Privacy Policy

1. Introduction

Welcome to Time Nomad. We respect your privacy and are committed to protecting your personal data. This privacy policy explains how we look after your personal data when you use our website and applications, who we share it with, how long we keep it, and how you can have it deleted.

Time Nomad is operated from Ireland. If you have any questions about this policy, contact us at support@time-nomad.app.

2. Data We Collect

  • Identity Data: first name, last name, username or similar identifier, and profile picture.
  • Contact Data: email address and telephone number.
  • Business Data: the clients, projects, milestones, time entries and invoices you create in the app.
  • Technical Data: IP address, login data, browser type and version, time zone setting, operating system and platform.
  • Usage Data: information about how you use our website, products and services.
  • Google User Data: described in section 4 below.

3. How We Use Your Data

We will only use your personal data when the law allows us to. Most commonly:

  • To perform the contract we are about to enter into, or have entered into, with you.
  • Where it is necessary for our legitimate interests and your interests and fundamental rights do not override those interests.
  • Where we need to comply with a legal or regulatory obligation.

4. Google User Data

If you sign in with Google, or connect Google Drive, Time Nomad accesses a limited set of data from your Google Account. We request the minimum scopes needed for the features you choose to use.

  • Sign-in (email, profile, openid): your name, email address and profile picture, used solely to create and authenticate your Time Nomad account. Signing in does not grant access to your Google Drive or Google Sheets.
  • Google Drive and Google Sheets (.../auth/drive.file): a per-file scope used only to create, read and update the client report spreadsheets that Time Nomad itself generates in your own Google Drive, containing your time logs, invoices and summary totals. It grants us no access to any other file in your Google Drive, and no access to any spreadsheet we did not create. Requested only when you explicitly click "Connect Google Drive" in Settings → Integrations.

The spreadsheets we create live in your Google Drive, under your ownership. We do not copy their contents onto our servers. Your Google OAuth access token is held only in your browser's local storage, expires approximately one hour after it is issued, and is never transmitted to or stored on Time Nomad servers.

5. Who We Share Your Data With

We do not sell your personal data or your Google user data. We do not use it for advertising, and we do not use it to develop, improve or train generalised artificial intelligence or machine learning models. We share data only with the following categories of recipient:

  • Google LLC (Firebase / Google Cloud Platform) — our hosting, authentication, database, file storage and serverless function provider. Your account and business data is stored on Google Cloud infrastructure.
  • Stripe, Inc. — payment processing for subscriptions and client invoice payments. Stripe receives your name, email address and billing details. Stripe does not receive any Google user data.
  • Twilio SendGrid — delivery of transactional email such as invoice notifications, reminders and password reset codes. SendGrid receives the recipient email address and the message content. SendGrid does not receive any Google Drive or Google Sheets content.
  • Google Analytics — aggregated, anonymised website usage statistics. Google Analytics does not receive any Google user data, and no Google Drive or Google Sheets content is ever sent to it.
  • Recipients you choose — when you enable a Client Report, the spreadsheet that Time Nomad creates is shared, at your direction, with the client email address you have entered for that client. This sharing happens only when you explicitly enable the report.
  • Law enforcement or regulators — where we are required to disclose data to comply with a legal or regulatory obligation, or to establish, exercise or defend legal claims.

These providers act as our processors, may only process your data on our instructions, and are bound by confidentiality obligations. Google user data is never transferred to any other party except as described above.

6. Data Retention and Deletion

  • Google OAuth tokens: stored only in your browser's local storage and expire approximately one hour after issue. They are erased immediately when you click "Disconnect" in Settings → Integrations, or when you sign out.
  • Google user data: we retain no copy of your Google Drive or Google Sheets content on our servers. The report spreadsheets remain in your own Google Drive until you delete them there. Your name, email address and profile picture obtained at sign-in are retained for as long as your account is active, and are deleted when your account is deleted.
  • Account and business data: retained for as long as your account remains active. When you delete your account, this data is permanently deleted from our systems within 30 days, except where we are required to retain records (for example invoices for tax purposes) by law.
  • Revoking access: you can revoke Time Nomad's access to your Google Account at any time at myaccount.google.com/permissions. Revoking access immediately and permanently ends our ability to access any Google user data.
  • Requesting deletion: you may delete your account from within the app, or follow the instructions on our Data Deletion page. You can also email support@time-nomad.app and we will action your request within 30 days.

7. Limited Use of Google User Data

Time Nomad's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

8. Data Security

We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. Data is transmitted over encrypted connections (HTTPS/TLS), and access to our production systems is restricted to authorised personnel.

9. Your Rights

Depending on where you live, you may have the right to access, correct, erase, restrict or object to the processing of your personal data, and the right to data portability. To exercise any of these rights, contact us at support@time-nomad.app.

10. Contact Us

If you have any questions about this privacy policy or our privacy practices, please contact us at: support@time-nomad.app

Last updated: 31 July 2026