Privacy Policy
Effective Date: October 3, 2026
1. Introduction
Mavops Inc. ("Company," "we," "us," "our") operates the TimeTracker platform ("Service"), a time tracking and billing solution for professional services firms. This Privacy Policy describes how we collect, use, store, and protect your personal information when you use our Service.
We are committed to protecting your privacy. We collect only what is necessary to provide the Service, and we never sell your personal data to third parties.
2. Information We Collect
2.1 Account Information
When you create an account, we collect:
- Name and email address
- Organization name
- Password (stored in encrypted/hashed form)
- Billing information (processed securely via Stripe)
2.2 Information Your Firm Provides During Setup
When your firm is set up on the Service, your employer (or someone acting for it, such as an office manager or IT administrator) may give us information about you so your account can be created before you first sign in. This can include:
- Your name, work email address, role and phone number
- Your billing rate and, if your firm chooses to provide it, your cost rate
- Your department or team
- The name of your work computer and your Windows sign-in name, so the desktop agent can be connected to your account automatically
- Whether you are the person who holds administrator access to a computer (we never ask for or accept passwords)
Your firm submits this through a setup form or file it sends to us. We use it only to create and configure your firm’s account, and it is handled under this Policy like the rest of your account data. Cost rates are visible only to your firm’s owner.
2.3 Time Tracking Data
In the course of using the Service, we collect:
- Application usage data from the desktop agent (active window titles, application names, timestamps, the address of the active browser tab, and the file path of the open document)
- Time entries, categories, and client assignments
- Notes and descriptions you add to time entries
2.4 Integration Data
When you connect third-party integrations (such as QuickBooks Online, Xero, Clio, Microsoft Outlook, Google Calendar or Gmail), we collect and store:
- OAuth access tokens and refresh tokens (encrypted at rest)
- Account identifiers required for the integration to function
- Data synchronized between the Service and the third-party platform (e.g., client lists, invoice data, time activities, calendar events, email headers). Google data is described in detail in Section 5.
2.5 Automatically Collected Information
- IP address and approximate location
- Browser type and device information
- Usage analytics (pages visited, features used)
3. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve the Service
- Process time entries and generate billing reports
- Synchronize data with connected third-party integrations
- Send transactional notifications (timesheet reminders, approval notifications, weekly summaries)
- Provide customer support
- Detect and prevent fraud, abuse, and security incidents
- Comply with legal obligations
We use AI-powered classification to help categorize your time entries. To do this, activity details (window titles, application names, and file names or paths) your firm’s client names, and the names of your firm’s service or activity codes are sent to our AI provider, OpenAI, through its API. OpenAI does not use data sent through its API to train its models, and we do not use your data to train AI models. Data received from Google APIs (Gmail and Google Calendar) is never sent to an AI provider.
4. Third-Party Integrations
The Service offers integrations with third-party platforms. When you authorize an integration:
- We access only the data scopes you explicitly authorize
- OAuth tokens are stored securely and refreshed automatically
- Some integrations act only when you initiate an action (e.g., pushing time entries, importing clients); others, such as calendar and email integrations, sync automatically in the background while connected
- You may disconnect any integration at any time from the Service settings
We encourage you to review the privacy policies of any third-party services you connect:
5. Google User Data (Gmail and Google Calendar)
You can optionally connect your Google account so that meetings and email are recorded against the right client. Each connection is separate: you can connect Google Calendar, Gmail, both, or neither.
5.1 What We Access
- Google Calendar (
calendar.events.readonly): events on your primary calendar only — start and end times, event title, and the email addresses of attendees. We do not read other calendars, calendar settings or sharing.
- Gmail (
gmail.metadata): message headers only — From, To, Cc, Subject and Date — for messages in your Inbox and Sent mail. Under this permission Google does not give us message bodies or attachments, and we never request them.
- Your Google account email address (
openid, email), to show which account is connected.
5.2 How We Use It
- Calendar events are matched against your firm’s client list so that time spent in a meeting is attributed to the client whose people attended.
- Email headers are used to match the other party’s email domain to a client, and the time between your activity in Gmail and a message you send is used to estimate how long you spent writing to that client.
- We use Google data only to provide these features to you. We do not use it for advertising, we do not sell it, and we do not use it to train AI or machine-learning models.
5.3 Who Can See It
- Email sender and recipient addresses and subject lines are visible only to you, on your own time entries.
- Your firm’s managers and administrators see only the client a meeting or email was matched to and the other party’s email domain — never addresses or subject lines.
- We do not transfer Google data to third parties, except as necessary to operate the Service (our hosting provider), to comply with law, or as part of a merger or acquisition with notice to you. Google data is never sent to an AI provider.
5.4 Storage, Retention and Deletion
- Google OAuth tokens are encrypted at rest. All Google data is transmitted over TLS.
- Email header records are kept for 30 days by default (your firm may set a different period) and are then deleted automatically.
- When you disconnect Gmail or Google Calendar in TimeTracker, the email or calendar data we stored from that connection is deleted immediately and the tokens are cleared. You can also remove TimeTracker’s access at any time at myaccount.google.com/permissions.
- To request deletion of any Google data we hold about you, contact privacy@mavops.ai.
TimeTracker’s use and transfer to any other app of information received from Google APIs will adhere to the
Google API Services User Data Policy, including the Limited Use requirements.
6. Data Storage & Security
We implement industry-standard security measures to protect your data:
- All data is transmitted over HTTPS/TLS encryption
- Passwords are hashed using industry-standard algorithms
- OAuth tokens are stored securely with encryption at rest
- Our infrastructure is hosted on reputable cloud providers with SOC 2 compliance
- Database connections use SSL/TLS encryption
- Access to production systems is restricted to authorized personnel
While we take reasonable measures to protect your data, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.
7. Data Retention
We retain your data for as long as your account is active or as needed to provide the Service. Specifically:
- Account data: Retained for the life of your account
- Time tracking data: Retained for the life of your account
- Raw activity events: Automatically deleted after 30 days
- Integration tokens: Deleted immediately upon disconnection
- Email header records (Gmail, Outlook): Deleted automatically after 30 days by default, and immediately when you disconnect
Upon account termination, you may request an export of your data within 30 days. After this period, your data will be permanently deleted from our active systems within 90 days. Backup copies may persist for up to an additional 90 days before being purged.
8. Data Sharing
We do not sell, rent, or trade your personal information. We may share your data only in the following limited circumstances:
- With your consent: When you explicitly authorize a third-party integration
- Service providers: Trusted vendors who help us operate the Service (hosting, email delivery, payment processing, and AI classification as described in Section 3), bound by confidentiality agreements. Google user data is shared only as described in Section 5
- Legal requirements: When required by law, regulation, legal process, or governmental request
- Business transfers: In connection with a merger, acquisition, or sale of assets, with notice to affected users
9. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you
- Correct inaccurate or incomplete data
- Delete your personal data ("right to be forgotten")
- Export your data in a portable format
- Opt out of non-essential communications
- Withdraw consent for data processing at any time
To exercise any of these rights, contact us at privacy@mavops.ai. We will respond within 30 days.
10. Cookies & Tracking
We use cookies and similar technologies for:
- Essential cookies: Authentication and session management (required for the Service to function)
- Analytics: Understanding how the Service is used to improve it
We do not use cookies for advertising or cross-site tracking. You may configure your browser to reject cookies, but some features of the Service may not function properly.
11. Desktop Agent
The TimeTracker desktop agent captures application usage data to automate time tracking. Important details:
- The agent captures active window titles, application names, the address of the active browser tab, and the file path of the open document. To find a document’s folder it may look the file name up in your computer’s own search index (Spotlight on macOS); that lookup happens only on your computer
- No screenshots, keystrokes, document contents, webcam images or microphone audio are captured. The agent only checks whether the camera or microphone is in use, so time spent on a call is not counted as idle
- Raw activity data is automatically deleted from our servers after 30 days
- You can pause or disable the agent at any time
- All data transmission is encrypted
12. Browser Extension
The optional TimeTracker URL Reporter browser extension is a companion to the desktop agent that helps attribute browser-based work to the correct client. It takes no action unless the desktop agent is running on the same computer.
12.1 What the Extension Accesses
- The URL and title of the active browser tab, only while a browser window is focused. The query string and fragment are removed from the URL first, so session tokens, account identifiers, and sharing links are discarded.
- On QuickBooks Online (
qbo.intuit.com) only: the identifier of the company you currently have open (the qbo.currentcompanyid cookie) and that company's display name, read from the page, so time can be attributed to the correct client when staff switch between client companies. No other cookies and no other page content are read on QuickBooks Online — not transactions, balances, customers, or anything you type.
12.2 Where the Data Goes
- The information above is sent only to the TimeTracker desktop agent running on the same computer (
http://127.0.0.1). The extension itself transmits nothing over the internet — not to us, and not to any third party. If the local agent is not running, nothing is sent.
- The extension stores no data itself beyond small local counters used for its own troubleshooting display, and retains nothing between browser sessions.
12.3 What the Extension Does Not Do
- It does not read page contents on ordinary websites (no content scripts).
- It does not access your browsing history, bookmarks, saved passwords, or other tabs.
- It does nothing while the browser is not the focused window.
- It does not sell or share data with third parties.
The extension requests only the permissions needed for this: the active tab's URL and title, local storage for its own counters, and — scoped to qbo.intuit.com only — the QuickBooks company id and name. Its only network destination is the local desktop agent on your own machine.
13. Mobile App
The TimeTracker mobile app may request access to the following device features:
-
Microphone — used optionally for voice entry. When you use the voice entry feature,
audio is transmitted to OpenAI's Whisper API for transcription only. The audio itself is never stored
on our servers, and transcribed text is processed solely to fill in your time entry fields.
Microphone access is never used passively or in the background.
-
Calendar — used optionally to suggest clients from your calendar event titles.
Calendar data (event titles, start and end times) is sent to our servers only at the moment you
save a time entry, to validate session duration and suggest the correct client. Calendar event
content is never stored on our servers and is not used for any purpose beyond this validation.
-
Local Storage — time entries may be saved locally on your device if you lose
internet connectivity, and will sync to our servers automatically when connection is restored.
Locally stored entries are cleared after successful sync.
All mobile data transmissions use HTTPS/TLS encryption. You may deny microphone or calendar
permissions at any time via your device Settings without affecting core app functionality.
14. Children's Privacy
The Service is not intended for use by individuals under the age of 16. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child under 16, we will take steps to delete it promptly.
15. International Data Transfers
Your data may be processed and stored in the United States. If you are accessing the Service from outside the United States, your data will be transferred to and processed in the United States, where data protection laws may differ from those of your jurisdiction.
16. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page, updating the effective date, and (where appropriate) sending an email notification. Continued use of the Service after changes constitutes acceptance of the revised policy.