Privacy Policy
Last updated 29 July 2026
1. Who we are
TimeIt is a family scheduling service for parents, guardians, tutors and coaches, operated from India at timeit.co.in. In this policy, “we” and “TimeIt” mean [insert registered legal entity name and CIN before launch], the company that operates the service and is the data fiduciary for the personal data described here.
TimeIt is currently a preview build. Parts of the backend described in this policy are not yet connected, so some data types listed below are not yet being collected at all. This policy describes the service as it is designed to work at launch.
2. What we collect, and why
When you create an account
Sign-in is by mobile number and a one-time SMS code. There is no password, no email login and no social login. We collect:
- Your mobile number. It is your account identifier and the only way we can send you a login code. Without it there is no account.
- Your name. So that other people in your family and your tutors know who they are talking to.
- Your role — parent, guardian, tutor or child — because it decides what you are allowed to see.
- One-time codes and their delivery status. Used to log you in and to spot abuse of the login system.
About your children
A child’s record is created by a parent or guardian, from the parent’s own account. A child does not sign themselves up and cannot create a record. We collect, because a parent enters it:
- Name and date of birth. The date of birth drives age-appropriate defaults and lets you separate two children with the same name.
- School and grade. To structure the term calendar and school-hours blocks.
- Medical notes, if you choose to add them. This field is optional and blank by default. It exists so that an allergy or a condition can reach the adult supervising an activity. It is sensitive information; add only what a tutor or coach genuinely needs to know, and see section 4 for who can read it.
Schedules and activities
Activity names, categories, times, recurrence, venues and any notes you attach. This is the core of the product; without it there is nothing to show you.
Tutors and sessions
- Tutor name and mobile number, so you can reach them and so they can log in.
- Hourly rate and travel allowance, so that hours can be turned into an invoice.
- Check-in and check-out records — the time each session started and ended, who approved it, and the duration. These are the basis of what you are billed, so they are kept as long as the invoice they support.
Payments
We record what was invoiced, what was paid and when. We do not hold your card number, CVV or UPI credentials. Card and UPI details are entered with our payment processor and stay with them. If you pay a tutor in cash or directly, we hold only the amount you mark as paid.
Technical data
Device type, browser, app version, IP address and error logs. We use these to keep the service running, to fix crashes and to detect abuse. We do not use them to build an advertising profile of you.
3. Location: exactly when, and only then
Location is the most sensitive thing in this product, so its scope is deliberately narrow. TimeIt records location in two situations, both tied to a tutor:
- At check-in and check-out. A single point is recorded at the moment a tutor taps to start or end a session, so that a parent can see the session happened where it was meant to.
- Along a travel route, while travel is running. A tutor must explicitly tap to start travel. While that is on, position is recorded periodically so a parent can see an arrival time. It stops when the tutor ends travel or checks in.
There is no continuous background tracking. We do not record where a tutor is between sessions, on their days off, or after they have checked out. We do not record parents’ or children’s locations at all.
Location points from check-ins are kept for 90 days and route points for 30 days, after which they are deleted. Your device can refuse location permission; a tutor who does so can still check in, and the session is simply recorded without a location.
4. Who can see what
Visibility is set per person by the parent who owns the family account, not by us and not by a blanket default.
- Parents and guardians see everything in their own family: all children, all schedules, all sessions, rates, invoices and location records.
- A tutor sees only the children assigned to them, and only the sessions they teach. They cannot see your other children’s schedules, your other tutors, your invoices, your rates with anyone else, or any information about another family. A tutor sees a child’s medical notes only if the parent has granted that permission for that tutor.
- A child, where a parent has given them access, sees their own activities only. Children cannot see rates, invoices or anyone’s location.
- TimeIt staff access family data only when it is needed to fix a fault you have reported, to comply with the law, or to investigate abuse. Such access is logged.
We do not sell personal data. We do not share it with advertisers, data brokers or other families. We do not use your children’s data to train machine-learning models.
5. Third parties who process data for us
We use a small number of service providers. Each receives only what it needs to do its job, is bound by contract to process it only on our instructions, and may not use it for its own purposes.
- Supabase
- Database, authentication and hosting. Holds all account, family, child, schedule, attendance and invoice data.
- Twilio
- SMS delivery. Receives your mobile number and the message text, including one-time login codes.
- Payment processor
- Card and UPI processing. Receives your name, contact details and the amount. We never see or store your card number.
- Speech provider
- Only if you use the voice assistant. Receives the audio you record and returns text.
Some of these providers operate infrastructure outside India. Where data is transferred abroad we do so under contractual protections and in line with the restrictions in force under the Digital Personal Data Protection Act, 2023. [Confirm the hosting region and the current list of restricted countries with counsel before launch.]
6. How long we keep things
- Account and family records
- Kept while the account is open. Deleted within 30 days of a deletion request.
- Child profiles
- Same as the account. Deleted with the family record.
- Attendance and session logs
- 7 years, because they support invoices that are tax records.
- Invoices and payment records
- 7 years, as required for Indian tax and audit purposes.
- Check-in and check-out location points
- 90 days, then permanently deleted.
- Travel route points
- 30 days, then permanently deleted.
- Voice assistant audio
- Not stored by us after the request is answered. Transcripts, 30 days.
- SMS delivery logs
- 12 months, for fraud and delivery troubleshooting.
- Backups
- Deleted data persists in encrypted backups for up to 35 days, then rolls off.
Financial and attendance records are the one category we cannot delete on request while they are still live: they evidence what was billed and paid, and Indian tax law requires them to be retained. After the period above they are deleted or irreversibly anonymised.
7. Your rights
Under the Digital Personal Data Protection Act, 2023 you can ask us to:
- Access the personal data we hold about you and your children, and a summary of how it is processed.
- Correct anything inaccurate, and complete anything that is missing.
- Export your family data in a machine-readable format (CSV).
- Delete your data. See the data deletion page for what is removed, what is retained, and how long it takes.
- Withdraw consent at any time — for example, for location capture or for the voice assistant. Withdrawing consent stops future processing; it does not undo processing that already happened lawfully, and some features stop working without it.
- Nominate another person to exercise these rights on your behalf if you die or become incapacitated.
- Complain to us, and then to the Data Protection Board of India if we have not resolved it.
To exercise any of these, email privacy@timeit.co.in from the account you want to act on, or write from any address and tell us the mobile number on the account. We will verify that the request is really from you before acting on it, and respond within 30 days.
8. Children and guardianship under the DPDP Act
In India, anyone under 18 is a child for data protection purposes. The Act requires verifiable consent from the child’s parent or lawful guardian before their personal data is processed.
TimeIt is built on that basis. A child’s record exists only because a parent or guardian created it from their own verified account, and that adult is the one giving consent. A child cannot register, cannot add themselves to a family, and can only reach the app through access a parent grants and can revoke.
We do not use children’s data for behavioural monitoring or for targeted advertising, and we do not advertise to children at all. If you believe a child’s record was created without the consent of their parent or lawful guardian, email privacy@timeit.co.in and we will remove it.
9. Security
Data is encrypted in transit and at rest. Access is restricted by role inside the product and by row-level rules in the database, so one family’s records are not reachable from another family’s session. Staff access is limited to those who need it and is logged.
No system is perfect. If a breach occurs that is likely to affect you, we will notify you and the Data Protection Board of India as the Act requires.
10. Changes to this policy
If we change this policy we will update the date at the top. For changes that materially affect your rights or widen what we collect, we will notify you in the app and by SMS before the change takes effect.
11. Contact
Privacy questions, requests and complaints: privacy@timeit.co.in
Everything else: support@timeit.co.in
[Insert the registered office address, and the name and contact details of the Data Protection Officer or the designated grievance officer, before launch. The DPDP Act requires a named point of contact.]