Privacy Policy

How Time4Tracking collects, uses, and protects your family's data.

Effective date: July 29, 2026

Time4Tracking ("we", "us") is a record-keeping service for homeschooling families. This policy explains what we collect, how we use it, who we share it with, and the choices and rights you have. We are built privacy-first: we collect only what is needed to run your homeschool records, we do not sell personal data, and we do not use your data — or your children's — for advertising.

Who controls the data

A parent or legal guardian creates and controls the family account. The student records in the account are entered and managed by that account owner (and anyone they invite, such as a co-guardian, tutor, or evaluator). For that content we act as a processor on the account owner's behalf; for account and billing data we act as a controller.

Information we collect

  • Account & identity: name and email address (managed through our identity provider), and your role in the account.
  • Student records you enter: student name, date of birth, grade level, subjects, grades, attendance and instructional hours, reading logs, portfolio entries and any work-sample files you upload, compliance documents you file, schedule, and budget entries.
  • Billing: plan and subscription status. Payments are processed by Stripe — we do not receive or store full card numbers.
  • Technical & usage: log, diagnostic, and security data (e.g. IP address, timestamps, error traces) needed to operate and secure the service.

Children's data

Student records often describe minors. That data is provided and controlled by the parent/guardian who owns the account — creating the account and entering a child's records constitutes the verifiable parental consent contemplated by COPPA. We handle minors' data with heightened care, aligned to FERPA and COPPA principles and the GDPR where it applies: no behavioral advertising, no sale, no use beyond providing the service, and strict per-family isolation. A parent can access, export, correct, or delete their child's records at any time (see "Your rights").

How we use the data

  • Provide and maintain the record-keeping features you use.
  • Generate compliance checklists, deadline reminders, reports, and transactional emails you request.
  • Process subscriptions and payments.
  • Secure the service, prevent abuse, debug, and provide support.
  • Meet legal obligations.

Where the GDPR applies, our legal bases are performance of our contract with you, your consent (e.g. for the records you choose to enter), our legitimate interest in operating a secure service, and compliance with law.

Who we share it with

We do not sell personal data and do not share it for advertising. We use a small set of service providers ("subprocessors") strictly to run the service:

  • Microsoft Azure — cloud hosting, application database, secret storage (United States).
  • Resend — sending transactional email (invitations, reminders, reports).
  • Stripe — subscription billing and payment processing.
  • Keycloak — our self-hosted sign-in / identity service.

We may also disclose data if required by law, or to protect the rights and safety of users and the public. If the service is ever involved in a merger or acquisition, we'll notify you before your data becomes subject to a different policy.

Where your data is stored & international transfers

Data is hosted in the United States. If you access the service from outside the US, you understand your data is processed in the US; where required we rely on appropriate transfer safeguards (such as Standard Contractual Clauses).

How long we keep it

We keep your data while your account is active. When an account is closed, its records are scheduled for deletion after a short wind-down window. You can delete individual records or your whole account at any time; deletion removes the associated files and data.

How it's protected

Data is encrypted in transit (HTTPS) and at rest. Each family's data is isolated at the database level (row-level security), access is governed by role-based permissions and least-privilege managed identities, and secrets are held in a managed vault.

Your rights

You can access, correct, export, or erase your data — much of it directly in the app (CSV and PDF exports, edit, and delete), and otherwise by contacting us. Depending on where you live, you may also have the right to restrict or object to processing, withdraw consent, or lodge a complaint with your data-protection authority. Reach us at privacy@time4tracking.com.

Changes to this policy

We'll update this page when our practices change and revise the effective date; material changes will be communicated in-app or by email.

Contact

Privacy questions or requests: privacy@time4tracking.com.