TimeQeeper

App privacy statement

How TimeQeeper B.V. handles personal data in the TimeQeeper Pocket mobile app.

Last updated: October 2026

In short

  • No tracking, no advertising, no profiling
  • No third-party analytics or crash-reporting SDKs
  • No location data, microphone, contacts or push notifications
  • Sign-in credentials encrypted on your own device
  • As little as possible on your device; your organisation's data is erased when you sign out
  • Storage within the EU

What this statement covers

This statement applies to the TimeQeeper Pocket mobile app (iOS and Android, app id com.timeqeeper.pocket). A separate privacy statement applies to the website timeqeeper.com.

TimeQeeper B.V., De Meeren 237, 4761 SJ Zevenbergen, The Netherlands. CoC 42023423. Privacy questions: info@timeqeeper.com.

Who is responsible for what

TimeQeeper Pocket is a business application. You use it with an account created for you by your employer or client, or — for My hours — with an activation code you receive from them. You cannot register yourself in the app.

For the data held in your organisation's TimeQeeper environment — such as articles, stock movements, counts, pick lists, reservations, notifications, work orders, planning, assets, clock and time entries, and photos — your organisation is the data controller. TimeQeeper acts as processor and follows the data processing agreement with that organisation.

For your account data and the technical data needed to run and secure the app, TimeQeeper is the controller.

What data the app processes

Account data: your name, email address, role and permissions, and the organisation your account belongs to. These are created and managed by your organisation's administrator.

Data you use or enter in the app: article data, stock movements, counts, pick lists, reservations and warehouse locations; maintenance notifications you raise, with the photo you attach; your work list from the plan; and photos you take or select for an article.

My hours, if your organisation uses Workforce: your clock and time entries — times, breaks, hours, kilometres, project, hour type and description — and, if the client signs on your phone, the name and signature of the person signing.

Technical data: IP address, timestamp and request type in server logs, plus operating system and app version. If you sign in with an activation code, the app on Android also passes on the device model, so the administrator can see which phone is linked to you. We use this for security, troubleshooting and delivering updates.

Activity: when you actually use the app — opening, unlocking, tapping or scanning — the app reports this to the server at most once a minute. This keeps track of when you were last active. Background processes do not count, and nothing is stored to be sent later.

Installation identifier: a randomly generated value stored locally on your device to tie your session to this device. It is not an advertising identifier and is not used to track you.

Permissions the app requests

Camera — to scan barcodes and QR codes on article labels and to take a photo of an article or for a maintenance notification. The camera is only used at the moment you scan or take a photo yourself.

Photo library — to select an existing photo for an article, a maintenance notification or a search by photo. The app only receives the photos you select, not your entire library.

Biometrics (Face ID, Touch ID or fingerprint) — optional, to unlock the app. Your biometric data stays in your device's secure hardware. The app never sees it and only receives the outcome: success or failure.

The app does not request access to your location, microphone, contacts or calendar, and does not send push notifications.

What is stored on your device

Sign-in and refresh tokens are stored encrypted in your device's secure storage (Keychain on iOS, Keystore on Android). They can only be read while your device is unlocked and are not transferred to another device.

The app fetches data from your organisation's environment live and shows it while you have the screen open. Two exceptions: article images are kept in a cache on your device so they load faster, and with My hours, clock entries and newly entered hours wait on your device if there is no connection for a moment; they are sent as soon as it returns. For everything else you need a connection; the app indicates this with a banner at the top.

Your preferences are also stored locally: your language choice, your theme setting and — if you choose to — your email address, so you don't have to type it every time.

As soon as you sign out or switch to another organisation, the session data, that organisation's data on your device and the image cache are erased. If clock or time entries are still waiting, you can only do so once they have been sent. If you delete the app, everything stored locally goes with it.

Sharing with others

We do not sell personal data, show advertising or build personal profiles.

The app contains no third-party analytics, crash-reporting or advertising software.

Data from the app goes to your organisation's TimeQeeper environment. This runs with hosting providers acting as our processors, with storage within the EU.

To deliver app updates, the app uses the update service provided by Expo (Expo, United States). The app checks whether a new version is available; in doing so Expo sees the device's IP address and technical characteristics. No data from your TimeQeeper environment is sent during this check.

The app is distributed through the App Store and Google Play. The data Apple and Google process in that context is governed by their own privacy policies.

Security

All traffic between the app and the server is encrypted over HTTPS; production builds of the app refuse an unsecured connection.

Tokens are held in the device's secure storage and can optionally be placed behind a biometric lock.

Signing in with your account always requires two-step verification. An activation code for My hours can be used once and is valid for seven days.

On the server side we use role-based access, per-module permissions and a log of changes, with storage within the EU.

How long data is kept

For data in your organisation's environment, that organisation sets the retention period, within the terms of the data processing agreement.

We keep account data for the duration of the customer relationship plus 24 months. Server logs are kept for a maximum of 24 months.

Data on your device remains until you sign out, switch organisation or delete the app.

Your rights and deleting data

You have the right of access, rectification, erasure, restriction of processing, objection and data portability.

Because your account is managed by your own organisation, requests about the data in that environment should be submitted to that organisation. We support them as processor.

If your request concerns data for which TimeQeeper is the controller, email info@timeqeeper.com. We respond within the statutory period.

If you want to remove everything from this device, you can do so straight away: sign out in the app or delete the app from your device.

You may also lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).

Children

TimeQeeper Pocket is a business application intended for use in a work environment. The app is not directed at children and we do not knowingly collect data from children.

Changes

We may update this statement, for example when the app gains new features. The current version is always on this page, with the date of the last change at the top.

A separate privacy statement applies to the website timeqeeper.com.

We use functional storage and cookieless statistics. With your consent, LinkedIn measures visits and demo requests and helps us show relevant ads. LinkedIn may link this data to your profile.

Functional storage and cookieless statistics
Always available
LinkedIn marketing
Disabled

Your choice lasts 180 days. Declining does not affect the website or your demo request. You can change your choice here at any time.

Privacy statementCookie statement