Legal

Privacy Policy

Effective and last updated: July 29, 2026
NOTE

This describes how Timesheets actually handles data today, written by the people who built it rather than adapted from a generic template. It's a real starting point, not a substitute for legal review in your jurisdiction, especially if your organization has its own regulatory obligations around employee data.

1.Scope, and two kinds of data

This policy covers Timesheets (the "Service"), operated by 8WhiteRock ("we," "us," "our"). It distinguishes two categories of data, because different people control each:

If you're an employee whose organization invited you, your organization (not us) is who to ask about how your work data is used within it — we're the infrastructure it runs on.

2.Information we collect

CategoryExamples
IdentityName, email address
CredentialsPassword (hashed, never stored or visible in plain text)
Work dataTime entries, timesheet status and approval history, notes attached to a return or an undo
CompensationHourly rate, where an Owner chooses to record one — visible only to that organization's Owner, never to peers
Organization setupOrganization name, approval chain and department configuration, property/location names, job board configuration
TechnicalIP address (used for abuse/rate-limit protection on account creation — see the Terms of Service), browser session identifiers
BillingSubscription plan and status; card details are handled entirely by Stripe and never reach our own servers

3.How we use information

We do not sell personal information, and we do not use Customer Data to train any model or for any purpose beyond providing the Service to the organization it belongs to.

4.Who we share information with

We use a small number of third-party providers to run the Service. None of them are permitted to use your data for their own purposes beyond providing their service to us.

ProviderRole
SupabaseDatabase, authentication, and file storage — where essentially all Service data lives
StripePayment processing for paid plans — handles and stores card details directly, we never see them
ResendDelivery of transactional email (invites, notifications, verification codes, digests)
VercelApplication hosting

We may also disclose information if required by law, or to protect the rights, safety, or property of 8WhiteRock, our users, or others. We do not sell personal information to third parties or use it for third-party advertising.

5.Security

Data is encrypted in transit (HTTPS). Passwords are never stored in plain text — authentication is handled by Supabase Auth using industry-standard hashing. Cross-organization data isolation is enforced at the database level (Postgres Row Level Security), not just in application code, so one organization's data isn't reachable through another's session even in the event of an application-layer bug. No method of transmission or storage is perfectly secure, and we can't guarantee absolute security.

6.Data retention

An organization's Owner can configure how long closed timesheets stay in the default view before being archived — archiving hides them from the default view, it doesn't delete them. An organization can be permanently deleted (by request), which removes its data from active use; brief residual copies may exist in infrastructure backups until they age out through our providers' normal rotation.

7.Cookies

We use essential session cookies to keep you signed in — nothing more. We don't currently use third-party analytics, advertising, or tracking cookies of any kind.

8.Your choices

If you're an individual whose data was entered by an organization that invited you, requests about that data (access, correction, deletion) should generally go through that organization's Owner first, since they control it. If you're an organization's Owner, or you'd like help we can't otherwise route through the app, contact us at the address below.

9.Children's privacy

The Service is a workplace tool, not directed at children, and we don't knowingly collect information from anyone under the age required to work in their jurisdiction.

10.International data

Our infrastructure providers may process and store data outside your own country. By using the Service, you consent to that transfer as necessary to provide it.

11.Changes to this policy

We may update this policy from time to time; the "last updated" date at the top reflects the most recent change. Material changes will be reflected here with an updated date.

12.Contact

Questions about this policy, or a data request: feedback@8whiterock.com.