TimeSubmit ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service. Please read this privacy policy carefully. If you do not agree with the terms of this privacy policy, please do not access the service.
1. Information We Collect
1.1. Information You Provide
We collect information that you voluntarily provide when using our Service:
- Account information (name, email address, password)
- Company/consultancy information
- Profile information and preferences
- Time tracking data (hours, projects, descriptions)
- Invoice data and financial information
- Communication data (support requests, feedback)
1.2. Automatically Collected Information
When you access our Service, we automatically collect:
- Device information (browser type, operating system)
- Log data (IP address, access times, pages viewed)
- Usage data (features used, interactions)
- Cookies and similar tracking technologies
2. How We Use Your Information
We use the information we collect for the following purposes:
- Provide, operate, and maintain our Service
- Process your transactions and manage subscriptions
- Send you technical notices and support messages
- Respond to your comments and questions
- Improve and personalise your experience
- Monitor and analyse usage patterns and trends
- Detect, prevent, and address technical issues
- Comply with legal obligations
3. Data Sharing and Disclosure
We do not sell your personal information. We may share your information in the following situations:
3.1. Service Providers
We share data with third-party service providers who perform services on our behalf:
- Cloud hosting providers (Supabase, Vercel)
- Payment processors (Stripe)
- Email service providers (SendGrid)
- Analytics providers
3.2. Legal Requirements
We may disclose your information if required by law or in response to valid requests by public authorities (e.g., court orders, subpoenas).
3.3. Business Transfers
If we are involved in a merger, acquisition, or asset sale, your personal information may be transferred. We will provide notice before your information is transferred.
4. Data Security
We implement appropriate technical and organisational security measures to protect your information:
- Encryption in transit (HTTPS/TLS)
- Encryption at rest for sensitive data
- Row-Level Security (RLS) policies for multi-tenant data isolation
- Regular security audits and monitoring
- Access controls and authentication
- Regular backups and disaster recovery procedures
However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee absolute security.
5. Data Retention
We retain your personal information for as long as necessary to fulfil the purposes outlined in this Privacy Policy, unless a longer retention period is required by law. When you delete your account, we retain your data for 30 days before permanent deletion, allowing for account recovery. After 30 days, all personal data is permanently deleted from our systems.
6. Your Data Rights
Under the UK GDPR and Data Protection Act 2018, you have the following rights:
- Right of access: Request a copy of your personal data
- Right to rectification: Correct inaccurate personal data
- Right to erasure: Request deletion of your personal data
- Right to restriction: Restrict processing of your data
- Right to data portability: Export your data in a structured format
- Right to object: Object to processing of your data
- Right to withdraw consent: Withdraw consent at any time
To exercise any of these rights, please contact us at privacy@timesubmit.com
7. Cookies and Tracking Technologies
We use cookies and similar tracking technologies to track activity on our Service:
- Essential cookies: Required for authentication and security
- Functional cookies: Remember your preferences
- Analytics cookies: Understand how you use our Service
You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept cookies, some portions of our Service may not function properly.
8. International Data Transfers
Your information may be transferred to and maintained on servers located outside of your country where data protection laws may differ. We ensure appropriate safeguards are in place, including Standard Contractual Clauses approved by the European Commission, to protect your information.
9. Children's Privacy
Our Service is not intended for individuals under the age of 16. We do not knowingly collect personal information from children under 16. If you become aware that a child has provided us with personal information, please contact us. If we discover that we have collected personal information from a child under 16, we will delete such information immediately.
10. Third-Party Links
Our Service may contain links to third-party websites. We are not responsible for the privacy practices of these third-party sites. We encourage you to read the privacy policies of every website you visit.
11. Changes to This Privacy Policy
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date. We will also notify you via email for material changes. You are advised to review this Privacy Policy periodically.
12. Contact Us
If you have any questions about this Privacy Policy, please contact us:
Email: privacy@timesubmit.com
General enquiries: support@timesubmit.com
13. Data Protection Officer
For data protection queries, you can contact our Data Protection Officer at dpo@timesubmit.com