Back to Home

Privacy Policy

Last updated: 2/25/2026

1. Introduction

At TimeSheet Pro ("we", "our", or "us"), we respect your privacy and are committed to protecting your personal data. This Privacy Policy will inform you about how we look after your personal data when you visit our website (regardless of where you visit it from) and tell you about your privacy rights and how the law protects you, in compliance with GDPR, CCPA, and other global privacy frameworks.

2. The Data We Collect

We may collect, use, store and transfer different kinds of personal data about you which we have grouped together as follows:

  • Identity Data includes first name, last name, username or similar identifier.
  • Contact Data includes email address.
  • Business Data includes company names, client details, addresses, and VAT numbers you enter to generate invoices.
  • Technical Data includes internet protocol (IP) address, your login data, browser type and version, time zone setting and location, and operating system.
  • Usage Data includes information about how you use our website, products and services (such as time entries).

3. How We Use Your Data

We will only use your personal data when the law allows us to. Most commonly, we will use your personal data in the following circumstances:

  • Where we need to perform the contract we are about to enter into or have entered into with you (i.e., providing the time tracking service).
  • Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests.
  • Where we need to comply with a legal or regulatory obligation.

4. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to track the activity on our Service and hold certain information. Specifically, we use highly secure HttpOnly cookies to maintain your authenticated session. We do NOT use invasive third-party ad tracking cookies. You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent, but some parts of our service will not function without authentication cookies.

5. Data Security

We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorized way, altered or disclosed. Your passwords are cryptographically hashed using Argon2/Bcrypt before being stored in our PostgreSQL database. Our API endpoints are secured via HTTPS, Helmet middleware, and strict CORS policies.

6. Your Legal Rights

Under certain circumstances, you have rights under data protection laws in relation to your personal data. These include the right to:

  • Request access to your personal data.
  • Request correction of your personal data.
  • Request erasure of your personal data (Right to be Forgotten).
  • Object to processing of your personal data.
  • Request restriction of processing your personal data.
  • Request transfer of your personal data.
  • Right to withdraw consent.

If you wish to exercise any of the rights set out above, please contact us via our contact form.

Contact Us

If you have any questions about this Privacy Policy, please contact us via the contact form on our landing page.