Hosted in Germany
Our servers, databases and files are with Hetzner, in Germany. Hetzner is named in our Data Processing Agreement, alongside every other sub-processor.
Security
Where your data lives, what is encrypted, who can see it, and what to do if something looks wrong. Written plainly, including what we do not do.
Where it lives
Your records are kept on servers in Germany, and every connection to HourSquare uses HTTPS.
Our servers, databases and files are with Hetzner, in Germany. Hetzner is named in our Data Processing Agreement, alongside every other sub-processor.
Cloudflare sits in front of every page and filters attack traffic, such as floods of requests, before it reaches our servers.
Connections to HourSquare use HTTPS, and browsers are told never to connect without it (HSTS).
Encrypted in the database
Not just hidden on screen. The application encrypts these values before it writes them, so the database holds only the encrypted form of each one.
Each value is encrypted with AES‑256 before it is saved. The database stores the encrypted form, never the plain number.
Every company has its own key, so one company's key does not open another company's numbers.
The keys are stored separately from the database, and are themselves locked by a master key kept in a separate secrets vault.
Payslip PDFs and uploaded documents are stored as files, like any other document. They are kept in private storage, not public storage, and are handed out only through links that expire or through signed-in requests. The encryption above covers the numbers and figures in the database, not the files.
Sign-in
What we store, what we never store, and the protections open to every company.
We keep only a salted, one-way hash of each password (PBKDF2), never the password itself. A hash checks a password but cannot be reversed to reveal it.
Sign-in sessions and API keys are also kept only as hashes. An API key is shown once, when you create it.
Use an authenticator app or a code by email. It is open to everyone. Authenticator secrets are stored encrypted.
Sign in with a passkey instead of a password: your fingerprint, face or PIN, or a hardware security key. Open to everyone.
A company can switch on single sign-on (OIDC), so people sign in through the company's own identity provider. It is set per company.
Password-reset links last one hour. The links we email for signing in or setting a password are not kept in our email log.
Who can see what
You decide who sees what, and the product records who looked.
Each person sees what their role allows. When a manager reviews a change to a sensitive number, they see only its last four digits by default. A company can choose to show managers the full number.
Changes to employee records and company settings, and every look at a sensitive number, are recorded with who did it and when.
HourSquare staff can open a customer account only to help. They must give a written reason, the session lasts 15 minutes, and their name and IP address are recorded.
Anonymity and control
What the anonymous features keep, and what you can do with your people's data.
Limits
Four time limits built into the product today.
A sensitive number you show in full hides itself again after five minutes.
A password-reset link stops working after one hour.
A session opened by our staff to help you ends after 15 minutes.
A company that was deleted can be reactivated for 30 days.
Report a problem
If you think you have found a security problem, or something on this page does not look right, write to us. We read every report.
Tell us what you saw and how to repeat it. Please do not include other people's personal data.
Our contact details are also published at /.well-known/security.txt.
FAQ
Short, exact answers, including the ones that start with no.
See all questionsReady when you are
Free for now, every module included, no card to sign up. We'll tell you before anything changes.
Free for now · No card to sign up · GDPR-native · EU-hosted