Privacy Policy

Last updated: 30 September 2026

1. Who we are

BunkerCheck (also offered at check360.bunker360.com) is a business-to-business workforce attendance service. It is operated by:

BUNKER360 LLC, a Florida limited liability company (Florida document number L15000189973)

5727 NW 7th St, Suite 320, Miami, FL 33126, USA

Website: bunker360.com · Product: check360.bunker360.com

Email: cto@bunker360.com · Phone: +972 52 790 2029

In this policy, “BunkerCheck”, “we”, “us” and “our” mean BUNKER360 LLC. “Customer” means the business that opens a BunkerCheck account to manage attendance of its own workforce.

2. Scope and our role

  • Workforce data. When a Customer uses BunkerCheck to record attendance of its employees, the Customer decides what data is collected and why. For that data we act as a service provider (processor) on the Customer’s behalf and only process it to provide the service to that Customer.
  • Account and alert data. For the people who administer a Customer account and for the people who receive alerts, and for visitors of our public pages, we are responsible for the data described in this policy.
  • If you are an employee of one of our Customers, your employer is your first point of contact for questions about your attendance data. You can also write to us (section 17) and we will forward or help with your request.

3. Information we process

3.1 Account users (Customer administrators and managers)

  • Name, business email address, company name and, if provided, mobile phone number.
  • Login credentials: passwords are stored only as a salted hash; one-time login codes are sent by email.
  • Settings you choose (sites, alert preferences, language) and a record of sensitive configuration changes (audit log).

3.2 Employees of our Customers (entered by the Customer or captured by the mobile app)

  • Profile data the Customer enters, such as name, contact details, identification data, work profile and pay rate, and, where the Customer uses it, an image of an identity document.
  • Check-in and check-out records: date and time, the work site, the GPS location of the device at that moment and the distance to the site.
  • A photo taken at check-in and check-out, used to verify that the right person is checking in (see section 4).
  • Failed check-in attempts (for example, outside the site radius or face not matched), with time and location.

3.3 Alert recipients

  • Name, email address and/or mobile phone number of the business owners, supervisors or managers that an account administrator adds as alert recipients, their language, the sites they follow and the alerts they chose.
  • Consent and verification records: the version of the consent text, date and time, the administrator who recorded the consent, the IP address, and the result of the one-time code verification of the mobile number.
  • Delivery records of each alert (channel, status, time) and opt-out / opt-in history.

3.4 Technical data

  • A session cookie that keeps you logged in, IP address and browser information used for security, rate limiting and consent evidence.

Demo accounts use only synthetic data (fictitious people, emails and phone numbers, no photos).

4. Face photos and biometric information

  • A Customer may enroll an employee’s face photo so that check-in photos can be compared with it. The comparison is performed with Amazon Rekognition, a service of Amazon Web Services (AWS).
  • Face enrollment requires that the Customer’s administrator confirm the employee’s biometric consent; that confirmation is recorded in our audit log. The Customer is responsible for giving employees any notice and obtaining any written consent required by the laws that apply to it.
  • Face data is used only to verify identity at check-in for that Customer. We do not sell, lease, trade or otherwise profit from biometric information, and we do not use it for marketing or advertising.
  • When an employee is deactivated, their face data is removed from the face comparison collection. Enrollment photos and check-in photos are kept while the employee is active and are permanently destroyed no later than 1 year after the employee is deactivated, and in any case within 3 years of the individual's last interaction with the service.

5. Location information

The BunkerCheck mobile app reads the device’s GPS location only at the moment of a check-in or check-out attempt, to confirm that the person is within the radius of the work site. We do not track employees continuously or outside of those moments. Site addresses entered by Customers are converted to map coordinates using AWS Location Service.

6. How we use information

  • To provide the service: record attendance, show the live view and reports, and detect operational events (for example, a location that did not open on time, repeated failed check-ins, open shifts, or sensitive configuration changes).
  • To send operational alerts by email and, for recipients who consented and verified their number, by SMS (section 7).
  • To authenticate users, keep the service secure, prevent fraud and abuse, and keep audit records.
  • To provide support and communicate with Customers about their account and the service.
  • To comply with legal obligations.

A check-in outside the site radius is automatically blocked and recorded as a failed attempt; the Customer can review these records. We do not sell personal information, we do not use it for advertising, and we do not use workforce data for any purpose other than providing the service to the Customer.

7. SMS program: BunkerCheck Alerts

  • Program name: BunkerCheck Alerts.
  • Who receives messages: business owners, supervisors and managers that a Customer’s account administrator adds as alert recipients. A mobile number receives alerts only after (1) the administrator records the person’s explicit consent to receive alerts, and (2) the person verifies the mobile number by entering a one-time code sent to it. Employees who only check in do not receive SMS alerts.
  • Message types: operational alerts only, for example: a location did not open on time, repeated failed check-in attempts, open shifts without check-out, and sensitive configuration changes. Also the one-time verification code and a welcome message after verification. No marketing messages.
  • Frequency: message frequency varies with the activity of the recipient’s sites.
  • Cost: Message and data rates may apply.
  • Opt-out: reply STOP (also BAJA or SAIR) to any message to stop receiving SMS. You may receive one final message confirming the opt-out. Reply START to receive messages again.
  • Help: reply HELP for help, or contact cto@bunker360.com / +972 52 790 2029.
  • Carriers are not liable for delayed or undelivered messages.
  • Consent to receive SMS alerts is not a condition of any purchase; alerts can also be received by email.

No mobile information will be shared with third parties/affiliates for marketing/promotional purposes. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.

Sample message:

BunkerCheck: Coral Gables Plaza did not open. No check-ins at 9:12 (opens 9:00). check360.bunker360.com/a/7Q2K Reply STOP to opt out.

Mobile numbers are used only to deliver the alerts the recipient chose and the verification code. They are visible only to the administrators of the Customer account and to the recipient, and they are masked in our system logs. Verification codes are stored only as a hash. See also the SMS terms in our Terms of Service.

8. Email alerts

Operational alerts and daily summaries by email are sent from alertas@check360.bunker360.com (display name “BunkerCheck”) only to addresses that were verified or confirmed. Every alert email includes a link to unsubscribe and supports one-click unsubscribe from your email client. Alerts can also be paused for a period of time.

9. How we share information

  • With the Customer. Workforce data and alert data are available to the administrators of the Customer account they belong to. Data of one Customer is never shown to another Customer.
  • Service providers. We use Amazon Web Services (AWS) to host and operate the service, including data storage, face comparison (Amazon Rekognition), email delivery (Amazon SES), SMS delivery (AWS End User Messaging) and address-to-map conversion (AWS Location Service). SMS messages are delivered through mobile carriers. These providers process data only to provide their services to us.
  • Legal reasons. When required by law, subpoena or court order, or to protect the rights, safety and security of our Customers, users and BUNKER360 LLC.
  • Business transfers. In a merger, acquisition or sale of assets, subject to this policy.

We do not sell or rent personal information, and we do not share mobile numbers or SMS opt-in data with third parties or affiliates for marketing or promotional purposes (section 7).

10. Retention

DataRetention
Email and mobile number of an alert recipient removed from an accountDeleted 90 days after removal (the history entry is kept without the contact data)
Destination address (email or phone) recorded on each alert delivery; message logDeleted after 180 days
Check-in evidence records (distance, status)400 days
Audit log (configuration changes, consents, opt-outs)2 years
Login sessions / sign-up codes1 day after expiry / 7 days after expiry
Attendance records (check-ins, check-outs, photos, locations) and employee profilesWhile the customer account is active, and up to 90 days after it is closed.
Customer data after the account is closedAvailable for export for 30 days after closing; deleted no later than 90 days after closing.

We may keep information longer when required by law or to resolve disputes.

11. Security

We use measures designed to protect information, including: HTTPS for all traffic; strict separation of data between Customer accounts; passwords, one-time codes and tokens stored only as hashes; email and phone numbers masked in logs; photos and documents accessible only to the Customer’s administrators through links that expire after 5 minutes; and an audit log of sensitive changes. No system is completely secure, and we cannot guarantee absolute security.

12. Where data is stored

BunkerCheck is hosted on Amazon Web Services in the United States (region us-east-1). If you use the service from another country (for example Uruguay, Argentina or Brazil), your information will be transferred to and processed in the United States.

13. Your choices and rights

  • SMS: reply STOP (or BAJA / SAIR) at any time. Email: use the unsubscribe link in any alert. Account users can also change or pause their alerts in “My notifications”.
  • Depending on where you live, you may have the right to access, correct, delete or obtain a copy of your personal information, or to object to or restrict its processing. Employees of a Customer should first contact their employer; we will support the Customer in answering the request.
  • To make a privacy request, write to cto@bunker360.com. We may need to verify your identity. We will respond within the time required by applicable law.

14. Children

BunkerCheck is a business service and is not directed to children. We do not knowingly collect information from children under 13. Dashboard users must be at least 18 years old. If a customer registers employees under 18, the customer is responsible for obtaining any consent required by law.

15. Cookies and local storage

We use a strictly necessary session cookie to keep you logged in and to protect forms, and your browser’s local storage to remember your language choice. We do not use advertising or third-party tracking cookies.

16. Changes to this policy

We may update this policy. We will change the “Last updated” date above and, for material changes, notify Customer administrators by email or in the product.

17. Contact

Privacy questions and requests: cto@bunker360.com · +972 52 790 2029 · BUNKER360 LLC, 5727 NW 7th St, Suite 320, Miami, FL 33126, USA.

© 2026 BUNKER360 LLC · Miami, FL · Privacy · Terms Powered by Bunker360 LLC