TimeVP ("TimeVP", "we", "us", or "our") respects your privacy and is committed to protecting personal information entrusted to us.

This Privacy Policy explains how TimeVP collects, uses, stores, discloses, and otherwise processes personal information when you use https://timevp.com, the TimeVP web application, desktop applications, integrations, and related services (collectively, the "Service").

Because TimeVP is a workforce productivity and management platform, the Service may process information relating to employees, contractors, teams, and other workers on behalf of organizations that use TimeVP. In those circumstances, the organization using TimeVP may determine what information is collected, why it is collected, and how it is used.

Please read this Privacy Policy together with any applicable Terms of Service, Data Processing Agreement ("DPA"), Acceptable Use Policy, Cookie Policy, or other agreements governing your use of TimeVP.

1. Who This Privacy Policy Applies To

This Privacy Policy applies to:

  • visitors to the TimeVP website;
  • individuals who create or use a personal TimeVP account;
  • administrators and other representatives of TimeVP customers;
  • employees, contractors, and other workforce members whose information is processed through a customer's TimeVP workspace;
  • individuals who contact TimeVP for support, sales, security, or other business purposes; and
  • individuals whose information is otherwise processed through the Service.

This Privacy Policy does not necessarily apply to processing performed by our customers independently of TimeVP or to third-party websites, services, or applications that have their own privacy policies.

2. Important Information About Your Organization

When TimeVP is used by an organization to monitor or manage its workforce, that organization generally determines:

  1. what workforce information is collected;
  2. the purposes for which the information is processed;
  3. which employees or contractors are included;
  4. how long information is retained;
  5. who within the organization can access the information; and
  6. how information may be used for employment or operational purposes.

In these circumstances, the organization may act as the data controller, business, or data fiduciary, as applicable under the law governing the processing, while TimeVP generally acts as a data processor, service provider, or data processor/contractor acting on the organization's documented instructions.

Accordingly, if you use TimeVP because your employer, client, or organization requires you to do so, privacy requests relating specifically to your workforce data may need to be directed to that organization first.

TimeVP will provide reasonable assistance to customers to help them respond to lawful privacy requests relating to personal data processed through the Service.

3. Information We Collect

The information TimeVP collects depends on how you use the Service and which features are enabled.

3.1 Account and Registration Information

When you create or manage an account, we may collect:

  • name;
  • email address;
  • password or authentication credentials;
  • profile information;
  • organization or company name;
  • job title or role;
  • account identifiers;
  • workspace information;
  • authentication provider information;
  • account preferences; and
  • other information you voluntarily provide.

If you sign in using a third-party authentication provider, such as Google or another supported provider, that provider may provide us with information necessary to authenticate your account. We only receive information permitted by the authentication flow and applicable permissions.

3.2 Organization and Workspace Information

If you create or administer a TimeVP workspace, we may collect:

  • company or organization details;
  • workspace name;
  • team information;
  • user roles and permissions;
  • billing and subscription information;
  • workspace configuration;
  • administrative settings;
  • invited-user information; and
  • records of actions taken by workspace administrators.

4. Workforce and Productivity Information

Depending on the TimeVP features enabled by a customer, the Service may process information relating to employee or worker activity.

This may include:

  • time worked or tracked;
  • start and stop times;
  • active and idle periods;
  • application usage information;
  • website or domain usage information;
  • productivity or activity metrics;
  • keyboard and mouse activity metrics, where enabled;
  • work-session information;
  • project, task, or team associations;
  • attendance-related information;
  • meeting or work-mode information, where supported;
  • device information;
  • operating-system information;
  • network or technical information;
  • screenshots or screen-related data, where the customer has enabled such functionality;
  • notes, comments, labels, or other information entered by users or administrators; and
  • AI-generated summaries, classifications, recommendations, or productivity insights based on information processed by the Service.

The specific information collected depends on the TimeVP configuration selected by the customer.

TimeVP should only be configured and used for workplace monitoring in a lawful, proportionate, transparent, and appropriate manner.

Customers are responsible for notifying affected workers and obtaining any required consent or other lawful authorization before enabling monitoring features where required by applicable law.

5. Device and Technical Information

When you access the Service, we may automatically collect certain technical information, including:

  • IP address;
  • approximate location derived from IP address;
  • browser type and version;
  • operating system;
  • device type;
  • application version;
  • language and regional settings;
  • device identifiers;
  • crash reports;
  • diagnostic information;
  • login timestamps;
  • session information;
  • referring URLs;
  • pages or features accessed; and
  • security and fraud-prevention information.

We use this information primarily to provide, secure, maintain, troubleshoot, and improve the Service.

6. Information From Integrations and Third-Party Services

TimeVP may integrate with third-party services or platforms.

Depending on the integration, we may receive information from services such as:

  • authentication providers;
  • communication tools;
  • productivity applications;
  • project-management platforms;
  • payment providers;
  • cloud-storage providers;
  • analytics services;
  • customer-support platforms; or
  • other services configured by you or your organization.

The information received through an integration depends on the permissions granted and the configuration selected by the applicable user or organization.

Third-party services remain subject to their own privacy policies and terms.

7. Payment and Billing Information

When a customer subscribes to a paid TimeVP plan, payment information may be processed by a third-party payment provider.

TimeVP may receive information such as:

  • billing name;
  • billing email;
  • billing address;
  • subscription plan;
  • transaction identifiers;
  • invoice information;
  • payment status;
  • limited payment-method information; and
  • renewal or cancellation information.

Unless expressly stated otherwise, TimeVP does not need to receive or store complete payment-card numbers when payments are handled by our payment provider.

Payment Provider: [Insert payment provider(s)]

8. Communications and Support Information

When you contact us, we may collect:

  • your name;
  • email address;
  • company or organization;
  • support requests;
  • messages;
  • attachments;
  • screenshots you submit;
  • troubleshooting information; and
  • other information you choose to provide.

We use this information to respond to inquiries, provide support, investigate problems, and improve our Service.

9. Cookies and Similar Technologies

TimeVP may use cookies, pixels, local storage, SDKs, and similar technologies.

These technologies may be used for purposes such as:

Strictly Necessary Technologies

These are used to:

  • authenticate users;
  • maintain sessions;
  • protect accounts;
  • prevent fraud;
  • maintain security; and
  • operate essential parts of the Service.

Preferences

These may remember settings such as:

  • language;
  • regional preferences;
  • interface settings; and
  • other user preferences.

Analytics

Analytics technologies may help us understand:

  • website traffic;
  • feature usage;
  • errors;
  • performance;
  • conversion behavior; and
  • general product usage.

Marketing Technologies

Where permitted, we may use marketing or advertising technologies to measure campaigns, understand website interactions, or deliver relevant marketing communications.

Where legally required, we will request consent before placing or accessing non-essential cookies or similar technologies.

You can control certain cookies through your browser or our cookie-consent controls, where available.

See our Cookie Policy for additional information.

10. How We Use Personal Information

We may use personal information for the following purposes:

Providing the Service

To:

  • create and manage accounts;
  • provide workforce-management functionality;
  • track work sessions;
  • generate productivity dashboards;
  • provide analytics and reporting;
  • support workspace administration;
  • synchronize information;
  • provide integrations;
  • process subscriptions;
  • and otherwise deliver the Service.

Security and Fraud Prevention

To:

  • detect suspicious activity;
  • prevent unauthorized access;
  • protect users and systems;
  • investigate security incidents;
  • enforce access controls; and
  • maintain the security and integrity of TimeVP.

Product Improvement

To:

  • understand how features are used;
  • identify technical issues;
  • improve usability;
  • develop new functionality;
  • evaluate performance; and
  • improve the reliability of our systems.

Where legally required, we will use aggregated, de-identified, or otherwise appropriately protected information for product analytics and improvement.

Customer Support

To:

  • respond to support requests;
  • diagnose technical issues;
  • investigate reported problems;
  • communicate service-related information; and
  • provide customer assistance.

Billing and Account Administration

To:

  • process subscriptions;
  • issue invoices;
  • administer plans;
  • manage payments;
  • detect billing fraud; and
  • handle cancellations and account changes.

Legal and Compliance Purposes

To:

  • comply with applicable law;
  • respond to lawful requests from authorities;
  • enforce agreements;
  • protect our legal rights;
  • investigate suspected abuse or violations; and
  • resolve disputes.

Communications and Marketing

Where permitted by law, we may use contact information to send:

  • product updates;
  • transactional communications;
  • security notices;
  • service announcements;
  • educational content; and
  • marketing communications.

You may unsubscribe from non-essential marketing communications at any time.

11. AI Features and Automated Processing

TimeVP may use artificial intelligence and machine-learning technologies to provide features such as:

  • productivity summaries;
  • activity classification;
  • work-session analysis;
  • insights;
  • recommendations;
  • categorization;
  • natural-language summaries;
  • administrative assistance; and
  • other AI-powered workforce-management functionality.

AI processing may involve analyzing information submitted to or generated through the Service.

Where AI features are enabled, TimeVP will process information according to the applicable customer configuration, agreements, and instructions.

Human Decision-Making

TimeVP's AI-generated outputs may contain errors or inaccuracies and should not automatically be treated as definitive facts about a person.

Customers are responsible for determining whether and how AI-generated information is used in employment, performance, disciplinary, compensation, hiring, termination, or other significant decisions.

Where applicable law restricts solely automated decision-making or profiling that produces legal or similarly significant effects, customers must configure and use TimeVP in accordance with those requirements.

TimeVP does not represent that AI-generated outputs are a substitute for appropriate human review.

12. How We Protect Worker Privacy

TimeVP is designed for organizational productivity and workforce-management use.

Customers should configure monitoring features in a manner that is appropriate for their workforce, jurisdiction, business purpose, and legitimate operational needs.

Customers should avoid collecting information that is unnecessary for the stated purpose of monitoring.

Where available, TimeVP may provide controls that allow organizations to configure monitoring settings, permissions, visibility, retention, work modes, or similar privacy controls.

Because laws governing employee monitoring vary significantly by jurisdiction, organizations using TimeVP are responsible for determining whether their use of monitoring features is permitted and what notices, consents, agreements, assessments, or policies are required.

TimeVP does not authorize customers to use the Service for unlawful surveillance.

Where laws such as the GDPR or UK GDPR apply, we process personal data only where an applicable legal basis exists.

Depending on the circumstances, the legal basis may include:

Performance of a Contract

Where processing is necessary to:

  • create an account;
  • provide the Service;
  • administer a subscription; or
  • fulfill contractual obligations.

Legitimate Interests

Where processing is necessary for legitimate interests pursued by us or a third party, provided those interests are not overridden by applicable individual rights and freedoms.

Examples may include:

  • maintaining Service security;
  • preventing fraud;
  • improving our products;
  • operating our business; and
  • communicating with business customers.

Consent

Where consent is required and we rely on consent, you may withdraw it as permitted by applicable law.

Withdrawal of consent does not affect the lawfulness of processing that occurred before withdrawal.

Legal Obligations

Where processing is necessary to comply with an applicable legal obligation.

Other Lawful Bases

Where applicable law provides additional lawful bases, we may rely on those bases where appropriate.

For workforce data processed on behalf of a customer, the customer's applicable legal basis may be different. The customer remains responsible for identifying and documenting the appropriate legal basis for employee monitoring.

14. How We Share Personal Information

We may disclose personal information to the following categories of recipients.

Service Providers and Subprocessors

We may use third-party service providers to operate the Service, including providers for:

  • cloud hosting;
  • databases;
  • authentication;
  • analytics;
  • monitoring;
  • customer support;
  • communications;
  • payments;
  • security;
  • AI or machine-learning infrastructure;
  • email delivery;
  • error tracking; and
  • other technical services.

These providers may process personal information only as necessary to provide services to us and subject to contractual or other applicable safeguards.

A current list of material subprocessors may be available at:

[Insert TimeVP Subprocessor Page URL]

Customers and Workspace Administrators

Where TimeVP processes workforce data on behalf of an organization, information may be accessible to authorized administrators and other users designated by that organization according to its settings and permissions.

Legal and Regulatory Authorities

We may disclose information where reasonably necessary to:

  • comply with applicable law;
  • comply with legal process;
  • respond to lawful government requests;
  • investigate fraud or security incidents;
  • protect the rights, property, or safety of TimeVP, our users, or others; or
  • establish, exercise, or defend legal claims.

Corporate Transactions

Personal information may be transferred as part of a merger, acquisition, financing, restructuring, sale of assets, bankruptcy, or similar transaction, subject to applicable law.

We do not sell personal information as a commodity or in exchange for money.

15. International Data Transfers

TimeVP may operate or use service providers in countries other than the country in which you live.

As a result, personal information may be transferred to and processed in countries that may have different data-protection laws.

Where required by applicable law, TimeVP will implement appropriate safeguards for international transfers, which may include:

  • adequacy decisions;
  • Standard Contractual Clauses;
  • contractual safeguards;
  • technical and organizational safeguards; or
  • other legally recognized transfer mechanisms.

Additional information regarding applicable transfer mechanisms may be provided in our DPA or subprocessor documentation.

16. Data Retention

We retain personal information only for as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer period is required or permitted by law.

Retention periods vary depending on the type of information and the circumstances.

For example:

  • account information may be retained while an account remains active;
  • billing and transaction information may be retained for legal, tax, and accounting purposes;
  • security logs may be retained for a limited period necessary to investigate incidents and maintain security;
  • workforce information may be retained according to the customer's configuration and agreement with TimeVP; and
  • certain backups may remain for a limited period after deletion due to technical backup processes.

Default TimeVP retention periods:

When a customer deletes or terminates a workspace, TimeVP may delete or anonymize associated information in accordance with the applicable contract, DPA, backup policies, and legal obligations.

17. Data Security

TimeVP uses reasonable technical and organizational measures designed to protect personal information against unauthorized access, alteration, disclosure, loss, destruction, or misuse.

Depending on the Service architecture and applicable risk, these measures may include:

  • encryption in transit;
  • encryption at rest;
  • access controls;
  • authentication and authorization controls;
  • role-based permissions;
  • logging and monitoring;
  • vulnerability management;
  • backup and recovery procedures;
  • security incident response processes;
  • infrastructure security controls; and
  • employee or contractor confidentiality obligations.

No method of transmission or storage is completely secure. Therefore, we cannot guarantee absolute security.

If you believe your TimeVP account or information has been compromised, contact us promptly at:

Support@timevp.com

18. Your Privacy Rights

Depending on your location and applicable law, you may have rights relating to your personal information.

These rights may include:

  • the right to know whether we process personal information about you;
  • the right to access personal information;
  • the right to obtain a copy of personal information;
  • the right to correct inaccurate information;
  • the right to request deletion;
  • the right to restrict certain processing;
  • the right to object to certain processing;
  • the right to data portability;
  • the right to withdraw consent where processing is based on consent;
  • the right to complain to a relevant data protection authority; and
  • rights relating to automated decision-making or profiling where applicable.

These rights are not absolute and may be subject to legal exceptions.

19. Requests Relating to Employee or Workforce Data

If you are an employee, contractor, or other worker whose information is processed through your employer's TimeVP workspace, your employer may be the primary controller of that information.

For requests relating to workplace monitoring data, such as:

  • time records;
  • application activity;
  • website activity;
  • productivity reports;
  • screenshots;
  • work-session history; or
  • other information generated within your employer's workspace,

please contact your employer or the organization responsible for your TimeVP workspace first.

You may also contact TimeVP at:

Support@timevp.com

Where appropriate, we may refer your request to the relevant customer because that customer determines the purposes and means of the applicable processing.

20. European Economic Area, United Kingdom, and Switzerland

Where GDPR, UK GDPR, or equivalent European data-protection laws apply, individuals may have additional rights and protections.

These may include rights of access, rectification, erasure, restriction, objection, portability, and the right not to be subject to certain solely automated decisions, subject to applicable legal conditions and exceptions.

If you believe your rights have been infringed, you may also have the right to lodge a complaint with the supervisory authority in the country in which you live, work, or where the alleged infringement occurred.

For European customers, TimeVP may enter into a Data Processing Agreement and applicable Standard Contractual Clauses or other transfer mechanisms where required.

21. California Privacy Rights

If the California Consumer Privacy Act ("CCPA"), as amended by the California Privacy Rights Act, applies to you, you may have certain rights regarding your personal information.

Depending on the circumstances, these rights may include:

  • the right to know what personal information we collect and how it is used;
  • the right to access personal information;
  • the right to correct inaccurate personal information;
  • the right to request deletion;
  • the right to opt out of the sale or sharing of personal information where applicable;
  • the right to limit certain uses of sensitive personal information where applicable;
  • the right to non-discrimination for exercising applicable privacy rights.

TimeVP does not sell personal information for monetary consideration.

To submit a California privacy request, contact:

Support@timevp.com

We may need to verify your identity before completing a request.

Where TimeVP acts only as a service provider or contractor for a customer, the customer's contractual and legal obligations may apply instead of, or in addition to, TimeVP's direct consumer obligations.

22. India — Digital Personal Data Protection Framework

Where India's Digital Personal Data Protection Act, 2023 ("DPDP Act") and applicable rules apply, TimeVP will process digital personal data in accordance with applicable requirements.

Depending on the circumstances, TimeVP or the relevant customer may act as the applicable Data Fiduciary or Data Processor.

Individuals may have rights under applicable Indian law, including rights relating to:

  • obtaining information about processing;
  • correction or updating of personal data;
  • erasure, subject to applicable requirements;
  • withdrawal of consent where consent is the applicable basis;
  • grievance redressal; and
  • nomination or other rights where applicable under law.

The applicable rights, mechanisms, and effective dates may depend on the provisions of Indian law and their applicable commencement dates.

Requests may be submitted to:

Support@timevp.com

23. Children

TimeVP is designed for businesses and workplace users and is not directed toward children.

We do not knowingly request or intentionally collect personal information from children where prohibited by applicable law.

If you believe a child has provided personal information to TimeVP in circumstances where such collection was not appropriate, contact us so that we can investigate and take appropriate action.

24. Your Responsibilities When Using TimeVP

Customers and users are responsible for using TimeVP lawfully.

In particular, organizations using employee-monitoring functionality are responsible for:

  • providing required notices to workers;
  • identifying an appropriate legal basis;
  • obtaining consent where required;
  • determining appropriate monitoring practices;
  • configuring the Service appropriately;
  • limiting monitoring to legitimate and necessary purposes;
  • complying with employment, labor, privacy, and workplace-monitoring laws;
  • determining appropriate retention periods; and
  • responding to employee privacy requests where they are the applicable controller.

TimeVP does not determine whether a customer's specific workforce-monitoring practice is lawful in a particular country, state, or workplace.

25. Data Accuracy

TimeVP uses reasonable measures to maintain accurate information where appropriate.

However, information generated from activity tracking, automated classification, AI models, device signals, or other technical systems may occasionally be incomplete, incorrect, or misclassified.

Users and customers should consider appropriate human review before relying on automatically generated information for consequential decisions.

26. Third-Party Websites and Services

The Service may contain links to third-party websites, applications, or services.

We are not responsible for the privacy practices, security, or content of third parties.

We encourage you to review the privacy policy of each third-party service you use.

27. Business Transfers

If TimeVP becomes involved in a merger, acquisition, financing, reorganization, sale of assets, bankruptcy, or another corporate transaction, personal information may be transferred as part of that transaction.

Where required by applicable law, we will provide notice or obtain consent before transferring personal information for a materially different purpose.

28. Changes to This Privacy Policy

We may update this Privacy Policy periodically.

When we make changes, we will update the "Last Updated" date at the top of this page.

If we make material changes that require notice under applicable law, we may notify you through the Service, by email, or by another legally appropriate method.

Your continued use of the Service after an updated Privacy Policy becomes effective is subject to the updated policy, except where applicable law requires additional consent.

29. Contact Us

If you have questions, concerns, or requests relating to this Privacy Policy or the processing of personal information, contact us:

TimeVP
Website: https://timevp.com/contact
Email: Support@timevp.com

For employee-monitoring questions relating to a specific workplace, you may also need to contact the organization that provided you with access to TimeVP.

30. Additional Contractual Privacy Protections for Business Customers

Business customers may enter into a Data Processing Agreement ("DPA") with TimeVP.

The DPA may contain additional provisions regarding:

  • processing instructions;
  • confidentiality;
  • security measures;
  • subprocessors;
  • assistance with data-subject requests;
  • breach notification;
  • international transfers;
  • deletion or return of data;
  • audits and compliance information; and
  • other requirements applicable to processor relationships.

Where a valid DPA conflicts with this Privacy Policy regarding the processing of customer data, the DPA may control to the extent specified in that agreement.

31. Definitions

For purposes of this Privacy Policy:

"Personal Information" or "Personal Data" means information that identifies, relates to, describes, or can reasonably be linked or associated with an individual, as defined under applicable law.

"Customer Data" means information submitted to or collected through the Service on behalf of a TimeVP customer.

"Workforce Data" means information relating to employees, contractors, or other workers processed through a customer's TimeVP workspace.

"Process" or "Processing" means any operation performed on personal information, including collection, storage, use, analysis, disclosure, modification, or deletion.

"Controller," "Processor," "Business," "Service Provider," "Data Fiduciary," and "Data Processor" have the meanings assigned to those terms under applicable privacy laws.

32. Effective Date

This Privacy Policy is effective as of October 2, 2026.

By using TimeVP, you acknowledge that you have had an opportunity to review this Privacy Policy.