Security

Last updated September 28, 2026

Crew hours and payroll records are sensitive. Here is how TimeThis keeps them protected.

Encryption

  • All traffic to timeth.is uses HTTPS, so data is encrypted between your browser and our servers.
  • Our database and file storage providers encrypt data at rest.

Private file storage

Files you upload, such as daily sheets, rosters and payroll registers, are kept in private storage that is never publicly readable. When you download a file, TimeThis creates a link that works for a few minutes and only after it has checked that you have access.

Signing in

  • There are no passwords to steal or reuse. You sign in with a six digit code sent to your email, which expires after 10 minutes and works once.
  • You can also sign in with Google, which lets you use your Google account's own protections, such as two-step verification.
  • Sessions are stored in secure, HTTP-only cookies and expire automatically.
  • Invites are single use and expire after 7 days.

Access controls

  • Each company's data is kept separate. Every request is checked against the company the signed-in person belongs to.
  • People only see the companies they have been invited to, with the access their role allows.
  • Company owners decide who is invited, including their payroll contact, and can remove access at any time.

Payments

When paid plans are active, card payments are handled by Stripe. Card numbers go directly to Stripe and never touch TimeThis servers.

Data we avoid

TimeThis does not need Social Security numbers, bank account numbers or tax IDs. Keeping them out of the system means they cannot be exposed through it.

Backups and reliability

Our database is backed up continuously so it can be restored to an earlier point if something goes wrong. The app runs on managed infrastructure that is monitored and updated by our hosting providers.

Service providers

We use a small number of established providers, each chosen for its security practices.

ProviderWhat it does for usLocation
VercelHosting and delivery of the app and websiteUnited States
NeonDatabase hosting and backupsUnited States
Cloudflare (R2)Private storage for uploaded filesUnited States
Twilio SendGridSign-in codes, invites and notifications by emailUnited States
GoogleOptional sign-in with a Google accountUnited States
StripeSubscription billing and payment processing, when paid plans are activeUnited States

Reporting a security issue

If you think you have found a vulnerability, please email support@timeth.is with the subject “Security” and enough detail for us to reproduce it. Please give us a reasonable time to fix it before sharing it publicly, and do not access or change other customers' data while testing. We will confirm receipt and keep you updated.

If we ever learn of a breach that affects your data, we will notify affected account owners without undue delay and as the law requires. See our Privacy policy for more.