This Privacy Policy explains how F The Hours ("we", "us", "our") collects, uses, stores, and shares your personal data when you use the service at fthehours.io or any related feature ("the Service"). It is written in plain English and structured to match the disclosure requirements of the UK GDPR and the Data Protection Act 2018.
Data controller: Caleb Thompson, sole trader, trading as F The Hours (the "Controller"). For the duration of the beta period the Controller is operating as a sole trader; we will update this page to reference our UK limited company once registration is finalised.
Contact: support@fthehours.io. A postal address is available on written request to that email.
1. The personal data we collect
We collect only what we need to deliver and improve the Service. Specifically:
1.1 Account data
- Name (first and last)
- Email address
- Hashed password (we never see or store your plaintext password — hashing is performed by our authentication provider, Supabase)
- Role assigned to your account within the Service
- Optional profile data you choose to add (avatar, business preferences)
1.2 Business data you enter into the Service
- Time entries, tasks, and planned tasks
- Projects, clients, and customers
- Invoices, expenses, mileage records, and home-office allowances
- Tax-related calculations and inputs you provide
1.3 Uploaded files
- Receipt, invoice, and avatar images uploaded by you, stored under a per-user path in our object storage
1.4 Payment data
- Subscription plan, billing cycle, and your Stripe customer identifier
- We never see or store your card number, CVC, or expiry — those are entered directly into Stripe-hosted elements and submitted to Stripe over an encrypted connection that we do not intercept
1.5 Technical data
- Browser type, device type, and IP address (used for rate-limiting and for delivering the right desktop or mobile experience)
- The cookies and similar storage described in our Cookie Policy
- On the public pages only, our own count of visits. It does not keep your IP address in our database; the Cookie Policy lists exactly what it stores
2. Why we collect it (lawful basis)
Under UK GDPR Article 6, each category of processing requires a lawful basis. Ours are:
- Contract (Art. 6(1)(b)) — to provide the Service you have signed up for: storing your business data, generating invoices, calculating tax estimates, and so on.
- Legitimate interests (Art. 6(1)(f)) — to keep the Service secure (rate-limiting, abuse detection, fraud prevention), to improve features by looking at how the Service is used, including the public-page visit count described in our Cookie Policy, and to communicate operational updates.
- Legal obligation (Art. 6(1)(c)) — to retain records where UK tax, accounting, or anti-fraud regulations require us to.
- Consent (Art. 6(1)(a)) — for marketing communications. You can withdraw consent at any time.
3. Who we share it with (sub-processors)
We share personal data only with the following sub-processors, each of which provides infrastructure required to run the Service and is bound by its own UK GDPR-aligned data-processing terms:
- Supabase — database, authentication, file storage, and edge function hosting. Customer data is stored in their Frankfurt, Germany region.
- Vercel — hosts the static application files and serves them from a global edge network. Your account data never passes through Vercel: every request that reads or writes it goes straight to Supabase. Like any web host, Vercel sees technical details of each request, such as your IP address.
- Stripe — payment processing. Stripe is the controller for the cardholder data; we never receive it. International transfers to Stripe entities outside the UK rely on the UK Addendum to the EU Standard Contractual Clauses.
- Microsoft — transactional email delivery via Microsoft Graph on a dedicated Business Standard tenant (from
no-reply@fthehours.ioandsupport@fthehours.io).
We do not sell your data to anyone. We do not share it with advertising networks. We do not use it to train AI models, ours or anyone else's.
4. Where it is stored
Customer data is stored in Supabase's Frankfurt, Germany region. Vercel serves the site from a worldwide network and runs our public-page visit counter, which receives visitors' IP addresses, so it also processes data outside the UK. Where a sub-processor processes data outside the UK — currently Supabase, Vercel, and also Stripe — we rely on the UK's adequacy regulations, the UK International Data Transfer Agreement (IDTA), or the UK Addendum to the EU Standard Contractual Clauses, as applicable.
5. How long we keep it
- Account and business data — for as long as your account is active.
- If you delete your account, all personal data and business records owned by your account are removed from the live database. Backup copies that exist for disaster-recovery purposes age out within 30 days.
- Rate-limiting records, which stop too many requests arriving from one place at once, are kept for 24 hours and hold no IP address.
- Records of visits to our public pages are kept for 13 months, then deleted.
- Records we are legally obliged to retain as a business — for example, the subscription invoices we issue you and payment receipts from Stripe for your F The Hours subscription — may be kept for the legally required period regardless of account deletion. This does not apply to the invoices, expenses, time entries or other business records you create using the Service: those are your data, and are deleted with the rest of your account as described above.
6. Your rights under UK GDPR
You have the right, at any time, to:
- Access the personal data we hold about you. You can export a full JSON copy yourself from Account Settings without contacting us.
- Rectify any inaccurate personal data — most of it is editable directly in the application.
- Erase your data. Account Settings has a "Delete account" action that wipes 28 owned tables and the authentication record itself in one step.
- Restrict or object to processing in certain circumstances.
- Withdraw consent at any time where we are relying on consent as our lawful basis.
- Data portability — the in-app JSON export is structured for re-import.
- Complain to us about how we have handled your personal data — see section 10 below — or lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk.
To exercise any right that cannot be self-served from Account Settings, email support@fthehours.io. We will respond within one calendar month, in line with UK GDPR Article 12.
7. Security
We protect your data with technical and organisational measures including encryption in transit (TLS), encryption at rest (provided by Supabase and Stripe at the infrastructure level), row-level security policies that scope every database query to the owning user, named-access controls on administrative dashboards, and rate-limiting on public endpoints.
A full security audit was conducted on 2 June 2026; the customer-facing summary is available on request. If you become aware of a security concern, please email support@fthehours.io. We will acknowledge receipt within one working day.
8. Personal data breach notification
If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you by email at the address held on file within the 72-hour window required by UK GDPR Article 34. The notification will describe the nature of the breach, the data affected, the likely consequences, and the steps we have taken in response.
9. Children
The Service is not directed at and not intended for use by anyone under the age of 18. We do not knowingly collect personal data from children. If you believe a child has provided personal data to the Service, please contact us and we will delete it.
10. How to complain to us
If you are unhappy with how we have handled your personal data, tell us first — most concerns can be resolved quickly. Email support@fthehours.io with "Data protection complaint" in the subject line.
We will acknowledge your complaint within 30 days of receiving it. We will look into it, make reasonable enquiries where needed, keep you updated on progress, and aim to give you a full response within three months.
You do not have to complain to us first. You can complain to the ICO at any time, as described in section 6.
11. Changes to this policy
If we make a material change to this policy we will email registered users at the address held on file and update the "Last updated" date at the top of this page. Continued use of the Service after the effective date of a change constitutes acceptance of the revised policy.