Security
Last updated September 28, 2026
Crew hours and payroll records are sensitive. Here is how TimeThis keeps them protected.
Encryption
- All traffic to timeth.is uses HTTPS, so data is encrypted between your browser and our servers.
- Our database and file storage providers encrypt data at rest.
Private file storage
Files you upload, such as daily sheets, rosters and payroll registers, are kept in private storage that is never publicly readable. When you download a file, TimeThis creates a link that works for a few minutes and only after it has checked that you have access.
Signing in
- There are no passwords to steal or reuse. You sign in with a six digit code sent to your email, which expires after 10 minutes and works once.
- You can also sign in with Google, which lets you use your Google account's own protections, such as two-step verification.
- Sessions are stored in secure, HTTP-only cookies and expire automatically.
- Invites are single use and expire after 7 days.
Access controls
- Each company's data is kept separate. Every request is checked against the company the signed-in person belongs to.
- People only see the companies they have been invited to, with the access their role allows.
- Company owners decide who is invited, including their payroll contact, and can remove access at any time.
Payments
When paid plans are active, card payments are handled by Stripe. Card numbers go directly to Stripe and never touch TimeThis servers.
Data we avoid
TimeThis does not need Social Security numbers, bank account numbers or tax IDs. Keeping them out of the system means they cannot be exposed through it.
Backups and reliability
Our database is backed up continuously so it can be restored to an earlier point if something goes wrong. The app runs on managed infrastructure that is monitored and updated by our hosting providers.
Service providers
We use a small number of established providers, each chosen for its security practices.
| Provider | What it does for us | Location |
|---|---|---|
| Vercel | Hosting and delivery of the app and website | United States |
| Neon | Database hosting and backups | United States |
| Cloudflare (R2) | Private storage for uploaded files | United States |
| Twilio SendGrid | Sign-in codes, invites and notifications by email | United States |
| Optional sign-in with a Google account | United States | |
| Stripe | Subscription billing and payment processing, when paid plans are active | United States |
Reporting a security issue
If you think you have found a vulnerability, please email support@timeth.is with the subject “Security” and enough detail for us to reproduce it. Please give us a reasonable time to fix it before sharing it publicly, and do not access or change other customers' data while testing. We will confirm receipt and keep you updated.
If we ever learn of a breach that affects your data, we will notify affected account owners without undue delay and as the law requires. See our Privacy policy for more.