Privacy policy
Last updated 25 September 2026
Timerfly is operated by Support Quad (GSTIN 29AFAPC6643Q1Z1) ("we", "us"), Ground Floor, H No 3914, Kangrali BK, VL Computer Education, Vaibhav, Belagavi, Karnataka 590010, India. This policy explains what we collect when you use timerfly.com, the Timerfly web app (my.timerfly.com) and the Timerfly desktop app, and what we do with it.
Who decides what is tracked
Timerfly is used by companies ("customers") to record their own team's working time. The company decides whether its people use Timerfly and which optional features are on (such as screenshots and window titles). For the activity data of a company's employees, the company is the data fiduciary (the one that decides why and how it is processed) and we process it on the company's behalf, under our Terms of service. If you are an employee, questions about why your company tracks time are best asked to your company; you can also write to us.
What we collect
Account details
- Name, email address and a password (stored only as a one-way hash), and the two-step sign-in secret if you turn it on.
- Your company's name, time zone, work schedules, departments and settings.
- Sign-in records for security: IP address, browser or device, and when.
Activity from the desktop app (only while "Start work" is on)
- Which application and website is in use and for how long, and whether the computer is active or idle.
- Whether there was keyboard or mouse input, to tell active from idle time. We never record what is typed or clicked.
- Window titles, only if the company turns them on.
- Screenshots, only if the company turns them on, taken every few minutes while the person is working; they can be blurred.
- The computer's name, operating system and app version.
Nothing is recorded during a break or private time, or when work is stopped: we only note that it was a break or private time.
Billing
Plan, number of people, invoices and the billing contact. Payments are handled by our payment provider; we do not see or store card numbers or bank passwords.
This website
timerfly.com does not use advertising or tracking cookies. Our hosting provider keeps standard server logs (such as IP address and pages requested) to keep the site running and secure. The web app uses a cookie and your browser's storage only to keep you signed in and remember your settings.
Why we use it
- To provide Timerfly: show time, attendance and reports to the people the company allows to see them.
- To send the emails and alerts the company sets up (reports, late or idle alerts), and messages about the account (sign-in codes, invites, billing).
- To keep the service secure, prevent misuse and fix problems.
- To bill for the service and meet legal obligations such as tax records.
We do not sell personal data, and we do not use activity data or screenshots for advertising.
Who can see it
- In the company: owners and admins see everyone's time, apps, attendance and (if on) screenshots. Employees see their own data only.
- Our staff: only when needed to run the service, fix a problem or answer a request from the company.
- Service providers who process data for us, under contract: cloud hosting and storage (including Cloudflare), email delivery (Zoho ZeptoMail), and payments (Razorpay).
- Apps the company connects: if a company links Telegram or Slack, the alerts it chooses are sent there.
- Authorities, when the law requires it.
How long we keep it
- Screenshots are deleted automatically after the period on the company's plan (Starter 45 days, Pro 90 days, Business 6 months).
- Other activity and account data are kept while the company's account is open, so its reports stay complete.
- When a company closes its account, we delete its data within 90 days, except records we must keep by law (such as invoices).
Security
Data is encrypted in transit (HTTPS). Each company's data is kept apart at the database level. Passwords are stored as one-way hashes, and two-step sign-in and office-network-only sign-in are available. No system is perfectly secure; if a breach affects your data, we will tell the affected companies and the authorities as the law requires.
Your rights
Under India's Digital Personal Data Protection Act, 2023, you can ask to see, correct or erase your personal data, and to withdraw consent where processing relies on it. Employees should usually ask their company first, since it controls its workspace; we will help the company respond. Write to us at the address below.
Questions and grievances
For anything about your data, or to raise a grievance, write to us.
Email: [email protected]
Address: Ground Floor, H No 3914, Kangrali BK, VL Computer Education, Vaibhav, Belagavi, Karnataka 590010, India
We reply within 30 days.
Changes
If we change this policy in a way that matters, we will tell account owners by email before it takes effect. The date at the top shows the latest version.