Privacy Policy

Last Updated: December 28, 2025

At Sheet This, we are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our workforce management platform and related services.

We comply with applicable data protection laws, including the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA). Please read this Privacy Policy carefully to understand our practices regarding your personal data.

1. Introduction

Sheet This ("we," "us," or "our") provides a workforce management and time tracking platform designed to help businesses manage employee time, attendance, and productivity. This Privacy Policy applies to all users of our Service, including administrators, employers, and employees.

By using our Service, you consent to the collection, use, and disclosure of your personal information as described in this Privacy Policy. If you do not agree with our practices, please do not use the Service.

Our Privacy Commitment

  • We never sell your personal data to third parties
  • We collect only the data necessary to provide our Service
  • We implement industry-standard security measures
  • We respect your privacy rights under GDPR and CCPA
  • We are transparent about our data practices

2. Information We Collect

We collect various types of information to provide and improve our Service. The information we collect includes:

Personal Information

Information that identifies you as an individual:

  • Name and contact information (email address, phone number)
  • Company or organization name
  • Account credentials (username, encrypted password)
  • Job title and department
  • Profile information and preferences
  • Billing and payment information (processed by third-party payment processors)

Location Data

GPS Location Information

When you use our mobile clock-in/clock-out features, we collect:

  • GPS coordinates (latitude and longitude) at the time of clock-in and clock-out
  • Location timestamps
  • Location accuracy information
  • Geofencing data (if configured by your employer)

Important: Location data is collected only during clock-in and clock-out events, not continuously throughout the day. You must explicitly grant location permissions on your device.

Usage Data

Information about how you use the Service:

  • Clock-in and clock-out times
  • Hours worked and overtime calculations
  • Device information (device type, operating system, browser type)
  • IP address and general location (city/region level)
  • Pages viewed and features accessed
  • Session duration and interaction patterns
  • Error logs and diagnostic information

Cookies and Tracking Technologies

We use cookies and similar technologies to enhance your experience:

  • Essential Cookies: Required for authentication and basic functionality
  • Analytics Cookies: Help us understand how users interact with the Service (via Vercel Analytics)
  • Preference Cookies: Remember your settings and preferences

You can control cookies through your browser settings, but disabling essential cookies may affect functionality.

3. How We Use Your Information

We use the information we collect for the following purposes:

Service Provision

  • Provide, operate, and maintain the time tracking and workforce management Service
  • Verify employee work locations using GPS data
  • Calculate hours worked, overtime, and labor costs
  • Generate reports and analytics for employers
  • Process payments and manage subscriptions

Account Management

  • Create and manage your account
  • Authenticate users and prevent unauthorized access
  • Provide customer support and respond to inquiries
  • Send important notices about your account or the Service

Communication

  • Send service-related notifications and updates
  • Respond to your questions and support requests
  • Send marketing communications (with your consent, which you may withdraw)
  • Notify you of changes to our Terms or Privacy Policy

Service Improvement

  • Analyze usage patterns to improve features and user experience
  • Develop new features and functionality
  • Conduct research and analytics
  • Monitor and improve system performance and reliability

Legal and Security

  • Comply with legal obligations and regulatory requirements
  • Detect, prevent, and address fraud, security issues, and technical problems
  • Enforce our Terms and Conditions
  • Protect the rights, property, and safety of Sheet This, our users, and the public

4. Legal Basis for Processing (GDPR)

If you are located in the European Economic Area (EEA), UK, or Switzerland, we process your personal data based on the following legal grounds:

Legal Bases:

  • Contractual Necessity: Processing is necessary to provide the Service under our Terms and Conditions (e.g., time tracking, account management)
  • Consent: You have given explicit consent for processing (e.g., GPS location tracking, marketing communications)
  • Legitimate Interests: Processing is necessary for our legitimate business interests (e.g., service improvement, fraud prevention, analytics)
  • Legal Obligations: Processing is required to comply with legal or regulatory obligations (e.g., tax laws, labor regulations)

You have the right to withdraw your consent at any time where we rely on consent as the legal basis for processing. However, this will not affect the lawfulness of processing before withdrawal.

5. How We Share Your Information

We do not sell your personal information. We share your information only in the following circumstances:

With Your Employer/Organization

If you are an employee using Sheet This, your time tracking data, location data, and work-related information are shared with your employer or organization administrators who have invited you to use the Service. This includes:

  • Clock-in/clock-out times and locations
  • Hours worked and overtime
  • Time tracking reports and analytics
  • Profile and contact information

Service Providers

We share information with third-party service providers who perform services on our behalf:

  • Cloud hosting providers (e.g., Vercel, AWS)
  • Analytics services (e.g., Vercel Analytics)
  • Payment processors (credit card information is handled directly by payment processors)
  • Email service providers
  • Customer support tools

These providers are contractually obligated to protect your data and use it only for the services they provide to us.

Legal Requirements

We may disclose your information if required to do so by law or in response to:

  • Valid legal processes (subpoenas, court orders, warrants)
  • Government or regulatory requests
  • Legal claims or disputes
  • Emergencies involving danger of death or serious physical injury

Business Transfers

If Sheet This is involved in a merger, acquisition, sale of assets, or bankruptcy, your information may be transferred to the new entity. We will notify you of any such change and provide you with choices regarding your data.

With Your Consent

We may share your information for other purposes with your explicit consent.

We Never Sell Your Data

Sheet This does not sell, rent, or trade your personal information to third parties for their marketing purposes. Your data is used solely to provide and improve our Service.

6. Data Security

We implement industry-standard security measures to protect your personal information from unauthorized access, disclosure, alteration, and destruction.

Security Measures:

  • Encryption: Data is encrypted in transit using TLS/SSL and at rest using industry-standard encryption protocols
  • Access Controls: Strict role-based access controls limit data access to authorized personnel only
  • Authentication: Secure password hashing and multi-factor authentication options
  • Security Audits: Regular security assessments and vulnerability testing
  • Monitoring: Continuous monitoring for suspicious activity and security threats
  • Employee Training: Regular security training for all team members with data access
  • Compliance: SOC 2 Type II compliance and adherence to industry best practices

While we implement robust security measures, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security, but we continuously work to protect your information.

If you believe your account has been compromised, please contact us immediately at security@sheetthis.com.

7. Data Retention

We retain your personal information for as long as necessary to provide the Service and fulfill the purposes described in this Privacy Policy.

Retention Periods:

  • Active Accounts: Data is retained while your account is active and for a reasonable period afterward to allow reactivation
  • Deleted Accounts: After account deletion, personal data is deleted or anonymized within 90 days, except where retention is required by law
  • Legal Requirements: Some data may be retained longer to comply with legal, accounting, or regulatory obligations (e.g., tax records for 7 years)
  • Backup Systems: Data may persist in backup systems for up to 90 days after deletion from active systems

Data Deletion Requests

You may request deletion of your personal data at any time by contacting us. We will respond to deletion requests within 30 days and delete data within 90 days, subject to legal retention requirements.

Before account deletion, you can export your data. Please request data export before account closure as we cannot retrieve data after it has been deleted.

8. Your Privacy Rights

Depending on your location, you have various rights regarding your personal data. We respect these rights and provide mechanisms to exercise them.

GDPR Rights (European Economic Area, UK, Switzerland):

  • Right of Access: Request a copy of the personal data we hold about you
  • Right to Rectification: Correct inaccurate or incomplete personal data
  • Right to Erasure (Right to be Forgotten): Request deletion of your personal data
  • Right to Data Portability: Receive your data in a structured, machine-readable format
  • Right to Object: Object to processing based on legitimate interests or for direct marketing
  • Right to Restrict Processing: Request limitation of how we process your data
  • Right to Withdraw Consent: Withdraw consent for processing based on consent (e.g., location tracking)
  • Right to Lodge a Complaint: File a complaint with your local data protection authority

CCPA Rights (California Residents):

  • Right to Know: Know what personal information is collected, used, shared, or sold
  • Right to Delete: Request deletion of personal information we have collected
  • Right to Opt-Out: Opt-out of the sale of personal information (we don't sell data)
  • Right to Non-Discrimination: Equal service and pricing even if you exercise your privacy rights
  • Right to Correct: Request correction of inaccurate personal information

How to Exercise Your Rights:

To exercise any of these rights, please contact us at:

  • Email: privacy@sheetthis.com
  • Use the privacy settings in your account dashboard
  • Submit a request through our support portal

We will respond to requests within 30 days and may require identity verification to protect your privacy. We do not charge fees for exercising your rights unless requests are manifestly unfounded or excessive.

9. Location Data and Employee Privacy

Given the nature of our Service, location data is a critical component. We are committed to transparent and responsible handling of GPS location information.

Important Information About Location Tracking:

  • Limited Collection: Location data is collected ONLY during clock-in and clock-out events, not continuously
  • Explicit Consent Required: You must grant location permissions on your device and consent to location tracking
  • Purpose Limitation: Location data is used solely to verify work location and cannot be used for other purposes
  • Employee Rights: Employees have the right to know when and why location is being tracked
  • Transparency: Employers must inform employees about GPS tracking before implementation

Employer Responsibilities:

Employers using Sheet This must:

  • Provide clear notice to employees about location tracking practices
  • Obtain necessary consent as required by local employment and privacy laws
  • Use location data only for legitimate business purposes (e.g., verifying work location)
  • Comply with all applicable labor and privacy regulations
  • Respect employee privacy and not misuse location data

How to Control Location Tracking:

  • Revoke location permissions in your device settings (this may limit Service functionality)
  • Disable GPS features if your employer allows alternative clock-in methods
  • Contact your employer or administrator with concerns about location tracking
  • Exercise your privacy rights to access or delete location data

We store location data securely and share it only with your employer/organization administrators. Location data is subject to the same retention and deletion policies as other personal data.

10. Third-Party Services

Our Service may integrate with or contain links to third-party services, websites, or applications. We are not responsible for the privacy practices of these third parties.

Third-Party Services We Use:

  • Vercel Analytics: Website analytics and performance monitoring - Privacy Policy
  • Payment Processors: Secure payment processing for subscriptions
  • Cloud Hosting: Infrastructure and data storage services
  • Email Services: Transactional and marketing email delivery

These third-party services may collect information as described in their own privacy policies. We encourage you to review their privacy practices.

When you click on third-party links or use third-party integrations, you leave our Service and are subject to the privacy policies of those third parties. We do not control and are not responsible for their data practices.

11. Children's Privacy

Our Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children under 18.

If you are under 18, you may not use the Service or provide any personal information to us. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at privacy@sheetthis.com.

If we learn that we have collected personal information from a child under 18, we will delete that information promptly.

12. International Data Transfers

Sheet This is based in the United States. Your personal information may be transferred to, stored, and processed in the United States or other countries where our service providers operate.

Data Protection for International Users:

If you are located outside the United States, please be aware that:

  • Data protection laws in the United States may differ from those in your country
  • Your data may be subject to U.S. government access requests under applicable laws
  • We implement appropriate safeguards to protect your data during international transfers

Transfer Mechanisms:

For transfers from the EEA, UK, or Switzerland, we rely on:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions where applicable
  • Your explicit consent for certain transfers

By using our Service, you consent to the transfer of your information to the United States and other countries as necessary to provide the Service.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.

How We Notify You of Changes:

  • Posting the updated Privacy Policy on our website with a new "Last Updated" date
  • Sending an email notification to your registered email address for material changes
  • Displaying a prominent notice within the Service

Material changes will take effect 30 days after notification. Your continued use of the Service after the effective date constitutes acceptance of the updated Privacy Policy.

We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.

14. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Sheet This - Privacy Team

Email:privacy@sheetthis.com

Data Protection Inquiries:dpo@sheetthis.com

General Support:support@sheetthis.com

Response Time: We will respond to privacy-related inquiries within 30 days.

For EU/UK Residents: You have the right to lodge a complaint with your local supervisory authority if you believe we have not adequately addressed your privacy concerns.

For questions about our Terms and Conditions, please see our Terms and Conditions page.

By using Sheet This, you acknowledge that you have read and understood this Privacy Policy and consent to the collection, use, and disclosure of your information as described herein.