Privacy Policy
Last updated: April 29, 2026
This Privacy Policy describes how Alex Andrews, doing business as tallytoday (“tallytoday,” “we,” “us”), collects, uses, and shares information about you when you use the tallytoday mobile app and website (the “Service”).
Who uses tallytoday
tallytoday is a business tool for contractors and crew-based businesses. The person who signs up for an account (the “Admin”) invites their workers (“Workers”) to the Service. Admins and Workers see different information, but this policy applies to both.
Information we collect
Account information. When an Admin creates a company account, we collect their name, email address, phone number, company name, and structured business address (street, unit, city/state/zip, and — when verified through address autocomplete — latitude/longitude coordinates). When an Admin invites a Worker, we collect the Worker's name, email address, and (optionally) phone number, structured home address (with the same fields), and hourly pay rate. Workers set their own password on first sign-in.
Authentication. We use a third-party authentication provider (Supabase) to store credentials. Passwords are hashed and we cannot see them.
Time and work data. We collect the information you enter into the Service: time logs (start/end times, job notes, admin-applied time adjustments), projects you create, scheduled shifts, and material purchases (vendor, amount, description, optional photo of the receipt).
Clients. Admins can store a directory of their own clients (general contractors, homeowners, property managers). For each client we collect the company name and any contact details the Admin chooses to enter (contact name, phone, email, structured address, free-text notes). This data is visible only to Admins of the company that owns the record.
Pay rates and payroll settings. Pay rates are entered by the Admin and used to calculate weekly pay totals. Admins can also enable an overtime rule (a configurable multiplier on hours past 40 in a Mon–Sun week); when enabled we record the date the rule was turned on so prior weeks keep their original calculation.
Notification preferences. We store per-user toggles controlling which in-app push notifications you receive (e.g. new shift assigned, shift updated/cancelled, new material purchase).
Location. When a Worker taps “clock in” or “clock out,” we request the device's current GPS coordinates and attach them to that time log so the Admin can verify the Worker was on-site. Admin and Worker home/business addresses are also geocoded to latitude/longitude when entered through address autocomplete, so the address can be matched to a verified location. We do not track location in the background — GPS is only read at the moment of clock-in/out, and address coordinates are recorded only at the time you save the address.
Push notification tokens. If you enable notifications, we store a device-specific push token so we can send shift reminders, schedule updates, and (for Admins) alerts when a Worker logs a new material purchase.
Weather data. The dashboard shows current weather for your jobsite location. To do this we send the Worker's most recent clock-in coordinates (or the company's saved address) to Open-Meteo, a third-party weather provider. We do not send your identity or any account information.
Device and log data. Our servers automatically log information such as your IP address and the time of each request, which we use to diagnose issues and prevent abuse.
How we use information
- To operate the Service — authenticate you, show your time logs, deliver notifications, calculate pay (including overtime when enabled), flag overlapping shifts, and generate reports for your company's Admin.
- To communicate with you about your account (password resets, invitations, service announcements).
- To improve the Service, diagnose bugs, and maintain security.
- To comply with legal obligations and enforce our Terms.
We do not sell your information. We do not use your information for targeted advertising.
How information is shared
Within your company. Admins can see time logs, schedules, projects, clients, material purchases, and profile information for every Worker in their company. That is the core purpose of the Service. Workers see only their own time logs, their own material purchases, the projects they are assigned to, and their own schedule.
Service providers. We share information with vendors who help us run the Service, including:
- Supabase (database, authentication, and file storage hosting)
- Resend (transactional email)
- Expo / Apple / Google (push notifications and app distribution)
- Vercel (web hosting)
- Open-Meteo (weather data; coordinates only, no identity)
- Photon / OpenStreetMap (address autocomplete suggestions)
These providers only process information on our behalf and are bound by confidentiality obligations.
Legal. We may disclose information if required by law, subpoena, or to protect the rights, safety, or property of tallytoday, our users, or others.
Business transfers. If we merge, are acquired, or sell assets, user information may be transferred as part of that transaction.
Data retention
We retain your information for as long as your account is active. When you delete your account (or your Admin deletes the company), we soft-delete the account and lock it from further use. You have a 30-day window during which you can sign in to confirm your identity and restore the account if it was deleted by mistake. After 30 days, personal information is anonymized or removed and the account record is permanently purged. Time-log records may be retained by your company in anonymized form for payroll and tax compliance.
Your choices and rights
Access and correction. You can view and correct your profile information in the app. Workers should contact their Admin to change profile fields they cannot edit directly (such as pay rate).
Account deletion and restore. Workers can delete their own account from the Settings tab. Admins can delete their entire company from the Settings page on the web dashboard or the admin Settings sheet on mobile. Once deletion is requested, the account is locked: data is no longer accessible through the app and the account behaves as if it were already deleted. You have a 30-day grace period during which you can sign in to confirm your identity and restore the account. After 30 days the account is permanently purged and cannot be recovered.
Location. You can deny or revoke the location permission at any time in your device settings. If you do, clock-in will still work but will not record a GPS coordinate.
Notifications. You can turn individual notification types on or off in the Settings tab, or disable all push notifications in your device settings.
California and other state rights. Residents of California and certain other U.S. states have rights to access, delete, or correct personal information. You can exercise these rights by contacting us at the address below.
Children
tallytoday is a workforce tool for adults. It is not directed to children under 16, and we do not knowingly collect information from children under 16.
Security
We use industry-standard security controls, including encryption in transit (HTTPS) and at rest. No system is perfectly secure; we cannot guarantee the absolute security of your information.
International users
tallytoday is operated from the United States. If you use the Service from outside the U.S., your information will be transferred to and processed in the U.S.
Changes to this policy
We may update this policy from time to time. If we make material changes, we will notify you by email or through the app.
Contact
Alex Andrews d/b/a tallytoday
Email: support@tallytoday.com