit (TLS/SSL)
- Encrypted storage of compensation and rate information
- Role-based access controls limiting data visibility by user role
- Account lockout after repeated failed login attempts
- Audit logging of sensitive operations and data changes
- Regular security reviews and dependency updates
Data Retention
We retain your personal information for as long as necessary to fulfill the purposes described in this policy, unless a longer retention period is required or permitted by law.
Payroll and financial records may be retained for extended periods to comply with accounting and tax regulations. When data is no longer needed, we securely delete or anonymize it.
You may request deletion of your personal data by contacting your administrator or our support team. Please note that some data may be retained where required by law or legitimate business purposes.
Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data. To exercise any of these rights, contact your administrator or our support team.
Access
Request a copy of the personal data we hold about you
Rectification
Request corrections to inaccurate or incomplete data
Erasure
Request deletion of your data where no legal basis for retention exists
Objection
Object to certain types of data processing in specific circumstances
Third-Party Services
We use a limited number of third-party services to operate the System. These providers are contractually required to handle your data securely and only for the purposes we specify.
Google OAuth 2.0
When you choose to sign in with Google, the following applies:
- We use Google's OAuth 2.0 service for secure, passwordless authentication
- We request only the minimum required scopes: email, name, and profile picture
- Your Google password is never transmitted to or stored by us
- You can revoke our access via your Google Account → Security → Third-party access
- Google's Privacy Policy governs the data Google collects during the authentication flow
Policy Changes
We may update this Privacy Policy periodically to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will:
- Update the effective date at the top of this page
- Notify users via email or in-app notification for significant changes
- Provide a summary of what has changed where possible
Continued use of the System after any policy update constitutes your acceptance of the revised terms.
Contact Us
If you have questions about this Privacy Policy, want to exercise your data rights, or have a privacy-related concern, please contact us.
Privacy Support
support@creativenookhr.comCreativeNook HR Privacy Policy — Version 2.0
Last updated April 16, 2026. Questions? Email support@creativenookhr.com