Privacy Policy
Version of September 30, 2026
This is a translation of the Russian version of the policy. If the two versions differ, the Russian version prevails.
This policy explains what data the TeamTime mobile app (the “service”) collects, why it is needed, who can see it, who receives it, how long it is kept and how to delete it. It applies to the iOS and Android apps, the web version, sign-in via Telegram, and the teamytime.com website.
1. Who processes the data
The personal data controller is ORKA Limited Liability Company (“we”, “the company”):
- registration number 333526-3301-ООО, TIN 00209202610334;
- address: Apt. 271, 199 Ankara St., Oktyabrsky District, Bishkek, Kyrgyz Republic;
- email for personal data questions: info@teamytime.com;
- phone: +996 550 250 998.
We process data under the laws of the Kyrgyz Republic (the Digital Code of the Kyrgyz Republic). For users from the Russian Federation we also comply with Federal Law No. 152-FZ “On Personal Data”.
2. What data we collect
2.1. Account
- Email and password. Your email is used to sign in and to receive verification codes. We store the password only as an irreversible hash and never know the password itself.
- Verification codes sent by email. Stored as a hash.
- Technical sign-in data: session tokens, last sign-in date, registration date.
2.2. Telegram data
If you sign in via Telegram or connect Telegram notifications, we receive from Telegram and store:
- your Telegram ID;
- your first name, last name and username in Telegram;
- a link to your Telegram profile photo;
- your Telegram interface language;
- the signed launch data package that Telegram passes on sign-in. It confirms that it was you who signed in. It is overwritten on every new sign-in.
2.3. Profile
- last name, first name and middle name;
- profile photo and cover;
- languages you hold meetings in;
- rank, about text and meeting rules;
- which meetings you hold (presentations, trainings, consultations);
- city and country (as text), time zone;
- your place in the team: your mentor (curator), your curator code, your position in the team structure.
The service does not ask for a user’s gender, date of birth or phone number.
2.4. What you create in the service
- Schedule: working hours, changes for individual days and their reason, favourite profiles.
- Events: meetings, calls, presentations, trainings and personal items. An event may have a title, time, address, map or video call link, notes, comments, participants, number of guests, meeting outcome, cancellation reason and reminder settings.
- Prospects (candidates) — people you work with in the service: name, gender, age, how they are related to you, occupation, colour type, free-form notes and hashtags. The service holds no phone numbers, emails or social media links of prospects. See section 8.
- Deals: stage, objections, needs, decision maker, probability, next contact date, comments and change history.
- Notification settings: which notifications you have turned off.
2.5. Technical data
- Device push token — the identifier used to deliver notifications to your phone.
- Notification delivery log: when and through which channel a notification was sent and whether it was delivered.
- IP address and email for brute-force protection. The email is stored as a hash for up to one hour. The IP address is stored for no more than a few minutes.
- Server logs: request time, errors, and the recipient’s email when a verification code email is sent.
2.6. Location
If you allow location access, the app sends your device coordinates to our server to determine your city and time zone. The coordinates are not saved in your profile: only the city, country and time zone are. You can turn off auto-detection in “My location” and enter the city manually.
2.7. What we do not collect
We do not use analytics, advertising identifiers, cross-app or cross-site tracking, or error-collection services. We do not accept payments and do not receive payment data. The service does not collect users’ phone numbers.
3. Why we process data and on what legal basis
| Purpose | Data | Legal basis |
|---|---|---|
| Registration, sign-in, password recovery | email, password, codes, Telegram data, tokens | performance of the contract with you (the Terms of Use) |
| Running the service: profile, schedule, booking meetings, events, prospects, deals, team | data from sections 2.3 and 2.4 | performance of the contract with you |
| In-app, push and Telegram notifications | push token, Telegram ID, notification text | performance of the contract with you |
| Detecting city and time zone | coordinates | performance of the contract with you; you can decline and enter the city manually |
| Protection against account takeover and abuse | email hash, IP address, logs | our legitimate interest in the security of the service and accounts |
| Answering requests, meeting legal obligations | email, correspondence | performance of the contract and legal obligations |
We do not make decisions that have legal effects on you based solely on automated processing. Data is not used for advertising and is not sold.
4. Who sees your data inside the service
- Your profile and free time are visible to any signed-in user: name, photo, cover, rank, about text, languages, city, time zone, curator code and your curator, as well as your free booking slots. A profile can be opened by link or found by name search. Your email, username and Telegram ID are not shown to other users.
- Your curator and curators above them in the team structure see your deals and prospects to help you work on them. You, in turn, see the deals and prospects of your team below you.
- Event participants see the event: time, place, notes and comments. If you invite a curator to hold a meeting with a prospect, the curator sees the prospect’s name and the meeting details.
- Company staff access data only for support, bug fixing and running the service, only to the extent needed for the task, and are bound by confidentiality.
Profile photos and covers open by direct link without signing in. The link contains a long random identifier, so it cannot be guessed, but anyone who has the link can open the photo. When a photo is uploaded, we remove its metadata, including the location where it was taken.
5. Who we share data with
We do not sell data and share it only with those the service cannot work without:
| Recipient | What they receive | Why | Location |
|---|---|---|---|
| Yandex Cloud | all service data | hosting and storage | Russian Federation (Moscow) |
| Postbox (Yandex Cloud) | your email and verification code | sending verification code emails | Russian Federation |
| Google LLC — Firebase Cloud Messaging | push token, notification title and text, link to an app screen | delivering push notifications on Android and iOS | USA |
| Apple Inc. — Apple Push Notification service | the same, for iPhone (via Firebase) | delivering push notifications on iOS | USA |
| Telegram | Telegram ID, notification title and text | sign-in via Telegram and bot notifications, if you connected them | outside Russia and Kyrgyzstan |
| OpenStreetMap Foundation — Nominatim | device coordinates, with no data about you | detecting the city from coordinates | United Kingdom |
| Open-Meteo | the text you typed in city search | city search | Switzerland |
A notification text may contain the name of another user or a prospect, for example in a “time to get in touch” reminder. Sending notifications through Google, Apple and Telegram is therefore a cross-border transfer of personal data, including to countries not on the list of countries with adequate protection. We make it to perform the contract with you. If you do not want push notifications, you can turn them off in your phone settings.
User and prospect data is stored on servers in the Russian Federation. For users from the Kyrgyz Republic and other countries this is a cross-border transfer based on the performance of the contract with you.
We may disclose data to public authorities only when required by law and upon a duly issued request.
6. How long we keep data
| Data | Period |
|---|---|
| Account, profile, schedule, settings | while the account exists |
| Prospects | until you delete them. Deleting a prospect also deletes their deals, meetings and history |
| Events | while the account exists. A deleted event is moved to the archive and kept there so other participants keep their meeting history |
| Deals | while the prospect exists. A deleted deal is hidden, and its history is kept |
| In-app notifications | while the account exists |
| Notification delivery log | 90 days |
| Push token | while you use the app on that device; tokens that no longer work are deleted after 30 days |
| Verification codes | deleted 1 day after they expire |
| Session tokens | deleted as soon as they expire (no later than 7 days) |
| Brute-force protection | email hash — up to 1 hour, IP address — a few minutes |
| Coordinates for city detection | not saved in the profile; in the server cache — up to 1 hour, rounded and not linked to you |
| Server logs | up to 30 days |
| Database backups | up to 30 days, then overwritten |
7. Your rights and account deletion
You can:
- find out what data about you we process and get a copy of it;
- correct your data: most of it can be changed right in the app, in your profile and settings;
- delete your account and data;
- withdraw consent where processing is based on consent;
- object to processing based on legitimate interest;
- complain to a supervisory authority: in the Kyrgyz Republic — the State Agency for Personal Data Protection, in the Russian Federation — Roskomnadzor.
How to delete your account. Email info@teamytime.com from the email linked to your account with the subject “Account deletion”. If you signed in via Telegram, include your Telegram username. We will delete the account within 30 days and let you know.
When an account is deleted:
- the profile, photos, schedule, prospects, deals, settings, push tokens and Telegram data are deleted;
- events that other users took part in stay with them, and “Deleted user” is shown instead of your name. Your personal events are deleted;
- if there are users below you in your team, their link to a curator moves to the curator above you;
- the data disappears from backups within 30 days as they are overwritten.
We answer other requests within 10 business days. We may ask you to confirm that the request came from you.
8. Prospects’ data
You add prospects yourself — people you know and do business with. Prospects do not use the service, and the company has no contact details for them.
- You decide whom and what to add and are responsible for having a basis for it, usually the person’s consent. You tell the prospect that you keep them in TeamTime and delete their data at their request.
- We process prospects’ data on your behalf and only to run the service: we store it, show it to you and to the curators above you in the team structure, and put the prospect’s name in your reminders.
- Notes about prospects must not contain information about health, religious or political views, ethnicity, sex life, criminal record or other special categories of personal data.
- A prospect can write to us at info@teamytime.com. We will forward the request to the user who added them, and if that is not possible, we will delete the data ourselves.
9. How we protect data
- Data is transmitted only over an encrypted connection (HTTPS).
- Passwords and verification codes are stored as hashes.
- Sign-in tokens are time-limited: the access token lasts 60 minutes, the refresh token 7 days.
- The number of password and code attempts is limited.
- Staff access to data is restricted and granted only for work.
No system is completely secure. If a breach affects your data, we will notify you and the authorities within the time limits set by law.
10. On-device storage and cookies
The app stores sign-in tokens, the list of favourite profiles and technical flags on your device, and your email during registration (for no more than 30 minutes). This keeps you signed in and saves you from re-entering data. Tokens are deleted when you sign out, everything else when you delete the app.
The app and the teamytime.com website do not use cookies, advertising or analytics counters.
11. Device permissions
- Location, only while the app is open — to detect your city and time zone. There is no background location.
- Camera and photos (iOS) — to take or choose a profile photo and cover.
- Notifications — to send push notifications.
- Messages from the bot (Telegram) — so the TeamTime bot can send you notifications.
You can revoke any permission in your phone or Telegram settings. The service keeps working, but without the related feature.
12. Children
The service is intended for people over 18. We do not knowingly collect children’s data. If you learn that a child has created an account, write to us and we will delete it.
13. Changes to this policy
We may update this policy, for example when new features appear in the service. The current version is always published at teamytime.com/en/privacy, and its date is shown at the top. We publish material changes at least 10 days before they take effect.