Privacy Policy
Last updated: 2026-06-03
ZopTime is a time-tracking product and brand operated by Zopware Ltd (“we”, “us”) (the “Service”). This policy explains what personal data we collect, why we use it, and your choices. By creating an account or using the Service, you agree to this policy.
Who we are
The data controller for the Service is Zopware Ltd . Contact us at [email protected] or via our contact page.
Data we collect
- Account data: name, email address, password (stored hashed), and email verification status.
- Workspace data: company name, logo, currency, billing preferences, and other settings you provide.
- Time-tracking data: clients, projects, time entries, work notes, categories, and reports you create.
- Technical data: IP address, browser type, session identifiers, and security logs needed to operate and protect the Service.
How we use your data
We use personal data to:
- provide, maintain, and secure the Service;
- authenticate you and send account-related emails (e.g. verification, password reset);
- generate reports and PDFs you request;
- prevent abuse, fraud, and unauthorised access; and
- comply with legal obligations.
We do not sell your personal data.
Legal bases (EEA/UK users)
Where applicable, we rely on: performance of a contract (providing the Service); legitimate interests (security, improving the Service); and consent where required (e.g. non-essential cookies, if any).
Sharing and processors
We share data only as needed to run the Service, including with:
- hosting and infrastructure providers where the application is deployed;
- email delivery providers to send transactional messages;
- Cloudflare Turnstile (when enabled) to help prevent automated abuse on sign-in, registration, and contact forms; and
- professional advisers or authorities when required by law.
Processors are bound by contracts that require appropriate safeguards.
Retention
We keep account and time-tracking data while your account is active. If you delete your account or ask us to delete data, we will remove or anonymise it within a reasonable period, except where we must retain information for legal, security, or backup purposes.
Security
We use industry-standard measures including encrypted connections (HTTPS), hashed passwords, access controls, and rate limiting. No method of transmission over the internet is 100% secure; we cannot guarantee absolute security.
Cookies and similar technologies
We use essential cookies and similar technologies for authentication, session management, and security (e.g. CSRF protection). These are necessary for the Service to function. See our Cookie Policy for details.
Your rights
Depending on your location, you may have rights to access, correct, delete, restrict, or port your personal data, and to object to certain processing. To exercise these rights, contact us at [email protected]. You may also lodge a complaint with your local data protection authority.
International transfers
Your data may be processed in countries other than your own. Where required, we use appropriate safeguards for cross-border transfers.
Children
The Service is not directed at children under 16. We do not knowingly collect personal data from children.
Changes
We may update this policy from time to time. We will post the revised version on this page and update the “Last updated” date. Material changes may be notified by email or in-app notice where appropriate.
Contact
Questions about this policy: [email protected].