My GSL

Privacy Policy

Effective date: July 20, 2026  ·  Last updated: July 20, 2026

This Privacy Policy explains how Gemstone Lights Canada LTD and Gemstone Lights USA Corp (together, “Gemstone Lights,” “we,” “us,” or “our”) collect, use, disclose, and protect personal information through the My GSL mobile application and the website at my.gemstonelights.com (together, the “Service”).

My GSL is a private, internal workforce application for Gemstone Lights employees and other authorized personnel. Accounts are issued by Gemstone Lights; there is no public sign-up. Because the Service is an employment tool, most information it processes is employee personal information handled to administer the employment relationship.

At a glance

1. Who this applies to

This Policy applies to Gemstone Lights employees, contractors, and other individuals who are issued My GSL credentials and use the Service, whether through the iOS app, the Android app, or the website. It applies to all information we process about you in connection with the Service.

2. Information we collect

We collect — and, depending on the features you use and future enhancements to the Service, may collect — the following categories of personal information. Items marked COLLECTED TODAY are processed by the current version; items marked MAY COLLECT describe data we may process as the Service evolves, disclosed here in advance.

a. Account & identity

COLLECTED TODAY Your name, work email address, employee identifier, and account password (stored only in irreversible hashed form). A profile photo if your employer has provided one. The device name you supply when signing in on a device.

b. Employment & HR information

COLLECTED TODAY Your department, job classification/role, reporting manager, hire date, pay type, country/region of employment, assigned work schedule, and leave-policy assignment.

c. Time & attendance

COLLECTED TODAY Clock-in/out and meal-break punches with their timestamps, calculated worked hours, attendance exceptions (for example, late arrival or a missed punch), and the source of each punch (in-office kiosk, mobile app, remote entry, or administrative correction).

d. Time-off / leave

COLLECTED TODAY Your time-off requests, approvals and denials, leave balances and the underlying transaction ledger, and any notes you attach.

e. Device & technical data

COLLECTED TODAY Basic technical information needed to operate and secure the Service, such as device model and operating-system version, app version, IP address, and server log data generated when your device communicates with our systems.

f. Communications

COLLECTED TODAY In-app notifications we send you, and the content of any support or feedback messages you choose to send us.

g. Diagnostics, crash & analytics data

MAY COLLECT The current app does not include third-party crash-reporting, performance-monitoring, or product-analytics software. As the Service evolves we may introduce such tools (which may include first- or third-party services) to diagnose crashes, measure performance, and understand how features are used so we can improve the Service. If and when we do, the data may include diagnostic identifiers, crash logs, and app-interaction events. We will update this Policy and our app-store data-safety disclosures, and obtain your consent where required by law, before enabling them.

h. Location information

COLLECTED TODAY We do not collect your device’s geographic location. The app uses Bluetooth scanning solely to detect nearby Gemstone Lights kiosks; on Android this scanning is declared with the neverForLocation flag, meaning it is not used to derive your location.

MAY COLLECT Future versions may offer location-aware features — for example, approximate or precise location to confirm that a clock-in occurs at an authorized worksite, geofenced punch validation, or worksite selection. If we enable any such feature, we will request the appropriate device permission, show a prominent in-app disclosure explaining what is collected and why, update this Policy and our app-store data-safety disclosures, and (where required) collect location only with your consent and while you are using the relevant feature.

i. Cookies & similar technologies (website)

COLLECTED TODAY The website uses strictly-necessary cookies for authentication, session management, security, and bot-protection. It does not use advertising or cross-site tracking cookies. MAY COLLECT If we later introduce optional analytics cookies, we will provide notice and controls as required.

3. Sources of information

Most information comes from you (when you sign in, punch, or submit a request) and from your employer’s HR records. Some information is generated automatically by your use of the Service (for example, punch timestamps, calculated hours, and technical logs).

4. How we use information

We use personal information to:

Legal bases. We process personal information as necessary to establish, manage, and (where applicable) end the employment relationship; to comply with legal obligations; for our legitimate business interests in operating a secure and accurate workforce system; and, where required, with your consent. Under Alberta’s Personal Information Protection Act (PIPA), an organization may collect, use, and disclose employee personal information without consent where reasonable for the purpose of managing the employment relationship, provided reasonable notice is given. This Policy, together with any notices in the Service, constitutes that notice.

5. Bluetooth & location

The mobile app can use your device’s Bluetooth to detect nearby Gemstone Lights in-office kiosks. When a kiosk is in range, a punch made through the app can be tagged to that kiosk and the kiosk can display a brief personalized greeting. This is optional and cosmetic — you can clock in and out without Bluetooth, and revoking Bluetooth permission in your device settings does not prevent you from using the core features.

As explained in Section 2(h), Bluetooth scanning is not used to determine your geographic location today. Any future location-based feature will be introduced with a separate permission request and disclosure.

6. Automated processing

The Service applies automated rules to flag possible attendance exceptions (for example, a late arrival or a missing punch). These flags are advisory and are reviewed by supervisors or HR before any employment decision is made. The Service does not make decisions that produce legal or similarly significant effects about you without human involvement.

7. How we share information

We do not sell your personal information, and we do not share it for advertising or cross-context behavioral advertising. We disclose personal information only as follows:

8. International data transfers

The Service is hosted on Amazon Web Services infrastructure located in the United States. If you are located in Canada, your personal information is transferred to and stored in the United States and may be accessible to U.S. courts, law-enforcement, and regulatory authorities under U.S. law, including lawful-access requests. We use contractual and technical safeguards to protect information in transit and at rest. By using the Service, you acknowledge this cross-border processing.

9. Data retention

We retain personal information for as long as necessary to fulfill the purposes described in this Policy and to meet our legal, accounting, and records-retention obligations — typically for the duration of your employment or authorization, plus any statutory retention period that applies to employment and payroll records. Audit and change-history records are retained in active storage for approximately eighteen (18) months and then moved to archival storage. When information is no longer required, we securely delete or de-identify it.

10. Security

We use technical and organizational measures appropriate to the sensitivity of the information, including: encryption of data in transit (TLS); irreversible hashing of passwords; storage of authentication tokens in the device’s secure keychain/keystore; role-based access control and least-privilege database accounts; audit logging of changes; and regular backups. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

11. Your rights & choices

Depending on your jurisdiction, you may have the right to access the personal information we hold about you, to request correction of inaccurate information, to receive information about how it is handled, and to withdraw consent or challenge our compliance (subject to legal and contractual limits). To exercise these rights, contact us at hr@gemstonelights.com.

Because My GSL is a workplace system of record, certain information (such as official time, attendance, and leave records) may need to be retained even if you request deletion, where retention is required or permitted by law.

12. Data & account deletion

My GSL accounts are issued by Gemstone Lights and are closed when your employment or authorization ends. To request access to, correction of, or deletion of your personal information, use our online Data & Account Deletion Request form, or email hr@gemstonelights.com with the subject line “Data Request.” We will verify your identity and respond within the time required by applicable law (generally within 30 days). We will delete or de-identify personal information that we are not required to retain; information subject to a legal retention obligation will be deleted at the end of the applicable retention period.

13. Children’s privacy

The Service is intended for Gemstone Lights personnel who are adults (18 years or older). It is not directed to children, and we do not knowingly collect personal information from children.

The Service may link to third-party websites or services that we do not control. This Policy does not apply to those third parties, and we are not responsible for their content or privacy practices.

15. Changes to this Policy

We may update this Policy from time to time. When we make material changes, we will revise the “Last updated” date above and, where appropriate, provide additional notice through the Service or by email. Your continued use of the Service after an update takes effect constitutes acceptance of the revised Policy.

16. Contact us

For questions, requests, or complaints about this Policy or your personal information, contact:

Gemstone Lights — Privacy
Gemstone Lights Canada LTD & Gemstone Lights USA Corp
Email: hr@gemstonelights.com