How does PeopleMuster handle my data?

PeopleMuster keeps each customer's records in a separate database, in the customer's own account and chosen region. Integration keys are stored there and masked once saved. Staff feedback stays masked until a reviewer reveals it, meeting risk signals are admin-only, and fingerprint templates never leave the attendance terminal.

Data questions come down to three things. Where it sits, who inside your company can read it, and what never arrives in the first place.

Where it sits. One customer, one database, in an account that belongs to that customer. Your records are never rows in a table shared with another company. The interface can even carry your own product name, which is why our own instance is branded differently throughout.

Who can read it. Inside your instance, the role model decides, and some data is restricted by design. Feedback arrives with names masked. The performance event log is admin-only and hidden behind a reveal. Meeting risk signals are marked admin-only on the screen itself.

One setting shows the care taken. Meeting digests can post to a Slack channel. The settings refuse a channel name that would push private meeting notes into a client's shared workspace. The mistake is blocked before it can happen.

What never arrives. The fingerprint terminal matches a scan on the device. PeopleMuster receives the device user, the terminal serial and the punch time, and nothing else.

Every change is traceable. Creates, updates and deletes are logged with the old value and the new one. That gives a disputed leave balance or an edited timesheet a clear history.

Related questions

Is my data shared with other customers?

No. Each customer has a separate database in its own account. Nobody else's records sit in the same tables.

Can I choose the region?

Yes. The region is chosen when your database is set up, and the database lives in your own account.

Who inside my company can see sensitive records?

The roles you set decide. Feedback identities, performance events and meeting signals are masked or admin-only by default.