ClockDocCreate an account

Privacy

Last updated 27 September 2026

ClockDoc is operated by Grasp d.o.o. in Slovenia. This page explains what the service collects, why it holds it, and what you can do about it. It is written to be read rather than to be survived.

The short version: ClockDoc holds the account details you give it and the work you record in it. There is no analytics, no advertising, and no third-party tracking of any kind — the application loads no tracking scripts and builds no profile of you.

What is collected

Your account

  • Name and email address.
  • A password, stored only as a salted hash. It cannot be read back, including by us.
  • If you sign in with Google or Microsoft, the account identifier, email address and name that provider returns, and your profile picture where it provides one. No password is created and none is stored. Signing in with Google covers exactly what Google sends.
  • Your display preferences, such as date and duration formats and your theme.

The work you record

  • Time entries: dates, durations, descriptions and the project or task they belong to.
  • Projects, tasks, clients, teams, rates, budgets and tags.
  • Invoices, quotes and expenses, including the billing details you enter for a client.
  • An audit record of significant changes, so an organisation can see who changed what.

Technical records

  • Server logs containing IP address, timestamp and the request made. These exist to keep the service running and to investigate abuse.
  • Refresh tokens tied to your sessions, so signing out of one device does not sign you out of the others.

Cookies and local storage

ClockDoc sets no advertising or analytics cookies. What it does set:

NamePurposeLifetime
clockdoc_rt Keeps you signed in. Marked HttpOnly, Secure and SameSite=Lax, so browser scripts cannot read it and it is not sent on cross-site requests. Strictly necessary. Until it expires or you sign out
clockdoc_external_auth Set only while you sign in with Google or Microsoft, to carry that provider's answer back to ClockDoc. Encrypted, HttpOnly. Strictly necessary. Until you close the browser
clockdoc_desktopRemembers that you asked for the desktop layout on a small screen.Until cleared

A few preferences — your theme and which timesheet view you last used — are kept in your browser's local storage. They never leave your device and are not readable by us.

Why it is held

Account and work data is processed to provide the service you asked for — the contract between you and us. Technical records are processed on the basis of legitimate interest in keeping the service available and secure. Where we ask for consent, such as for a non-essential email, you can withdraw it at any time.

Who else sees it

Your data is not sold, rented, or shared for advertising. It reaches other parties only in these cases:

  • Other people in your organisation. ClockDoc is a shared tool; managers and administrators can see the time and projects of the people they manage.
  • Email delivery. Transactional email — invitations, password resets, notifications — is sent through an email provider on our behalf.
  • Integrations you switch on. If you connect an accounting integration, the data needed for that integration is sent to it. Turning it off stops that.
  • The law. If we are legally required to disclose something, we will.

Signing in with Google

"Sign in with Google" asks Google for your basic profile and nothing more — the openid, email and profile permissions. From that, ClockDoc receives:

  • Your Google account identifier, to recognise you the next time you sign in.
  • Your email address and whether Google has verified it. The address becomes your ClockDoc login; an unverified one is never linked to an existing account.
  • Your name and a link to your profile picture, to fill in your ClockDoc profile.

That is used only to sign you in and to show who you are to the people in your organisation. It is not sold, not used for advertising, and not shared beyond what is described above. ClockDoc has no access to your Gmail, Drive, Contacts, Calendar or any other Google service, and never uses the token Google issues at sign-in to call Google on your behalf.

ClockDoc's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

To stop Google sharing this with ClockDoc, remove ClockDoc from the third-party connections in your Google account. That does not delete your ClockDoc account — see Your rights for that.

Where it is held

ClockDoc's servers and database are hosted in the European Union. Data is not transferred outside the EU except where an integration you have switched on requires it.

How long it is kept

  • Account and work data: for as long as your organisation has an account.
  • Deleted organisations: purged from the database on a scheduled job after deletion, not merely hidden.
  • Expired refresh tokens: removed automatically by a cleanup job.
  • Server logs: kept only as long as they are useful for operations and security.

Your rights

Under the GDPR you can ask for a copy of your data, correct it, have it deleted, restrict or object to how it is processed, and receive it in a portable form. Two of those you do not need to ask for:

  • Access and portability. Time, reports and invoices export to CSV, Excel and PDF from inside the app, whenever you want, without contacting anyone.
  • Correction. Account and work data is editable in the app.

For anything else, including deletion of an entire organisation, write to [email protected]. You also have the right to complain to the Slovenian Information Commissioner.

Children

ClockDoc is a tool for workplaces and is not intended for anyone under 16. We do not knowingly collect their data.

Changes

If this page changes in a way that affects you, the date at the top changes and we will say so in the app. Continuing to use ClockDoc after a change means the new version applies.

Contact

Grasp d.o.o., Slovenia — [email protected].

HomeWhat's newPrivacyTermsSecurityContact

© 2026 Grasp