Questions, answered
Frequently asked questions
Setting up TempClock, how face clock-in works, pricing, support and where your data lives.
Frequently asked questions
Getting Started
4 questionsWhat hardware do I need?
A standard tablet at each clocking point: an Android tablet (Android 8.0 or later, ideally 10 to 11 inch with a front camera) running the TempClock kiosk app, or an iPad running the kiosk in the browser. Add a lockable stand, permanent power and, for 24/7 sites, a 4G failover router. A USB badge reader and NFC cards are optional. There are no proprietary terminals, and workers need no app to clock in.
How long does it take to go live?
A single small site can be configured in a day. For a multi-site agency we run a planned onboarding: configuration and rate checks, a Sage test import, a pilot site with 2 to 4 weeks of paper running alongside, then the other sites one at a time. For four sites that is typically 13 to 15 weeks from contract to paper being retired. We agree the timetable with you at the start.
What does onboarding involve?
Setting up your sites, pay and charge rates, pay week and Sage codes; importing workers from a spreadsheet (with a preview that checks every row first); enrolling workers for face clock-in or setting PINs; installing kiosks; training coordinators, payroll and client supervisors; and a pilot with paper running alongside so every difference is explained before paper stops.
Can I see it working before committing?
Yes. We can walk you through the full system with sample data shaped like yours, and run a pilot at one site before you roll out further. Talk to us and we will arrange it.
How It Works
8 questionsHow does face clock-in work?
The worker enters their badge number (typed, scanned from a QR badge, or tapped with an NFC card), then looks at the camera. The photo is matched by a major cloud provider's face-matching service, hosted in Ireland, against that client's enrolled workers, and the clock is accepted only if the best match is the badge holder. The photo is then discarded. In our production measurements the face match itself took a median of 0.36 seconds (95% within 0.58 seconds). From one worker to the next at the same kiosk, the fastest gap was 8 seconds and a good queue ran at about 11 seconds, so we plan on about 4 workers a minute per kiosk at a shift change.
How are workers enrolled?
The worker gets a one-time link (by email, text or a QR code shown by a supervisor), reads the face clock-in notice and chooses whether to agree. If they agree, a short video selfie on their phone passes a liveness check that proves a real person is present, and their face template is created. If they decline, they set a PIN instead.
What happens if the camera or internet does not work?
Workers can clock in with their badge and PIN; each PIN clock takes a photo and is flagged for review. If the face-matching service is unreachable the kiosk switches to PIN-only and alerts you. If a face-verified clock cannot be sent, the kiosk keeps it and sends it, with the original time, when the connection returns. If the kiosk cannot reach the server at all, it says so and points people to the paper sign-in sheet, which you key in afterwards on the Backfill page.
Does it stop buddy clocking?
It makes it much harder, but no system makes it impossible. A face clock only succeeds when the face matches the badge holder, and a mismatch is refused and logged. You can switch on an optional anti-photo movement check at the kiosk, and set clients to require a valid match before a clock is accepted. PIN clocks remain available as a fallback, so every PIN clock is photographed and listed on the Exceptions page for review.
How do I adjust the face matching threshold?
Each client has its own match threshold. The default is 90%, which keeps the risk of a false match low at the cost of an occasional retry in poor lighting. You can change it in the face recognition settings; changes take effect immediately. In our production measurements about 18% of match attempts were refused and retried, mostly in poor lighting or with the face at an angle.
What face recognition technology do you use?
Matching and the enrolment liveness check use a major cloud provider's face-matching service, hosted in Ireland (eu-west-1). We do not build our own face model. Our privacy policy and data processing agreement name the provider as a sub-processor.
What if someone changes their appearance?
Face templates cope well with glasses, facial hair and hairstyle changes. If a worker starts failing to match, a coordinator sends them a re-enrolment link and they take a fresh video selfie on their phone.
What face data is stored, and where?
The face template is held by the face-matching service in Ireland, in a separate collection for each client. TempClock keeps the enrolment reference photo and the photo taken at each PIN clock or phone clock-in, in your instance hosted in the UK, visible only to users with access to that worker or site. The photo taken at a face clock-in is not kept. Face templates and reference photos are deleted within 4 hours of a worker being made inactive, and at once if they withdraw consent. PIN clock photos are kept for 90 days by default; you set the periods in Data retention.
Features
16 questionsCan I use TempClock at multiple sites?
Yes. Each site is a location with its own address, geofence, kiosk settings and rules, and every clock is recorded against the site where it happened. Workers can move between sites and their hours are split by site for payroll and invoicing. Everything flows into one agency console.
Can my clients approve timesheets?
Yes. The client portal lets your clients approve, reject, query or propose an amendment to their workers' hours, limited to the sites each user is allowed to see. Portal users are Approvers, Supervisors or Viewers. Clients see hours and charges, never pay rates. You can require client approval before hours go to payroll.
Can workers see their shifts?
Yes, if you switch on worker self-service for a client. Workers sign in with a one-time link and can see their shifts, confirm or decline them, accept cover offers, set their availability, request time off and check their hours, in English, Polish, Romanian or Lithuanian. Clocking in from a phone is a separate option, off by default; when on, it needs a face match, GPS within the site geofence, a registered phone and a booked shift.
How do visitors and contractors sign in?
The kiosk has separate flows for visitors and contractors. Visitors enter their name, company and who they are visiting. Contractors also record their trade, permit number and induction status. Both appear on that site's fire register until they sign out.
What reports can I generate?
Timesheets, payroll with pay elements, margin, spend, charge schedules, attendance and fulfilment, overtime, exceptions, working time, AWR tracking, reliability, cancellations, occupancy and workforce insights. Most can be exported as CSV, and several can be emailed on a schedule.
Can I set different rates for different clients?
Yes. Rate rules set pay and charge rates per client, site, job role or cost code, with overtime (daily and weekly), weekend, Sunday, bank holiday and night premiums as a multiplier or a fixed rate. You can import a rate card from CSV with a preview step.
How does overtime calculation work?
You set daily and weekly thresholds in rate rules. Daily overtime is the time beyond a set number of hours in one shift; weekly overtime applies once a worker passes the weekly threshold in your pay week, counting paid time in clock-in order. The payroll screen, the Sage file and the overtime report all use the same calculation.
Can I track margins between pay and charge rates?
Yes. Pay rates and charge rates are kept separately. The margin report shows pay cost, charge and margin by client, site and worker, and warns you about shifts that have no charge rate. Clients on the portal only ever see charges.
How does GPS geofencing work?
Each site can have a centre point and a radius. When a kiosk clocks someone, TempClock records the device location and the distance from the site. In warning mode an off-site clock is recorded and flagged; in strict mode it is refused. Phone clock-in, where switched on, always requires the phone to be inside the site geofence.
Can I send messages to workers when they clock in?
Yes. Clock messages show a notice at the kiosk. You can target them at workers, sites or clients, show them at clock-in, clock-out or both, and set start and end dates.
What are kiosk surveys?
Short questions shown at clock-in or clock-out, such as a fit-to-work declaration or a safety briefing check. A question can be set as blocking, so a particular answer refuses the clock-in and asks the worker to see a supervisor. Responses are kept per worker and can be exported.
What languages does the kiosk support?
The kiosk screens are available in English, Polish, Romanian and Lithuanian. You set a default language for each site, and the kiosk switches to a worker's own language once their badge is entered. Messages and survey questions you write are shown as you wrote them. Worker names with accented letters are stored correctly.
Can a worker request all the data you hold about them?
Yes. From Workers, Privacy (GDPR), an authorised user can produce a subject access export for a worker: a ZIP with their record, clock events, documents, photos and audit entries. The same page records or withdraws consent, deletes face data and anonymises leavers. The action is logged.
Does TempClock support two-factor authentication?
Yes, on the agency console, client dashboard and client portal. It uses an authenticator app (TOTP), with 10 single-use backup codes and optional 30-day trusted devices that can be revoked. It is compulsory for agency administrators, and you can make it compulsory for other users.
How does worker document tracking work?
You define document types (right to work, DBS, CSCS, driving licence and so on) and upload documents per worker with expiry dates. TempClock alerts you before and when a document expires.
Can I watch a live camera feed from a kiosk?
Only if you switch it on. The kiosk camera feed is off by default and is switched on per site. When on, agency staff and that client's own users can watch it, and frames are deleted after 24 hours by default.
Pricing & Billing
6 questionsHow does billing work?
TempClock costs £150 per active site per month, with every feature included. On top, each month there is a per-worker charge only for workers who clock a shift on 2 or more different days in that month: 45p each for the first 50 such workers, 35p each for workers 51 to 250 and 25p each above 250. Workers who clock on only one day that month are not charged. At 10 or more sites the site charge drops by 25% to £112.50. All prices exclude VAT.
What would four sites cost?
With 4 sites the site charge is £600 a month. With 600 workers clocking on 2 or more days in a month the per-worker charge is £180, so £780 in total; with 1,200 workers it is £930; with 1,500 workers it is £1,005 (all ex VAT). Use the calculator on the pricing page for your own numbers.
Is SMS included?
Email notifications are included. Text messages to workers (shift reminders, offers, confirmations) are an optional add-on at £25 a month, pro rata for the days it is on, plus 8p per SMS segment sent. It is off unless you ask for it.
How is support provided?
Through support tickets raised in the app, the kiosk "Report an issue" button and email. P1 issues (clocking stopped at a site, the system down, or a suspected data breach) get a first response within 30 minutes from 07:00 to 22:00 UK time and within 2 hours overnight, every day of the year, with a fix or workaround within 4 hours of the response. Other issues are handled in business hours (Monday to Friday, 08:00 to 18:00 UK time) with published response times. See our terms.
Can I add or remove sites?
Yes. Each additional site is £150 a month (less 25% at 10 or more sites). If you deactivate a site, billing for it stops at the end of that billing month.
What counts as an active site?
An active location in your account, where workers can clock in. Deactivated locations are not charged.
Privacy & Compliance
2 questionsIs TempClock GDPR compliant?
TempClock is built to support your UK GDPR obligations as controller: a versioned face clock-in notice with recorded consent, a PIN alternative, retention periods you set, subject access exports, anonymisation and an audit log. We act as your processor under a data processing agreement, and a DPIA template is available on request. The app and database are hosted in a UK data centre; face matching runs in Ireland. Our sub-processors are listed in our privacy policy.
How do I get my data into Sage or Xero?
Close the pay week and download the payroll file: one line per worker per pay element (basic, overtime, nights, weekend, bank holiday) using your Sage payment codes, from approved hours only. It is built for Sage 50 Payroll's import, and there is a Sage Payroll (cloud) layout that we test-import with you during setup. For client invoicing, the charge schedule produces Sage 50 Accounts and Xero sales invoice CSV files. TempClock also connects to Sage Accounting (cloud) through Sage's API to send invoices and read back paid status; a send button on the charge schedule screen is being added.
Still have a question? Talk to us.
Know who turned up, and pay every hour right.
Face-verified clock-ins, live geofencing and payroll-ready timesheets in one system. Tell us how your shifts run and we will show you how it fits.
App hosted in the UK · Onboarding led by a pilot site · No app needed to clock in