Who this notice covers
Timecard Lab provides workforce timekeeping and operations software to customer organisations. The customer normally decides why employee and contractor records are processed and acts as the data controller. Timecard Lab processes that workspace data on the customer’s instructions. We act as controller for account administration, product security, billing, and our own website communications.
Information we process
- Identity and account information, including names, work email addresses, roles, invitations, and authentication events.
- Workspace records, including time entries, work codes, schedules, leave, approvals, corrections, attachments, rates, and operational evidence entered by a customer.
- Technical and security data, including device, session, IP-derived security signals, audit events, and service logs.
- Subscription and billing metadata. Payment card details are handled by Stripe and are not stored by Timecard Lab.
- Integration data when a customer enables services such as QuickBooks Online.
Why we use it
We use information to provide and secure the service, authenticate users, run the workflows selected by a customer, send operational messages, support users, administer subscriptions, prevent abuse, meet legal obligations, and improve reliability. We do not sell personal information or use workspace data for advertising.
Providers and international processing
Our current service providers include WorkOS for authentication, AWS for production compute, database, backups, storage, and secrets, Cloudflare for network delivery and protection, Resend for transactional email, and Stripe for billing. Intuit receives data only when a customer enables QuickBooks Online. Production infrastructure is currently hosted in AWS US East (N. Virginia), so information may be processed outside the user’s country. We use provider and contractual safeguards appropriate to the service and can provide current transfer details during procurement.
Retention and deletion
Workspace records are retained while the customer account is active and for the period required to provide exports, recovery, security evidence, billing records, or comply with law. Backup copies expire through controlled backup cycles. A customer administrator can request account closure or deletion, subject to legal and security retention needs. Customers remain responsible for choosing a retention period that fits their contracts and policies.
Cookies and local storage
We use essential cookies and browser storage for secure sessions, authentication, and product operation. The public calculators run in the browser and do not submit their inputs to Timecard Lab. We do not currently use advertising trackers on the public website.
Your choices and rights
Depending on where you live, you may have rights to access, correct, export, restrict, object to, or delete personal information. Employees should normally begin with their employer, which controls the workspace. You can also contact us at privacy@timecardlab.com. We may need to verify a request before acting on it.
Changes
We will update this page when our practices materially change and will change the date above. Material changes affecting customer workspace data may also be communicated to account administrators.