We enforce TLS 1.2 everywhere. Data at rest is encrypted by default and we secure all sensitive information with strong hashing algorithms like AES-256 and AES-128.
GDPR is a priority to us. We have specific processes and tools in place to ensure compliance and protect your data and privacy.
Penetration & Security Audits
Join 2,000+ amazing businesses already using TimeTackle
Network, application, and data security is vital for any enterprise solution
Data encryption in transit and at rest
Annual penetration tests
Principle of least privilege policy
Frequently asked questions
What permissions does TimeTackle need?
When you login to TimeTackle you provide TimeTackle permission to read your calendars. This is a read-only permission, that means, we can’t write or edit any information on your calendars. This permission enables features like calendar exporting.
If you want to use the Google Sheets Sync feature then you will need to provide an additional limited write permission to your Google Drive. This additional permission allows TimeTackle to create new files to your Google Drive. TimeTackle can only read and edit files created by itself. The application can not access any other files in your Google Drive.
Are you ISO 27001 and SOC2 certified?
How secured is the payment method?
We use Stripe as our payment service provider. Stripe is certified to PCI Service Provider Level 1. This is the most stringent level of certification available. So you can be rest assured that security is not an issue.
Can we control data retention?
Yes, of course! Once you set a data retention period, TimeTackle will automatically delete data older than the retention period from its storage and database.
* This feature is only available to our business users
Are you HIPAA compliant?
Using our product does not in itself meet HIPAA (Health Insurance Portability and Accountability Act) compliance standards. The duty to comply still rests with the account holder and is dependent on what data is collected and how it is shared. However it is possible to use our system without breaching any of those requirements.
How is my account secured?
How is my data protected?
We protect all customer data at the storage and database level using Google Cloud Platform (GCP) encryption at rest mechanisms. At the account level, customers can set their own data retention limits.
Where are you located?
What is your stability and uptime?
We aim for 99.99% uptime. We use active monitoring and alerting using Google Cloud Monitoring. For internal anomalies, we use Google Cloud Logging.