Privacy Policy

Effective July 17, 2026

1. Introduction and Scope

This Privacy Policy explains how AcznTeams, operated by RCME Legacy LLC ("we", "us", "our"), collects, uses, discloses, and protects information in connection with the App. It applies to personal information we process about Users, including Employers, their administrators, and Team Members.

2. Definitions

In addition to terms defined elsewhere in this Policy, the following terms have the meanings given below when used with an initial capital letter:

“App” or “Service” means the AcznTeams workforce-management application delivered through iOS, Android, and the web at app.acznteams.com, together with the marketing site at acznteams.com.

“Company,” “we,” “us,” and “our” mean RCME Legacy LLC, a Hawaii limited liability company that operates the App.

“Employer” means a business customer that subscribes to the App and invites Team Members into its Workspace.

“Administrator” or “Admin” means a Team Member designated by the Employer with elevated permissions to manage the Workspace.

“Team Member” means an individual (typically an employee, contractor, or manager of an Employer) who accesses the App through the Employer’s Workspace.

“User” means any person who uses the App, including Employers, Administrators, and Team Members.

“Workspace” means the tenant instance of the App provisioned for a single Employer.

“Personal Information” means information that identifies, relates to, describes, or could reasonably be linked with a particular person or household. We use “Personal Information” and “personal data” interchangeably in this Policy.

“Sub-processor” or “Service Provider” means a third-party vendor we engage to process Personal Information on our behalf under written contract.

“Sensitive Personal Information” has the meaning given under applicable U.S. state privacy laws and, for the App, is limited to precise geolocation captured at clock-in/out and account log-in credentials (stored in hashed form).

3. Our Role: Controller and Processor

Roles: For most personnel data in a workspace, the Employer that invited you is the "controller" (or "business"), and we act as its "processor"/"service provider", processing data on the Employer's instructions. For limited purposes — such as account registration, billing, security, and operating and improving the Service — we act as a controller. Where the Employer is the controller, please also review the Employer's own privacy notices and direct rights requests to the Employer; we will assist as required.

4. Information we collect

Account information: name, email address, phone number, job role, department, location assignment, employment status, and wage (where provided by you or your Employer), and login credentials (stored in hashed form).

Work data: shifts, schedules, time punches, tasks, training and quiz results, availability, time-off requests, scorecards, points, rewards, announcements, and messages you send within the App.

Location data: when you tap clock-in or clock-out, we collect your device's precise location at that moment (foreground only) to verify you are within your Employer's designated work area (geofence). We do not collect location in the background, before or after the clock-in/out event, or when you are not actively using that feature.

Payment information: for paid plans, billing contact and subscription details. Card numbers are collected and processed by our payment processor; we do not store full card numbers.

Device & usage data: a push-notification token (if you enable notifications), and basic technical and log information (such as app version, device type, and event timestamps) needed to operate, secure, and troubleshoot the App.

We do not collect biometric identifiers, and the App's geofencing relies on device location, not biometrics.

5. Sources of information

We collect information directly from you (e.g., when you register, update your profile, or use features), from your Employer (e.g., when an administrator creates your account or sets your role, location, or wage), and automatically from your device (e.g., location when you clock in, push token, and log data).

6. How we use information

To provide and operate the App's features — scheduling, time and attendance, tasks, training, recognition, messaging, and notifications; to verify clock-in location against your Employer's geofence; to authenticate users and secure accounts; to process subscriptions and payments; to provide support and send service-related communications such as password-reset codes; to maintain, troubleshoot, and improve the Service; to detect, prevent, and address fraud, abuse, and security incidents; and to comply with legal obligations.

7. Automated decision-making and profiling

Automated processing: scorecards and points are generated automatically from work data to summarize performance for your Employer. We do not use this to make decisions producing legal or similarly significant effects about you; any employment decisions are made by your Employer, which is responsible for them.

We do not use Personal Information for automated decision-making that produces legal or similarly significant effects about you within the meaning of Article 22 GDPR or U.S. state privacy laws (for example, hiring, firing, promotion, discipline, or compensation decisions). Where an Employer uses App outputs (such as scorecards or points) to inform employment decisions, the Employer is the decision-maker and is responsible for its own compliance, including any human review, explanation, or opt-out rights that apply to it.

8. Advertising, sale, and "sharing"

We do not sell your personal information for money. We do not use the personal information inside the App — your work data, messages, location, scorecards, or any Team Member information — for advertising, and we do not build advertising profiles from it.

The one exception is our marketing website (acznteams.com). If you consent through our cookie banner, that website loads the Meta Pixel (provided by Meta Platforms, Inc.), which we use to measure our advertising, understand which visits lead to sign-ups, and reach similar audiences on Meta's platforms. Under some U.S. state privacy laws — including the California Consumer Privacy Act, as amended (CCPA/CPRA) — using the Meta Pixel this way may be considered a "sale" or a "share" for cross-context behavioral advertising. We do not treat it as a sale for money, but we treat it as "sharing" and give you a way to opt out.

How to opt out. You can decline the Meta Pixel at any time by clicking "Decline" on our cookie banner (or by not accepting it), which prevents it from loading. Where required by law, we also honor the Global Privacy Control (GPC) browser signal as a request not to load it. The Meta Pixel is used only on our marketing website — never inside the App, on app.acznteams.com, or in our mobile apps. See our Cookie Policy for details. If our other practices change, we will update this Policy and provide any required opt-out mechanisms before doing so.

9. Legal bases for processing (EEA/UK)

Where the EU/UK GDPR applies and we act as a controller, we process personal information on the following bases: performance of a contract (to provide the App and account); our legitimate interests (to secure, operate, and improve the Service and prevent abuse), balanced against your rights; your consent (for example, device location and push notifications, which you can withdraw at any time); and compliance with legal obligations. Where the Employer is the controller, the Employer is responsible for establishing the legal basis for its processing.

10. How we share information

With your Employer: administrators in your workspace can access the account and work data described above for their business.

With service providers (sub-processors): we use trusted vendors who process data only on our behalf and under written contract. Our current sub-processors are: application hosting and content delivery — Render (hosting) and Cloudflare (DNS/CDN); database — Neon; payments — Stripe (which collects and processes card data; we do not store full card numbers); transactional email (e.g., password resets) — Resend; mobile builds and push notifications — Expo/EAS; and internal business tools — Google Workspace. This list may be updated from time to time; the current list is available on request.

For legal and safety reasons: we may disclose information to comply with law, regulation, legal process, or governmental request, or to protect the rights, property, safety, or security of users, the public, or AcznTeams.

Business transfers: if we are involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to this Policy.

11. Sub-processors

We use a limited number of Sub-processors to help us operate the App. The current list of Sub-processors and the functions they perform is set out in Section 10. We select Sub-processors that we believe provide appropriate technical and organizational security. Before we engage a Sub-processor, we enter into a written contract that imposes, at minimum: (i) confidentiality obligations at least as protective as this Policy; (ii) use of Personal Information only for the purposes we specify and only on our documented instructions; (iii) reasonable security measures appropriate to the categories of Personal Information processed; (iv) assistance to us in responding to User rights requests, security incidents, and regulator inquiries; (v) restrictions on onward transfer of Personal Information to further sub-processors without our prior authorization; and (vi) deletion or return of Personal Information at the end of the engagement.

We remain responsible to you for the acts and omissions of our Sub-processors to the extent required by applicable law. Card payment data is collected and processed directly by Stripe under Stripe’s own privacy policy and PCI-DSS compliance program; we do not receive or store full card numbers.

12. Location data and electronic monitoring

Location capture. The App collects your device’s precise geolocation only in the foreground and only at the moment you tap clock-in or clock-out, for the sole purpose of verifying you are inside your Employer’s designated work area (geofence). We do not collect location before you initiate clock-in/out, after clock-in/out completes, in the background, or while the App is closed. You can revoke location permission at any time in your device settings; if you do, clock-in/out features that rely on location may not work.

Electronic monitoring notice (Employer responsibility). The App’s location and time-tracking features are workplace-monitoring tools deployed by the Employer. Several U.S. states require employers to give their own written notice to employees before conducting electronic monitoring (for example, New York Civil Rights Law § 52-c, Connecticut Gen. Stat. § 31-48d, and Delaware Code Ann. tit. 19 § 705). Providing that notice, and obtaining any required acknowledgment, is the Employer’s obligation, not ours. We provide the tools; the Employer is the controller of the monitoring program and is responsible for lawful use, including any consent, notice, or works-council requirements that apply in the Employer’s jurisdiction. If you have questions about the monitoring program in your Workspace, please contact your Employer.

Wage-and-hour records. Location data captured at clock-in/out is retained as part of the Employer’s wage-and-hour records and is available to the Employer’s Administrators. We do not use this data to profile Team Members or to make decisions about them.

13. Push notifications and communications

Push notifications. If you enable notifications, we deliver in-app and system push notifications through Expo/EAS using the push token issued by Apple (APNs) or Google (FCM). Push tokens do not identify you outside the App and are used only to route notifications to your device. You can disable push notifications at any time in your device settings; if you do, you may miss shift reminders, schedule changes, and other operational messages.

Transactional email. We use Resend to send transactional emails such as account verification, password-reset codes, security alerts, and service notices. Because these communications are necessary to operate the account, they are not marketing communications and there is no opt-out while your account is active.

Marketing. We do not send marketing emails or promotional push notifications to Team Members. If we contact business decision-makers about the App itself (for example, product updates for Administrators), we will include an unsubscribe mechanism where required by the CAN-SPAM Act, 15 U.S.C. §§ 7701–7713.

14. User content and team chat

Content. The App enables Users to create and share content including team chat messages, announcements, task notes, training and quiz responses, uploaded company logos, and similar workplace content (collectively, “User Content”). User Content is stored on our infrastructure and is accessible to Administrators of the Workspace in which it was created.

Employer visibility. Administrators can view, export, moderate, retain, and delete User Content in their Workspace, including private direct messages between Team Members. Team Members should not use the App for personal communications and should not have an expectation of privacy in User Content vis-à-vis their Employer.

Our use. We access User Content only as needed to operate, secure, and troubleshoot the App; to detect abuse, spam, or security threats; to enforce our Terms of Service; or as required by law. We do not use User Content to train artificial-intelligence models, to build advertising profiles, or for any commercial purpose beyond operating the App.

Prohibited content. Users must not upload content that is unlawful, infringing, harassing, or discriminatory, or that includes categories of Personal Information the App is not designed to hold, such as Social Security numbers, government-issued identification numbers, payment card numbers, health information, or biometric identifiers.

15. Sensitive Personal Information

Categories collected. The only categories of Sensitive Personal Information the App collects are (i) precise geolocation captured at clock-in/out (see Section 12) and (ii) account log-in credentials (stored in hashed form). We do not collect Social Security numbers, driver’s license numbers, financial account numbers, biometric identifiers, genetic data, health or medical information, information about race, ethnicity, religion, philosophical beliefs, union membership, sexual orientation, or immigration status.

Purpose limitation. We use Sensitive Personal Information only for the purposes described in this Policy — to verify clock-in/out location against the Employer’s geofence and to authenticate the User. We do not use Sensitive Personal Information to infer characteristics about a User, to profile a User, or for advertising.

Rights. Because we use Sensitive Personal Information only for the permitted business purposes described in Cal. Civ. Code § 1798.121 and equivalent U.S. state laws, we do not currently offer a separate right to limit its use and disclosure. If you believe an Employer is requesting Sensitive Personal Information beyond what the App is designed to hold, please contact your Employer; if the issue is not resolved, contact us.

16. International data transfers

We operate in the United States, and information may be processed in the U.S. and other countries that may have different data-protection laws than yours. Where we transfer personal information out of the EEA, UK, or Switzerland, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK Addendum) or another lawful transfer mechanism. Contact us for more information.

17. Data retention

We retain personal information for as long as your account is active and as needed to provide the App to your Employer, and thereafter as necessary to comply with legal, payroll, tax, and recordkeeping obligations, resolve disputes, and enforce agreements. Where we act as processor, your Employer determines retention of work records within its workspace. When information is no longer needed, we delete or de-identify it.

Downgrading or cancelling a paid subscription does not, by itself, delete your workspace data. When you downgrade or cancel, your account remains active on a lower-tier or free plan and your existing content is retained (access to certain paid features may be disabled), subject to this Policy and applicable law. Data is deleted or de-identified following full account termination as described above and in the Terms of Service.

18. Data security

We implement reasonable and appropriate technical and organizational measures designed to protect Personal Information against unauthorized or unlawful processing and accidental loss, destruction, damage, alteration, or disclosure. These measures include encryption of passwords using industry-standard hashing, encryption in transit (TLS), access controls and least-privilege permissions, logging and monitoring, workforce confidentiality obligations, and vendor security review. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security. You are responsible for keeping your log-in credentials and clock-in PIN confidential and for notifying us promptly of any suspected unauthorized use of your account.

19. Breach notification

If we determine that a breach of security has resulted in the unauthorized acquisition of, or access to, Personal Information that we hold, we will notify affected individuals, Employers (where we act as their processor), and regulators as and when required by applicable law. Applicable laws include the Hawaii breach-notification statute (Haw. Rev. Stat. §§ 487N-1 et seq.), the California breach-notification statute (Cal. Civ. Code §§ 1798.29, 1798.82), and the breach-notification laws of other U.S. states in which affected residents reside.

Where we act as processor for an Employer, we will notify the Employer of a security incident affecting its Workspace without undue delay after becoming aware of it and will provide the information the Employer reasonably needs to comply with its own notification obligations. The Employer, as controller, is responsible for notifying its Team Members and any regulators to the extent required by law.

20. Your privacy rights (EEA/UK and similar)

If you are in the EEA, UK, or a similar jurisdiction, you may have rights to: access your personal data; correct inaccurate data; delete data; restrict or object to processing; data portability; and withdraw consent at any time (without affecting prior processing). You also have the right to lodge a complaint with your local data-protection supervisory authority. Where the Employer is the controller, please direct these requests to your Employer; we will assist as required.

21. Your privacy rights (U.S. state residents)

Depending on your state of residence (e.g., California, Virginia, Colorado, Connecticut, Utah, Texas, and others with comprehensive privacy laws), you may have rights to: know/access the personal information we hold about you and how we use and disclose it; correct inaccuracies; delete personal information; obtain a portable copy; and opt out of sale, sharing for cross-context behavioral advertising, or certain profiling. We do not sell personal information for money or use it for profiling; we do "share" limited information through the consent-based Meta Pixel on our marketing website, which you can opt out of at any time by declining our cookie banner (see Section 8 and our Cookie Policy). We do not discriminate against you for exercising these rights.

California (CCPA/CPRA): we do not sell personal information for money, and we do not use or disclose sensitive personal information for purposes requiring an opt-out. If you consent to the Meta Pixel on our marketing website, we may "share" limited website and device information for cross-context behavioral advertising as defined by the CCPA; you can opt out at any time by declining our cookie banner (see Section 8). Categories of personal information we collect are described in Section 1; purposes in Section 3; and disclosures in Section 5.

Other states with comprehensive laws. Comprehensive privacy laws in Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Indiana, Tennessee, New Jersey, Kentucky, Rhode Island, Minnesota, Maryland, and Nebraska provide similar rights to access, correction, deletion, portability, and opt-out of certain processing. To exercise these rights, use the contact details in Section 25; we will handle your request in accordance with the applicable state law, including its authenticated-request and appeal procedures.

Washington (My Health My Data Act). Washington’s My Health My Data Act (Wash. Rev. Code Ch. 19.373) regulates “consumer health data.” The App is not designed for consumer health data and we do not collect it. Location captured at clock-in/out is used exclusively for workforce timekeeping and geofence verification and is not used to infer health, medical, or reproductive information.

Nevada. Nevada residents have the right under Nev. Rev. Stat. § 603A.340 to direct businesses not to sell certain covered information about them. We do not sell Personal Information as defined by Nevada law, so no separate opt-out is required; to submit a request in any event, use the contact details in Section 25.

California (CCPA/CPRA) additional disclosures. In addition to the rights listed above, California residents have the right to know the categories of Personal Information we have collected, sold, or shared in the preceding 12 months (see Section 4 for the categories; we do not sell Personal Information for money, and the only "sharing" is the consent-based Meta Pixel described in Section 8); the categories of sources of that information (see Section 5); the business or commercial purposes for collecting or sharing it (see Section 6); and the categories of third parties with whom we disclose it (see Sections 10 and 11). We do not use or disclose Sensitive Personal Information for purposes that would trigger a right to limit under Cal. Civ. Code § 1798.121 (see Section 15). Metrics on rights requests received under the CCPA/CPRA are available on request.

How to exercise rights: contact us at the address below. You may use an authorized agent where permitted. We will verify your request by reasonable means and may decline where an exception applies. Where applicable, you may appeal a decision by replying to our response. Because much workplace data is controlled by your Employer, certain requests may be directed to your Employer.

22. Cookies & similar technologies

Our mobile apps do not use advertising cookies, ad-tracking SDKs, or third-party analytics, and neither does our web application (app.acznteams.com). Our marketing website (acznteams.com) uses strictly necessary and functional cookies to operate the site (for example, to keep you signed in and to remember basic preferences), plus one optional advertising cookie — the Meta Pixel — that loads only if you consent through our cookie banner. You can control cookies through your browser settings and can decline the Meta Pixel through our banner. Where required by law, we honor recognized opt-out preference signals (such as Global Privacy Control) as a request not to load the Meta Pixel, and we do not respond to other "Do Not Track" signals. See our Cookie Policy for full details.

23. Children's privacy

The App is intended for adults 18 years of age and older. It is not directed to, and is not intended to be used by, anyone under 18, and we do not knowingly collect personal information from anyone under 18. If you believe a child has provided us personal information, contact us and we will take appropriate steps to delete it.

24. Third-party links

The App or related communications may link to third-party sites or services that we do not control. Their privacy practices are governed by their own policies, and we are not responsible for them.

25. Changes to this Policy; Contact us

We may update this Privacy Policy from time to time. Material changes will be indicated by updating the "Effective" date above and, where appropriate, by additional notice. Your continued use of the App after changes take effect constitutes acceptance of the updated Policy.

For privacy questions or to exercise your rights, contact RCME Legacy LLC at [email protected]. If you are in the EEA or UK and wish to raise a concern, you may also contact your local data-protection authority.