Security

How HourSquare protects your data.

Where your data lives, what is encrypted, who can see it, and what to do if something looks wrong. Written plainly, including what we do not do.

Stored in GermanyHTTPS onlyID numbers and pay encrypted
A sketch of how HourSquare shows sensitive numbers: hidden until someone with permission chooses to show them.

Where it lives

Stored in Germany. Reached over HTTPS.

Your records are kept on servers in Germany, and every connection to HourSquare uses HTTPS.

Hosted in Germany

Our servers, databases and files are with Hetzner, in Germany. Hetzner is named in our Data Processing Agreement, alongside every other sub-processor.

Cloudflare in front of every page

Cloudflare sits in front of every page and filters attack traffic, such as floods of requests, before it reaches our servers.

HTTPS, and only HTTPS

Connections to HourSquare use HTTPS, and browsers are told never to connect without it (HSTS).

Encrypted in the database

Sensitive numbers are encrypted before they are saved.

Not just hidden on screen. The application encrypts these values before it writes them, so the database holds only the encrypted form of each one.

What is encrypted

  • National ID numbers
  • Tax and social-insurance numbers
  • Bank account numbers
  • Passport and ID-card numbers
  • Salaries and payslip figures
  1. 1

    Encrypted first

    Each value is encrypted with AES‑256 before it is saved. The database stores the encrypted form, never the plain number.

  2. 2

    One key per company

    Every company has its own key, so one company's key does not open another company's numbers.

  3. 3

    Keys kept apart

    The keys are stored separately from the database, and are themselves locked by a master key kept in a separate secrets vault.

On screen, numbers are masked

  • Numbers show as hidden dots until someone chooses to show them.
  • Seeing another person's number in full needs a specific permission.
  • Numbers hide again after five minutes.
  • Every look is recorded in the access log, with who looked and when.

A note on files

Payslip PDFs and uploaded documents are stored as files, like any other document. They are kept in private storage, not public storage, and are handed out only through links that expire or through signed-in requests. The encryption above covers the numbers and figures in the database, not the files.

Sign-in

Sign-in that keeps nothing it does not need.

What we store, what we never store, and the protections open to every company.

Passwords are never stored

We keep only a salted, one-way hash of each password (PBKDF2), never the password itself. A hash checks a password but cannot be reversed to reveal it.

Sessions and API keys

Sign-in sessions and API keys are also kept only as hashes. An API key is shown once, when you create it.

Two-step sign-in

Use an authenticator app or a code by email. It is open to everyone. Authenticator secrets are stored encrypted.

Passkeys

Sign in with a passkey instead of a password: your fingerprint, face or PIN, or a hardware security key. Open to everyone.

Single sign-on

A company can switch on single sign-on (OIDC), so people sign in through the company's own identity provider. It is set per company.

Links that expire

Password-reset links last one hour. The links we email for signing in or setting a password are not kept in our email log.

Who can see what

Access follows the roles you set.

You decide who sees what, and the product records who looked.

Roles and permissions

Each person sees what their role allows. When a manager reviews a change to a sensitive number, they see only its last four digits by default. A company can choose to show managers the full number.

An audit log

Changes to employee records and company settings, and every look at a sensitive number, are recorded with who did it and when.

Our staff, only to help

HourSquare staff can open a customer account only to help. They must give a written reason, the session lasts 15 minutes, and their name and IP address are recorded.

Anonymity and control

Anonymous stays anonymous. Your data stays yours.

What the anonymous features keep, and what you can do with your people's data.

Anonymous means anonymous

  • Anonymous Speak up reports store no name and no account.
  • In anonymous pulse surveys, answers are saved without a name or an account. A separate list only notes that a person has responded, so reminders skip them.

Your data, your control

  • Export a person's data from the product.
  • Erase a person's data after they leave. It anonymises who they were; leave, time and pay history stays as anonymised records.
  • Deleting a company locks everyone out at once. For 30 days you can still reactivate it. After 30 days everything is removed, files included, and the company's key is destroyed.

Limits

Numbers worth knowing.

Four time limits built into the product today.

5 min

Numbers hide again

A sensitive number you show in full hides itself again after five minutes.

1 hour

Reset links

A password-reset link stops working after one hour.

15 min

Staff access to help

A session opened by our staff to help you ends after 15 minutes.

30 days

To reactivate a company

A company that was deleted can be reactivated for 30 days.

Report a problem

Found something? Tell us.

If you think you have found a security problem, or something on this page does not look right, write to us. We read every report.

Tell us what you saw and how to repeat it. Please do not include other people's personal data.

Our contact details are also published at /.well-known/security.txt.

FAQ

Questions about security

Short, exact answers, including the ones that start with no.

See all questions
Is our data encrypted?
Parts of it, and here is exactly which. National ID, tax and social-insurance numbers, bank account numbers, passport and ID-card numbers, salaries and payslip figures are encrypted in the database (AES-256), each company with its own key. Connections to HourSquare use HTTPS. Payslip PDFs and uploaded documents are kept in private storage and handed out through expiring links or signed-in requests, but they are stored as files and are not encrypted. Other information, such as names, contact details and leave records, is protected by roles, permissions and the audit log, but is not encrypted separately in the database.
Can HourSquare staff see our data?
A member of our staff can open a customer account, but only to help you and only with a written reason. The session lasts 15 minutes, their name and IP address are recorded, and while it is open they see the account as that person does. Sensitive numbers and pay figures are encrypted in the database, so reading the database directly does not show them.
Where is our data stored?
On servers in Germany, with Hetzner: the servers, the databases and the files. Cloudflare sits in front of every page and filters attacks. Our Data Processing Agreement lists every sub-processor and where it operates.
Do you hold SOC 2 or ISO 27001?
No. We do not hold a certification today. Our Data Processing Agreement and this page describe the controls we run.
What happens to our data when we leave?
You can export lists, reports and a person's data from the product whenever you like, and erase a person's data after they leave. Deleting a company locks everyone out at once, and for 30 days you can still reactivate it. After 30 days everything is removed, files included, and the company's key is destroyed.
How do I report a problem?
Write to support@hoursquare.com. We read every report. Our contact details are also published at /.well-known/security.txt.

Ready when you are

See it working in your own account.

Free for now, every module included, no card to sign up. We'll tell you before anything changes.

Free for now · No card to sign up · GDPR-native · EU-hosted

HOURSQUARE · EST 2026 HR you run yourself.