LEGAL
Privacy Policy
This policy explains how ITSUA handles personal data when you use GITiempo, including its Chrome extension.
Last updated: 14 September 2026
1. Controller and contact
ITSUA is responsible for the processing described in this policy. For privacy questions or requests, emailadmin@itsua.com.
2. Information we process
- Account and profile information, including your email address, authentication identifier, name, and profile image when supplied by your sign-in provider.
- Workspace, project, task, and time-entry information, including the timers you manually start and stop. Records are available to authorized workspace members according to their roles and project access.
- GiTiempo access and refresh tokens in the extension’s
chrome.storage.local. Google and email/password sign-in also use Firebase Authentication, which stores authentication state in extension-local IndexedDB. Your email and password are submitted to Firebase for email/password sign-in; GiTiempo receives a Firebase identity token to establish its own session. - A local, token-free status flag when Firebase sign-out needs to be retried. This flag survives reopening the extension and is removed after provider cleanup succeeds.
- When you start a timer from a supported GitHub issue page, the repository name and issue number sent to GITiempo to create or start the linked time entry.
The extension may read the issue title and page address locally to recognise a supported GitHub surface and show its control. It does not send the issue title or full page address in the timer-start request. GiTiempo subsequently retrieves issue information, including its title, from GitHub to create the linked task. This integration does not monitor your general browsing history or passively record your activity.
3. How we use information
We process this information to authenticate you, maintain your session, provide time tracking and workspace features, link a timer to GitHub issue context when you choose to start one, protect the service, and meet legal obligations. We do not sell personal data or use GitHub page content for advertising.
4. Sharing and authentication services
We share information with providers that help operate GITiempo, with authorized workspace members for time tracking, or where required by law. Google and Firebase provide Google and email/password authentication. If you choose GitHub sign-in, GitHub provides identity information through the GiTiempo authentication service. GitHub also supplies repository and issue information for linked tasks. Hosting and infrastructure providers process service data to operate the website and API.
Our handling of all extension user data, including GitHub-derived data and information received from Google APIs, follows the Chrome Web Store User Data Policy and its Limited Use requirements. We use this data only to provide or improve the extension’s disclosed time-tracking purpose. We do not sell it or use or transfer it for advertising, creditworthiness assessment, or lending.
Transfers are limited to supporting that purpose, meeting legal requirements, preventing abuse, or a business transfer with your prior explicit consent. Human access is limited to your explicit consent for specific data, security needs, legal obligations, or aggregated and anonymized data for internal operations.
5. Retention and security
We retain personal data only for as long as needed to provide the service, comply with legal obligations, resolve disputes, and enforce agreements. Access is limited to people and providers who need it to operate the service. No method of transmission or storage is completely secure, so please protect your account credentials and keep your browser up to date.
6. Your choices and rights
Successful extension sign-out clears its GiTiempo session and extension-local Firebase authentication state. If provider cleanup fails, use Retry sign-out in the popup, including after reopening it. Backend session revocation is attempted but may fail when the service is unavailable. Signing out does not sign you out of the GiTiempo web apps or Google/GitHub websites.
Signing out or uninstalling the extension does not delete server-held account, workspace, or time-entry records and does not stop a running timer. To request access, correction, deletion, or a portable copy of your personal data, contact the privacy email above and describe your request. Depending on where you live, you may also have rights to restrict or object to processing and to complain to your local data-protection authority.
7. Optional landing-page analytics
When Google Analytics 4 is configured for our homepage, it loads only after you choose Allow analytics. It measures page views and clicks on the entry buttons for the user and admin apps. Page views contain the page title and a page location limited to its origin, path, and approved campaign parameters (utm_source, utm_medium, utm_campaign, utm_term, utm_content, gclid, dclid, gbraid, and wbraid). Button events contain only fixed button-location and destination-app labels. We exclude URL fragments, other query parameters, form values, and account, workspace, project, task, or repository data from these events.
Google processes these measurements and may use analytics cookies and browser or network information. Your consent choice is saved in this site’s local storage. Advertising consent remains disabled. These measurements are separate from the browser extension, which does not collect analytics, and this Privacy Policy page runs no analytics scripts.
You can decline analytics or change your choice through Analytics settings in the homepage footer when analytics is configured. Declining stops subsequent analytics events from our integration and attempts to remove accessible analytics cookies. Cookie removal is best effort; withdrawing consent does not delete information already received by Google. When analytics is not configured, the homepage emits no analytics controls or Google tag.
8. Changes to this policy
We may update this policy when our service or legal obligations change. We will publish the updated version on this page and revise the date above.