TEDGE Time Tracker

Privacy Policy

Last updated: 7 September 2026

This Privacy Policy explains what personal data TEDGE Time Tracker collects, why we collect it, who we share it with, and what rights you have.

1. Who we are

Mostafa Mohamed Safwat Ibrahim Shalaby, a sole proprietorship trading as tedge

Commercial Register No. 29807 (Ismailia Chamber of Commerce)

Tax Registration No. 775786969

20 Block C, Ring Road, Sheikh Zayed, Ismailia Third, Ismailia, Arab Republic of Egypt

Email: info@tedgeltd.com

2. Two different roles

It matters which role we are in when your data is processed.

We are the controller for data about the customer organisation itself and the person who signs up — for example the account holder's email address, billing details and support correspondence. We decide why and how that data is used.

We are the processor for the working data inside a customer's workspace — the members, their time entries, timesheets and project assignments. The customer organisation is the controller of that data. It decides who is invited, what is recorded and how long it is kept. We only process it on the customer's instructions.

If you are an employee, contractor or member of an organisation using TEDGE Time Tracker and you have questions about your own time records, please contact your employer first. They control that data. We will assist them in responding to you.

3. What we collect

Account data. Your email address, password (stored only as a cryptographic hash, never in readable form), and full name if you provide one.

Workspace data. The company name, timezone and week start day; the projects, clients and tasks you create; the members you invite and the role and engagement type assigned to them.

Time and timesheet data. Time entries including start time, end time, duration, description, and the project and task they relate to; whether each entry came from the timer or was entered manually; weekly timesheets, their status, submission and review timestamps, and any review notes written by a manager.

Location data. If your workspace has location capture switched on, the Service records where your device is at the two moments you clock in and clock out: the latitude and longitude, how accurate that reading is in metres, and when it was taken. It also stores a street address worked out from those coordinates. Nothing is recorded in between — the Service does not follow your location while a timer is running, in the background, or at any other time. Your browser asks your permission first and you may refuse; if you do, the clock in still goes ahead and we record only that no location was captured. New workspaces are created with location capture set to "optional", which means it is on and recording wherever your device provides a position, and never blocks a clock in when it cannot. An Owner or Admin can change it at any time to "required", where a clock in without a position is refused, or to "off", where nothing is prompted for or stored. Workspaces created before 10 September 2026 were not changed and keep whatever setting they already had.

Idle time. Only if an Owner or Admin has switched idle time tracking on for you individually — it is off for everyone until then — the Service records, for each timer entry, how many seconds passed with no mouse, keyboard, scroll or touch input in the browser tab that is running the timer, counting any stretch of a minute or more. It records a single total per entry. It does not record what you typed, what you clicked, which windows or sites you had open, or anything from your camera, microphone or screen. It cannot see work done away from the screen: a phone in a pocket, a paper form or a conversation all count as no input. The figure is shown to you beside your hours on your timesheet and to the managers who review it, and is never subtracted from your hours or your pay. Whether it is switched on for you is visible on the Members page to the Owners and Admins of your workspace, and you can ask them.

Invitation data. The email address, role and engagement type of people you invite, along with the invitation token and its status.

Technical data. Standard server logs generated when you use the Service, including IP address, browser type and timestamps. These are produced by our hosting and database providers as part of normal operation.

What we do not collect. Inside the Service — everything you reach after signing in — there are no advertising or analytics trackers of any kind. Our public website pages do use Google Analytics and Google Ads, but only if you accept optional cookies; section 10 sets out exactly what those send and how to refuse or withdraw. We do not monitor keystrokes, take screenshots, record which windows or sites you have open, or access your device camera or microphone. The one activity signal the Service can record is the idle time total described above, and only for members it has been switched on for. We do not track your location continuously or in the background: location is recorded only at the moment you clock in and the moment you clock out, and only where your workspace's location capture setting allows it, as described under Location data above. Apart from that optional idle total, the Service records only the time entries that you or your members deliberately create.

4. Why we use it and our legal basis

PurposeLegal basis
Creating and securing your account, authenticating loginsPerformance of a contract
Providing time tracking, timesheets, approvals and reportingPerformance of a contract
Recording location at clock in and clock out, where a workspace's location capture setting allows itPerformance of a contract. The customer organisation, as controller, determines the legal basis that applies to its workers
Recording an idle time total per timer entry, where an Owner or Admin has switched it on for a memberPerformance of a contract. The customer organisation, as controller, determines the legal basis that applies to its workers and whether the measure is appropriate for that worker
Sending invitation, password reset and account emailsPerformance of a contract
Billing and keeping tax and accounting recordsLegal obligation; performance of a contract
Responding to support requestsLegitimate interests — running and supporting the Service
Keeping the Service secure and investigating abuseLegitimate interests — protecting the Service and its users
Measuring how our public website and our adverts performYour consent, given through the cookie banner and withdrawable at any time

The legal bases above are those under the UK and EU GDPR, which apply where our customers or their members are in the UK or the European Economic Area. We apply the same standards to all customers regardless of location.

We do not sell personal data. We do not use personal data to train machine learning models. We do not use the data you or your members enter into the Service — accounts, time entries, timesheets, locations or payroll figures — for advertising, and none of it is sent to Google.

5. Who we share it with

We use a small number of service providers ("sub-processors") to run the Service. Each is bound by contract to protect the data and to process it only on our instructions.

ProviderWhat they doWhere data is held
SupabaseDatabase, authentication and file storageEuropean Union (Ireland)
VercelApplication hosting and content deliveryGlobal edge network
ResendSending transactional email (invitations, password resets)European Union (Ireland)
Geoapify (KEPTAGO LTD)Converting clock in and clock out coordinates into a street addressEuropean Union
Google Ireland LimitedWebsite analytics and advertising measurement on our public pages, only if you accept optional cookiesGlobal

Where location capture is enabled, the coordinates recorded at clock in and clock out are sent to Geoapify so that a street address can be shown next to them. Only the coordinates are sent. No name, email address or other identifier goes with them, so Geoapify cannot tell whose location it is. Geoapify holds request data for no longer than 24 hours and processes it in EU data centres. The coordinates themselves remain the record; the address is a convenience.

We will update this list before adding a new sub-processor that handles personal data.

We may also disclose personal data where we are legally required to do so, or where it is necessary to establish, exercise or defend legal claims. If we receive a legally binding request for a customer's data, we will notify that customer unless we are legally prohibited from doing so.

6. International transfers

We are based in Egypt, and our sub-processors operate internationally. This means personal data may be transferred outside the country where you are located, including outside the UK and the European Economic Area.

Where data is transferred out of the UK or EEA, we rely on appropriate safeguards, including Standard Contractual Clauses in our agreements with sub-processors. You can request further information about these safeguards at info@tedgeltd.com.

7. How long we keep it

We keep Customer Data for as long as the customer's account is active.

After an account is terminated, we make the data available for export for 30 days, then delete it within a further 60 days from our live systems. Backups are overwritten on a rolling basis and any residual copies are removed within 90 days of deletion.

We keep billing and tax records for as long as Egyptian tax law requires, currently five years, even after an account closes.

A customer may ask us to delete their workspace and its data earlier by contacting info@tedgeltd.com.

8. Security

We protect data with:

encryption in transit using TLS, and encryption at rest at the database layer

passwords stored only as salted cryptographic hashes

row level security in the database, so each query is restricted to the workspaces the signed-in user actually belongs to

role based permissions enforced both in the interface and on the server

access to production systems limited to those who need it

No system is perfectly secure. If a personal data breach occurs that is likely to result in a risk to people's rights and freedoms, we will notify the affected customer without undue delay and in any event within 72 hours of becoming aware of it, and will notify regulators where required.

9. Your rights

Where the UK or EU GDPR applies, you have the right to:

access the personal data we hold about you

rectify data that is inaccurate or incomplete

erase your data in certain circumstances

restrict or object to processing in certain circumstances

data portability — receive your data in a structured, machine-readable format

withdraw consent where we rely on consent, without affecting processing already carried out

complain to a data protection authority

To exercise any of these, email info@tedgeltd.com. We will respond within one month. We may ask you to verify your identity first.

If your data is inside a customer's workspace, we are the processor. In that case we will forward your request to the customer organisation, which is the controller, and support them in responding.

If you are in the UK you may complain to the Information Commissioner's Office (ico.org.uk). If you are in the EEA you may complain to your national supervisory authority.

10. Cookies and analytics

We use strictly necessary cookies. These keep you signed in and remember which company workspace you are currently viewing. They are required for the Service to function and cannot be switched off.

We also use two optional Google services on our public website: Google Analytics 4 and Google Ads. We use them to understand how people find the site, which pages they read before signing up, and whether an advert led to a trial account being created. These are advertising and measurement purposes, not profiling of you as an individual by us.

We do not use Google Analytics or your activity on this site to build remarketing lists or personalised advertising audiences — Ads personalisation is switched off in our Google Analytics property, and the consent signal our pages send to Google keeps it denied even when you accept optional cookies.

These are optional. Nothing from Google is loaded until you choose Accept optional cookies on the banner we show on our public pages. If you choose Reject optional cookies, or ignore the banner, no Google script is requested and no Google cookie is set. Rejecting has no effect on signing up, signing in, paying, or any part of the Service.

You can change or withdraw your choice at any time using the Cookie settings link in the footer of this page and of our home and pricing pages. When you withdraw, we tell Google immediately that consent is denied, delete the Google analytics and advertising cookies your browser lets us read, and reload the page so that no Google code already running can carry on.

What is sent to Google if you accept: the address of the public page you are viewing, an anonymous cookie identifier Google sets in your browser, your approximate location derived by Google from your IP address, your device, browser and language, the referring page or advert that brought you, and the fact that a trial account was created. We also send the fact that someone clicked a Start free trial button and reached the signup form.

What is not sent: we do not include your name, email address, password, telephone number, account identifier, company name, or any employee, timesheet, location or payroll data in anything sent to Google. The signup event records only that a signup happened and that the method was email. Enhanced conversions are switched off, so no hashed email address or telephone number is collected or sent.

The optional Google services run on our public pages only, which are the home page, pricing, sign in, sign up, password reset and these legal pages. They are not loaded inside the signed-in application, so your work in the Service is not measured by Google.

Google acts as an independent controller for the data it receives through these services. How Google uses it is described at https://policies.google.com/privacy and at https://policies.google.com/technologies/partner-sites. Google's own explanation of advertising cookies is at https://business.safety.google/privacy/.

11. Children

The Service is for use by businesses and their workers. It is not directed at children, and we do not knowingly collect personal data from anyone under 18. If you believe a child has provided us with personal data, contact us and we will delete it.

12. Changes to this policy

We may update this policy. If a change materially affects how we handle personal data, we will notify account holders by email or through the Service at least 30 days before it takes effect. The date at the top shows when this policy was last revised.

13. Contact

Questions, requests or complaints about privacy: info@tedgeltd.com