Privacy policy

Privacy policy

Effective 2026-10-09

1. Who we are

TradesTimer is an automatic time-tracking app for tradespeople, operated by 17114401 Canada Inc. ("we", "our", "the app"). This policy describes what data TradesTimer collects, how it is used, and where it lives. You can reach us at support@tradestimer.com.

2. Data TradesTimer collects and stores on your device

When you allow background location access, TradesTimer records locations to identify stops and trips. The app creates and stores these records in its private storage on your phone:

  • Location readings: latitude, longitude, accuracy, speed, and timestamp
  • Stops, trips, and gaps in recorded history
  • Any labels, client names, billable flags, or notes you add
  • Your optional home zone coordinates and radius
  • App settings (billing increment, unit preferences, toggles)

You can delete recorded locations, edits, and saved places using Erase all captured data in Settings > Privacy & data. The following section describes when data leaves your phone.

3. Data that leaves your device

The following features send data outside your phone:

3a. Reverse geocoding (address lookups)

When TradesTimer needs to turn GPS coordinates into a human-readable address (for example, to suggest a label for a new stop), it sends the coordinates to the operating system's built-in geocoder (Apple Location Services on iOS, Google Play Services on Android). If the OS does not resolve an address, TradesTimer may additionally send the coordinates to the public OpenStreetMap Nominatim service. These requests include coordinates and network information such as your IP address. We do not add your name or subscription identifier. Nominatim's provider records requests for service operation, security, and analysis. See OpenStreetMap Foundation's privacy policy .

3b. Subscription management

Builds with Pro purchases enabled use RevenueCat to load subscription options, process purchase records, and check access to Pro. These builds initialize RevenueCat when the app starts, even if you have not subscribed. RevenueCat processes an app user identifier, purchase history, and device and network information needed to provide its service. Apple or Google processes your payment; TradesTimer does not receive your payment card details. We do not send recorded locations, stops, trips, saved places, or notes to RevenueCat.

The backup service uses your subscription identifier to check whether new uploads are allowed. Existing retained backups remain recoverable with your recovery code after your subscription expires.

Apple Ads measurement on iOS

Attribution-enabled iOS versions send Apple's AdServices attribution token to RevenueCat. RevenueCat asks Apple whether an installation follows an Apple Ads advertisement and associates the returned campaign, ad group, and keyword information with subscription records. We use this information to measure advertising results and subscription revenue. This measurement does not request the advertising identifier (IDFA). We do not send your recorded locations, work history, saved places, notes, or contact information to RevenueCat for advertising measurement.

3c. Sharing you initiate

When you tap Share / export on billable hours or a travel log, select text or CSV. Your phone opens its sharing options, and you choose the destination, such as email, messages, or files. TradesTimer does not retain a server copy of that export.

Feedback you send

Sending feedback shares your message, optional email address, app version, and platform with the feedback service. The app does not attach your timeline to the message.

Encrypted backup and phone transfer (optional)

The paid version requires Pro access for new backups, through a subscription, referral reward, or approved early-adopter unlock. Backup is off by default. Older test builds can include a free preview. Nothing is uploaded until you set up encrypted backup in Settings. After setup, the app uploads changes automatically when it can, including during background operation.

What is encrypted. Your phone encrypts recorded locations, dates, stops and trips, saved places, notes, edits, and settings before upload. The recovery code contains the information needed to restore this history on another phone. We do not hold the decryption key. Neither we nor our storage provider can read the encrypted history.

Protect your recovery code. Anyone with the code can restore your history and take over future backups. Sharing or emailing a recovery sheet shares that access. If you lose the code and access to your phone, we cannot reset it or decrypt your backup.

Service metadata. The backup service processes an opaque backup identifier, subscription association, device authorization records, encrypted files, file sizes and hashes, upload times, and network information such as your IP address. History content remains encrypted.

Storage and retention. We use Cloudflare R2 for encrypted files and Cloudflare D1 for service metadata. See Cloudflare's privacy policy. Completed backup versions currently have no automatic expiry. Deleting local history or uninstalling the app does not delete existing cloud versions. The upcoming paid release adds Delete cloud backup in the backup screen on the phone authorized to upload. Deletion revokes recovery access and removes encrypted files and saved versions. Local history remains. If deletion is interrupted, use Finish deleting cloud backup. We retain a minimal deletion record, including the backup identifier, authorization hashes, and deletion time, to prevent reuse and permit interrupted deletion to finish. We clear its subscription association. You can also request help with deletion by contacting support@tradestimer.com. Do not email your recovery code or encryption key.

Referrals and app updates

Early-adopter unlocks use a random authorization secret stored on your iPhone with device-only Keychain protection. The server stores its hash, a support reference code, request and approval dates, and approval status. We use these records to approve and verify free access for that installation. The visible support code cannot unlock another phone. If you email us, your support correspondence includes the code and your email address. Note: Emailing your support code links that code to your email address. You can use a separate email address for support; you do not need to provide your name.

Referral features store your anonymous app user identifier, referral code, redemption records, and reward dates. We use these records to operate the referral program, grant rewards, and prevent abuse. They are not linked to the optional email you send with feedback.

The app checks for software updates through Expo. Update requests include the operating system, app project, and a random installation token. See Expo's explanation of end-user data .

4. Permissions we request

  • Camera. Optional, used to scan your recovery code. You can enter the code manually instead.
  • Location, including background ("Always") access. Required to record stops and trips while the app is closed. Location access limited to app use does not support background tracking.
  • Notifications. Optional. Used only for review reminders and tracking alerts. The app does not send promotional notifications.

5. Analytics and tracking

TradesTimer does not include third-party analytics SDKs that profile your behavior (no Google Analytics, no Mixpanel, no Facebook SDK, no Segment). RevenueCat provides purchase analytics. Address and update providers process requests as described above. We do not use these records for third-party advertising or sell your location history.

Website analytics

Our website counts page views and App Store or Google Play link clicks to help us improve useful content and download links. We store daily totals by page, platform, and link placement for up to 91 days. We do not store individual event records, visitor identifiers, IP addresses, browser information, or query strings in our analytics database. We use no tracking cookies or browser storage. We respect Do Not Track and Global Privacy Control.

We operate this system ourselves using Cloudflare hosting and database infrastructure. Cloudflare processes network requests to deliver and protect the website. We do not send these events to a separate analytics provider. Google Search Console provides search performance reports without an analytics script on this site.

6. Data retention and deletion

You control the history stored on your phone:

  • Delete older location history in the storage settings.
  • Open Settings > Privacy & data and tap Erase all captured data to delete recorded locations, edits, and saved places. You cannot undo this.
  • Uninstalling the app removes its local history. Secure credentials may remain in the iOS Keychain. Uninstalling does not delete cloud backups or cancel subscriptions.

Request deletion. Email support@tradestimer.com with the subject "TradesTimer data deletion". Tell us whether you want to delete cloud backup, purchase-service and referral records, or support correspondence. We may ask for information needed to verify your request. Never include your recovery code or encryption key. We explain any records we must retain for security or legal obligations. Store payment records remain subject to Apple's or Google's policies. Deleting these records does not cancel a store subscription. Manage or cancel subscriptions through Apple or Google.

7. Children

TradesTimer is not directed to children under 13, and we do not knowingly collect data from anyone in that age group.

8. Changes to this policy

If we materially change how the app handles data, we will update this page and note the new effective date at the top. Substantive changes that expand data collection will also be announced in-app.

9. Contact

Questions, deletion requests, or concerns: support@tradestimer.com.