Security & Privacy
How we protect students.
Students aged 15-20 use this platform. Many are minors. We take that seriously and we're transparent about exactly how their data is handled. This page is for parents, school administrators, and IT professionals who want specifics — not marketing talk.
At a glance
- Minimum age to register: 15. Under-15 accounts are blocked at Cognito before any record is created.
- Personally-identifiable data (names, emails, birthdates, school info) is stored on AWS Aurora in the US-East (Ohio) region. Encrypted at rest. Encrypted in transit.
- Authentication handled by AWS Cognito. Passwords are never stored by us in any form.
- No advertising, no data resale, no third-party tracking pixels. Students are the users, not the product.
- Employers see only what's needed to hire: applicant name, age range, school, and application message. No emails or phone numbers until a student opts in.
- Full account deletion available from your profile. We honor deletion requests within 30 days, including all historical data.
For students and families
Signing up is free and always will be. You give us your email, a password, your birthdate (so we can confirm you're at least 14), and basic school information. That's it.
Who sees your information
Your profile is not public. Employers only see your information when you apply to their listing — not before, not without your action. Even then, they see a limited view (name, age range, school, your application message). Contact information is shared only after mutual opt-in.
Parent and guardian involvement
For users under 18, Ohio work permit law requires parent or guardian involvement at the actual employer. ClockIn does not currently require pre-registration parental consent (we only collect the minimum needed to connect you with jobs), but we strongly encourage a parent or guardian to be part of your job search — especially for your first position.
If something feels off
Every listing on ClockIn comes from a verified employer. If you encounter a listing, employer, or message that feels wrong — inappropriate, unsafe, or deceptive — email trust@clockin.jobs or use the in-app "Report this listing" option. We investigate reports within 24 hours.
For school and district administrators
We're built to support districts, not replace them. If your district chooses to formally integrate with ClockIn (via a partnership agreement), you get district-level visibility and controls that an individual employer on the platform does not.
FERPA posture
ClockIn is not a school record system. We do not store grades, disciplinary records, IEPs, or any educational records regulated by FERPA. Student-provided information (name, email, birthdate, school name, self-reported grade level) is personal data, not an education record. That said: we operate as a "school official with a legitimate educational interest" posture when integrated with a district, and are willing to sign a Data Processing Agreement that formalizes this relationship.
District-level data access
When a district formally partners with ClockIn, a designated district administrator gets a dashboard showing aggregate and individual-level data for their district's students only. Data is strictly scoped by district at the database layer — one district cannot see another's data, ever.
Data portability and deletion
Districts can export their students' data on demand in CSV or JSON. Students can delete their accounts at any time, and any district-tied data is removed from the district's dashboard immediately. Full backend deletion completes within 30 days.
Want a formal partnership?
Email partnerships@clockin.jobs. We'll send a DPA template, answer procurement questions, and schedule a 30-minute technical walkthrough with your IT lead.
For IT and security professionals
The detail you actually want, in the order you'd ask for it.
Architecture
us-east-2. Encrypted at rest (AES-256 via AWS KMS). TLS required for all connections. Daily automated snapshots, 14-day retention in prod.Authentication and session handling
Data access and isolation
organization_id in a shared data access layer (TenantRepository base class). Individual feature code cannot bypass tenant scope. This is enforced architecturally, not by convention.Logging and audit
Incident response
Compliance posture
Vendor list
Questions about security or privacy?
IT professionals and administrators: security@clockin.jobs
Parents, students, and general inquiries: privacy@clockin.jobs
Partnership and integration: partnerships@clockin.jobs
This page is updated as our infrastructure and compliance posture evolve. Last reviewed: April 18, 2026.
