1.Scope, and two kinds of data
This policy covers Timesheets (the "Service"), operated by 8WhiteRock ("we," "us," "our"). It distinguishes two categories of data, because different people control each:
- Account data — information about the person who created an organization: name, email, password (never stored in plain text — see Section 5). We're the ones who decide how this is used, within this policy.
- Customer data — everything an organization enters once it's set up: its team's names and emails, time entries, approval history, pay rates, project and job details, property/location names. Your organization's Owner controls this data — we process it on the organization's behalf to provide the Service, not for our own separate purposes.
If you're an employee whose organization invited you, your organization (not us) is who to ask about how your work data is used within it — we're the infrastructure it runs on.
2.Information we collect
| Category | Examples |
|---|---|
| Identity | Name, email address |
| Credentials | Password (hashed, never stored or visible in plain text) |
| Work data | Time entries, timesheet status and approval history, notes attached to a return or an undo |
| Compensation | Hourly rate, where an Owner chooses to record one — visible only to that organization's Owner, never to peers |
| Organization setup | Organization name, approval chain and department configuration, property/location names, job board configuration |
| Technical | IP address (used for abuse/rate-limit protection on account creation — see the Terms of Service), browser session identifiers |
| Billing | Subscription plan and status; card details are handled entirely by Stripe and never reach our own servers |
3.How we use information
- To provide the Service — authenticate you, route timesheets through your organization's chain, send the notifications your organization's people have opted into, and generate exports the Owner requests.
- To secure the Service — detect and limit abuse (e.g. the signup rate limit noted above), and to enforce that one organization's data is never visible to another's.
- To communicate with you — transactional email only (invites, password resets, approval notifications, digests) through our email provider; not marketing email unless you separately opt in somewhere we make that explicit.
- To bill you — if your organization is on a paid plan, through Stripe.
We do not sell personal information, and we do not use Customer Data to train any model or for any purpose beyond providing the Service to the organization it belongs to.
4.Who we share information with
We use a small number of third-party providers to run the Service. None of them are permitted to use your data for their own purposes beyond providing their service to us.
| Provider | Role |
|---|---|
| Supabase | Database, authentication, and file storage — where essentially all Service data lives |
| Stripe | Payment processing for paid plans — handles and stores card details directly, we never see them |
| Resend | Delivery of transactional email (invites, notifications, verification codes, digests) |
| Vercel | Application hosting |
We may also disclose information if required by law, or to protect the rights, safety, or property of 8WhiteRock, our users, or others. We do not sell personal information to third parties or use it for third-party advertising.
5.Security
Data is encrypted in transit (HTTPS). Passwords are never stored in plain text — authentication is handled by Supabase Auth using industry-standard hashing. Cross-organization data isolation is enforced at the database level (Postgres Row Level Security), not just in application code, so one organization's data isn't reachable through another's session even in the event of an application-layer bug. No method of transmission or storage is perfectly secure, and we can't guarantee absolute security.
6.Data retention
An organization's Owner can configure how long closed timesheets stay in the default view before being archived — archiving hides them from the default view, it doesn't delete them. An organization can be permanently deleted (by request), which removes its data from active use; brief residual copies may exist in infrastructure backups until they age out through our providers' normal rotation.
7.Cookies
We use essential session cookies to keep you signed in — nothing more. We don't currently use third-party analytics, advertising, or tracking cookies of any kind.
8.Your choices
If you're an individual whose data was entered by an organization that invited you, requests about that data (access, correction, deletion) should generally go through that organization's Owner first, since they control it. If you're an organization's Owner, or you'd like help we can't otherwise route through the app, contact us at the address below.
9.Children's privacy
The Service is a workplace tool, not directed at children, and we don't knowingly collect information from anyone under the age required to work in their jurisdiction.
10.International data
Our infrastructure providers may process and store data outside your own country. By using the Service, you consent to that transfer as necessary to provide it.
11.Changes to this policy
We may update this policy from time to time; the "last updated" date at the top reflects the most recent change. Material changes will be reflected here with an updated date.
12.Contact
Questions about this policy, or a data request: feedback@8whiterock.com.