Time Tracker Hub
ControlsHow it worksPricingContact
Log inStart free trial

Legal

Privacy policy

Version 1.0 · Last updated 27 August 2026

Contents
  1. Who we are
  2. Controller or processor
  3. What we collect
  4. Why, and on what basis
  5. Timesheet data
  6. Who we share it with
  7. Where it is stored
  8. How long we keep it
  9. Security
  10. Cookies
  11. Your rights
  12. If you are an employee
  13. Changes
  14. Complaints and contact

This policy explains what we do with personal data when you visit timetrackerhub.com, enquire about the service, or use Time Tracker Hub. It is written to be read, not to be survived.

1Who we are

Time Tracker Hub is provided by [LEGAL ENTITY], registered in England and Wales under number [COMPANY NUMBER], registered office [REGISTERED ADDRESS]. We are registered with the Information Commissioner's Office under [ICO REGISTRATION NUMBER].

For anything in this policy, contact us at [PRIVACY EMAIL].

2When we are the controller, and when we are not

This distinction matters, so it comes first.

We are the controller for personal data about people who visit our website, make an enquiry, or hold an account with us for billing and administration purposes. We decide what happens to that data, and this policy explains it.

We are the processor for the data that a subscribing organisation puts into the application about its own staff: timesheets, hours, projects, comments, absence records, approvals. The employer is the controller of that data. They decide what is collected and why. We only act on their instructions, under a data processing agreement.

If you are an employee whose timesheets are in the system, section 12 is for you.

3What we collect

Where fromWhat
Enquiry formYour name, company, work email, phone if given, team size, what you currently use, and your message
Account signupName, work email, company name and address, job title, and the password you set (stored only as a hash)
BillingBilling contact, address, VAT number, plan, invoice history. Card details go directly to Stripe and never reach our systems
Using the serviceLogin times, IP address, browser and device type, pages and actions within the application, and an audit record of approvals, rejections and administrative changes
SupportEmails you send us and our replies

We do not buy personal data from third parties, and we do not run advertising or tracking pixels on the website.

4Why we use it, and our lawful basis

PurposeLawful basis
Replying to an enquiry and arranging a walkthroughLegitimate interests — responding to someone who has asked us to
Providing the service, managing accounts and supportPerformance of a contract
Taking payment and keeping financial recordsPerformance of a contract, and legal obligation for tax and accounting records
Keeping the service secure, investigating misuse, keeping audit logsLegitimate interests — protecting the service and its users
Improving the service using aggregated usage dataLegitimate interests — building a product that works
Service emails, such as billing notices and material changesPerformance of a contract

We do not send marketing emails to people who have not asked for them. If we ever start a product newsletter it will be opt-in, and unsubscribing will take one click.

5Timesheet and project data

When your employer subscribes, the data they enter about you and your work is theirs. We hold it on their behalf and use it only to run the service for them: storing it, showing it to the people they have authorised, generating their reports and exports, and backing it up.

We do not sell it, mine it for our own purposes, or use it to train machine learning models. Access by our staff is limited to what is needed to keep the service running or to resolve a support request, and administrative access to a customer account is logged.

6Who we share it with

We use a small number of suppliers to run the service. Each is bound by contract to protect the data and to use it only for the service they provide to us.

SupplierWhat forWhere
SupabaseDatabase, authentication and file storage[HOSTING REGION]
StripePayment processing and card handlingEU and USA
ResendSending service and notification emailsEU and USA
Google FontsServing the typefaces used on the websiteUSA

We will also disclose data where the law requires it, or to establish or defend legal claims. If our business is sold or reorganised, data may transfer to the buyer, who would be bound by this policy.

We will tell customers before adding or changing a supplier that processes their data, so they have the opportunity to object.

7Where it is stored

Application data is held in [HOSTING REGION]. Some suppliers listed above process data outside the UK. Where that happens we rely on the UK International Data Transfer Addendum to the European Commission's standard contractual clauses, or on UK adequacy regulations where they apply.

8How long we keep it

DataKept for
Enquiries that do not become customers12 months
Account and timesheet data, active subscriptionFor as long as the account is open, and as directed by the customer
Account and timesheet data, after cancellationRead-only for 90 days, then deleted. Backups overwritten within a further 30 days
Trial accounts not converted90 days after the trial ends
Invoices and financial records6 years, as required for tax purposes
Security and audit logs12 months

Employers often need to keep time records for six years for payroll, tax and working time purposes. That retention decision is theirs, not ours, and they can export the records before an account closes.

9Security

We take security seriously because the whole point of the product is a record people can rely on. Measures include:

  • encryption in transit and at rest
  • row-level security in the database, so isolation between companies is enforced by the data layer rather than only by the interface
  • passwords stored only as salted hashes, never in readable form
  • role-based access, with permissions checked on the server
  • optional multi-factor authentication for administrators
  • daily backups with point-in-time recovery
  • audit logging of approvals, rejections and administrative actions

No system is perfect. If a breach occurs that is likely to result in a risk to people's rights, we will report it to the ICO within 72 hours and tell affected customers without undue delay.

10Cookies

We use only what is necessary to make the service work. There are no advertising cookies, no tracking pixels and no third-party analytics, which is why you are not being asked to click through a consent banner.

CookiePurposeLife
Session and authenticationKeeps you logged in and secures the sessionSession, or until you log out
PreferencesRemembers settings such as your billing period toggleUp to 12 months

Typefaces are served from Google Fonts, which means your browser makes a request to Google and your IP address is visible to them. If you would rather that did not happen, the fonts can be self-hosted; tell us and we will consider it.

If we ever add analytics, this section will be updated and a consent banner added first.

11Your rights

Under UK data protection law you can ask us to:

  • give you a copy of the personal data we hold about you
  • correct anything inaccurate
  • delete it, where there is no lawful reason for us to keep it
  • restrict or object to how we use it, including where we rely on legitimate interests
  • send it to you or another provider in a portable format

Write to [PRIVACY EMAIL]. We will respond within one month. There is no charge unless a request is clearly unfounded or excessive.

12If your employer uses Time Tracker Hub

Your timesheet data is controlled by your employer, not by us. If you want to see it, correct it or have it deleted, ask them first, because they decide what happens to it and we cannot act on your data without their instruction.

If you contact us directly we will pass the request to your employer and tell you we have done so. We will also help them respond, which is part of our agreement with them.

13Changes to this policy

If we change this policy we will update the version and date at the top. For changes that materially affect how we use personal data, we will email account holders at least 30 days before they take effect.

14Complaints and contact

If something concerns you, tell us first at [PRIVACY EMAIL] and we will try to put it right.

You also have the right to complain to the Information Commissioner's Office, the UK supervisory authority for data protection, at ico.org.uk or on 0303 123 1113.

[LEGAL ENTITY], [REGISTERED ADDRESS].

Time Tracker Hub
PricingTermsPrivacyContact