Back to home

Privacy Policy

Last updated: March 25, 2026

This privacy policy is currently under legal review and is subject to change.

1. Introduction

TimeFlov AB ("We") is the data controller for the personal data we process when you use our service. This privacy policy explains how we collect, use, and protect your personal data in accordance with the EU General Data Protection Regulation (GDPR).

2. Data We Collect

Account Data

First and last name, email address, role, company affiliation, profile picture (via OAuth provider).

Business Data

Time entries, expense reports, invoices, projects, clients, vendors, approval workflows, and accounting records you create in the Service.

Technical Data

IP address, browser type, device information, session data, and usage analytics to provide and improve the Service.

3. Purpose & Legal Basis

Purpose Legal Basis
Providing the Service Contract (Art. 6.1.b)
Account management & authentication Contract (Art. 6.1.b)
Billing & payment processing Contract (Art. 6.1.b)
Improving the Service Legitimate interest (Art. 6.1.f)
Legal obligations (accounting) Legal obligation (Art. 6.1.c)

4. Data Retention

We retain your personal data for as long as your account is active or as needed to fulfill the purpose of processing. Upon account deletion, your data is removed within 30 days, except for data we are legally required to retain (e.g., accounting records for 7 years).

5. Your Rights

Under GDPR, you have the following rights regarding your personal data:

  • Right of Accessrequest a copy of your personal data.
  • Right to Rectificationcorrect inaccurate or incomplete data.
  • Right to Erasurerequest deletion of your personal data.
  • Right to Portabilityreceive your data in a machine-readable format.
  • Right to Objectobject to processing based on legitimate interest.
  • Right to Restrictionrestrict processing under certain circumstances.

To exercise your rights, contact us at privacy@timeflov.com.

6. Data Protection Officer

Our Data Protection Officer can be contacted at:

dpo@timeflov.com

7. Cookies & Local Storage

We use session cookies for authentication (Supabase Auth) and localStorage for language preferences (i18nextLng) and UI preferences (theme, sidebar). We do not use third-party cookies for advertising or tracking.

8. Data Sharing & Transfers

We share your data with the following sub-processors: Supabase (database hosting, EU), Cloudflare (CDN/hosting), Stripe (payment processing). We do not transfer your data outside the EU/EEA without appropriate safeguards.

9. Security

We employ technical and organizational measures to protect your data, including: encryption in transit (TLS) and at rest, row-level security (RLS) for data isolation, regular security audits, and multi-factor authentication via OAuth providers.

10. Complaints

If you are dissatisfied with how we handle your personal data, you have the right to lodge a complaint with Integritetsskyddsmyndigheten (IMY), the Swedish data protection authority.

www.imy.se

Contact

Questions about this privacy policy may be directed to:

TimeFlov AB
privacy@timeflov.com