Legal
Privacy Notice
Status: draft, pending final legal review · Last updated 15 September 2026
1. Who this notice covers
This notice explains what personal data TimeMarkd collects and how we use it. It covers visitors to this website, the people who sign an Organisation up to TimeMarkd, and the Members that Organisation invites (including contractors who log time). We are the data controller for the personal data described below.
2. Data we collect
Account and profile data: name, email address, and phone number, collected when you sign in or are invited to an Organisation.
Organisation data: organisation name, plan, member roles, and invitations.
Timesheet and job data: hours logged, job and work-package details, approvals, and rejection notes entered through the Services.
Photo evidence: images Members upload to timesheets or jobs as proof of work, which may incidentally show people, vehicles, or property at a job site.
Billing data: when an Organisation subscribes, our payment processor Stripe collects payment details directly; we only receive limited billing metadata such as the subscription status, plan, and a customer reference — we don't see or store full card numbers.
Usage and device data: technical information like IP address and browser type, and the cookies described in section 5.
Contact form submissions: name, email, and message content when you contact us for sales or support.
3. How we use this data
We use personal data to: provide and maintain the Services, including authenticating sign-in and running the timesheet and approval workflow; process subscriptions and payments; respond to support and sales enquiries; keep the Services secure and prevent abuse; and meet our legal and accounting obligations. We rely on performance of a contract with the Customer, our legitimate interests in operating and securing the Services, and legal obligation as the legal bases for these uses, and on consent where we ask for it separately (for example, optional email updates).
4. Who we share data with
We share personal data with the following subprocessors, each bound by a data processing agreement, solely to help us run the Services:
- WorkOS — authentication and sign-in.
- Stripe — subscription billing and payment processing.
- Cloud infrastructure providers — hosting the application and storing uploaded photo evidence.
- Sentry — error monitoring, so we can detect and fix bugs. Configured not to collect IP addresses or other default personal identifiers, and any authentication tokens are stripped before an error report leaves our servers.
- Better Stack — application logs, metrics and uptime monitoring for our backend, so we can keep the Services running reliably.
- PostHog (EU-hosted) — product analytics, so we can see which pages and features are used. Only loaded in your browser if you accept analytics cookies; see section 5.
We don't sell personal data. We may disclose it if required by law, to enforce these terms, or as part of a merger, acquisition, or asset sale, in which case we'll tell affected customers.
5. Cookies
We use a small number of strictly necessary cookies to keep you signed in and to secure the sign-in process, and — only if you accept them in the cookie banner — PostHog analytics cookies. We don't use advertising cookies. See our Cookie Notice for the full list and how to control them.
6. International transfers
Some of our subprocessors may process data outside the UK or EEA. Where that happens, we rely on appropriate safeguards, such as the UK International Data Transfer Addendum or the EU Standard Contractual Clauses, to protect that data.
7. Retention
We keep Organisation and timesheet data for as long as the Organisation's subscription is active, plus a limited period afterwards to allow for data export and to meet legal and accounting retention requirements. Account data for a Member who is removed from every Organisation is deleted or anonymised within a reasonable period, unless we need to keep it longer for a legal reason. You can request deletion sooner as described in section 8.
8. Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, restrict or object to certain processing, and withdraw consent where we rely on it. To exercise any of these rights, email hello@timemarkd.com. If a Member's data is held as part of an Organisation, we may need to check with that Organisation's owner before acting on the request. UK residents can also complain to the Information Commissioner's Office (ico.org.uk) if they believe their data has been mishandled.
9. Security
We use technical and organisational measures, including encryption in transit, access controls, and reputable third-party infrastructure providers, to protect personal data. No system is completely secure, but we work to keep the Services safe and to respond quickly if something goes wrong.
10. Children
TimeMarkd is a business tool and isn't directed at, or knowingly used to collect data from, children.
11. Changes to this notice
We may update this notice from time to time. We'll post the updated version here with a new "last updated" date, and for material changes we'll take reasonable steps to let customers know.
12. Contact
Questions about this notice, or requests relating to your personal data, can be sent to hello@timemarkd.com.