Privacy and data protection you can rely on
Comprehensive privacy and enterprise grade security programs to help protect and empower your organization and team's work.
Network, application, and data security is vital for any enterprise solution.
GDPR is a priority to us. We have specific processes and tools in place to ensure compliance and protect your data and privacy.
Penetration & security audits
Our systems are penetration tested and audited annually by an independent security firm.
Data encryption in transit and at rest
We use TLS 1.2 to encrypt the data in motion and follows several security measures to help ensure the authenticity, integrity, and privacy of all data in transit. We also use Google Cloud Platform that encrypts data at rest managed the same way as for Google’s production services.
Annual penetration tests
We penetration test our service annually to make sure our application and infrastructures are not vulnerable. We also make sure our code goes through a thorough code review process.
Principle of least privilege policy
Application infrastructure is completely hosted on Google Cloud with least privilege access policy. We also have logging in place to audit any authorized access. Furthermore our application infrastructure is completely separated from our public facing website for enhanced security.
You’re in good company
A few of the amazing brands who trust us with their time
Frequently Asked Questions
When you login to TimeTackle you provide TimeTackle permission to read your calendars. This is a read-only permission, that means, we can’t write or edit any information on your calendars. This permission enables features like calendar exporting.
If you want to use the Google Sheets Sync feature then you will need to provide an additional limited write permission to your Google Drive. This additional permission allows TimeTackle to create new files to your Google Drive. TimeTackle can only read and edit files created by itself. The application can not access any other files in your Google Drive.
TimeTackle itself is not ISO 27001 or SOC2 certified. However, we are completely hosted on Google Cloud Platform (GCP) which is compliant to these standards and has been for several years.
We use Stripe as our payment service provider. Stripe is certified to PCI Service Provider Level 1. This is the most stringent level of certification available. So you can be rest assured that security is not an issue.
Yes, of course! Once you set a data retention period, TimeTackle will automatically delete data older than the retention period from its storage and database.
* This feature is only available to our business users
Using our product does not in itself meet HIPAA (Health Insurance Portability and Accountability Act) compliance standards. The duty to comply still rests with the account holder and is dependent on what data is collected and how it is shared. However it is possible to use our system without breaching any of those requirements.
Login is secure using secure OAuth 2.0 authentication with single sign-on (SSO) provided by Google or Microsoft. Application programming interface (API) secured through HTTPS.
We protect all customer data at the storage and database level using Google Cloud Platform (GCP) encryption at rest mechanisms. At the account level, customers can set their own data retention limits.
TimeTackle is a California LLC , based in San Jose, CA, USA. Our data centers are in the United States using Google Cloud.
We aim for 99.99% uptime. We use active monitoring and alerting using Google Cloud Monitoring. For internal anomalies, we use Google Cloud Logging.