Legal
This policy explains what we do with personal data when you visit timetrackerhub.com, enquire about the service, or use Time Tracker Hub. It is written to be read, not to be survived.
Time Tracker Hub is provided by [LEGAL ENTITY], registered in England and Wales under number [COMPANY NUMBER], registered office [REGISTERED ADDRESS]. We are registered with the Information Commissioner's Office under [ICO REGISTRATION NUMBER].
For anything in this policy, contact us at [PRIVACY EMAIL].
This distinction matters, so it comes first.
We are the controller for personal data about people who visit our website, make an enquiry, or hold an account with us for billing and administration purposes. We decide what happens to that data, and this policy explains it.
We are the processor for the data that a subscribing organisation puts into the application about its own staff: timesheets, hours, projects, comments, absence records, approvals. The employer is the controller of that data. They decide what is collected and why. We only act on their instructions, under a data processing agreement.
If you are an employee whose timesheets are in the system, section 12 is for you.
| Where from | What |
|---|---|
| Enquiry form | Your name, company, work email, phone if given, team size, what you currently use, and your message |
| Account signup | Name, work email, company name and address, job title, and the password you set (stored only as a hash) |
| Billing | Billing contact, address, VAT number, plan, invoice history. Card details go directly to Stripe and never reach our systems |
| Using the service | Login times, IP address, browser and device type, pages and actions within the application, and an audit record of approvals, rejections and administrative changes |
| Support | Emails you send us and our replies |
We do not buy personal data from third parties, and we do not run advertising or tracking pixels on the website.
| Purpose | Lawful basis |
|---|---|
| Replying to an enquiry and arranging a walkthrough | Legitimate interests — responding to someone who has asked us to |
| Providing the service, managing accounts and support | Performance of a contract |
| Taking payment and keeping financial records | Performance of a contract, and legal obligation for tax and accounting records |
| Keeping the service secure, investigating misuse, keeping audit logs | Legitimate interests — protecting the service and its users |
| Improving the service using aggregated usage data | Legitimate interests — building a product that works |
| Service emails, such as billing notices and material changes | Performance of a contract |
We do not send marketing emails to people who have not asked for them. If we ever start a product newsletter it will be opt-in, and unsubscribing will take one click.
When your employer subscribes, the data they enter about you and your work is theirs. We hold it on their behalf and use it only to run the service for them: storing it, showing it to the people they have authorised, generating their reports and exports, and backing it up.
We do not sell it, mine it for our own purposes, or use it to train machine learning models. Access by our staff is limited to what is needed to keep the service running or to resolve a support request, and administrative access to a customer account is logged.
We use a small number of suppliers to run the service. Each is bound by contract to protect the data and to use it only for the service they provide to us.
| Supplier | What for | Where |
|---|---|---|
| Supabase | Database, authentication and file storage | [HOSTING REGION] |
| Stripe | Payment processing and card handling | EU and USA |
| Resend | Sending service and notification emails | EU and USA |
| Google Fonts | Serving the typefaces used on the website | USA |
We will also disclose data where the law requires it, or to establish or defend legal claims. If our business is sold or reorganised, data may transfer to the buyer, who would be bound by this policy.
We will tell customers before adding or changing a supplier that processes their data, so they have the opportunity to object.
Application data is held in [HOSTING REGION]. Some suppliers listed above process data outside the UK. Where that happens we rely on the UK International Data Transfer Addendum to the European Commission's standard contractual clauses, or on UK adequacy regulations where they apply.
| Data | Kept for |
|---|---|
| Enquiries that do not become customers | 12 months |
| Account and timesheet data, active subscription | For as long as the account is open, and as directed by the customer |
| Account and timesheet data, after cancellation | Read-only for 90 days, then deleted. Backups overwritten within a further 30 days |
| Trial accounts not converted | 90 days after the trial ends |
| Invoices and financial records | 6 years, as required for tax purposes |
| Security and audit logs | 12 months |
Employers often need to keep time records for six years for payroll, tax and working time purposes. That retention decision is theirs, not ours, and they can export the records before an account closes.
We take security seriously because the whole point of the product is a record people can rely on. Measures include:
No system is perfect. If a breach occurs that is likely to result in a risk to people's rights, we will report it to the ICO within 72 hours and tell affected customers without undue delay.
We use only what is necessary to make the service work. There are no advertising cookies, no tracking pixels and no third-party analytics, which is why you are not being asked to click through a consent banner.
| Cookie | Purpose | Life |
|---|---|---|
| Session and authentication | Keeps you logged in and secures the session | Session, or until you log out |
| Preferences | Remembers settings such as your billing period toggle | Up to 12 months |
Typefaces are served from Google Fonts, which means your browser makes a request to Google and your IP address is visible to them. If you would rather that did not happen, the fonts can be self-hosted; tell us and we will consider it.
If we ever add analytics, this section will be updated and a consent banner added first.
Under UK data protection law you can ask us to:
Write to [PRIVACY EMAIL]. We will respond within one month. There is no charge unless a request is clearly unfounded or excessive.
Your timesheet data is controlled by your employer, not by us. If you want to see it, correct it or have it deleted, ask them first, because they decide what happens to it and we cannot act on your data without their instruction.
If you contact us directly we will pass the request to your employer and tell you we have done so. We will also help them respond, which is part of our agreement with them.
If we change this policy we will update the version and date at the top. For changes that materially affect how we use personal data, we will email account holders at least 30 days before they take effect.
If something concerns you, tell us first at [PRIVACY EMAIL] and we will try to put it right.
You also have the right to complain to the Information Commissioner's Office, the UK supervisory authority for data protection, at ico.org.uk or on 0303 123 1113.
[LEGAL ENTITY], [REGISTERED ADDRESS].