Privacy Policy

Last updated July 26, 2026

This policy explains what Worktime collects, why, and what control you have over it. Worktime is a scheduling and time-tracking service sold to businesses. Where your employer uses Worktime, your employer is the controller of the workforce data and Worktime is the processor acting on their instructions.

What we collect

  • Account data — name, email address, hashed password or linked sign-in provider, and any passkey or two-factor credentials you register.
  • Organization data — organization name, members and their roles, and settings such as timezone, pay period, overtime and rounding rules.
  • Workforce data your organization enters — employee names, contact details, positions, locations, pay rates, schedules and shifts, availability, time-off requests, and time-clock punches.
  • Billing data — subscription status and plan. Card details are entered directly with Stripe and are never stored on our servers.
  • Technical data — IP address, browser user agent, and session records used for security, plus aggregate performance measurements.

How we use it

To operate the service: authenticate you, build and publish schedules, record hours, compute timesheets, send the notifications your organization enables, take payment, and protect the service from abuse. We do not sell personal data, and we do not use your workforce data to train machine-learning models.

Who we share it with

Only the processors needed to run the service: our hosting and database providers, our email delivery provider, our bot-protection provider, and Stripe for payments. Each is bound to use the data only to provide their service to us. We may also disclose data when required by law.

How long we keep it

Account and workforce data is retained while your organization's account is open. Time punches and timesheets are retained as business records even when your plan hides older schedule history — plan limits change what is visible, not what is stored. Deleting your organization permanently deletes its data, including employees, schedules, punches, timesheets, and audit records. Backups age out on a rolling basis.

Your choices and rights

You can update your profile, manage sign-in methods, review active sessions, and delete your account from the account page; deletion is confirmed by email. Depending on where you live you may also have the right to access, correct, export, or delete your personal data, and to object to certain processing. If your employer entered the data, we will refer your request to them as the controller.

To exercise any of these, email support@worktime.guru from the address on the account.

Cookies

We use strictly necessary cookies to keep you signed in and to protect sign-in forms from automated abuse. We do not use advertising or cross-site tracking cookies.

Security

Data is encrypted in transit. Passwords are hashed, and every record is scoped to a single organization and checked on each request. Sensitive actions — punch edits, timesheet approvals, permission changes — are written to an audit log. No system is perfectly secure; tell us promptly at support@worktime.guru if you suspect a problem.

Children and international transfers

Worktime is not intended for anyone under 16. The service is operated from the United States; if you use it from elsewhere, your data is processed in the United States.

Changes

We will update this page when the policy changes and revise the date above. Material changes affecting existing customers will also be emailed to organization owners.