Privacy Policy
This Privacy Policy explains how Steve Barnard, a Washington sole proprietor doing business as Time Machine Online (“Time Machine Online,” “we,” “us,” or “our”), collects, uses, discloses, retains, and protects personal information through the Time Machine Online websites, applications, support services, and related features (the “Service”). It also explains your privacy choices and request procedures.
This Policy applies to account users, prospective customers, website visitors, and people who contact us. A workspace customer decides which client, contact, invoice, receipt, and other business records to enter. For personal information in those records, the customer is generally the business deciding why and how it is used, and we process it to provide the Service under the customer's instructions. Direct privacy requests about a customer's records may need to be referred to that customer.
1. Information we collect
| Category | Examples and source |
|---|---|
| Account and contact information | Name, email address, password hash, workspace, invitations, role, support preferences, and acceptance records that you or an administrator provide. |
| Workspace business records | Clients and contacts, projects, time entries and notes, invoices and line items, expenses, receipts, mileage, categories, tax-planning settings and payments, reports, email templates, and uploaded files that users enter or upload. |
| Billing and transaction information | Subscription status, Stripe customer and subscription identifiers, billing contact, price, dates, cancellation feedback, payment-link identifiers, and transaction results. Stripe collects complete payment-card data directly; we do not receive or store full card numbers or CVCs. |
| Support and communications | Tickets, messages, attachments, consent to workspace access, email delivery events, sender and recipient information, and communication history. |
| Security, analytics, and technical information | Session identifiers, IP address, request time, route and response metadata, page-view and visitor analytics, limited browser/device information, audit events, security signals, error traces, and diagnostic context. Optional error monitoring is configured to remove request bodies, cookies, credentials, query strings, and direct user identifiers before transmission. |
| Information from others | Subscription and fraud results from Stripe, address suggestions and validation results from Google Maps Platform, delivery and inbound-message events from email providers, bot-risk signals from Cloudflare Turnstile, password-compromise results from Have I Been Pwned, and information an authorized workspace user provides about clients or colleagues. |
Receipts, support attachments, free-text notes, and invoice content may contain information you choose to include. Do not submit Social Security numbers, full payment-card data, account passwords, health information, or other highly sensitive personal information unless a Service field expressly requests it.
2. How we use information
We use personal information to:
- create and authenticate accounts, provide tenant-separated workspaces, and operate requested features;
- generate records, invoices, exports, reports, emails, and payment links at your direction;
- process subscriptions, trial conversion, renewal, cancellation, failed-payment recovery, reactivation, refunds, and tax obligations;
- provide support, investigate problems, communicate service and legal notices, and document consent to workspace access;
- secure the Service, prevent abuse, screen compromised passwords, enforce terms, audit sensitive activity, and respond to incidents;
- maintain, troubleshoot, and improve reliability using minimized operational information; and
- comply with law, preserve legal claims, and respond to lawful process.
We do not use Customer Data to train a general-purpose artificial-intelligence model. We do not make decisions producing legal or similarly significant effects through automated profiling. We do not use personal information for targeted or cross-context behavioral advertising.
3. How we disclose information
We may disclose personal information:
- to service providers that host, secure, monitor, email, store, or support the Service under contractual restrictions;
- to Stripe and payment networks to process transactions, prevent fraud, and satisfy financial or legal obligations;
- within a workspace, according to the workspace's access controls and administrator choices;
- to professional advisers, auditors, insurers, or authorities when reasonably necessary to comply with law, protect rights and safety, investigate abuse, or establish legal claims; and
- in a merger, financing, reorganization, bankruptcy, or sale of relevant assets, subject to appropriate confidentiality and notice where required.
We do not sell personal information for money. We do not share personal information for cross-context behavioral advertising. We do not knowingly collect or disclose personal information for targeted advertising.
4. Providers and third-party services
| Provider | Purpose and information |
|---|---|
| Stripe | Checkout, Customer Portal, recurring billing, fraud prevention, and optional invoice payment links; receives billing, payment, device, and transaction information. Stripe may act independently for payment-network, fraud, and compliance purposes. |
| Vercel | Application hosting, delivery, and cookie-free Web Analytics; may process requests, IP addresses, headers, operational logs, page-view and visitor statistics, and customer data needed to serve requests. |
| Supabase | Managed PostgreSQL database and backups; stores workspace, account, support, billing-state, and audit records. |
| Cloudflare Turnstile | Signup bot and abuse prevention; processes browser, device, network, interaction, and IP signals. |
| Google Maps Platform | At your request, provides U.S. address suggestions and validation. Our server sends the address search text, selected address, or postal-address fields needed for the lookup; unrelated workspace records and the server API key are not included. Google's processing is also described in the Google Privacy Policy. |
| Resend | Primary support, account-lifecycle, password-reset, invitation, and transactional email; processes message content, attachments where allowed, and sender/recipient/delivery metadata. |
| Postmark | May be configured as an alternative provider for invoice or account email; processes message content and delivery metadata. Support email remains Resend-only. |
| Sentry | Optional error monitoring using minimized stack traces and diagnostic context. Default personal-information collection is disabled; request bodies, cookies, credentials, query strings, and direct identifiers are scrubbed; Session Replay is not approved. |
| Have I Been Pwned | Password-compromise screening. Our server sends only a padded five-character prefix of the password's SHA-1 hash, never the password or complete hash. |
| Google Fonts | The public website and application may request font files directly from Google, disclosing IP address and ordinary HTTP request metadata. No workspace record is intentionally included. |
Providers may use their own subprocessors under their data-processing terms. An up-to-date operational subprocessor list and request channel are available through Support. Third-party services you independently choose may apply their own privacy policies.
6. Retention and deletion
We keep personal information only for the Service, security, legal, and recordkeeping purposes described below, subject to a documented legal or security hold:
| Record | Retention |
|---|---|
| Active workspace content | While the account is active and as needed to provide the Service. |
| Canceled or expired workspace content | 90 days after lockout, followed by deletion from active systems within 30 days. |
| Backups containing deleted content | Up to 35 additional days after active-system deletion; used only for disaster recovery. |
| Sessions | Until logout, invalidation, or 30 days after creation, whichever occurs first. |
| Expired reset and invitation tokens | 30 days after expiration or use. |
| Application, security, analytics, and performance logs | 30 days where Time Machine Online controls retention; relevant excerpts may be preserved for up to one year for a documented security investigation. Vercel Web Analytics retention is managed in Vercel under the selected plan and account settings. |
| Sentry error events | No more than 30 days. |
| Support tickets | Messages and events: three years after closure. Attachment content: 90 days after closure; attachment metadata: three years. |
| Email delivery and application audit records | Three years, unless required for an unresolved dispute or security matter. |
| Subscription, payment, refund, tax, contract, policy-acceptance, fraud, and deletion evidence | Seven years after account closure or the transaction, whichever is later. We retain only the information reasonably necessary for those purposes. |
Stripe and independently used third-party services may retain records under their own legal obligations. De-identified information that cannot reasonably identify a person may be retained. Where immediate deletion from a provider backup is impracticable, the data remains protected and is deleted on the backup schedule.
7. Privacy requests and account deletion
Depending on where you live, you may have rights to know or access personal information, obtain a portable copy, correct inaccurate information, delete information, opt out of sale, sharing, or targeted advertising, limit certain sensitive-information uses, and appeal a denial. We do not discriminate for exercising a privacy right. Authorized agents may submit requests where law permits, subject to proof of authority and verification.
How to submit. If you can sign in, create a Support request with the type Data, privacy, or security concern. If you cannot sign in, email team@timemachineonline.com from the account email. State the request and the relevant account or workspace. Do not send a password, full card number, government ID, or unrelated sensitive document.
Timing and verification. We acknowledge requests within 10 business days and respond within 45 calendar days. When reasonably necessary, we may extend once by 45 days and explain why during the first period. We verify through an authenticated session or a one-time link to the account email. Workspace-wide export or deletion also requires authority as the billing contact or original workspace creator. We use information from a request only to verify and fulfill it.
Access and portability. Signed-in users can request or use a tenant-scoped account export. We deliver exports through an authenticated or expiring path and do not email raw workspace exports. Information about another person may be redacted where required.
Account deletion. Cancellation alone does not delete a workspace. For early deletion, submit a verified request. We explain the scope, offer an export, and require a second explicit confirmation. We then stop renewal, invalidate sessions and account tokens, revoke public invoice links and connected credentials, lock new writes, and delete active workspace content within 30 days, subject to the narrow retention exceptions above. We send completion notice and preserve minimal evidence of the request and result. Deletion is irreversible after backups expire and applies to the entire workspace, including its users.
If we deny a request or rely on an exception, we will explain the reason where legally permitted. You may appeal by replying to the request ticket; a different reviewer will decide the appeal within 45 days. You may also contact your state attorney general or other privacy regulator.
8. Security, processing location, and children
We use administrative, technical, and physical safeguards designed for the nature of the information, including encrypted transport, password hashing, tenant separation, restricted production access, security headers, rate limiting, audit logging, and provider access controls. No method is perfectly secure. Report a suspected vulnerability through Security or Support.
The Service is operated for United States customers and information is processed in the United States. Providers and their subprocessors may process information in other locations under their contractual safeguards. The Service is not directed to children, and users must be at least 18. We do not knowingly collect personal information directly from children. Contact us if you believe a child provided information without authorization.
9. Changes and contact
2026-07-27 update: This Policy now discloses cookie-free Vercel Web Analytics and the URL sanitization applied before analytics events are sent.
We may update this Policy. We will provide reasonable notice of material changes. Changes to data categories or purposes, disclosure, retention or deletion, privacy rights, or the operator require a new dated version and acknowledgement before further account use. A changed document is also detected by its cryptographic hash. Prior acceptance records are retained and never backfilled.
For questions or requests, contact:
Steve Barnard, a Washington sole proprietor doing business as Time Machine Online
21006 154th St E
Bonney Lake, WA 98391
Email: team@timemachineonline.com