1. Introduction
This Privacy Policy explains how ProjectPacer LLC (“ProjectPacer,” “we,” “us,” or “our”) collects, uses, discloses, and protects personal information in connection with the ProjectPacer web application, desktop application, and related services (the “Service”). It applies to personal information we handle as a business, and supplements our Terms & Conditions. Capitalized terms not defined here have the meaning given in the Terms.
Controller and processor roles. For personal information about your own account and your use of the Service, ProjectPacer acts as the business or controller. For the data you put into the Service about your clients, projects, and team members (your “Customer Data”), you are the controller and ProjectPacer acts as a service provider or processor, handling that data on your behalf and under your instructions. If you added personal information about another person to the Service, this policy explains our practices, but you are responsible for your own privacy obligations to those individuals.
2. Who This Policy Covers & Geographic Scope
This policy covers visitors to our website, people who create or use a ProjectPacer account, and individuals whose information is included in Customer Data. The Service is intended for business use by users located in the United States.
US-focused Service. The Service is directed to users in the United States and is not intended for or directed to individuals located in the European Economic Area, the United Kingdom, or Switzerland. We do not currently offer the Service to those regions. If we begin offering the Service in those regions, we will update this policy to add the disclosures and safeguards those laws require (such as lawful-basis and international-transfer terms) before doing so.
3. Information We Collect
We collect the following categories of personal information, depending on how you use the Service:
| Category | Examples |
|---|---|
| Account & identity | Name, email address, password (stored only in hashed form using industry-standard hashing, never readable), workspace name, and role. Used to sign you in and show you to teammates. |
| Consent records | When you accept the Terms of Service or this Privacy Policy, we record which version you accepted, the date and time, and the IP address and browser user agent the acceptance came from. If you erase your account, the IP address and user agent are deleted; we retain only the record that the account accepted a given version, and when, as proof of agreement. |
| Billing & payment | Subscription plan, transaction history, and limited billing details. Full payment card numbers are handled by our payment processor and are not stored by ProjectPacer. |
| Your work data | Time entries, tasks, projects, clients, engagements, rates, timesheets, invoices, and reports — the data you enter, which may include personal information about your clients, collaborators, or team members. This is your Customer Data; it is yours. |
| Mileage & travel | Only if you use mileage: trips and any addresses you save as trip origins. Saved addresses are geocoded to coordinates using our mapping provider (Mapbox). |
| Connected sources (opt-in) | Only if you or your workspace connect them: signals from the work tools you already use — calendar events, issue and project trackers, task boards, chat presence and message timestamps, and time entries imported from other trackers — used to suggest time you may have missed and to match your work to the right project. Today these are a read-only calendar link (event title, description, time, location, organizer, attendees), GitHub repositories you map, entries imported from Clockify, and Slack (your presence, the timestamps of messages you send, and the names of channels you belong to, including private channel names); we may add similar tools over time for these same purposes, and we will name the current ones here. Connections that read only shared workspace content are enabled by a workspace owner; connections that read your own activity require you to connect your own account. Slack can also send you direct messages and accept slash commands you issue to start or stop your timer. |
| Programmatic access (opt-in) | Only if you create one: a personal access token, or an AI-assistant connection authorized through our sign-in flow, that lets a tool you choose act in your workspace as you — for example, an AI assistant connected over the Model Context Protocol (MCP). We store the credential only in non-reversible hashed form (never the raw secret), together with a label, the workspace it belongs to, and its creation and last-used times, so you can see and revoke it. It is off until you create one, grants only the access you already have, and only in the one workspace you connected. |
| Browser notifications (opt-in) | Only if you turn on browser alerts in a given browser or installed app: we store a push subscription for that browser or app — a delivery endpoint issued by your browser’s own push service, and the cryptographic keys used to encrypt messages sent to it — together with that browser’s user-agent string, so we can send the notifications you asked for and show you which device is subscribed. The contents of each notification are encrypted end-to-end, so the push service that relays it cannot read them. It is off until you enable it, applies only to the browser or installed app you enable it in, and the subscription is deleted when you turn it off. |
| Financial Accounts (opt-in) | If you connect a Financial Account — a bank, corporate card, or accounting platform such as Mercury or QuickBooks — we process the account and transaction data we retrieve, including merchant or payee names, dollar amounts, dates, and transaction descriptions, as your Customer Data, to power billing, expense, and reconciliation features. This connection is opt-in and applies only to accounts you choose to connect. |
| Desktop presence (opt-in) | If you install the desktop application and turn on activity tracking, it records only coarse device session events — each event is a timestamp plus a one-word label from a fixed list: startup, sleep, wake, lock, unlock, or idle. “Idle” means input stopped for a period; it reflects only that the machine went idle, never what was typed. These come from the operating system’s power/session signals. The app has no ability to read, and does not request the system permissions that would be required to read, window titles, application names, keystrokes, screen contents, or files. Each stored record contains only your user ID, the timestamp, the source, and the event label. |
| Operational logs | Request timings, error messages, and diagnostic data used to keep the Service running and debug failures. Visible to us, not shared with third parties for their own use. |
| Communications | Messages you send us, including support requests and feedback. |
Sensitive information. The Service is a general-purpose time tracker and is not built for you to type sensitive or regulated data into it. Our Terms and Documentation ask you not to enter protected health information, government identifiers, full payment card numbers, or similar sensitive data — in entry descriptions, task or project names, or connected calendar events. Because a connected calendar pulls in text you did not type, do not connect a calendar whose events could contain sensitive or health information. This is distinct from connecting a Financial Account, where account and transaction data is imported through a secure, opt-in connection and used only for the billing, expense, and reconciliation features you enable.
4. How We Use Information
We use personal information to:
- Provide, operate, maintain, and secure the Service, including the features you use;
- Generate the features and suggestions you request, such as suggesting time you may have missed based on your connected calendar and, if you enable it, coarse desktop session events (when your machine slept, woke, locked, unlocked, started, or went idle);
- Send you the notifications you turn on, through the channels you choose — a Slack direct message, a desktop notification, or a browser alert;
- Process payments, manage subscriptions, and send billing and renewal communications;
- Provide customer support and respond to your requests;
- Monitor, troubleshoot, and improve the Service, and develop new features;
- Detect, prevent, and address fraud, abuse, security incidents, and technical issues;
- Send administrative and, where permitted, marketing communications (you can opt out of marketing); and
- Comply with legal obligations and enforce our agreements.
How AI suggestions work. ProjectPacer’s suggestions are generated to help you capture time you might otherwise miss — for example, matching a calendar meeting to a project, or using desktop activity-state timestamps to flag time you may not have logged. We do not use your Customer Data or other personal information to train or improve any AI or machine-learning model, and we do not permit any provider that processes data for these features to use it to train their models. Suggestions are generated only to serve your own account.
De-identified & aggregated data. We may create and use aggregated or de-identified information (which does not identify you or any individual) to understand usage, improve the Service, and for analytics and reporting. We maintain such information in de-identified form and do not attempt to re-identify it except as permitted by law.
5. How We Share Information
We do not sell your personal information, and we do not use it for cross-context behavioral advertising or ad targeting. We share information only as described here:
- Service providers. We use trusted foundational infrastructure and operational partners to run the Service — such as hosting, database administration, backup management, transactional email, (if you use mileage) address geocoding, and (if you enable browser notifications) delivery of those alerts through your browser’s push service. These partners — which currently include Render (hosting and database), Cloudflare R2 (encrypted off-site backups), Resend (transactional email), if you use mileage Mapbox (address geocoding), and if you enable browser notifications the push service of your browser, Apple, Google, or Mozilla (notification delivery), among others — may process data including IP addresses and operational metadata solely on our behalf to keep the platform stable and provide their service, and are contractually restricted from using your data for their own external commercial or profiling purposes. A browser push service receives only the delivery endpoint and the end-to-end-encrypted notification, which it cannot read. Error and performance monitoring is performed within our own systems (first-party), not by a third-party analytics provider. Your time entries are not sold or shared for advertising.
- Sources you connect. If you connect a calendar, GitHub, Clockify, Slack, or a Financial Account, we exchange data with that source, and (for Financial Accounts) with our financial-data aggregation provider, as needed to provide the connected feature. Connected sources and aggregation providers operate under their own terms and policies, and we are not responsible for their data processing, security, or availability.
- AI assistants you connect. If you connect an AI assistant to your workspace (over MCP), it accesses your data as you, at your direction, and within your existing permissions in the workspace you connected. Whatever you share with it, or ask it to retrieve, is then handled by that assistant’s provider under their own terms and privacy policy, which we do not control. You can disconnect it at any time, which ends its access immediately.
- Within your workspace. Data in a shared workspace is accessible to the workspace’s owner, administrators, and members according to the roles and permissions set by that workspace. Cost rates are restricted to owners and admins by default.
- Legal and safety. We may disclose information to comply with law or legal process, enforce our agreements, or protect the rights, safety, and security of ProjectPacer, our users, or the public.
- Business transfers. If we are involved in a merger, acquisition, financing, or sale of assets, personal information may be transferred as part of that transaction, subject to this policy; we will provide notice before your information becomes subject to a different privacy policy.
No sale, sharing, or targeted advertising. We do not sell personal information or share it for cross-context behavioral (targeted) advertising, and we do not use advertising trackers. Error and performance monitoring is performed within our own systems; we do not currently use third-party analytics or monitoring providers, and any monitoring we do is used only to keep the Service running, measure stability, and fix bugs — not for cross-context tracking or ad targeting. If we ever engage in a “sale” or “share” as defined by US state privacy laws, we will update this policy and provide the notices and opt-out mechanisms those laws require (including a “Do Not Sell or Share My Personal Information” control and honoring opt-out preference signals such as Global Privacy Control) before we begin.
6. Cookies & Similar Technologies
We and our providers may use cookies and similar technologies in the following categories:
- Strictly necessary. Required for the Service to function — for example, keeping you signed in and remembering which workspace you are in. These cannot be disabled while you use the Service.
- Functional. Remember your preferences to improve your experience.
- Performance & error monitoring. First-party technologies that help us measure uptime, diagnose bugs, and improve reliability. These may collect operational data such as IP address and diagnostic metadata within our own systems, and are used only to operate and improve the Service — not for cross-context tracking or advertising. We do not currently use third-party analytics or monitoring cookies.
- Advertising. Used to deliver or measure advertising. We do not use advertising cookies or ad trackers, and we do not share cookie data for cross-context behavioral advertising.
You can control cookies through your browser settings; disabling strictly necessary cookies may prevent the Service from working. If we introduce cookies that constitute a “sale” or “share” under applicable law, or otherwise require consent, we will update this policy and provide the required controls before doing so.
7. Data Retention & Deletion
We retain personal information for as long as your account is active and as needed to provide the Service, and afterward as needed to comply with legal obligations, resolve disputes, and enforce our agreements.
30-day deletion grace window. Deleting an account or a workspace is not instant. It starts a 30-day grace window during which the data is locked but fully restorable; only after the window closes does a cleanup permanently erase it. Keep an export if there is any chance you will want the data back.
What happens to logged time. When your user account is deleted or unlinked, raw time-allocation entries remain tied to the parent workspace history for corporate billing and continuity purposes, but are de-linked from your individual profile — that is, we remove the profile identifier that associates those entries with you. We do not claim this de-linking renders every entry “anonymized” in a strict statutory sense, because free-text you or others entered (such as an entry description) may still reference a person; the workspace owner controls that content and can edit or delete it. Your calendar summaries, metadata caches, and active sync access tokens are permanently deleted upon completion of the 30-day grace period.
Connected-source data. Disconnecting a calendar, GitHub, Clockify, Slack, or Financial Account source deletes the data stored for that source and revokes the associated access tokens. Desktop presence events are retained only for a rolling window you choose (options of 3, 7, 14, or 30 days; 14 days by default), after which they are automatically pruned; turning desktop presence off deletes its stored session events. Connected calendars store only a rolling window of recent and upcoming events, which refreshes on each sync, so older events age out automatically. Turning off browser notifications for a device — or clearing them in that browser — deletes the push subscription stored for it; we also drop a subscription automatically once its push service reports it is no longer valid. Data retrieved from a connected financial service may be delayed, incomplete, or inaccurate due to the third party’s systems, and you are responsible for verifying it before relying on it.
Backups. Encrypted off-site backups are retained for approximately 30 days on a rolling basis before being overwritten. Exports never include secrets such as passwords, calendar-feed URLs, or integration tokens. Billing and tax records are retained as required by law.
8. Security
We maintain administrative, technical, and organizational safeguards designed to protect personal information appropriate to its nature and the risks involved. These include: encryption of traffic in transit; industry-standard encryption at rest for the secrets you connect, such as calendar-feed URLs and integration tokens, which are decrypted only when used; industry-standard password hashing, so passwords are never stored in readable form; server-enforced isolation between workspaces and role-based access controls within a workspace; rate-limited sign-in; audit logging of privileged administrative actions; and validation of user-provided addresses to protect against server-side request forgery. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for safeguarding your account credentials and managing access within your workspaces. If a security incident affects your personal information, we will notify you as required by applicable law.
9. Your Choices
- Account information. You can review and update much of your account information within the Service.
- Marketing. You can opt out of marketing emails using the unsubscribe link; we may still send administrative messages about your account and the Service.
- Integrations & presence. You can disconnect any connected source — calendar, GitHub, Clockify, Slack, or a Financial Account — at any time, which deletes the data stored for it and revokes its access tokens. You can turn desktop presence on or off at any time (it is off until you opt in), which deletes its stored session events. Browser notifications are off until you enable them and are per-browser; turning them off deletes that browser’s push subscription. You can revoke a personal access token, or disconnect a connected AI assistant, at any time from Settings → Apps & integrations → MCP, which cuts off its access immediately.
- Export and deletion. You can export a complete copy of your data (personal or, with permission, the whole workspace) and delete your account or a workspace, with a 30-day grace window, as described in the Documentation.
10. Your US State Privacy Rights
Depending on your state of residence, US privacy laws (including in California, Virginia, Colorado, Connecticut, Utah, Texas, and other states with comprehensive privacy laws) may give you the following rights regarding personal information we handle about you as a business or controller:
- Access / know. Request confirmation of whether we process your personal information and access to it, including the categories collected, sources, purposes, and categories of recipients.
- Correction. Request correction of inaccurate personal information.
- Deletion. Request deletion of personal information we hold about you.
- Portability. Request a copy of certain personal information in a portable format.
- Opt out. Opt out of any “sale” or “sharing” of personal information and of targeted advertising and certain profiling. As noted above, we do not currently engage in these activities.
- Non-discrimination. You will not receive discriminatory treatment for exercising these rights.
How to exercise your rights. Submit a request using the contact details in the Contact section. We will verify your request as required by law and respond within the timeframes the applicable law provides. You may use an authorized agent where permitted. If we deny a request, you may appeal by replying to our response; where required, we will provide information about further appeal or how to contact your state regulator.
Requests about Customer Data. Where another business uses ProjectPacer and your personal information appears in their workspace as Customer Data, that business is the controller. Please direct your request to them; we will assist them as their service provider as required by law.
11. Additional California Disclosures
This section provides additional detail for California residents under the CCPA/CPRA. In the preceding 12 months, we have collected the categories of personal information described in the “Information We Collect” section, for the purposes described in “How We Use Information,” and disclosed personal information to the categories of recipients described in “How We Share Information.”
Sale/sharing. We have not sold personal information or shared it for cross-context behavioral advertising, and we do not knowingly do so for individuals under 16.
Sensitive personal information. We do not use or disclose sensitive personal information for purposes that would require offering a right to limit under the CPRA. We ask that you not submit sensitive information to the Service.
Retention. We retain each category of personal information for the period described in the Data Retention section.
12. Children’s Privacy
The Service is intended for business use by adults and is not directed to children. We do not knowingly collect personal information from children under 16. If you believe a child has provided us personal information, please contact us and we will take appropriate steps to delete it.
13. Third-Party Services & Links
The Service integrates with and may link to third-party services you choose to use, such as calendars, financial and accounting platforms, and other tools. Those third parties handle your information under their own privacy policies, which we do not control. Review their policies before connecting or using them. Information retrieved from a connected service is used only to provide the connected feature, as described in the Terms.
14. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or through the Service and update the “Last updated” date. If you continue to use the Service after the effective date of an update, the updated policy will apply to personal information we handle from that date forward, except where applicable law requires your affirmative consent.
15. Contact Us
For questions about this Privacy Policy or to exercise your rights, contact us at:
ProjectPacer LLC
2461 N New Jersey St, Indianapolis, IN 46205
Email: support@projectpacer.com