Privacy Policy
Filed by the clock instead of by topic. Walk one day with TimeTied and see, hour by hour, exactly what personal data has come into existence, who is holding it and when it disappears.
In force from 15 August 2026 · third edition · TIMETIED LTD, Company No. NI740404
Policies are normally filed by topic, which hides the one thing people actually want to know: at what point does information about me start existing, and in whose hands. TimeTied is a product about the shape of a day, so this document borrows that shape. Read from the top and you travel through a single ordinary Thursday — the phone wakes, a plan gets built, a timer runs, a sync happens, an invoice arrives, the day closes. Every stop states the data created at that instant, why it is allowed to exist, who can see it and when it goes. The matters that belong to no particular hour — borders, security, incidents, your rights — wait at the end of the day, where they can be read in one piece.
One note on scope before the alarm goes. The hours below cover two things at once: this website, and the TimeTied apps for iPhone and Android. Where a stop belongs to the app rather than the site, its opening line says so.
Before the alarm: whose day this is
Somebody has to be answerable before any of this begins, so start there.
TIMETIED LTD builds TimeTied and settles what becomes of the personal data described here. In UK GDPR vocabulary that makes us the controller: the purposes are ours to set, the means are ours to choose, and any question about either is ours to answer. A controller cannot pass that job along, and we do not try to. The distinction matters practically — a processor may only follow the written instructions it is given and decides nothing about the purpose of the work. Every supplier named later in this policy sits on the processor side of that line, with two exceptions flagged where they arise: the app stores, which run their own payment relationship with you, and our professional advisers, who owe their own duties.
Post reaches us at the office filed against company number NI740404 at Companies House. Everything to do with personal data goes to one address — hello@gettimetied.it.com — which a director reads rather than a ticket queue, and no part of data protection here is handed to anyone outside the company.
No statutory Data Protection Officer has been appointed. Article 37 compels one where the organisation is a public authority, where watching people in a regular, systematic way at scale is the core of what it does, or where special category and criminal-offence records pass through it in volume. A planning app that shows you your own diary answers to none of those descriptions. That assessment is revisited when the product changes, and a DPO with published contact details appears in this section the moment one is required.
Most outfits handling personal data by automated means owe the ICO a yearly fee and a place on its register of fee payers; the 2018 charges regulations are where that comes from. We meet it for as long as it attaches to us, and anyone running due diligence is welcome to ask for our current entry.
Inside this policy: the website at gettimetied.it.com and the TimeTied apps for iPhone and Android. Outside it: whatever Apple or Google do with the store account you hold with them, your handset maker's backup service, and any destination you reach by following a link away from here. Those answer to their own notices. Cookie and browser-storage detail lives in our Cookie Policy; the contractual side sits in the Terms of Use.
The people whose data passes through here are: readers of this site, people who ask for email updates, anyone who writes to us, people using the apps, and the named individuals who work at our suppliers and advisers. Nobody sends us files of somebody else's customers, and no clause below is written for that situation. A shared team workspace brings its own paperwork — an Article 28 addendum, a maintained sub-processor list, advance notice of changes — and that paperwork is published with the feature rather than after it.
06:40 — the app opens and knows nobody
In the app. The alarm goes, you unlock the phone, TimeTied opens. At this precise instant no personal data about you exists anywhere in our systems, and that is a design decision rather than a coincidence of the hour: planning a day here does not require an account.
What you make goes straight into a database held in the app's own private area on the handset — the sandbox container on iOS, the private data directory on Android. No other app installed on that phone can reach into it. Neither can we, for the simple reason that nothing has been transmitted. If the handset backs itself up to iCloud or to Google's backup service, that file travels with the backup, encrypted, under Apple's or Google's terms rather than ours; whether that backup runs at all is a switch on the device.
Two things follow from keeping it local-first, and the second is a real cost rather than a boast. Nothing you write is visible to us until you deliberately turn sync on at 11:40. And if the phone is lost before you do, the plan goes with it, because there is no copy here to hand back.
06:44 — you read this website first
Perhaps the app is not installed yet and you are on this page instead. A page request cannot be anonymous — a server has to learn where to post the reply — so it is worth being precise about the small amount that creates.
Cloudflare, Inc. delivers these pages as static files from whichever edge location is nearest you and screens arriving traffic for attack patterns. They act on our written instructions as our processor. Nothing here counts your visit: no analytics product runs on this site, in any flavour — hosted, self-hosted or the sort that advertises itself as cookie-free — there is no visitor dashboard for anyone here to look at, and no page carries a measurement pixel.
Exactly one request leaves our own domain. The display and body typefaces come from Google's font service — fonts.googleapis.com for the stylesheet, fonts.gstatic.com for the files themselves. Handing a font file over means your IP address and browser string arrive at Google's servers, and that is the whole of it; the request carries no identifier from us and writes nothing to your device. Block both hostnames and every page stays perfectly readable in whatever your system reaches for instead.
A general rule, since legitimate interests recurs below: wherever we lean on it, the interest is named rather than gestured at, and a balancing exercise sits underneath. Is the processing genuinely necessary for that interest, is there a gentler route to the same result, and would your rights and reasonable expectations be run over by it. Ask about any one of those assessments and you will get the reasoning in ordinary English, and you can object under what you can require of us.
06:58 — an account, if you want one
In the app. Fifteen minutes in, you decide the plan should follow you to a second device. That needs an account, and an account is the first thing all day that puts your details on a server of ours.
Creating one produces: the email address you sign up with, a display name if you choose to set one, a stored verifier of your password rather than the password itself, the moment the account was made, and the preferences that ought to follow the person instead of the handset. The lawful basis is Article 6(1)(b), performance of a contract — you asked for an account and an account is what we are supplying. A verification message goes to the address so that a typo does not lock you out of your own data, and sign-in afterwards issues a session token to the device.
Where signing in through Apple or Google is offered, that route hands us a token and an address and nothing more. Apple's private relay option means the address may be a forwarding one that never reveals your real mailbox. That suits us entirely; a forwarding address reaches you just as well for the two or three messages we would ever send.
07:02 — how old is the person holding the phone
TimeTied is built for adults arranging adult obligations, and its age rules follow from that. Accounts are for people aged 16 or over. Below that age, consent-based processing under UK law needs the authorisation of someone holding parental responsibility, and a planning app has no business collecting it.
Nothing on this website is aimed at children, no part of it is styled to appeal to them, and the app asks nothing about a user's age beyond the age rating the store itself applies. We run no age-estimation technology, because doing so would mean collecting far more about you than the question is worth.
If we learn that an account belongs to somebody under 16, we close it and erase what is attached to it without waiting to be asked. A parent or guardian who thinks their child holds an account should write to hello@gettimetied.it.com and it gets dealt with ahead of the queue.
07:12 — the plan gets built
In the app. Coffee in hand, you lay the day out: a two-hour block for the proposal, half an hour of email, the school run, a run of your own if the afternoon holds. Each block carries a title, a start and an end, a colour, an area label, sometimes a note. Templates repeat the routine ones. Tasks waiting for a slot sit in the tray.
This is the most personal material in the product and deserves saying plainly: a day's schedule tells a reader an enormous amount about a life. Who you see, what you treat as urgent, when you are at home, what you are avoiding. It is handled accordingly.
Where you hold an account with sync switched on, the lawful basis for holding this content is Article 6(1)(b) — the contract is that we keep your plan and give it back on every device you own. Where you do not, the content never leaves the handset and we hold none of it.
Free text, and Article 9. A block title is an empty box, so nothing stops sensitive things going in one. "Physio, 3pm" says something about health. "Mosque" or "Mass" says something about religious belief. "Counselling" says a good deal. Article 9 calls these special category data and holds them to a higher bar. We do not solicit them, do not scan for them, do not index on them and do not act on them — but if you type one, it exists, and we hold it because holding your plan is precisely what you asked us to do. Anyone who would rather keep such an entry off a server can leave sync off, or title the block something only they will understand.
Nobody at TIMETIED LTD reads your content as a matter of routine. Support staff cannot open an account's blocks, no one browses user data out of curiosity, and the single exception is a specific fault you report and expressly ask us to look into — which happens with your knowledge and leaves a record. None of it trains a machine-learning model: not ours, not a supplier's, not in aggregate, not after some hand-waving about anonymisation.
07:30 — three prompts, all refusable
In the app. The app now needs to ask you for things, and it asks at the moment a feature is first reached for, never as a stack of dialogs thrown at you on day one. Every one of them can be refused, and the core of the product keeps working when they are.
The permission dialogs are the operating system asking on our behalf, and granting one is your consent under Article 6(1)(a) to the processing it enables. Consent given at 07:30 can be taken back at 07:31, from the system settings rather than from us, and the app carries on without it.
On App Tracking Transparency: iOS raises that prompt only where an app follows you across other companies' apps and websites, or hands data to a data broker. TimeTied does neither, so there is nothing for the prompt to ask and our declaration to Apple records no data used for tracking. If you never see that dialog in TimeTied, that is the reason, and it is the answer we mean to keep giving.
08:00 — the first reminder fires
In the app. Ten minutes before the first block, the phone buzzes. Almost every alert TimeTied produces is a local notification: the app asks the operating system to raise it at a stated time, the text is composed on the handset, and nothing about it travels anywhere.
A small number of messages genuinely have to originate on a server — a sync conflict needing your decision, a subscription that failed to renew. Those ride Apple Push Notification service or Firebase Cloud Messaging, because on iOS and Android no other road exists. Delivery needs a push token, which identifies an installation on a device rather than a person; we hold it against your account until the platform retires it or the account closes. What we hand to Apple or Google to carry is deliberately thin, and never the contents of a block.
Switch notifications off at system level and the whole mechanism stops, with no message reaching you by another route.
09:15 — a focus session runs
In the app. You start a timer on the proposal block. When it stops, a session record exists: which block it belonged to, when it started and finished, how long it ran, whether breaks were taken, whether it completed or was abandoned, and the note you jotted at the end if you jotted one.
These records are the raw material of the figures at 19:45. Without an account they stay on the handset and go no further. With sync on, they travel the same road as the rest of your content and live under the same rules.
11:40 — sync, and the moment data leaves the phone
In the app. Nothing you wrote this morning has moved. Turning on cross-device sync changes that, which makes it the most consequential switch in the app — so it stays off until you deliberately turn it on.
From then, blocks, tasks, templates, focus sessions, area labels and settings are copied to our servers so a second device can pick them up, keyed to your account identifier. In flight they are encrypted with current TLS; at rest they sit on encrypted storage. Where the hosting provider lets us pick a region, we pick the UK, or the EEA if that is the closest option. The provider runs infrastructure under an Article 28 written contract as our processor: instructions only, staff under confidentiality obligations, approved sub-processors, help with your rights requests, and deletion or return when the engagement ends.
Turning sync back off stops the flow. It does not by itself remove what already arrived — that takes the route described at the day you leave.
12:30 — a meeting appears beside your blocks
In the app. You connected the phone's calendar earlier, so a client call now shows up alongside what you laid out, and the 2 p.m. block you were about to create would have collided with it.
Calendar access is read-only and entirely optional. The app reads what the plan view needs to draw an event: its identifier, title, start and end, and which calendar it came from. We never write to your calendar, never create events, never move or delete one.
Other people live in a calendar, which is the part worth being careful about. An invitation carries the organiser's address and often a list of attendees. We keep as little of that as the display requires: no contact list is built out of it, nobody found there is ever emailed by us, and none of it is enriched, matched or cross-referenced against anything. Those individuals never asked us for anything, and the least we owe them is not to accumulate them.
Disconnect the calendar in the app, or revoke the permission at system level, and the cached references are cleared at the next sync. No purpose for them survives the disconnection.
14:05 — something breaks
In the app. A block refuses to resize and the app closes itself. What that produces depends on a choice you made when you set the phone up.
Crash reports reach us through the platform's own developer reporting, and only where you left that sharing enabled — "Share with App Developers" on iOS, the equivalent switch in Android's settings. A report holds a stack trace, the app version, the OS version, the device model and a timestamp. It describes a fault, not a person, and it carries none of your blocks. We keep them 90 days, long enough to chase a defect across a release cycle, then delete or aggregate them beyond identification.
The apps generate a random install identifier so that two crash reports from the same installation can be recognised as related. Reinstalling the app produces a new one. It is never joined to an advertising identifier, because we do not collect one: TimeTied reads neither the iOS advertising identifier, the IDFA, nor its Android counterpart, and neither app carries an advertising SDK, an attribution SDK or a split-testing SDK.
TimeTied carries no product analytics at all. Should they ever arrive, they will be counts of the plainest kind — a screen opened, a feature used — with no block contents attached, and the supplier will be named in the recipients table below in the same release that introduces them rather than in a later edit of this page.
15:20 — you write to us
You email hello@gettimetied.it.com about the block that would not resize. That message is now personal data too: your address, whatever you wrote, and anything attached.
Where the exchange concerns a product you hold, the basis is Article 6(1)(b); where it concerns something else — a press question, a partnership, a general query — Article 6(1)(f) carries it, the interest being that people who take the trouble to write deserve a reply. Correspondence is kept for 24 months after the last message in the thread, which covers a problem that recurs and a question about a purchase made a while ago, then deleted.
Mail for our domain runs through a provider acting as our processor, stored in the UK, or in the EEA where that is the region on offer. Two practical requests: never send us a password, since we will never ask for one and cannot use it; and remember that a screenshot of a schedule usually contains a good deal more than the bug. Anything you do send is treated as content, with the same care as the rest.
17:00 — you subscribe
In the app. The free tier has done its job and you take out a paid one. The route that purchase travels has a direct privacy consequence worth stating flatly.
Your card number, bank details, billing address and payment credentials never arrive at TIMETIED LTD. The transaction happens inside Apple's or Google's payment system, where they act as merchant of record and as independent controllers of the payment relationship, under their own privacy notices rather than this one. We could not disclose your card details if a court ordered it, because we have never held them.
What the stores pass back to us is entitlement information: a transaction identifier, which product was bought, the purchase and expiry dates, whether it is set to renew, the platform, the store-account country, and signals about refunds, cancellations or failed billing. We use it to switch on the right features, keep them consistent across your devices, answer a billing question and keep the accounts the law requires. The basis is contract for the first three of those, and legal obligation under Article 6(1)(c) for the last — the Companies Act 2006 and HMRC between them set six years, measured from the point that financial year closed, and the duty outlives your account.
Subscriptions renew until cancelled, and cancelling happens in the store rather than here: App Store → Settings → your name → Subscriptions, or Play Store → profile → Payments & subscriptions, with a full day still in hand before the period ends. Deleting the app cancels nothing. Refunds are Apple's or Google's to give under their policies; we will help you ask. Your rights under the Consumer Rights Act 2015 and the Consumer Contracts Regulations 2013 stand regardless, and the Terms of Use set them out.
19:45 — the day gets reviewed
In the app. The evening summary appears: your plan against the hours you truly spent, totals by area, the focus figure, a streak if you have one going.
Every figure there is arithmetic performed on what you entered. A calculation shown to you is not a decision made about you. Nothing in TimeTied produces a legal effect or anything close to one: no score attaches to you, nothing ranks you against other users, no eligibility for anything is determined, and no figure is shared with a soul. That is the substance of Article 22, which hands you a right against being subjected to purely automated decisions carrying legal or comparably serious consequences — a right that has nothing to bite on here, and which stays available if that ever stops being true.
The one automated judgement anywhere in the picture happens at the network layer, where traffic that behaves like a script may be challenged before a page is served. It assesses the request rather than the requester, and a human is reachable at hello@gettimetied.it.com whenever it gets someone wrong.
22:30 — lights out: the full inventory
The day is done. Everything created along the way is listed below with the date it stops existing. Where a period comes from law we name the law; where it is our judgement we give the reason.
When a period runs out the record is deleted, or stripped until nothing in it can point back to a person. Figures that have genuinely become anonymous may stay indefinitely, the material having ceased to be personal data with nobody left inside it to protect.
Quiet hours: who else has touched any of it
While you slept, a handful of organisations held some part of the day. Every one of them is listed here, with the role it plays.
A demand from an authority gets checked before it gets answered: we look at whether the request is valid, whether the body making it has power to make it, and whether its scope is narrower than what was asked for. Where we are lawfully able to tell you about it, we will.
We do not sell personal data. Not in the everyday meaning of the phrase, and not in the wider sense some overseas privacy statutes give the word. No advertising network, data broker, enrichment service or list vendor receives anything from us, and none ever will while the table above is accurate.
Quiet hours: when data crosses a border
Some of those organisations operate outside the United Kingdom. Chapter V of the UK GDPR demands an appropriate safeguard whenever personal data leaves it, and which safeguard applies depends on where it is going.
Ask which of these covers a particular supplier and you will be told. Where an IDTA or the Addendum is the answer, we will send a copy with the commercial terms blanked out.
Quiet hours: what keeps it safe
Security has to be appropriate to the risk, which is the standard Article 32 sets. What follows is what is actually in place, rather than a wish list.
- In transit. Every connection to this website and to the sync backend runs over current TLS, with HTTP requests redirected to HTTPS rather than merely offered it.
- At rest. Server-side content sits on encrypted storage. Passwords are never stored in a readable form — a slow, salted hash is kept instead, so a stolen database does not hand over anybody's password.
- Access. Administrative accounts are individually named rather than shared, carry multi-factor authentication, and are granted the narrowest permissions that let the work happen. Access is removed the day somebody stops needing it.
- Keys and secrets. Credentials live in a secret store rather than inside source code, and get rotated whenever somebody with access moves on.
- Separation. Development and testing run against synthetic data. Real user content is not copied into a test environment to reproduce a bug.
- Patching. Dependencies are monitored for known vulnerabilities and updated on a schedule, with anything critical taken out of turn.
- Backups. Encrypted, rotated, and restore-tested — because a backup that has never been restored is a hope rather than a control.
- People. Everyone with access is bound by confidentiality, briefed on handling personal data, and expected to raise a suspected incident immediately, with no penalty attached to a false alarm.
- Suppliers. Anyone touching personal data is assessed before engagement and bound by an Article 28 contract; nobody is added on a handshake.
Found a flaw? Write to hello@gettimetied.it.com. Anyone who reports a flaw honestly, leaves us a reasonable run at fixing it before going public, and neither takes nor breaks anything on the way has nothing to fear from us.
03:00 — the hour something goes wrong
A personal data breach means a security failure that wrecks personal data, mislays it, alters it, exposes it, or lets somebody at it who had no business being there. Incidents rarely announce themselves at a convenient hour, so the procedure runs regardless of the clock.
- Detect and raise. Anyone who suspects an incident tells a director at once. Nobody waits for certainty first, and nobody is penalised for raising something that turns out to be nothing.
- Contain. Stop the spread before anything else: revoke credentials, isolate the affected system, rotate keys.
- Assess and record. We write down what happened, which categories of data and roughly how many people and records were caught, the likely consequences and what was done — for every incident, notifiable or not, as Article 33(5) demands.
- Tell the ICO. Where the breach is likely to risk people's rights and freedoms, the Information Commissioner's Office is notified without undue delay and inside 72 hours of us becoming aware. If the full picture is not assembled by then, we notify inside the window anyway and complete it in stages afterwards.
- Tell you. Where the risk to your rights and freedoms looks high, you hear from us directly and without undue delay, in plain words: what happened, which of your data was in it, what we are doing, and what you should do at your end. Where reaching everyone individually is genuinely disproportionate, we make a public announcement that gets the same information across.
- Suppliers. Every processor contract obliges them to tell us without undue delay once they become aware, so that our own clock can start on time.
- Afterwards. Each incident is reviewed for the change that would have prevented it, and that change is actually made rather than minuted.
Because we are the controller throughout, the duty to tell you is ours. It is not passed to a supplier, and it does not wait for the last detail to be nailed down — an incomplete notification inside the deadline beats a tidy one after it.
The day you leave
At some point you stop using TimeTied, and the whole of the above should stop existing. Two routes lead there.
In the app: Settings → Account → Delete account. You confirm, you re-authenticate, and the account is marked for deletion straight away; you are signed out on every device and sync stops. Both stores require an in-app deletion route, and we would provide one regardless.
By email: write to hello@gettimetied.it.com from the address the account uses, saying you want it deleted. Writing from that address is normally all the identity checking needed.
Then: the server-side copy of your content and account is erased within 30 days, and rolls out of encrypted backups within a further 30 as those backups cycle. Anything held on your own handset goes when you delete the app — deleting an account cannot reach into a device we have no sight of, so uninstalling is the step that finishes the job there.
A short list survives deletion, each item for a stated reason: accounting and transaction records, held six years from the end of the financial year (17:00); a minimal suppression record if you opted out of mail, being your address and the fact that you opted out, kept precisely so we do not contact you again by accident; the record of your deletion request itself, so we can show it was honoured; incident records under Article 33(5); and anything genuinely caught up in a live legal claim. Nothing on that list is used for any other purpose.
Taking your data with you. Ask and you get your content in a structured, commonly used, machine-readable file — the portability right at Article 20, done as a working export rather than a formality. Ask before you delete, since the export cannot be produced from data that no longer exists.
Any hour: what the store listings declare
Both stores make developers publish a structured summary of what an app collects, and both are checked against this policy before every release.
- Apple's App Store privacy label. Our listing declares the categories described above — contact information, meaning your email address; user content, meaning your plan; identifiers, meaning our install identifier and not an advertising one; diagnostics; and purchases — each marked as linked or not linked to you as the case may be. It declares no data used for tracking, which is the same statement made at 07:30 about the App Tracking Transparency prompt.
- Google Play's Data Safety section. The Play listing mirrors those categories, confirms that everything travels encrypted, confirms that erasure can be asked for, and points at this page and at the deletion route at the day you leave.
- Keeping the three in step. When what the app collects changes, the two store declarations and this policy are updated in the same release cycle. They are meant to describe one reality; if you ever spot daylight between them, tell us and the discrepancy gets fixed.
Any hour: what you can require of us
These rights belong to you at every hour of the day described above. Using one costs nothing and never worsens the service you get.
- See it (Article 15). Ask whether we hold anything about you and get a copy, together with why we have it, who else has seen it, how long it stays and where it came from.
- Correct it (Article 16). Have wrong details put right and gaps filled. Most of what we hold is editable by you in the app; tell us about anything that is not, and the correction travels on to anyone we passed it to, unless that turns out impossible or absurdly disproportionate.
- Erase it (Article 17). Have it deleted where we no longer need it, where consent was the basis and you have withdrawn it, or where we should not have had it. The route and the exceptions are at the day you leave.
- Freeze it (Article 18). Have us stop using data while a dispute about its accuracy or our grounds is worked out. We store it and leave it alone until the question is settled.
- Move it (Article 20). Receive the data you gave us in a structured, commonly used, machine-readable form, and have it sent straight to another provider where that is technically feasible.
- Object (Article 21). Object to anything resting on legitimate interests and we stop, unless our grounds are compelling enough to outweigh yours. Object to direct marketing and we stop full stop, with no balancing to be done.
- Withdraw consent (Article 7(3)). Wherever consent is what permits something — email updates, calendar access, notifications — take it back as easily as you gave it. Earlier processing does not become unlawful, and anything resting on another basis carries on.
- Not be decided about by machine (Article 22). As explained at 19:45, there is no such decision here for the right to bite on, and it remains available if that changes.
Asking. Email hello@gettimetied.it.com and say which right you want and what you are after; a narrower question usually produces a faster and more useful answer. There is no form to complete, no particular wording to use, and no need to cite the legislation for a request to count.
Checking it is you. Before anything is disclosed or deleted we have to be satisfied we are dealing with the right person, since handing your schedule to an impostor would be the worse failure. Writing from the address linked to your account normally settles it. Where we cannot match a request to an account we may ask for a little more, we ask for as little as settles it, identity documents are not demanded as a matter of course, and the response clock starts once that much is in hand.
Timing. We answer a valid request inside one month. Knotty requests, and batches of several landing at once, can stretch that by two further months at most; take an extension and we tell you inside the first month, with the reason for it.
When we might say no. Asking costs nothing. Only a manifestly unfounded or excessive request — the same one repeated without new grounds, typically — can attract a reasonable administrative charge or be turned away outright. Material may also be held back where an exemption in the Data Protection Act 2018 bites, or where letting it go would trample somebody else's rights; you still receive everything releasable, together with an account of what stayed behind and why. Say no and we give you the reasoning, plus the routes below.
Somebody asking for you. A solicitor, relative or friend can make a request on your behalf with reasonable evidence of their authority, such as a signed authority or a power of attorney. The answer normally goes to you rather than to them, unless you tell us otherwise.
If we get it wrong: the ICO
Start with us, at hello@gettimetied.it.com. A complaint that lands here can usually be fixed here, and faster than anywhere else. You are not obliged to come to us first, though, and you can go to the UK's supervisory authority at any point.
Complaining to the ICO carries no charge, and it does not close off your separate right to a remedy through the courts.
Email updates, and other mail
Our marketing amounts to a single mailing list, and it only exists because you asked to be on it.
- TimeTied updates by email. Ask for them and an occasional note arrives: what the app does that it did not do before, and the odd idea about running a day in blocks. It rests on your consent under Article 6(1)(a), plus Regulation 22 of PECR, the 2003 rules covering electronic marketing.
- Service messages are a different thing. A security notice, a change to the terms, a failed payment — those get sent because they must be, and while you hold an account you cannot opt out of them, though you can of course close the account.
- Nothing is measured. Our email carries no tracking pixel, so whether you opened it is not something we know.
- Nothing is shared. The list is never rented, sold or handed to anyone, and no marketing is ever pushed to your phone as a notification.
- Leaving. Use the unsubscribe link, send back a reply saying so, or write to hello@gettimetied.it.com. Opt-outs are actioned promptly, and the minimal suppression record described at the day you leave exists so that the promise holds.
When this policy changes
This page changes when the product does, when a supplier changes, or when the law moves. Every edition carries its effective date and version at the top.
- Small changes — a clearer sentence, a corrected menu path — take effect on publication.
- Substantive changes — a new category of data, a new purpose, a new class of recipient, a retention period that moves against you — are announced before they take effect, by notice on this website and, where we can reach you, in the app or by email to account holders. Where a change genuinely requires consent, we come and ask; assuming it is not on the table.
- Earlier editions. Want to see the version that applied when you signed up? Ask and we will send it.
Version 3.0, effective 15 August 2026. This edition restructures the policy around the day it describes and expands the inventory, the recipient list and the transfer safeguards. It replaces the edition dated 5 August 2026.
Reaching a person
- Email: hello@gettimetied.it.com — privacy questions, rights requests, complaints and security reports all arrive at the same place.
- Help pages: the support page covers the questions that come up most often.
- Post: the registered office recorded against company number NI740404 at Companies House.
Putting the word "privacy" in the subject line genuinely helps — it routes the message to the right person on the first hop and starts the clock on the correct day.