TIMEZPRO — PRIVACY POLICY

TIMEZPRO — PRIVACY POLICY

Tdevcom

Effective date: 14 May 2026

Last updated: 14 May 2026


Data protection contact — Email: tdevcom@hotmail.com


Application: TimezPro (“the App”), a mobile application for businesses and their workers or staff, and related client scheduling, bookings, storefront or catalog features, messaging helpers, media and advertising tools, and business profile management. Data handled depends on how you use the App.


---


1. Introduction


This Privacy Policy explains how information is collected, used, disclosed, and safeguarded when you use TimezPro. By using the App, you agree to this policy. If you do not agree, please do not use the App.


This policy is intended to meet common application store expectations. It does not replace any statutory rights available to you under laws that apply in your jurisdiction.


---


2. Who is responsible


TimezPro is operated by the party identified with the listing on the Apple App Store and Google Play (“we”, “us”, “our”).


Privacy inquiries: tdevcom@hotmail.com


---


3. Information we collect


We collect information only as reasonably needed to provide the App. Actual categories depend on the features you choose (for example business owner onboarding, worker sign‑in, client records, uploads, messaging helpers, scheduling, or storefront features).


3.1 Account and authentication


• Phone numbers used to create accounts, verify identity, and sign in via one‑time SMS or comparable carrier verification administered through our authentication provider (Google Firebase Authentication).

• Technical identifiers tied to authentication (for example user IDs maintained by Firebase).


We do not use these messages to market to you unless separately allowed by applicable law and, where needed, consent.


3.2 Business, worker, scheduling, booking, storefront, and operational data


Information you voluntarily enter related to operating a business, including for example names, addresses or localities, schedules, appointments, listings, catalogue or marketplace style items, purchases or orders documented in the App (where enabled), pricing or availability fields, notes, identifiers for workers/staff/clients contained in workflow screens, roles or permissions arrays for staff, advertising or carousel content descriptors, technical fields required by the product to link records across Firestore paths, timestamps, and statuses of records you create inside the workspace.


Exact fields evolve with product releases; they are scoped to legitimate business‑operations use tied to authenticated accounts unless described otherwise in storefront listings.


3.3 Media and files you provide


Photos or images captured with the camera or chosen from your library when you initiate those actions—for example profiles, logos, catalogue images, storefront images, uploads to media or advertising areas, composites or thumbnails produced by cropping or resizing features in the toolchain.


Uploaded objects may reside in Firebase cloud storage namespaces tied to Property or business identifiers (for example carousel or advertising bundles). Derived metadata (URLs, filenames, ordering, versioning) forms part of operational records visible to permitted users of the same tenant.


Aspects consistent with expo‑image‑picker and related native wrappers may temporarily copy bytes on device solely to complete uploads you authorise.


3.4 Generated or captured visuals from screens


Advertising or comparable modules may programmatically rasterise portions of UI (for export, thumbnails, carousel assembly, previews, troubleshooting captures you trigger). Pixel data originates from visuals already visible to you in-session.


3.5 Address suggestion, autocomplete, mapping assistance


Registration or editable profile flows integrate Google Places Autocomplete and Geocoding (Google Maps Platform) for address locality search, refinement, approximate biasing radii tied to locality selection or city centroid geocoding, and route display fields where shown in UI.


Texts you type plus optional coordinate seeds or locality bias selections are exchanged with Google pursuant to Maps Platform APIs. Queries may correlate with coarse location context even when continuous GPS background tracking is not required for baseline navigation between tabs.


Google processes such traffic under its Maps / Cloud terms; see also Section 8.


3.6 SMS beyond authentication


Operational messaging helpers may assemble recipient lists drawn from datasets you configured (clients, appointment targets, groups) and optionally open your handset’s SMS composer prefilled (`sms:` URLs). Sending occurs through your carrier—not by silently reading handset SMS history.


Certain batch paths may remain partially implemented; UI copies should not promise delivery until backend wiring publishes; policy still acknowledges intent to minimise extraneous handset access beyond OS composer launch.


Even when stubs exist, refrain from interpreting absence of outbound queue as carte blanche misuse; data subjects still deserve transparency regarding planned capability.


3.7 Video and audio stacks


Introductory cinematic assets or explanatory loops may stream local bundle or remote authorised media using Expo Video primitives. Supporting native capabilities may advertise microphone & audio session categories for playback routing and ducking—even if microphones are inactive.


Android manifests may expose RECORD_AUDIO, MODIFY_AUDIO_SETTINGS for libraries linked with media playback—not secret recording.


Deny unreasonable fears: microphone cannot activate without explicit capture flows you trigger (camera video with audio, unavailable without permission prompts at OS gate).


If future versions add audible capture, storefront listings will cite updated rationales prior to widening scope.


3.8 Technical diagnostics and security telemetry


Approximate timestamps, hashed device model strings, OS build level, Expo runtime channel, coarse IP as seen by edge hosts, anomaly counters (failed auth bursts), Crash artifacts optionally emitted by RN / Hermes if platform toggles unify, outbound TLS metadata, referrer style deep links resolving `timezpro://` URIs—all processed for reliability, auditing, contractual abuse prevention.


We deliberately exclude dedicated third‑party behavioural ad networks present in tracked dependencies at time of authoring; nonetheless OS vendors may classify generic networking under their umbrellas.


---


4. Uses of processing


Operational delivery, personalization for tenant scope, enforcing security posture, complying with subpoenas, safeguarding minors (age gate messaging), iterating reliability, notifying about material policy shifts, archiving evidentiary artefacts where law demands.


No sale of personal information for unsolicited cross‑context behavioural ads.


---


5. Legal bases where GDPR-like regimes intersect


Contracts, legitimate interests (balanced), consent when narrow opt‑in overlays exist (camera), legal obligation.


---


6. Service providers and subprocessors (non exhaustive)


Firebase (Auth, Firestore, Functions where deployed, Hosting where used, Remote Config incidental, Storage) under Google Workspace / GCP contracting vehicles.


Google Maps Platform (Autocomplete, Geocoding, ancillary JSON endpoints).


CDN / certificate authorities implicit to TLS stacks.


Hosting of static policy documents (your chosen host e.g., Telegraph infrastructure under Telegram—but policy text remains ours).


Processors change; material replacements posted via updated storefront metadata when feasible.


---


7. Sharing outward


Court orders; merger diligence under NDAs; processor DPAs.


---


8. International transfers & safeguards


US / EU cloud regions—Standard Contractual Clauses or equivalents when mandated.


---


9. Retention


While account economically active plus statutory backstops—tax archives, unresolved disputes, lawful preservation letters.


Deletion requests honoured except carved‑outs enumerated in Section 4 bullet on legal overrides.


Worker offboarding cascades revoke tokens but may retain bookkeeping skeleton rows masked.


---


10. Security


Industry baseline TLS (1.2+), least privilege IAM, secrets via platform vaults—not infallible but proportionate SME posture.


Notify competent authority plus affected users within regulatory windows upon qualifying breach cognition.


---


11. Your controls


Access / rectification / erasure via email channel; SSO future roadmap not guaranteed.


Operating system toggles revoke camera/storage/mic—even if revocation degrades storefront photography features.


/opt marketing absent today.


Workers may request managerial reassignment referencing internal ticketing.


---


12. Youth policy


Directed at adult business personas; no knowing collection under 13 (or jurisdictional analogue). Prompt parental routing if discovered.


---


13. Third‑party gateways


Outbound links disclaim governance.


---


14. Changes


Bump Last updated atop; push App Store Connect + Play Data safety questionnaires if divergence exceeds immaterial typography.


Continued usage post effective date signifies assent absent contrary imperative law.


---


15. Closing contact


Repeat: tdevcom@hotmail.com


—


END OF DOCUMENT

Report Page