Privacy Policy

Last updated: August 3, 2026

This is a template draft, not legal advice. Review it with a lawyer for your jurisdictions and data practices before publishing.

1. Who we are

TimeWave is a time-tracking and task-management service for teams. This policy explains what data we process when you use TimeWave.

2. Data we collect

• Account data: name, email and a password hash (we never store your password).

• Organization data: members, roles, rates, exchange rates, settings.

• Work data: time entries, projects, tasks, comments, knowledge-base documents and uploaded attachments.

• Technical data: server logs and the request IP address (for security and rate limiting).

3. Cookies

We use strictly necessary cookies only: a signed, http-only session cookie (sign-in), plus cookies for your chosen language and theme. No advertising or third-party tracking cookies.

4. Web analytics

We count visits with our own installation of Umami, on our own server. It sets no cookies and collects no personal data: it records the page, the referrer, country, device type and browser. The visitor identifier is a hash that changes every day, so visits on different days cannot be tied together.

Nothing leaves our infrastructure and nothing goes to an advertising network. That is why there is no consent banner — there is nothing to consent to.

5. How we use data

To provide the service: authentication, showing your organizations and work data, computing time and money analytics, and sending service email (invites, password resets). We do not sell your data.

6. Storage and security

Structured data is stored in a PostgreSQL database; documents and attachments are stored as files (disk or S3-compatible object storage). Passwords are hashed with bcrypt; API keys are hashed and scoped. Traffic is encrypted with TLS.

7. Sharing

Organization data is accessible only to its members according to their roles. We use infrastructure providers (hosting, object storage, email delivery) solely to operate the service. We do not share data with third parties for advertising.

8. Retention and deletion

Data is kept while your organization is active. Deleting an organization cascades the deletion of its data and removes associated files from storage. Backups may be retained for a limited period.

9. Your rights

You may request access to, correction of, or deletion of your data by contacting us. An organization owner manages membership and can delete the organization.

10. Changes

We may update this policy. Material changes will be reflected by the “last updated” date at the top of this page.

11. Contact

Privacy questions: support@timewave.cloud.