Back to home

Privacy Policy

Last updated: September 18, 2026

Tempora ("Tempora", "we", "us") is a property of ByteTech OÜ, a company registered in Estonia. This Privacy Policy explains what information we collect when you or your organization ("Agency") uses Tempora, why we collect it, and the choices you have.

1. What we collect

  • Account and Agency data: name, email address, password (stored securely by our authentication provider, never in plain text), agency name, and role (owner, admin, or employee).
  • Workforce data your Agency enters: employee names, contact details, job titles, departments, shift schedules, attendance/check-in records, and certification records (type, issue date, expiry date, and any file or reference number you attach).
  • Billing data: if your Agency subscribes to a paid plan, payment processing is handled entirely by Stripe. We store only the resulting subscription status, plan, and Stripe customer/subscription identifiers — we never see or store your card details.
  • Usage and log data: basic technical logs (timestamps, IP address, browser type) generated automatically by our hosting provider for security and reliability purposes.

2. How we use it

We use this data to:

  • Provide and operate the scheduling, check-in, certification-tracking, and billing features of Tempora.
  • Send transactional emails: shift notifications, check-in reminders, certification expiry alerts, and request/approval notices.
  • Process payments and manage subscriptions through Stripe.
  • Maintain the security, integrity, and availability of the service.
  • Respond to support requests sent to us directly.

We do not sell your data, and we do not use employee data collected on behalf of an Agency for advertising purposes.

3. Legal basis (GDPR)

For users in the European Economic Area, we process personal data on the following legal bases: performance of a contract (providing the service your Agency subscribed to), legitimate interest (securing and improving the service), and, where applicable, consent (e.g. optional communications).

4. Who processes your data

We use a small number of trusted subprocessors to operate Tempora, each bound by their own data protection terms:

  • Supabase — authentication and database hosting.
  • Vercel — application hosting and infrastructure.
  • Resend — transactional email delivery.
  • Stripe — payment processing and subscription billing.
  • Cloudflare (R2) — storage of uploaded certification files, isolated per Agency.

5. Security

Access to your Agency's data is isolated at the database level so that no other Agency using Tempora can see it. Passwords are never stored in plain text, all traffic is encrypted in transit (HTTPS/TLS), and payment details are handled exclusively by Stripe's PCI-compliant infrastructure — Tempora never receives or stores raw card numbers.

6. Data retention

We retain Agency and workforce data for as long as the Agency's account remains active. If an account is closed, we delete or anonymize personal data within a reasonable period, except where we are required to retain records for legal, tax, or accounting purposes.

7. Your rights

Depending on your location, you may have the right to access, correct, export, or request deletion of your personal data, and to object to or restrict certain processing.

An employee can request deletion of their personal data directly from their Profile page; their Agency's owner or admin reviews and carries out the deletion (name, email, phone, date of birth, and any uploaded certification files are erased -- shift and certification history is kept, but anonymized, since Agencies have their own legitimate operational and compliance record-keeping needs). An Agency owner can also erase the entire Agency's account, once any active subscription has been canceled, from Settings: every teammate and employee's personal data is erased and every login revoked in the same way, and the Agency's own name is anonymized. Shift, schedule, and compliance records are kept on file, anonymized, rather than deleted outright, for the same record-keeping reasons.

For anything else, contact us using the details on our Contact page.

8. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last updated" date above.

9. Contact

Questions about this policy or your data can be sent to office@bytetech.ee, or via our Contact page.