Privacy Policy
Last Updated: January 13, 2025
Introduction
Function Timetrack ("we", "our", "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our time tracking and financial management application ("Service", "Application", "Software").
By using our Service, you agree to the collection and use of information in accordance with this policy. If you do not agree with this policy, please do not access or use our Service.
1. Information We Collect
1.1 Personal Information
We collect personal information that you voluntarily provide when using our Service:
- Account Information: Name, email address, phone number, company name
- Authentication Data: Username, password (hashed), OAuth access and refresh tokens
- Two-Factor Authentication Data: If you enable two-factor authentication, your TOTP shared secret and your recovery codes are stored on your account
- Session Records: A session token, the IP address and browser user-agent string recorded when the session was created, and its expiry
- Profile Information: Job title, union affiliation, workspace preferences
- Business Contact Details: The business name, postal address, phone number, email address, website and logo you set for use on invoices and timesheets
- Tax Identifiers: Where you record a payee entity for yourself or a loan-out company, its legal name and its tax identification number — a Social Security Number for an individual, or an EIN for a company
1.2 Work and Financial Data
To provide time tracking and invoicing services, we collect and store:
- Time Tracking Data: Work hours, dates, start/end times, overtime calculations
- Project Information: Project names, codes, descriptions, contract types
- Financial Data: Rates, expenses, income records, invoice details
- Union Contract Data: Rate codes, benefit calculations, penalty rules
- Union Membership and Local Affiliation: The union local you are affiliated with, its local number and parent union, and the membership figures the application uses to assess standing — cumulative earnings, hours worked and years of membership
- Benefit Fund and Health-Fund Eligibility Data: Contributions to health, pension, annuity, welfare, vacation, training and dues funds; vesting tiers and the annual earnings thresholds they turn on; and annuity account balances you record from fund statements
- Tax Profile Data: Filing status, state of residence and local jurisdiction, dependent credits, other household income, deduction adjustments, extra withholding, expected annual income and prior-year tax — the figures used to estimate withholding and quarterly payments
- Tax Documents: Records of tax documents received or expected (type, issuing company, tax year, amount) and links to any stored copy
- Client Information: Client names, contact details, payment terms
- Uploaded Files: Receipt images you attach to expenses, which are stored in our object-storage provider
- Document Records: Entries you create for project paperwork — the document's name, how you classify it (including agreements, W-4/I-9 paperwork, timesheets and pay stubs), and a link or reference to wherever the file itself is held
1.3 Third-Party Integration Data
When you connect third-party services, we collect:
- QuickBooks Data: Customer lists, invoice information, payment status, company details
- Plaid (Bank Connections): Linked account details, balances, and transaction history from financial institutions you connect. For each connected account we store the institution, the account name and official name, the last digits of the account number, and its type. For each imported transaction we store the amount, currency, posted and authorised dates, the merchant name and the raw description from your bank, the payment channel, Plaid's category classification, the city, region and postal code Plaid associates with the transaction, and Plaid's complete raw response for the transaction
- Bank Credentials: Your bank username and password are entered into Plaid's own interface and are never sent to or stored by us. What we hold is an access token issued by Plaid, encrypted at rest
- Google OAuth: Email address, profile name, profile picture (for authentication)
- OAuth Tokens: Encrypted access and refresh tokens for maintaining integrations
1.4 Automatically Collected Information
We automatically collect certain information when you use our Service:
- Usage Data: Pages visited, features used, actions performed, session duration
- Device Information: Browser type, operating system, IP address, device identifiers
- Log Data: Access times, error logs, performance metrics
- Error and Performance Traces: Stack traces, console warnings and errors, and performance profiles, sent to our error-monitoring provider with the signed-in user's identity attached
- Session Replays: Recordings of browser sessions — a sample of ordinary sessions, and sessions in which an error occurs — captured by our error-monitoring provider for debugging
- Audit Records: For records created, changed or deleted in your workspace, we store who acted, what was acted on, and a copy of the record both before and after the change
- Query Performance Metrics: Timing measurements for database queries the application runs
1.5 Information About Other People
Some of what you record is personal information about people other than you. You supply it; we store and process it on your behalf:
- Professional Contacts: Names, disciplines, company names, email addresses, phone numbers, city and state, relationship type, tags, and any free-text notes or interaction history you record about people in your professional network
- Client and Customer Records: Names, contact details and billing addresses for the clients you invoice
- Payee and Referral Records: Legal names and tax identification numbers for loan-out entities you record, and referrals, introductions and coverage arrangements between contacts
1.6 Information Stored On Your Device
Some information is held in your browser's local storage rather than sent to us:
- Held Clock Stamps: If you clock in or out while your device cannot reach our servers, the time you recorded and the project it belongs to are kept in your browser until the application can save them
- Entry Shortcuts: The category and project you last used when adding an expense, so they can be offered again
- Interface Preferences: Feature-flag overrides, colour-scheme choice, and sidebar and layout state
2. How We Use Your Information
We use the collected information for the following purposes:
- Service Provision: To provide, maintain, and improve our time tracking and invoicing features
- Account Management: To create and manage your account, authenticate users, and maintain workspaces
- Calculations: To calculate overtime, benefits, penalties, and generate accurate timesheets
- Integration Services: To sync data with QuickBooks, generate invoices, and manage payments
- Communications: To send service notifications, updates, and respond to inquiries
- Analytics: To understand usage patterns and improve application performance
- Security: To detect, prevent, and address fraud, security issues, and technical problems
- Legal Compliance: To comply with legal obligations and protect our rights
3. Data Sharing and Disclosure
3.1 Third-Party Service Providers
We share data with trusted third-party service providers who assist in operating our Service:
- Intuit QuickBooks: For invoice creation, payment tracking, and accounting integration. Where you sync a customer, we send its display name, email address, phone number and billing address to QuickBooks, and read the corresponding records back
- Plaid: For connecting your bank accounts and importing transaction history. Plaid receives an identifier for your account and, through its own interface, the credentials for the institution you are connecting; it returns account and transaction data to us
- Google OAuth: For secure authentication and login services
- Database Hosting: Neon PostgreSQL for secure data storage — this holds all data described in Section 1 that is not held elsewhere
- Cloudflare R2: For storage of receipt images you upload
- Mapbox: Address autocomplete. When you type an address into a customer or payment-source form, the partial address text is sent to Mapbox's geocoding service, which returns matching addresses
- Vercel: Application hosting and delivery — all requests to the Service pass through Vercel's infrastructure
- Vercel Analytics and Speed Insights: Page-view and page-performance measurement in the browser
- Sentry: Error monitoring, performance tracing and session replay, including the signed-in user's identity, and captured console warnings and errors
- Axiom: Application logging, server-side request errors, and client-side web-vitals and route-change events
- Managed Redis: Short-lived caching of API responses, rate-limit counters, and workspace change notifications
- Mapbox: Address autocomplete — the address text you type into an address field is sent to Mapbox as you type it, in order to return suggestions
3.2 Legal Requirements
We may disclose your information if required by law, court order, or government regulation, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
3.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity. We will notify you of any such change in ownership or control of your information.
3.4 What We Don't Do
We DO NOT:
- Sell your personal information to third parties
- Share your data with advertisers or marketing companies
- Use your time tracking data for purposes other than providing our Service
- Access your QuickBooks data beyond what's necessary for invoice synchronization
4. Data Security
We implement industry-standard security measures to protect your information:
- Encryption: All data transmitted between your device and our servers is encrypted using TLS/SSL
- Password Security: User passwords are hashed and encrypted using industry-standard algorithms
- OAuth Token Encryption: Third-party access tokens are encrypted at rest in our database
- Access Controls: Multi-tenant workspace isolation ensures users can only access their own data
- Regular Security Audits: We perform regular security assessments and updates
- Database Security: Our database providers implement enterprise-level security and backup systems
While we strive to protect your information, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security.
5. Data Retention
We retain your information for as long as necessary to provide our Service and comply with legal obligations. Specifically:
- Active Accounts: Data is retained while your account remains active
- Time Tracking Data: Retained for at least 7 years for tax and legal compliance
- Financial Records: Retained in accordance with applicable accounting regulations
- Deleted Accounts: Data is permanently deleted 90 days after account closure
- Backup Data: Backup systems may retain data for up to 30 days after deletion
- Sessions: A signed-in session expires seven days after it is created; the session record, including the IP address and user-agent captured with it, remains until it is removed
- Cached Responses: Copies of API responses held in our cache are short-lived and expire automatically; rate-limiting counters expire on the same basis
- Audit Records: The record of changes described in Section 1.4, including the before-and-after copies, is kept for as long as the workspace exists
- Device Storage: Information described in Section 1.6 stays in your browser until the application clears it or you clear your browser storage
- Third-Party Providers: The providers listed in Section 3.1 retain the data they receive according to their own retention schedules, which we do not set
6. Your Rights and Choices
You have the following rights regarding your information:
- Access: Request a copy of the personal information we hold about you
- Correction: Request correction of inaccurate or incomplete information
- Deletion: Request deletion of your personal information (subject to legal retention requirements)
- Data Portability: Request a machine-readable copy of your data
- Opt-Out: Unsubscribe from marketing communications (service emails are required)
- Revoke Integrations: Disconnect third-party integrations at any time from settings
To exercise these rights, please contact us at privacy@functiontimetrack.com.
7. Cookies and Tracking Technologies
We use cookies and similar tracking technologies to:
- Authentication Cookies: To keep you logged in and maintain your session
- Preference Cookies: To remember your settings and preferences
- Security Cookies: To detect and prevent security threats
- Analytics: To understand how users interact with our Service
Specifically, the Service sets a session cookie issued by our authentication provider, which identifies your signed-in session and expires after seven days. A short-lived cached copy of your session, refreshed every five minutes, is held alongside it so that not every request has to reach the database.
Our analytics, performance and error-monitoring providers — described in Section 3.1 — may set their own cookies or use equivalent browser storage. Section 1.6 describes what the Service itself stores in your browser outside of cookies.
You can control cookies through your browser settings, but disabling certain cookies may affect Service functionality. Browser settings do not control the analytics, performance-measurement, error-reporting or session-replay providers listed in Section 3.1, and the Service does not currently offer an in-application control over them.
8. Children's Privacy
Our Service is not intended for children under 18 years of age. We do not knowingly collect personal information from children. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately.
9. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. These countries may have data protection laws different from your jurisdiction. By using our Service, you consent to the transfer of your information to the United States and other countries where we operate.
As a matter of fact: our error-monitoring, tracing and session-replay provider receives data at a United States ingest endpoint. The other providers listed in Section 3.1 process data in the regions their own terms specify.
10. California Privacy Rights (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act:
- Right to know what personal information is collected, used, and shared
- Right to delete personal information (subject to exceptions)
- Right to opt-out of the sale of personal information (we do not sell personal information)
- Right to non-discrimination for exercising your privacy rights
To exercise these rights, contact us at privacy@functiontimetrack.com.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by:
- Posting the updated policy on this page with a new "Last Updated" date
- Sending an email notification to your registered email address
- Displaying a prominent notice in the application
Your continued use of the Service after changes are posted constitutes acceptance of the updated policy.
12. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Function Timetrack - Privacy Team
Email: privacy@functiontimetrack.com
Legal: legal@functiontimetrack.com
Website: https://functiontimetrack.com
Mailing Address:
Function Timetrack
Privacy Compliance Department
Los Angeles, CA 90001
By using Function Timetrack, you acknowledge that you have read, understood, and agree to this Privacy Policy.