Privacy Policy
Last updated: July 2026
Overview
Cadence is a time-tracking and timesheet platform. This policy describes what information Cadence collects, how it is used, and the choices available to you. Cadence operates the service and is referred to as “Cadence,” “we,” or “us” in this document.
What we collect
- Account information — name, email address, and profile details you provide. Sign-in is via Google OAuth; we receive your Google account email and basic profile information from Google.
- Work and time data — time entries, timesheets, projects, leave requests, rates, and related metadata you log in the app.
- Payroll and documents — pay advices, contractor invoices, and uploaded documents generated or stored in your workspace.
- Banking and tax details — bank account name, account number, BSB/SWIFT, tax identifiers, and address used for invoicing. Sensitive banking fields are encrypted at rest.
- Organization data — org name, settings, memberships, invites, and audit log entries when you use or manage an organization workspace.
- Integration data — if you connect optional integrations, Cadence stores OAuth tokens (encrypted) and synced data such as Asana project names or Google Calendar events you choose to sync.
- Technical data — standard server logs, session cookies required for authentication, and usage data needed to operate and secure the service.
How we use your information
- Provide time tracking, timesheets, leave, and document features.
- Calculate earnings estimates and generate payroll documents.
- Send transactional email (e.g. document delivery) via Resend.
- Sync leave and calendar events when you connect Google Calendar.
- Enforce workspace isolation, role-based access, and audit logging.
- Maintain, secure, and improve the Cadence service.
Cadence does not sell your personal information. We do not use your data for third-party advertising.
Storage and security
Data is stored in Supabase (PostgreSQL) with row-level security scoped to your workspace. Files (timesheets, PDFs, uploads) are stored in private Supabase Storage buckets and accessed via time-limited signed URLs. Banking fields are encrypted using a server-side encryption key. OAuth tokens for integrations are encrypted at rest.
No system is perfectly secure. We apply industry-standard practices, but you should use a strong Google account and keep access credentials confidential.
Third-party services
- Supabase — database, authentication, and file storage.
- Google — OAuth sign-in and, if enabled, Google Calendar sync.
- Asana — optional project import when you connect your account.
- Resend — transactional email delivery.
- Vercel — application hosting.
Each provider processes data according to its own privacy policy and only to the extent needed to deliver the integration you enable.
Data retention and deletion
We retain your data while your account is active and as needed to provide the service, comply with legal obligations, or resolve disputes. Organization owners may remove members; superadmin and audit records may be retained for platform integrity.
To request account or data deletion, contact Cadence through the support channel listed on the Cadence website or app. We will verify your identity before processing deletion requests.
Your choices
- Update profile, rate, and banking details in your Profile settings.
- Disconnect Asana or Google Calendar integrations in Settings.
- Switch between personal and organization workspaces in the app.
- Export audit logs (where your role permits).
Changes to this policy
We may update this policy from time to time. The “Last updated” date at the top will change when we do. Continued use of Cadence after changes take effect constitutes acceptance of the revised policy.
Contact
Questions about this policy or your data may be directed to Cadence via the contact information published on the Cadence website.