Facial Recognition Explained
How TempClock enrols a worker's face, how a kiosk clock is matched to the badge holder, the settings you control, what is stored and where, and what affects accuracy.
Overview
A cloud face-matching service, used with care.
TempClock uses a major cloud provider's face-matching service, hosted in Ireland, to check that the person at the kiosk is the worker whose badge was entered. We do not build our own face model. Face clock-in is optional for every worker: anyone who says no clocks in with their badge and a PIN, or a supervisor clocks them in. The provider is named in our privacy policy.
Enrolment
With a notice, consent and a liveness check.
The worker gets a link
A coordinator sends a one-time set-up link by email or text, or shows a QR code for the worker to scan in person. Links can also be sent in bulk.
They read the notice and choose
Before any camera use, the worker sees a versioned notice: what is captured, why, who processes it and where, how long it is kept, that it is optional, and how to withdraw. Their answer is recorded with the notice version. If they decline, they set a PIN instead and their coordinator is told.
A short video selfie
If they agree, a short video selfie on their phone passes a liveness check that proves a real person is present, and their face template is created in that client's own face collection. A reference photo is kept so authorised staff can check who is enrolled.
Matching at the Kiosk
The face must be the badge holder.
Settings
Setup > Face recognition (agency console).
| Setting | What it does |
|---|---|
| Per-client threshold | How close a match must be. 90% by default. The Face dashboard shows match rates per client before you change it. |
| Anti-spoof check | Takes two frames about 300 ms apart and refuses a still photo or screen held up to the camera. Off by default; can be set per site. |
| PIN clocking (per client) | PIN allowed, supervisor check (each PIN clock flagged for review), or not allowed (face only). |
| Face match proof (per client) | Off, Log (flag clocks without a valid match from the kiosk) or Enforce (refuse them). |
What Is Stored
And for how long, by default.
| Item | Where | Kept |
|---|---|---|
| Face template | The face-matching service, Ireland, in the client's own collection | While the worker is active or dormant; deleted within 4 hours of leaving, at once on withdrawal |
| Enrolment reference photo | Your TempClock instance, UK | As the face template |
| Photo taken at a face clock | Not stored | Discarded after matching |
| PIN clock photo, and phone clock-in selfie (if phone clock-in is on) | Your TempClock instance, UK | 90 days |
| Match score and outcome | Your TempClock instance, UK | 90 days |
You set these periods in Data retention.
Getting Good Matches
Most problems are light and position.
Honest Limits
What face matching does not do.
Know who turned up, and pay every hour right.
Face-verified clock-ins, live geofencing and payroll-ready timesheets in one system. Tell us how your shifts run and we will show you how it fits.
App hosted in the UK · Onboarding led by a pilot site · No app needed to clock in