ClockOut does not support fingerprint scanners or facial recognition. We get asked about this often enough that we wanted to explain why, clearly, rather than bury it in a feature FAQ. The short answer: biometric time clocks carry legal and operational costs that most small teams do not realize until it is too late, and GPS geofencing solves the same problem with a fraction of the risk.
What biometric time clocks are actually solving
The case for biometrics usually goes like this: a fingerprint or face scan proves that the person clocking in is actually the person named on the timesheet. It eliminates buddy punching entirely. That is true. The problem is that buddy punching is not the only problem you are solving, and it is rarely severe enough to justify the overhead that biometrics bring with them.
Most small-business buddy punching is casual and low-stakes: someone runs five minutes late and a coworker clocks them in as a favor. GPS geofencing stops this cold. If the phone is not at the location, the clock-in is blocked. For teams that share a device, a PIN-based kiosk at the door has the same deterrent effect, because the employee has to physically be present to punch.
The legal exposure most owners discover too late
Biometric data is regulated differently from other employee data, and the regulations are getting stricter, not looser. Illinois led the way with the Biometric Information Privacy Act (BIPA), which requires:
- Written notice to each employee before collecting biometric data
- Written consent from each employee
- A publicly available retention and destruction schedule
- Destruction of biometric data within three years of last use, or when the purpose is fulfilled, whichever comes first
- No sale or profit from biometric data
Violations under BIPA: $1,000 per negligent violation, $5,000 per intentional or reckless violation, plus attorney fees. Class action exposure has made BIPA one of the most litigated privacy statutes in the country. A class of 15 employees with procedural violations can generate a seven-figure liability.
Illinois is not alone. Texas, Washington, New York City, and other jurisdictions have enacted or are considering similar rules. For a full breakdown of what Illinois requires, see Illinois BIPA compliance for biometric time clocks.
The consent problem in hourly workforces
Obtaining meaningful, documented consent from every hourly employee, including seasonal hires, part-timers, and workers who turn over every few months, is genuinely difficult. You need the consent before the first biometric scan. You need to document it. You need to track it per employee. When someone refuses consent, you need a fallback process. When someone leaves, you need to destroy their data on a documented schedule.
For a restaurant, retail shop, or clinic with 15-50 employees and moderate turnover, this is an ongoing administrative burden. Most operators we talk to do not realize this until after they have ordered the hardware.
What biometrics actually cost
The hardware cost of a fingerprint or facial recognition time clock is usually the most visible number: anywhere from a few hundred to a few thousand dollars per unit. But the full cost includes:
- Hardware: $300-$1,500 per unit, depending on the reader technology
- Ongoing maintenance: firmware updates, reader cleaning, hardware replacement when units fail
- Consent infrastructure: written disclosure forms, employee acknowledgments, HR tracking per employee
- Data destruction workflow: documented process run each time an employee leaves
- Legal review: at least a one-time review by employment counsel for the states where you operate
- Exception handling: what happens when the reader fails to match? Every reader has false-rejection rates.
Compare that to GPS geofencing: employees already have phones, the software is the time-clock app they are using anyway, and the geofence is a radius you draw on a map once.
What actually stops time fraud
We have spent time on this question. Here is what the data and the operator experience show.
GPS geofencing stops remote clock-ins
The most common buddy punching scenario is an employee asking a coworker to clock them in while they are still on the bus. Geofencing makes this impossible. The app checks coordinates at clock-in against the geofence drawn around each location. If the phone is not inside the fence, the punch is blocked or flagged depending on your settings.
This is the problem that biometrics are supposed to solve, and GPS solves it without storing any sensitive biometric data. See how to set up a GPS time clock for the setup walkthrough.
Kiosk mode handles the shared-device scenario
For teams that do not use personal phones at work, a tablet kiosk at the entrance handles the same job. Employees clock in with a 4-digit PIN. A PIN can technically be shared, but sharing a PIN requires the person to physically come to the kiosk to use it, which removes most of the appeal of buddy punching.
For the small number of situations where that gap matters, a kiosk photo on punch-in adds a layer of visual verification without storing biometric templates. A manager reviews photos of any flagged punches. That is a reasonable middle ground.
The exception inbox catches what slips through
No system stops every edge case. The exception inbox is the backstop: every flagged punch, missed clock-out, or out-of-bounds attempt lands in one queue for manager review. Five minutes a day in the inbox catches what the automated rules miss. For more on the full approach, see how to stop buddy punching.
When biometrics might actually be the right call
We are not saying biometrics are never appropriate. There are situations where the added certainty is worth the overhead.
- High-security environments where access control and time tracking are unified (data centers, pharmacies, controlled substance storage).
- Very low turnover, small teams in states with no biometric privacy laws, where the consent and destruction workflow is manageable and documented.
- Contexts where GPS is impractical (Faraday-cage environments, facilities with GPS signal issues).
If your situation is on this list, get employment counsel involved before deploying anything. The consent forms and data destruction schedule are not optional paperwork.