Who we are

Timecoda is a timesheet and workforce application operated by Innovative Data Solutions LLC (“we”, “us”, “our”). The product lives at app.timecoda.com (production) and staging.timecoda.com (staging). Privacy questions and requests: support@timecoda.com.

Scope and roles

Timecoda is a multi-tenant service. Organizations invite people to track time, request leave, and run reports. How responsibility is split:

  • Account and authentication data (your Timecoda user, Google Sign-In identity, session cookies) — we are the controller.
  • Organization workspace data (timecards, charge codes, leave, compensation when enabled, memberships, employee notes, imports) — the customer organization is typically the controller, and we process that data on the organization’s instructions.

If your employer or client invited you, they decide what workplace data is stored and who inside the organization can see it. Contact their Timecoda admin first for those records; we can help at support@timecoda.com.

Google Sign-In

You can sign in or create a Timecoda account with Google. We request only the OpenID Connect scopes openid, email, and profile. From Google we receive:

  • Your Google user identifier (sub)
  • Email address and whether Google has verified that email
  • Name (including given name and family name when Google provides them)

We use that Google user data only to authenticate you, create or link a Timecoda account, and show your name and email in Timecoda. We store the Google provider, user identifier, and email on a linked identity record. We do not store Google access tokens or refresh tokens. We do not access Gmail, Google Drive, Google Calendar, Contacts, or any other Google product API.

Timecoda’s use of information received from Google APIs adheres to the Google API Services User Data Policy , including the Limited Use requirements.

If we ever want to use Google user data for a new purpose, we will update this policy and obtain any consent required before that new use.

Information we collect

Account profile

Email, first and last name, password hash (if you set a password), timezone, optional street address, city, state, postal code, country, phone, and emergency contact name and phone.

Organization and membership

Organization name and settings, your role (for example owner, admin, approver, employee, or viewer), hire and timecard dates, FLSA classification when recorded, notification preferences, and invitation details.

Workplace records

Timecard entries (dates, hours, comments, charge codes), live timers, leave requests and balances, flex time, holidays, benefits enrollments, employee notes, and — when an organization enables compensation features — salary or hourly rate records. Organizations can import historical timecards from CSV and download report CSVs (hours, leave liability, labor cost, and similar).

Communications

Transactional product email (invitations, reminders, approvals, leave, and similar). We keep delivery history so we can see whether a message was requested, queued, or sent. You can turn off many membership notification emails in settings or via an unsubscribe link.

Security, audit, and device data

We record audit events that can include the action, resource, IP address, request host, and user agent. We record first-party product analytics sessions (viewport, device class, browser, operating system, optional coarse country/region, path, and LiveView). Authorized operators may access accounts to provide support.

How we use information

  • Provide, maintain, and secure the Timecoda service
  • Authenticate users, including via Google Sign-In
  • Run organization workflows (time, leave, approvals, reports, imports)
  • Send product email you or your organization has a reason to receive
  • Diagnose problems, prevent abuse, and keep audit records
  • Understand how the product is used so we can improve it
  • Comply with law and respond to lawful requests

How we share information

We do not sell personal information. We share it only as needed to operate Timecoda:

  • Your organization. Admins, approvers, and other roles see the workplace data their permissions allow.
  • Service providers. Google (Sign-In); Postmark (email); hosting and databases (including Railway for production, Fly.io for staging, and PostgreSQL); optional MaxMind GeoLite2 for coarse IP geolocation; Google Fonts for typefaces loaded in the app.
  • Legal and safety. If required by law, to protect rights and security, or in connection with a corporate transaction.

Cookies and similar technologies

  • _timecoda_key — signed session cookie (login, CSRF-related session data, and temporary Google Sign-In state)
  • _timecoda_web_user_remember_me — signed remember-me cookie, valid for 14 days
  • A CSRF token in page metadata used to protect form posts
  • Theme preference in localStorage (phx:theme)

These are needed to sign you in, keep the session secure, and remember display preferences. We do not use them to serve third-party advertising.

Retention and deletion

  • First-party client analytics sessions are deleted after 90 days.
  • Audit logs are kept so organizations and operators can reconstruct history.
  • There is no self-serve “delete my account” control today. Email support@timecoda.com to request access, correction, export, or deletion. Deletion of a user who has timecard history may be limited so the organization’s records stay intact; we may deactivate or anonymize instead where we cannot hard-delete.
  • Organization admins can archive or remove memberships according to whether workplace history exists. Users left without a membership may be deactivated after a waiting period.

Security

We use HTTPS in production, hashed passwords (when you set one), signed session cookies, CSRF protection, and role-based access inside each organization. No method of transmission or storage is perfectly secure.

International transfers

We host Timecoda on infrastructure that may process data in the United States and other countries where our providers operate. If you access Timecoda from elsewhere, your information may be transferred to those locations.

Your rights

Depending on where you live, you may have rights to access, correct, delete, export, or restrict certain personal data, or to object to certain processing. Send requests to support@timecoda.com. We may need to verify your identity and, for workplace records, coordinate with your organization.

Children

Timecoda is a workplace product. It is not directed at children under 13 (or under 16 where that is the applicable age), and we do not knowingly collect personal information from children. Google Sign-In must not be used for a child-directed app.

Changes

We may update this policy. The “Last updated” date will change, and we will post the new policy at this URL. If we change how we use Google user data, we will notify users and obtain any required consent before that new use.

Contact

Innovative Data Solutions LLC
Product: Timecoda
Email: support@timecoda.com