Privacy Policy
Last updated: August 8, 2026
This Privacy Policy explains how Timing (“Timing”, “we”, “us”, or “our”), operated by [Company Legal Name], collects, uses, and protects your personal information when you use our time-tracking service at ontiming.io (the “Service”). By using the Service, you agree to the practices described here.
1. Information we collect
We collect only what we need to run the Service:
- Account information — your name, email address, and a securely hashed password. If you sign in with Google, we receive your name, email address, and profile picture from Google (we never see your Google password).
- Content you create — the projects, time entries (including their descriptions, start/end times, and durations), tags, and daily goals you add while tracking your time.
- Technical & usage data — limited log data such as your IP address and browser/device information, used to keep the Service secure, apply rate limits, and diagnose problems.
- Cookies & local storage — a secure, HTTP-only cookie that keeps you signed in (your refresh token), plus your access token and preferences (such as your theme choice) stored in your browser. We do not use advertising or third-party tracking cookies.
2. How we use your information
- Provide, operate, and maintain the Service and your account.
- Authenticate you and keep your session secure.
- Store and display the time-tracking data and analytics you create.
- Send you essential transactional emails (for example, password resets and account verification).
- Protect the Service against abuse, fraud, and security threats.
- Understand how the Service is used so we can improve it.
- Comply with our legal obligations.
We do not sell your personal data, and we do not use it for third-party advertising.
3. Legal bases for processing (EEA/UK)
If you are in the European Economic Area or the United Kingdom, we rely on the following legal bases: performance of a contract (to provide the Service you request), our legitimate interests (to secure and improve the Service), your consent (where required, which you may withdraw at any time), and compliance with legal obligations.
4. How we share information
We share personal data only with service providers who process it on our behalf, under contract, and only as needed to run the Service:
- Google — authentication when you choose “Sign in with Google”.
- Resend — delivery of transactional emails.
- Cloudflare R2 — file/asset storage, where used.
- Our hosting and database providers — to run the application and store your data.
We may also disclose information if required by law, to enforce our terms, to protect the rights, safety, or property of Timing or others, or in connection with a merger, acquisition, or sale of assets (in which case we will notify you).
5. Data retention
We keep your personal data for as long as your account is active. When you delete your account, we delete or anonymize your personal data within a reasonable period, except where we are required to retain it to comply with legal obligations, resolve disputes, or enforce our agreements.
6. Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Delete your data (“right to be forgotten”).
- Export your data in a portable format — the Service also lets you export your time entries directly.
- Object to or restrict certain processing, and withdraw consent where processing is based on consent.
- Lodge a complaint with your local data protection authority.
To exercise any of these rights, email us at [email protected]. If you are a California resident, you have the right to know what personal information we collect, to request its deletion, and not to be discriminated against for exercising your rights. We do not sell your personal information.
7. Data security
We protect your data using encryption in transit (HTTPS), hashed passwords, short-lived access tokens, and access controls. No method of transmission or storage is completely secure, so while we work hard to protect your information, we cannot guarantee absolute security.
8. International data transfers
Your information may be processed and stored in countries other than the one you live in, including where our service providers operate. Where required, we put appropriate safeguards in place for such transfers.
9. Children’s privacy
The Service is not directed to children under 16 (or the minimum age required in your jurisdiction), and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, please contact us and we will delete it.
10. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you. Your continued use of the Service after changes take effect means you accept the updated policy.
11. Contact us
If you have questions about this Privacy Policy or how we handle your data, contact us at [email protected] — [Company Legal Name], [Mailing Address]. See also our Terms of Service.