TrackTime
HomeProductPricingAboutBlog
Sign inStart trial

Privacy Policy — TrackTime Lite

Last updated: May 22, 2026

TrackTime Lite is the Google Play Store edition of TrackTime. It captures time only when you start it — there is no background detection, no reading of your messages, no reading of your call log. This page describes what Lite collects. If you're looking for the policy that covers the full sideload edition (with auto-detection), see the main privacy policy.

Operator

TrackTime is operated by TripleDot LLC. References to “we,” “us,” or “TrackTime” in this policy refer to TripleDot LLC. Contact: [email protected].

1. What Lite collects

  • Account data — your name, email, password (stored as a salted argon2id hash), and organization details if you sign up as part of a firm.
  • Time entries you create — every entry in Lite is one you started manually with the Start/Stop timer or recorded via the “Drive to Client” travel feature. We store the entry's start and end timestamps, derived duration, the client or project you assign it to, and any notes you choose to add.
  • Travel summaries — when you complete a “Drive to Client” trip, we store the start time, end time, total duration, and total distance. We do not store the GPS trail; only the derived total.
  • Billing data — if you subscribe to a paid plan, Stripe handles your payment information and shares only a customer ID and subscription status with us.
  • Operational logs — IP address, user-agent, and timestamps of authentication and admin actions, retained for security auditing.

2. What Lite never collects

  • The body of your SMS, RCS, or messaging-app threads.
  • Your call history, phone state, or call duration. Lite does not request the READ_CALL_LOG or READ_PHONE_STATE permissions.
  • Notifications, accessibility events, or anything from other apps on your phone. Lite does not request the Notification Listener or Accessibility Service permissions.
  • Email subject lines, bodies, attachments, or your address book beyond clients you explicitly import.
  • Your precise GPS trail. Travel tracking computes distance locally and only sends the totals.
  • Audio or video from your calls.

3. How we use your data

We use your data to provide the service: showing you your time entries, generating invoices, syncing across your devices, sending receipts and security notifications. We do not sell your data, and we do not use your data to train AI models.

4. Storage and security

  • All data in transit is protected with TLS (HTTPS).
  • Server-side databases are run on encrypted disks; passwords are hashed with argon2id; API keys and refresh tokens are stored as cryptographic hashes only.
  • The Android app stores its local database with SQLCipher, with the encryption key bound to the device's hardware-backed Keystore.
  • We follow OWASP Top 10 hardening for the API surface and run regular security reviews.

5. Sharing and third parties

We share data only with vendors required to run the service:

  • Stripe for payment processing.
  • Postmark (or your configured SMTP provider) for transactional email delivery.
  • Cloud infrastructure providers for hosting.

We do not share your data with advertisers or data brokers under any circumstances.

6. Your rights

You can export every time entry, client, and invoice you've created. You can delete your account at any time, which removes your data from our active systems within 30 days. Backups are purged on a 90-day rolling cycle. To request export or deletion, use our contact form.

7. Cookies and analytics

We use a single session cookie for authentication. We do not use third-party advertising or behavioral analytics cookies. Aggregate usage telemetry (page views, feature usage counts) is collected only to size capacity; no individual user is identified in those aggregates.

8. Children

TrackTime is a professional product and is not directed at children under 16. We do not knowingly collect data from minors.

9. International transfers

Our infrastructure is located in the United States. If you sign up from outside the US, your data is transferred to the US for processing. We rely on Standard Contractual Clauses where required by GDPR.

10. Android permissions used by Lite

TrackTime Lite requests only the permissions it needs for manual time tracking and travel. We don't request a permission “just in case.”

  • Location (ACCESS_FINE_LOCATION, ACCESS_COARSE_LOCATION) — used to measure travel distance and duration while you have an active “Drive to Client” trip running. The trip runs as a foreground service with a persistent notification, which allows distance to accumulate accurately if your screen turns off during the drive. We never store the GPS trail; only the start time, end time, and derived totals (duration, distance). We do not request the ACCESS_BACKGROUND_LOCATION permission.
  • Contacts (READ_CONTACTS, optional) — only used when you tap “Import Contacts” to populate your client list. If you decline, you can still create clients manually; no contacts are read in the background.
  • Notifications (POST_NOTIFICATIONS) — used to display the persistent “Timer running” or “Driving to client” notification while a manual timer or travel trip is active, so you can return to the app or stop the timer quickly.
  • Display over other apps (SYSTEM_ALERT_WINDOW) — optional; used only by the travel feature to show a small “Trip in progress” overlay you can tap to return to the app while driving. Toggleable from Android Settings.
  • Battery optimization exemption (REQUEST_IGNORE_BATTERY_OPTIMIZATIONS, optional) — prevents Android Doze from killing the travel service during long drives. You can decline; short drives will still work.
  • Foreground service (FOREGROUND_SERVICE, FOREGROUND_SERVICE_DATA_SYNC, FOREGROUND_SERVICE_LOCATION) — keeps the manual timer and travel service running with a visible notification while active.
  • Boot completed (RECEIVE_BOOT_COMPLETED) — declared in the manifest but inert in Lite; Lite does not restart anything on reboot.
  • Network (INTERNET, ACCESS_NETWORK_STATE) — used to sync your time entries to your account.

You may revoke any permission at any time from Android Settings; the app degrades gracefully. Revoking Location, for example, simply disables “Drive to Client” — the manual Start/Stop timer keeps working.

11. Changes to this policy

We'll email all account holders at least 30 days before any material change to this policy. Non-material changes (clarifications, typo fixes) may be made without notice but are reflected in the “Last updated” date above.

12. Contact

Questions or requests: email [email protected] or send a note via our contact form.