Almost every time clock sold today is a cloud product, so the word has stopped narrowing the field and started hiding the questions that matter. The record now lives on somebody else's infrastructure, reachable from anywhere, and the useful interrogation is what happens on the days it is unavailable and on the day you leave.
What happens when the connection drops
A terminal or app that cannot queue punches offline will simply lose a morning, and the reconstruction afterwards is done from memory. Ask how many punches the device can hold and how they reconcile when the link returns. Ask also when planned maintenance windows fall, because vendors serving one market often schedule for that market's small hours.
Account security is now a payroll control
The record is reachable by whoever holds a password, which makes multi factor authentication for anybody who can edit hours the single highest value thing most employers can do here. Review the list of who can edit twice a year. This costs nothing and closes the gap that the move to the cloud actually opened.
Leaving, and the records you must keep
Your retention duties do not move to the vendor. If the service keeps two years and you owe longer, the gap is yours, and the remedy is a scheduled export you actually perform rather than an intention to perform one. Ask whether exports can run automatically, because a manual monthly export survives about four months in any organisation.
Questions people ask about cloud time clock
Is cloud less secure than a local box?
Not inherently, and often more secure than a server in a back office nobody patches. The risk moves from physical to credential.
What if the vendor closes or is acquired?
Read the notice and data return terms before signing. This category consolidates regularly and the employers who cope are already exporting.
Where is the data stored?
Ask for the region and the sub processors in writing. It matters for data protection and it should not require escalation to answer.