Privacy Policy

Updated: 23 September 2026

Introduction

This Privacy Policy explains how HourChimp LLC ("HourChimp," "we," "us," or "our") collects, uses, discloses, and protects information in connection with the HourChimp web application (the "Service"), located at hourchimp.com. This policy is designed to comply with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA), and Stripe's merchant data-handling requirements.
By using the Service, you agree to the collection and use of information as described in this policy. If you do not agree, please do not use the Service.

Who We Are

HourChimp is a B2B SaaS micro-retainer tracking platform that allows freelancers and agencies ("Users," "you") to manage client retainer hours, log time, and share transparent balance views with their own clients ("End Clients").
Data Controller: HourChimp LLC Email: info@hourchimp.com

Scope

Because of how HourChimp works, this policy addresses two distinct groups:
• Users - freelancers and agency owners who register an account, subscribe, and log data into HourChimp.
• End Clients - the clients of our Users, who may view retainer balances via a shared link but do not register an account or submit login credentials.

Information We Collect

- Account & Billing Data (Users)

Data PointPurposeRetention
EmailAccount identification, authentication (magic links), transactional communicationDuration of account + 30 days post-deletion for fraud/legal review
Profile image (optional)Personalization of the dashboard UIDuration of account
Account preferencesApplication functionality (timezone, notification settings, etc.)Duration of account
Subscription status & plan tierService delivery, billing logicDuration of account
Stripe Customer ID / Subscription IDLinking your account to your billing record in StripeDuration of account + standard financial record retention (typically 7 years, per applicable tax law)

We do not collect or store your payment card number, CVC, or full billing address on our servers. See Payment Processing.

- Authentication Data

HourChimp uses NextAuth.js (Auth.js) for authentication via email magic links and/or OAuth providers (e.g., Google). We do not create or store plaintext or hashed passwords for standard magic-link sign-in. If you authenticate via a third-party OAuth provider, we receive only the basic profile information (name, email, avatar) permitted by that provider's consent screen.

- Retainer & Client Data (User-Generated Content)

As part of using the Service, Users input operational data about their own clients, including:
• Client names or labels (as entered by the User)
• Retainer hours allocated
• Hourly rates (optional)
• Time entry descriptions
• Timestamps of logged hours

This data is entered, owned, and controlled by the User. We process this data solely as a data processor on the User's behalf to provide the Service. Retention: This data is retained for the duration of the User's active account and is deleted in accordance with Section 9 (Data Retention & Deletion) upon account closure or a verified deletion request.

- End Client Data & the Tokenized Portal

End Clients do not create accounts, register, or submit passwords. Instead, Users generate a unique, unguessable, tokenized UUID link that grants read-only access to a specific retainer balance view. We log minimal technical data (e.g., access timestamps, general request metadata) associated with the use of these links for security and abuse-prevention purposes. We do not require or knowingly collect personal identifying information directly from End Clients through this portal beyond what the User has already entered as "client labels."

- Automatically Collected Technical Data

When you use the Service, we and our infrastructure providers may automatically log:
• IP address
• Browser type and device information
• Session/authentication tokens
• Error and performance diagnostics (via Sentry)
• General usage patterns (pages visited, feature interactions)

Cookies & Local Storage

HourChimp uses a minimal, functionality-first approach to cookies and browser storage:
• Session/Authentication Cookies: NextAuth.js sets a secure, HTTP-only session cookie to keep you signed in. This is strictly necessary for the Service to function and is not used for advertising or cross-site tracking.
• No Third-Party Advertising Cookies: We do not use the Service to serve behavioral advertising, and we do not sell data to ad networks.
• Local Storage: May be used sparingly for non-sensitive UI state (e.g., collapsed sidebar preference, theme selection).

Because our cookies are limited to strictly necessary authentication functions, a cookie consent banner is generally not required under GDPR's ePrivacy guidance; however, we disclose this usage transparently here in accordance with best practice.

Third-Party Subprocessors

We rely on the following vetted infrastructure and service providers ("Subprocessors") to operate HourChimp. Each processes data strictly to the extent necessary to perform their function, under contractual data protection obligations

SubprocessorPurposeData InvolvedLocation/Compliance
VercelApplication hosting, edge/serverless compute, request routingRequest metadata, IP address, application code executionSOC 2 Type II
Neon (Postgres)Primary database - stores all application dataAll User, retainer, and client data (encrypted at rest)SOC 2 Type II
StripePayment processing, subscription billing, customer portalBilling/payment data, Customer ID (we never receive full card numbers)PCI-DSS Level 1 Certified
ResendTransactional email delivery (magic links, retainer threshold alerts)Email address, email content for transactional messagesGDPR-compliant DPA available
SentryApplication error logging and performance monitoringTechnical error logs, stack traces, limited request contextSOC 2 Type II

We do not sell, rent, or trade your personal information to third parties for their own marketing purposes.

Payment Processing (Stripe Compliance Statement)

All payment transactions are processed exclusively through Stripe Checkout and managed via the Stripe Customer Portal. HourChimp:
• Does not collect, transmit, process, or store credit card numbers, CVC codes, or full cardholder data on our servers at any point.
• Redirects Users to Stripe-hosted, PCI-DSS Level 1 compliant checkout flows for all payment entry.
• Retains only the Stripe-generated Customer ID and Subscription ID to associate a User's account with their billing state.

This architecture means HourChimp maintains a minimal PCI-DSS scope (SAQ-A eligible), as no cardholder data touches our infrastructure.

Legal Basis for Processing (GDPR)

Where GDPR applies, we process personal data under the following legal bases:
• Contractual necessity - to provide the Service you've subscribed to (Art. 6(1)(b))
• Legitimate interest - to secure the platform, prevent fraud, and improve the Service (Art. 6(1)(f))
• Legal obligation - to retain billing records as required by tax and accounting law (Art. 6(1)(c))
• Consent - where applicable, for optional communications (Art. 6(1)(a))

Your Rights

Depending on your jurisdiction (GDPR, CCPA/CPRA, or similar), you may have the right to:
• Access - request a copy of the personal data we hold about you.
• Export - request your retainer, client, and time-entry data in a portable format (CSV or PDF export), available directly within your account dashboard or by request.
• Rectification - correct inaccurate data.
• Erasure ("Right to be Forgotten") - request deletion of your account and associated data, subject to Data Retention & Deletion.
• Restriction & Objection - limit or object to certain processing activities.
• Non-Discrimination (CCPA) - we will not deny service, charge different prices, or provide a different quality of service for exercising your privacy rights.

To exercise any of these rights, contact us at support@hourchimp.com. We will respond within the timeframe required by applicable law (typically 30 days under GDPR, 45 days under CCPA).

Data Retention & Deletion

• Active Accounts: Data is retained as long as your account remains active.
• Account Deletion Requests: Upon a verified deletion request, we will permanently delete your account data, including retainer and time-entry records, from our production database within [30] days, except where retention is required by law (e.g., financial records tied to Stripe transactions, which follow standard statutory retention periods).
• Backups: Residual data may persist in encrypted backups for a limited period (up to [90] days) before being purged through our standard backup rotation cycle.

Data Security

We implement industry-standard technical and organizational measures to protect your data, including encryption in transit (TLS/HTTPS), encryption at rest (via Neon's managed Postgres infrastructure), tokenized access controls for shared client views, and secure authentication via NextAuth.js. See our full [Security Page] for details.
No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

International Data Transfers

Our subprocessors may process data in the United States or other jurisdictions outside your country of residence. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) to ensure adequate protection for cross-border transfers.

Children's Privacy

HourChimp is not directed at individuals under the age of 18. We do not knowingly collect personal information from minors. See our Terms of Service for our age eligibility requirement.

Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or an in-app notice. Continued use of the Service after changes take effect constitutes acceptance of the revised policy.

Contact Us

For any privacy-related questions, requests, or concerns:
Email: info@hourchimp.com

Product

FeaturesPricingIntegrations

© 2026 HourChimp. All rights reserved.