Kiosk & Clock-In

Facial Recognition Explained

How TempClock enrols a worker's face, how a kiosk clock is matched to the badge holder, the settings you control, what is stored and where, and what affects accuracy.

Talk to us Browse all guides

Overview

A cloud face-matching service, used with care.

TempClock uses a major cloud provider's face-matching service, hosted in Ireland, to check that the person at the kiosk is the worker whose badge was entered. We do not build our own face model. Face clock-in is optional for every worker: anyone who says no clocks in with their badge and a PIN, or a supervisor clocks them in. The provider is named in our privacy policy.

Enrolment

With a notice, consent and a liveness check.

The worker gets a link

A coordinator sends a one-time set-up link by email or text, or shows a QR code for the worker to scan in person. Links can also be sent in bulk.

They read the notice and choose

Before any camera use, the worker sees a versioned notice: what is captured, why, who processes it and where, how long it is kept, that it is optional, and how to withdraw. Their answer is recorded with the notice version. If they decline, they set a PIN instead and their coordinator is told.

A short video selfie

If they agree, a short video selfie on their phone passes a liveness check that proves a real person is present, and their face template is created in that client's own face collection. A reference photo is kept so authorised staff can check who is enrolled.

Matching at the Kiosk

The face must be the badge holder.

The worker enters their badge, then the kiosk takes a photo.
The photo is searched against that client's enrolled workers. The clock goes ahead only if the best match is the badge holder, at or above the client's threshold (90% by default).
If the best match is someone else, the clock is refused, no identity is shown, and the refusal is logged. You can add an automation rule to email you when this happens.
The photo is discarded after matching. The match score and outcome are kept with the clock.

Settings

Setup > Face recognition (agency console).

Setting What it does
Per-client threshold How close a match must be. 90% by default. The Face dashboard shows match rates per client before you change it.
Anti-spoof check Takes two frames about 300 ms apart and refuses a still photo or screen held up to the camera. Off by default; can be set per site.
PIN clocking (per client) PIN allowed, supervisor check (each PIN clock flagged for review), or not allowed (face only).
Face match proof (per client) Off, Log (flag clocks without a valid match from the kiosk) or Enforce (refuse them).

What Is Stored

And for how long, by default.

Item Where Kept
Face template The face-matching service, Ireland, in the client's own collection While the worker is active or dormant; deleted within 4 hours of leaving, at once on withdrawal
Enrolment reference photo Your TempClock instance, UK As the face template
Photo taken at a face clock Not stored Discarded after matching
PIN clock photo, and phone clock-in selfie (if phone clock-in is on) Your TempClock instance, UK 90 days
Match score and outcome Your TempClock instance, UK 90 days

You set these periods in Data retention.

Getting Good Matches

Most problems are light and position.

Mount the tablet at face height, facing away from windows and bright lights behind the worker.
Use the kiosk's ring light setting in dim entrances.
Ask workers to remove sunglasses and face the camera straight on.
If a worker keeps failing, send them a re-enrolment link and they take a fresh video selfie.
Check the Face dashboard for clients whose match rate is low before lowering their threshold.

Honest Limits

What face matching does not do.

In our production data about 18% of match attempts were refused first time and retried, mostly because of light or angle.
The liveness check runs at enrolment. At the kiosk, the anti-photo check is optional and off by default.
No system makes buddy clocking impossible. PIN clocks stay available as an alternative, which is why each one is photographed and flagged.
No accuracy figures by demographic group are published, and no third-party certification is held.

Know who turned up, and pay every hour right.

Face-verified clock-ins, live geofencing and payroll-ready timesheets in one system. Tell us how your shifts run and we will show you how it fits.

App hosted in the UK · Onboarding led by a pilot site · No app needed to clock in