HourChit Privacy Policy

Effective: Last updated:

This policy covers three things: the hosted HourChit service (your own instance at a subdomain of hourchit.app), the HourChit iOS app, and the marketing site at hourchit.app. HourChit is operated by BPS Enterprises LLC, doing business as 1507 Systems, from Colorado, USA. "We" and "us" mean 1507 Systems. "You" means the person or business that holds a HourChit account.

Who this policy is about

There are two kinds of people whose information passes through HourChit.

You, the account holder. The business that signs in and uses HourChit to track time, log mileage, and send invoices.

Your clients. The businesses and people you enter into HourChit, and anyone who sends email to your HourChit mailbox. You are responsible for that information. Under privacy laws you are the controller (or business) for your clients' information and we are your processor (or service provider); our hosting agreement with you governs that, and the providers listed under "Who else touches your data" are our sub-processors. We hold and handle your clients' information on your instructions, to run your instance and do what you tell it to do (for example, send an invoice). We do not use it for anything else.

If you are a client of a HourChit user and have a question about your information, contact that business first. You can also contact us at the address at the end of this policy, and we will pass your request along and help them answer it.

What we hold about you

Sign-in email addresses. The email addresses allowed to sign in to your instance. These are set up with us when your instance is created and are used to send you sign-in codes and to record which address owns a session.

One-time sign-in codes. HourChit has no passwords. When you sign in we email you a six-digit code. We store a hash of the code (not the code itself), when it was created, when it expires (ten minutes), and how many times it was tried. Only three codes can be requested per address every fifteen minutes.

Session cookie. After you sign in, your browser or the iOS app holds one cookie, named hourchit_session, for up to 30 days. It contains a random token. We store a hash of that token with your sign-in address and the times it was created, expires, and, if you sign out, was revoked. This is the only cookie HourChit sets. There are no analytics or advertising cookies.

Business identity. Your business name, postal address, billing email address, and phone number. These appear on your invoices, in invoice emails, in notice letters, and in the subject line of sign-in code emails. They live in your instance's private configuration, which is kept in a private GitHub repository and built into your instance when it is deployed.

Routes. Named routes with a start address, an end address, and one-way miles. If you work from home, the start address is often your home address.

Terms and rates. Your billing increment, minimum call-out, mileage rate, hourly rates per task, the dates they took effect, and a free-text note of who agreed to them. These are kept as a history and are never overwritten.

Settings and dashboard preferences. Instance settings such as your default invoice delivery mode, plus the order and visibility of dashboard modules, keyed by your sign-in address.

Our own access. We can reach your instance to host, maintain, and support it, including through an emergency sign-in that does not use an emailed code. We use that access only to run the service or to help you when you ask.

What we hold about your clients

All of this is entered by you, or arrives by email to your instance, and is held on your instructions.

Customer records. Business name, postal address, billing email address, free-text notes, notice period, invoice delivery mode, and an optional document folder reference.

Contact people. Name, email address, title, phone number, and role (booking, accounts payable, or signatory) for individuals at your clients.

Work records. Tasks, time entries (start and stop times, an event name, and an optional charge code), and mileage trips (route, date, miles, reason, and rate).

Invoices. Invoice number, period, line items, totals, status, how and when it was sent, and the delivery status of each invoice email.

Email. Every message received at your HourChit mailbox (the billing@ and hello@ addresses on your subdomain) is kept in full: headers, sender, To and CC recipients, subject, text and HTML bodies, every attachment, and the raw message exactly as it arrived. Every message sent from those addresses through HourChit is kept as sender, recipients, subject, and plain-text body; we do not keep a second copy of the attachments we send. Anyone who writes to those addresses, and anyone copied on the message, has their message stored in your instance.

Free text. Notes, event names, terms notes, and email bodies can contain whatever you or a sender type. Treat them accordingly.

Where your data lives

Each business runs on its own isolated instance: its own Cloudflare Worker, its own Cloudflare D1 database, its own Cloudflare R2 storage bucket for raw email and attachments, its own mail subdomain, and its own delivery-event queue. Your data is never in a shared table with another business. Everything runs on Cloudflare's network. Raw email and attachments are stored in Cloudflare's Western North America region. We have not restricted your database to a particular country or region. If you are in Canada or elsewhere outside the United States, your data is stored and processed outside your country, including in the United States.

What HourChit sends by email

Sign-in codes. Sent from [email protected] to one of your allowed sign-in addresses. The email contains the code and nothing else; there is no link to click.

Invoices, on your behalf. If you turn on hosted sending for a client, HourChit emails the invoice from billing@ on your subdomain to that client's billing address, with the PDF attached. The email carries your business name and contact details and a footer saying it was sent on your behalf through HourChit. We keep the text of that email and its headers with your records. We do not keep a copy of the PDF; it is rendered fresh each time it is downloaded or sent. Hosted sending can only deliver to recipient addresses set in your instance's configuration.

Replies from your inbox. A reply you write in HourChit is sent from whichever of your addresses the original message arrived at, and stored with the thread.

Send with your mail app. If a client is set to this mode, HourChit prepares the draft and hands it to your own mail app (on iPhone, with the PDF attached; see "The iOS app" below). Nothing is sent from our servers, and HourChit only records that you marked the invoice as sent.

Delivery status. For every email HourChit sends, Cloudflare reports back whether it was delivered, deferred, bounced, rejected, failed, or reported as spam by the recipient's mail provider. We store that event, including the recipient address and the receiving server's response, so you can see whether an invoice landed. We do not use open-tracking pixels and we do not rewrite links in email.

Who else touches your data

Only the following, and only to run the service.

Cloudflare. Hosts all of HourChit. Workers run your instance; D1 holds your database; R2 holds raw email and attachments; Email Routing receives mail for your subdomain; Email Sending sends mail and reports delivery events; Queues carries those events to your instance; Browser Rendering turns invoice HTML into PDF (Cloudflare states this content is processed ephemerally and not retained); Pages serves the marketing site. Because Cloudflare's network sits in front of your instance, Cloudflare sees every request and response, including your IP address, browser details, your session cookie, and everything you submit. Cloudflare's Workers Logs keep a log of each request to your instance (the request, the response, and related metadata) for up to 7 days, and we can read those logs. Cloudflare may also ask your browser to report failed connections to Cloudflare so it can monitor its network. Cloudflare's Email Sending keeps its own list of addresses that have hard-bounced or complained. Cloudflare handles all of this on our instructions under our agreement with Cloudflare, including its data processing addendum. Cloudflare's own privacy policy covers only the data Cloudflare collects for itself, such as its network logs.

GitHub. Your instance's private configuration (business identity, allowed sign-in addresses, allowed recipient addresses for hosted sending, and your first customer and route as seeded) lives in a private GitHub repository, and your instance is built and deployed from it.

Zoho. Our back office. Support and privacy requests you send us become tickets in Zoho Desk. Mail to [email protected] is forwarded to a mailbox we operate on Zoho Mail. Zoho does not touch anything inside your instance.

Apple. Distributes the iOS app through TestFlight and the App Store. See "The iOS app" below.

Cloudflare, GitHub, and Zoho handle your data only on our instructions, under contract terms that require them to protect it to at least the standard described in this policy, and none of them may use it for its own purposes. Apple collects TestFlight and App Store data for itself under its own policies, as described below.

We do not sell your data or your clients' data, and we do not share it with anyone for advertising. Beyond the providers above, we would disclose data only if the law required us to, or to a successor that takes over running HourChit, who must keep honoring this policy for your data.

What we do not do

How long we keep it

HourChit is built as a ledger, so records are kept for as long as your instance exists. The app never physically erases records. When you archive a client, deactivate a contact, void a time or mileage entry, cancel an invoice, or sign out, the record is marked rather than removed. Used sign-in codes and expired or revoked sessions are kept as an audit trail. Emails, attachments, and delivery events have no automatic expiry.

When your account ends, or when you ask us, we delete your instance's data by hand: the database, the storage bucket, the mail subdomain, the delivery-event queue, and your private configuration, which we also remove from the repository's history. We complete deletion within 30 days of your request or the end of your account, and we confirm it by email to your sign-in address. Archives of our own source repositories may hold earlier copies of configuration or test data; we remove your data from those as part of the same deletion.

We do not run scheduled backups of your instance's database or mail. If we take a one-off export before maintenance, we delete it when the maintenance is finished. After deletion, Cloudflare's database service keeps point-in-time recovery copies for up to 30 days, and Cloudflare's request logs age out within 7 days; both expire on Cloudflare's schedule, not ours. Our own records of your hosting account, such as our agreement with you and our invoices to you, are kept as business records for as long as the law requires.

Email you send to us (support and privacy requests, or mail to [email protected]) is kept for as long as we need it to handle the matter and keep our records.

Your rights

You can ask us to show you what we hold about you, correct it, export it, or delete it. Today there is no self-serve export beyond downloading invoice PDFs and no self-serve delete button, so we handle these requests by hand. Write to [email protected] from one of your sign-in addresses so we know the request is yours. We will respond within 45 days. Deletion is completed within 30 days and confirmed by email, as described above. Deleting your account deletes your whole instance, including your clients' records and your mailbox, so take what you need from it first.

If you are in Canada, Canadian privacy law gives you the right to access and correct the personal information we hold about you and to withdraw your consent, which for HourChit means closing your account. Residents of Colorado and California may have additional rights under those states' privacy laws. Write to us and we will honor these rights where they apply. Because we do not sell data or use it for targeted advertising, there is nothing to opt out of.

If you are a client of a HourChit user, the business that entered your information is responsible for it. Send your request to them; we will help them respond, and we will not change their records without their instruction unless the law requires it.

Children

HourChit is a business tool and is not for anyone under 16. We do not knowingly collect information from anyone under 16. If you believe a child has used HourChit, contact us and we will delete the information.

Security

HourChit requires HTTPS. HTTP requests are redirected to HTTPS, and HTTP Strict Transport Security tells browsers to keep using encrypted connections. Sign-in uses one-time emailed codes with no stored password, and we store only hashes of codes and session tokens. Each business runs in its own isolated instance, and the session cookie is marked HttpOnly and Secure, so page scripts cannot read it and browsers send it only over https. If we learn of a security incident affecting your data or your clients' data, we will tell you at your sign-in address without undue delay so you can meet your own obligations to your clients.

The iOS app

The HourChit iOS app is a native shell around the same web app: a web view pinned to your instance's address. On your device it keeps your session cookie and the web view's page cache, in storage that belongs to the app. It stores no other files, no keychain items, and no device identifiers. It does not ask for location, contacts, camera, photos, or notifications. It contains no third-party SDKs, no crash reporter, and no analytics. Links that lead outside your instance are handed to iOS (mail, phone, and messages) or refused. Deleting the app removes the cookie and cache.

Sending an invoice with your mail app. For a client set to send with your mail app, the app opens the iOS mail composer with the recipient, subject, body, and invoice PDF filled in. That message is sent through the mail account on your phone, not through HourChit; HourChit does not see the message and does not learn whether you sent it. The only thing the app tells the web page about your device is that this composer is available, along with the app's version; it exposes no device identifier.

TestFlight. While the app is distributed through TestFlight, Apple collects crash logs and usage data automatically, and for testers invited by email, your name and email address. Apple states that testers cannot opt out of this collection. Apple shares with us your device model, iOS version, session and crash counts, and any feedback and screenshots you choose to send. Testers who join through a public link appear to us as anonymous. Apple says it keeps beta feedback for one year and crash and usage data until the related bugs are resolved. We use this only to fix the app, and Apple's terms prohibit us from sharing it with anyone else. Apple's TestFlight and Privacy notice governs the rest.

App Store. When the app is installed from the App Store, Apple's own privacy policy governs what Apple collects during download and use. We receive from Apple only what App Store Connect provides to developers.

The marketing site

hourchit.app is a static site on Cloudflare Pages. It sets no cookies, runs no analytics, and has no forms. Cloudflare sees your IP address and request details in order to serve the page and, as with the hosted service, may ask your browser to report failed connections. Icons are bundled with the site and served by Cloudflare; your browser does not contact an external icon service. The contact link opens your own mail app addressed to [email protected]; that mail is received by Cloudflare Email Routing and forwarded to a mailbox we operate on Zoho Mail. Links to GitHub and to 1507.systems lead to sites with their own policies.

Running your own copy

The HourChit core is open source at github.com/1507-systems/hourchit. If you run your own copy, you are its operator and this policy does not apply to it. Nothing you enter reaches us; the only request that does is your browser fetching the HourChit icon from hourchit.app, which you can change in your copy.

Changes to this policy

When we change this policy we will post the new version at the address where this policy is published, with a new effective date at the top. If a change affects how we handle your data, we will tell account holders by email at their sign-in address before it takes effect.

Contact

Privacy and data requests: [email protected]
Support: [email protected]
Help center: https://support.1507.systems/

BPS Enterprises LLC, doing business as 1507 Systems, operating from Colorado, USA.

The 1507 Systems Team