Buddy punching costs up to 5% of payroll. But fingerprinting can feel creepy if you don’t say what you check.
We’ll tell you exactly — and what we never touch.
The Real-World Context
A worker hands their phone to a colleague who clocks in for them. A password alone can’t tell the difference. You need to know which device made the punch — without reading personal files or tracking all day.
The Test Scenario
We took the same worker and clocked in once from their registered phone and once from a colleague’s phone 10 minutes later, same site, same QR. Both punches had valid GPS inside the fence.
How It Works (The Mechanics)
- Fingerprint at tap only — at Clock In, Chegatta hashes
User-Agent + Accept-Language + app version/device modelinto a SHA-256 fingerprint. No contacts, photos, or browsing history. This is thedevice_fingerprintstored with theShift/KioskSession. - Site-bound check — that fingerprint is tied to
site_id. An unknown device at the same site is flagged as anomaly, not auto-rejected. - 90-day privacy — IP and raw fingerprint are anonymized after 90 days (
GDPR), kept asanomalystats only. No biometric template is stored.
The Results / What We Verified
- Known device: accepted. Unknown device: flagged for review, not silently accepted. Pass.
- Same device at two distant sites within minutes: flagged. Pass.
- Raw device data anonymized after 90 days in our test dump. Pass.
Honest caveat: Fingerprinting flags, it doesn’t prove intent. A worker with a new phone will be flagged once — a manager still approves it. And it doesn’t replace GPS: a borrowed phone at the right site still looks “inside” without the fingerprint.
Where Chegatta Is Today
You get fraud prevention without surveillance: a stable, minimal fingerprint, checked only at the tap, site-bound, with a clear Needs Review queue before payroll is locked. Instant 2-Minute Setup • No Credit Card Required. Try Chegatta free at Chegatta.com.