TimeApp Privacy Policy
Last updated: July 28, 2026 · Version: 1.1
1. Introduction
This Privacy Policy explains how TimeApp (displayed in-app as "XpertTime — Staff Time Management System", referred to here as "TimeApp," "we," "us," or "our") collects, uses, discloses, and protects personal information when you use our workforce scheduling, time-off, and coverage management platform (the "Service").
This policy applies to everyone who interacts with the Service: Tenant Admins, Managers, Staff/employee users, Super Admins, and visitors to our public website. If your employer or organization ("Tenant") has set up a TimeApp account for you, your organization is generally the data controller for your employment data, and TimeApp acts as its data processor (or "service provider," under CCPA/CPRA terminology) — see Section 5 for what this means in practice.
We wrote this policy to comply with the EU General Data Protection Regulation (GDPR), the UK GDPR and Data Protection Act 2018, Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), and the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), and to generally reflect good-practice global data protection standards.
We've tried to use plain language throughout rather than dense legal text. If anything is unclear, contact us — see Section 15.
Table of Contents
- Introduction
- Information We Collect
- How We Collect Your Information
- Why We Collect and How We Use Your Information
- Legal Bases for Processing
- Data Retention
- Data Security
- Your Privacy Rights
- Cookies & Tracking Technologies
- Third-Party Services & Integrations
- International Data Transfers
- Children's Privacy
- Automated Decision-Making
- Changes to This Policy
- Contact Us
2. Information We Collect
| Category | Examples | Who it's collected from |
|---|---|---|
| Account & identity data | Full name, email address, password (stored as a salted hash — we never see or store your plain-text password), assigned role (Staff/Manager/Admin/Super Admin), profile changes | You, or the Tenant Admin who creates your account |
| Employment & scheduling data | Shift schedules, time-off requests and their status/history, leave balances, self-reported availability, shift-role labels, coverage-gap assignments, approval decisions and notes, hourly pay rate (where your organization records one) | You and your organization's Admins/Managers, as part of using the Service |
| Billing data | Subscription plan, billing history, invoices, payment method metadata (card brand and last 4 digits only) | Collected and stored primarily by our payment processor, Stripe — see Section 10 |
| Communications | Support requests, emails you send us, content of password-reset and account-invite emails | You, when you contact us, or generated automatically by the Service |
| Usage & technical data | Pages viewed, general interaction and performance data, browser type, approximate location (from IP address), device type | Automatically, only with your cookie consent — see Section 9 |
| Audit & security data | Login timestamps, session activity, a record of actions taken in the Service (for Tenant Admin visibility into their own organization's activity) | Automatically, as part of operating the Service securely |
We do not knowingly collect biometric data, government ID numbers, precise geolocation, or other sensitive categories of personal data through TimeApp.
3. How We Collect Your Information
- Directly from you — when you log in, submit a time-off request, set your availability, update your profile, or contact support.
- From your organization — your Tenant Admin creates your account and may enter or edit certain employment data (role, manager assignment, pay rate) on your behalf.
- Automatically — technical and usage data collected via cookies and similar technologies, only after you've given consent through our Cookie Preference Centre.
- From service providers — for example, Stripe confirms payment and subscription events to us; we don't independently verify or store your full card details.
4. Why We Collect and How We Use Your Information
We use personal information to:
- Provide the Service — authenticate you, display your schedule, process time-off requests and approvals, calculate leave balances, flag coverage gaps, and generate reports your organization requests.
- Operate your account — send account-related emails (invites, password resets, notifications about requests relevant to you).
- Process payments and manage subscriptions — via Stripe, on behalf of Tenant Admins who manage billing.
- Maintain security and prevent abuse — detect suspicious login activity, enforce session timeouts, and maintain audit trails Tenant Admins can review for their own organization.
- Improve the Service — understand aggregate usage patterns and performance, only where you've consented to analytics/performance cookies.
- Comply with legal obligations — such as responding to lawful requests from authorities or fulfilling tax/billing record-keeping requirements.
We do not sell personal information, and we do not use personal information for cross-context behavioral advertising. We have no marketing or advertising trackers on the Service today.
5. Legal Bases for Processing
Where GDPR/UK GDPR applies, we rely on the following legal bases:
| Purpose | Legal basis |
|---|---|
| Providing the core Service (scheduling, time-off, approvals) | Performance of a contract with your organization / legitimate interest in operating the Service your employer subscribed you to |
| Account security, fraud prevention, audit logging | Legitimate interest in keeping the Service secure and reliable |
| Optional analytics/performance cookies | Consent — you can withdraw this at any time via Cookie Settings |
| Billing and payment processing | Performance of a contract with the Tenant, and legal obligation (tax/accounting records) |
| Responding to legal requests | Legal obligation |
For most employment-related data (schedules, time-off, pay rate), your employer (the Tenant) is the data controller and determines why that data is processed; TimeApp processes it on their instructions as a data processor/service provider. Requests to access, correct, or delete this data should generally start with your organization's Tenant Admin, who can action most of these directly within the Service (see Section 8) — we'll also assist directly if asked.
6. Data Retention
- Active account data is retained for as long as your account and your organization's subscription remain active.
- Time-off, schedule, and approval history is retained to preserve an accurate employment record and audit trail, consistent with your organization's own record-keeping obligations — deletions (e.g. cancelling a time-off request) are typically soft deletes that preserve history rather than erasing it outright, which your Tenant Admin can see reflected in Audit Logs.
- Billing records (invoices, payment metadata) are retained for as long as required by applicable tax and accounting law after the relevant transaction.
- Support communications are retained for as long as reasonably needed to resolve your enquiry and for a reasonable period afterward for quality and dispute-resolution purposes.
- Consent records made before you sign in are kept in your browser for up to 12 months. Once signed in, consent decisions are kept as a permanent, append-only history tied to your account (so we can demonstrate compliance over time) — you can always view this in your Privacy Centre, and you'll be asked to reconfirm a category if we publish a materially updated policy for it.
- If a Tenant's subscription is cancelled, we retain the organization's data for a limited grace period (to allow export/reactivation) before it is deleted or anonymized, unless a longer period is required by law.
You or your Tenant Admin can request earlier deletion — see Section 8.
7. Data Security
We apply layered technical and organizational safeguards, including:
- Encryption of data in transit (HTTPS/TLS) between your browser and our servers.
- Passwords stored as salted cryptographic hashes — never in plain text.
- Short-lived access tokens (10 minutes) with a separate, longer-lived refresh token, plus server-side session-activity tracking so idle sessions expire automatically.
- Role-based access control, enforced server-side, so users only ever see data their role and organization permit.
- Tenant data isolation — every request is scoped to your organization; cross-tenant access is blocked except for platform-level Super Admin operations, which are themselves logged.
- Infrastructure hosted on established cloud providers (Amazon Web Services and Vercel — see Section 10) with their own independent security and compliance programs.
No method of transmission or storage is 100% secure, and we can't guarantee absolute security — but we work to apply practices appropriate to the sensitivity of the data we hold.
8. Your Privacy Rights
Depending on where you live, you may have the following rights over your personal information. Where a right is more naturally exercised through your organization (because they control the underlying employment data), we note that too.
If GDPR/UK GDPR applies to you (EU/UK):
- Right of access — request a copy of the personal data we hold about you.
- Right to rectification — correct inaccurate or incomplete data (many fields, like your name and email, you can edit yourself in your Profile, via the account menu in the top bar).
- Right to erasure ("right to be forgotten") — request deletion, subject to our retention obligations above.
- Right to restrict processing and right to object to certain processing based on legitimate interest.
- Right to data portability — receive certain data in a structured, machine-readable format.
- Right to withdraw consent at any time, for anything based on consent (e.g. analytics cookies), without affecting the lawfulness of processing before withdrawal.
- Right to lodge a complaint with your local supervisory authority (e.g. the ICO in the UK, or your national/regional Data Protection Authority in the EU).
If PIPEDA applies to you (Canada):
- Right to know what personal information we hold and why, and to whom it's been disclosed.
- Right to access and challenge accuracy — request corrections to inaccurate information.
- Right to withdraw consent, subject to legal or contractual restrictions.
- Right to file a complaint with the Office of the Privacy Commissioner of Canada if you believe we've mishandled your information.
If CCPA/CPRA applies to you (California):
- Right to know/access the categories and specific pieces of personal information we've collected about you.
- Right to delete personal information we hold, subject to legal exceptions.
- Right to correct inaccurate personal information.
- Right to opt out of sale/sharing — not applicable in practice, since we do not sell or share personal information for cross-context behavioral advertising.
- Right to limit use of sensitive personal information — we don't use sensitive personal information beyond what's necessary to provide the Service.
- Right to non-discrimination for exercising any of these rights.
Exercising your rights: Many of these — updating your name/email, viewing your own schedule and time-off history, managing cookie and consent preferences — are available directly in the app. Once signed in, your Privacy Centre (account menu → Privacy Centre) lets you view and change your consent for each category, download your consent history, and submit a formal data request (access, rectification, deletion, portability, or restriction) — this creates a tracked request our team reviews and resolves; it isn't instant. For anything else, contact us (see Section 15) or your Tenant Admin, and we'll respond within the timeframe required by applicable law (generally 30 days, or 45 days for CCPA/CPRA requests). We may need to verify your identity before fulfilling a request.
9. Cookies & Tracking Technologies
TimeApp uses a small number of cookies and browser-storage technologies, and keeps a record of your consent choices.
Before you sign in. We use a couple of strictly necessary items regardless — signing you in, keeping your session secure, remembering your cookie choice itself, and your light/dark mode display preference. None of these are tracking technologies and none require consent under ePrivacy/GDPR. Beyond that:
| Category | Purpose | Currently used for | Can be disabled? |
|---|---|---|---|
| Cookies | General, non-essential cookie usage | Reserved for future use — nothing beyond the strictly-necessary items above uses this today | Yes, via the cookie banner or the Cookie Settings link in the footer |
| Analytics | Understand aggregate usage of the Service to improve it | Vercel Web Analytics (page views and general usage trends; not used to build individual advertising profiles) | Yes — no analytics script loads until you consent |
Your choice here is stored locally on your device (and mirrored in a first-party cookie) before you sign in, since there's no way to attach an anonymous visitor's choice to an account. It's not shared with anyone.
After you sign in. Your choices for Cookies and Analytics move to your account and are recorded by our backend (with the timestamp and policy version, per Section 5) instead of only living in your browser — if you'd already made a choice before logging in, it's carried over automatically so you're not asked twice. Three additional consent categories become available in your Privacy Centre (account menu → Privacy Centre, once signed in), each managed separately rather than bundled into "Accept All," since marketing consent in particular has to be freely given and specific, not implied by a cookie banner:
| Category | Purpose |
|---|---|
| Marketing Communications | Whether we can email you optional product updates or announcements (separate from required transactional emails like password resets, which aren't consent-gated) |
| Privacy Policy | Your acknowledgment of the current version of this policy |
| Terms of Service | Your acknowledgment of our Terms of Service |
We do not currently use marketing or advertising cookies of any kind — the Marketing Communications category above governs email, not tracking.
Policy updates & re-consent. If we publish a materially updated version of a policy you'd previously agreed to, your Privacy Centre (and, for Cookies/Analytics, the cookie banner) will flag that category as needing review the next time you visit, so you can confirm or change your choice under the new version.
Every consent decision you make while signed in — including changes — is kept as a permanent, append-only history entry, viewable in your Privacy Centre's Consent History tab.
10. Third-Party Services & Integrations
We share limited personal information with the following service providers, each acting under their own privacy commitments and only to the extent necessary to provide the Service:
| Provider | Purpose | What they may process |
|---|---|---|
| Stripe | Payment processing, subscription billing | Billing contact details, payment method metadata; Stripe is PCI-DSS compliant and we never receive or store full card numbers |
| Vercel | Application hosting, content delivery, and (only with your consent) privacy-focused Web Analytics | Technical request data necessary to serve the app; aggregate usage data if you've consented to analytics |
| Amazon Web Services (AWS) | Backend application and infrastructure hosting (us-east-1 region) | Application and account data needed to run the Service |
| Email delivery provider (SMTP) | Sending account invites, password resets, and notification emails | Your name and email address, and the content of the relevant email |
We do not permit these providers to use your personal information for their own independent marketing purposes. We do not currently integrate any advertising, social-media tracking, or marketing-automation services.
11. International Data Transfers
TimeApp's infrastructure is hosted in the United States (AWS us-east-1, plus Vercel's global network). If you're accessing the Service from the UK, EU, Canada, or elsewhere outside the US, your information will be transferred to and processed in the US. Where required, we rely on appropriate safeguards for such transfers (such as our providers' own standard contractual clauses or equivalent mechanisms) to protect your information consistent with applicable law.
12. Children's Privacy
TimeApp is a workplace scheduling tool intended for use by working adults on behalf of their employer. It is not directed at children, and we do not knowingly collect personal information from anyone under the age of 16. If you believe a child has provided us with personal information, contact us and we'll take steps to delete it.
13. Automated Decision-Making
TimeApp does not use your personal information to make decisions that produce legal or similarly significant effects about you through fully automated means (for example, automated hiring or termination decisions). Certain values shown in the app — such as overtime warnings, availability conflicts, and leave-balance calculations — are computed automatically to inform a human decision-maker (your manager or admin), not to replace one.
14. Changes to This Policy
We may update this Privacy Policy from time to time — for example, to reflect a new feature, a new service provider, or a change in the law. Material changes will update the "Last updated" date at the top of this page, and where a change meaningfully affects how cookies are used, we'll ask you to reconfirm your cookie preferences the next time you visit.
Revision history
| Version | Date | Summary |
|---|---|---|
| 1.1 | July 28, 2026 | Added the account-based Privacy Centre: per-category consent history, re-consent on policy updates, and self-service data subject request (access/rectification/deletion/portability/restriction) submission and tracking. |
| 1.0 | July 27, 2026 | Initial publication of the Privacy Policy and Cookie Preference Centre. |
15. Contact Us
For questions, concerns, or to exercise any of the privacy rights described above, contact us at:
Email: support@vervemobileng.com
We have not currently appointed a dedicated Data Protection Officer; privacy enquiries are handled directly by our support team and escalated internally as needed. If you're not satisfied with our response, see Section 8 for how to lodge a complaint with your local data protection authority.