1. Introduction
TimeFlov AB ("We") is the data controller for the personal data we process when you use our service. This privacy policy explains how we collect, use, and protect your personal data in accordance with the EU General Data Protection Regulation (GDPR).
2. Data We Collect
Account Data
First and last name, email address, role, company affiliation, profile picture (via OAuth provider).
Business Data
Time entries, expense reports, invoices, projects, clients, vendors, approval workflows, and accounting records you create in the Service.
Technical Data
IP address, browser type, device information, session data, and usage analytics to provide and improve the Service.
3. Purpose & Legal Basis
| Purpose | Legal Basis |
|---|---|
| Providing the Service | Contract (Art. 6.1.b) |
| Account management & authentication | Contract (Art. 6.1.b) |
| Billing & payment processing | Contract (Art. 6.1.b) |
| Improving the Service | Legitimate interest (Art. 6.1.f) |
| Legal obligations (accounting) | Legal obligation (Art. 6.1.c) |
4. Data Retention
We retain your personal data for as long as your account is active or as needed to fulfill the purpose of processing. Upon account deletion, your data is removed within 30 days, except for data we are legally required to retain (e.g., accounting records for 7 years).
5. Your Rights
Under GDPR, you have the following rights regarding your personal data:
- Right of Access — request a copy of your personal data.
- Right to Rectification — correct inaccurate or incomplete data.
- Right to Erasure — request deletion of your personal data.
- Right to Portability — receive your data in a machine-readable format.
- Right to Object — object to processing based on legitimate interest.
- Right to Restriction — restrict processing under certain circumstances.
To exercise your rights, contact us at privacy@timeflov.com.
6. Data Protection Officer
Our Data Protection Officer can be contacted at:
7. Cookies & Local Storage
We use session cookies for authentication (Supabase Auth) and localStorage for language preferences (i18nextLng) and UI preferences (theme, sidebar). We do not use third-party cookies for advertising or tracking.
8. Data Sharing & Transfers
We share your data with the following sub-processors: Supabase (database hosting, EU), Cloudflare (CDN/hosting), Stripe (payment processing). We do not transfer your data outside the EU/EEA without appropriate safeguards.
9. Security
We employ technical and organizational measures to protect your data, including: encryption in transit (TLS) and at rest, row-level security (RLS) for data isolation, regular security audits, and multi-factor authentication via OAuth providers.
10. Complaints
If you are dissatisfied with how we handle your personal data, you have the right to lodge a complaint with Integritetsskyddsmyndigheten (IMY), the Swedish data protection authority.
Contact
Questions about this privacy policy may be directed to:
TimeFlov AB
privacy@timeflov.com