Work Time ReportPRO For workers For companies Sign in
← Back to home

Privacy Policy

Last updated: May 15, 2026 · Effective: May 15, 2026

This Privacy Policy describes how Work Time Report Pro ("the Service", "we", "us") collects, uses, and shares information when you use our web application available at work-time-report-pro.vercel.app.

We comply with the Brazilian General Data Protection Law (LGPD — Lei 13.709/2018) and apply equivalent protections to users outside Brazil.

1. Who we are

The Service is built and operated by Surround.Services, based in Brazil. For privacy, billing, or LGPD-related questions, reach us at https://www.surround.services/.

2. What information we collect

Information you provide

  • Account information: email and password (hashed by Supabase Auth) when you sign up; full name and company name when you complete your profile.
  • Time tracking data: entry/exit times, lunch duration, optional comments, and clock-in/out timestamps you record.
  • Hourly rate: the rate you optionally configure to calculate earnings.
  • Payment information: if you upgrade, payment is processed by Stripe. We never see or store your card details — only a Stripe customer ID and subscription status.

Information collected automatically

  • Technical data: approximate request timestamps and rate-limited error logs maintained by our hosting providers (Vercel, Supabase) for security and reliability.
  • No analytics or tracking pixels. We do not use Google Analytics, Meta Pixel, or any third-party tracker.

Guest mode

If you use the Service without signing in ("Guest mode"), all data stays on your device in your browser's local storage. We do not see, collect, or have any access to it.

3. How we use your information

  • Provide the time-tracking and reporting features you signed up for.
  • Authenticate you and protect your account.
  • Process subscription payments via Stripe.
  • Send transactional emails (password resets, billing receipts).
  • Comply with legal obligations (e.g., tax records for paid subscribers).

We do not sell your data, use it for advertising, or share it with third parties for marketing.

4. Who can see your data

  • You — full read/write access to your own data via the app.
  • Your manager (if you join an organization) — can see only the time entries and reports for the organization you joined them through. They cannot edit your data. They cannot see data you saved in other organizations.
  • Service providers — Supabase (database hosting), Vercel (web hosting), Stripe (payments). Each operates under strict data-processing agreements.
  • Law enforcement — only when compelled by a valid Brazilian court order.

5. Data retention

  • Active accounts: we retain your data as long as your account exists.
  • Deleted accounts: we delete your data within 30 days of account deletion, except where retention is required for tax or legal compliance (typically 5 years for subscription records).
  • Inactive trial accounts: automatically purged after 90 days of inactivity if no payment was made.

6. Your rights under LGPD

As a data subject in Brazil, you have the right to:

  • Confirm whether we process your data.
  • Access your data.
  • Correct inaccurate data.
  • Anonymize, block, or delete unnecessary or excessive data.
  • Port your data to another service (we provide CSV/JSON export inside the app).
  • Withdraw consent at any time.
  • Object to processing under certain conditions.

To exercise any of these rights, contact us at https://www.surround.services/. We respond within 15 days.

7. Security

  • All data is transmitted over HTTPS.
  • Passwords are hashed with bcrypt (handled by Supabase Auth).
  • Database access is gated by Row-Level Security (RLS) policies enforced at the SQL level.
  • Payment data never touches our servers — Stripe handles it end-to-end.

No system is 100% secure. If you suspect unauthorized access to your account, contact us immediately.

8. Cookies

We use a single first-party cookie (or local storage entry) to maintain your sign-in session via Supabase. We do not use third-party cookies or tracking cookies.

9. Children

The Service is not intended for users under 18 years of age. We do not knowingly collect data from minors.

10. International users

Data may be stored in the Supabase region "South America (São Paulo)" or in Vercel's global edge network. By using the Service from outside Brazil, you consent to processing within these regions.

11. Changes to this policy

We may update this policy. Material changes will be announced via in-app notification at least 7 days before taking effect. Continued use after the effective date constitutes acceptance.

Contact / DPO For privacy questions, data requests, or LGPD compliance matters, reach out via Surround.Services.