Cookie Policy
Information We Collect
We collect personal data such as name, work email, and job title during account creation. Usage data includes interaction logs with TimeFlow™ (clickstream, feature usage frequency, and IP address). Sensitive data like calendar event titles and meeting attendees are processed in accordance with GDPR Article 9 exemptions for employment context.
- Financial data: Stripe tokenization (no raw card storage)
- Biometric data: Not collected
- Children’s data: Intentional collection prohibited under COPPA
Processing Purposes & Legal Bases
We process data for: (a) performance of contract (Art. 6(1)(b) GDPR) to deliver time management services; (b) legitimate interest (Art. 6(1)(f)) for product improvement and fraud detection; (c) consent (Art. 7) for optional marketing emails. We do not sell personal data under CCPA.
Data Subject Rights
Under GDPR, you may request access, rectification, erasure, portability, or restriction. Submit via [email protected]. We respond within 30 days. For CCPA, verified users may opt-out of sale (though none occurs) and request deletion of collected data.
Data Retention & Security
Activity logs retained 24 months for analytics; account data retained until account closure + 90 days for backup. We use AES-256 encryption at rest, TLS 1.3 in transit, and SOC 2 Type II audited data centers. Breach notification within 72 hours per GDPR Art. 33.
