Privacy Policy

Last updated August 28, 2026 - Version 2.2

This policy explains what personal data wallticker collects, why, who it reaches, and the rights you have over it. wallticker is operated by Luwall AB (org. nr 559359-5993), Sweden.

1. Data Controller

The data controller is Luwall AB, org. nr 559359-5993, Sweden. We are the controller for every wallticker account, including accounts paid for by an employer or client.

One exception. If you record a contact person on a client, that is personal data about someone who is not a wallticker user. There you are the controller - you decide what to record and why - and we store it on your instructions as your processor. The terms for that are in our Data Processing Agreement, which applies automatically to every account and forms part of the Terms of Service. We rely on you to have a lawful basis for recording those details; if such a person contacts us directly, we refer them to you rather than answer on your behalf.

We have not appointed a Data Protection Officer; we are not required to. You can reach us about any privacy matter through our Discord community, linked from our Contact page.

2. Data We Collect

We collect only what the Service needs to work:

  • Account data - your email address and, if you sign in with Google or GitHub, the identity link from that provider.
  • Profile data - your name and phone number, if you choose to enter them. These are optional and used to identify you on documents you produce, such as exports. When you change them we keep the previous values as well; see "Retention" below.
  • Your organisations - the businesses you operate as, including name, company registration and VAT number, and address. These describe a business, but a sole trader's business details can also identify a person.
  • Client records - the clients you work for: name, registration and VAT number, the VAT rate you bill them at, address, and optionally a contact person (name, email address, phone number). A contact person is information about someone other than you. For that data you are the controller and we act on your behalf - see the Data Processing Agreement.
  • Time data - entries you record (start and end times, type, optional notes), projects (including any hourly rate you set on them), tags, and planned hours. If you use the Bokio integration, we also record which entries you have placed on which draft invoice.
  • Absence data - days you mark as vacation, sick, or care of child. See "Health data" below.
  • Settings and preferences - targets, display options, export presets.
  • Account lifecycle records - deletion and reactivation events, kept until the account is erased.

With your consent, we also collect product analytics: which features are used and how often, page views, and error reports - as counts and category values keyed to a pseudonymous account identifier. Analytics never contains your entries, project or client names, notes, search text, or absence types, and it never runs unless you allowed it in the cookie banner. We do not build advertising profiles and we do not make automated decisions with legal effects about you.

3. Health Data and Your Explicit Consent

Marking a day as sick or care of child creates data concerning health, which is a special category of personal data under Article 9 GDPR.

We process it only on the basis of your explicit consent (Article 9(2)(a)). The first time you select one of these absence types, we ask for that consent separately and record when you gave it. Nothing is stored until you confirm. Marking a day as vacation does not involve health data and is never gated.

We store only the date, the type, and whether it was a full or half day. We never store a reason, a diagnosis, or any free text about it.

You can withdraw your consent at any time in Settings. Withdrawing deletes your existing sick and care-of-child records. Withdrawal does not affect the lawfulness of processing before it.

4. Connected Services: Google Calendar and Bokio

If you choose to connect a Google Calendar, we read events from your primary calendar so you can turn meetings into time entries. We request read-only access to calendar events and nothing else.

We import only the title, start time, and end time of an event. We do not store the names or email addresses of other attendees, descriptions, locations, or attachments. Because you choose which meetings to import, an imported title may mention other people; that information reaches us only through your action, and you can edit or delete it at any time (Article 14 GDPR).

Access tokens are encrypted before storage using AES-256-GCM. You can disconnect at any time, which revokes our access and deletes the stored tokens.

Google Limited Use disclosure: wallticker's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, we do not sell it, and we do not allow humans to read it except with your explicit permission, for security purposes, to comply with applicable law, or where the data is aggregated and anonymised.

If you connect Bokio, the direction is reversed: at your explicit request, wallticker creates draft invoices and customer records in the Bokio company you authorize. What is sent is exactly what you preview before confirming: project names, summed hours, your hourly rates and VAT rates, and your client's business details (name, registration and VAT number, address) - never a client's contact person, and never your notes. Nothing is sent to Bokio except on your action; nothing is published or booked by us - a draft stays a draft until you act on it in Bokio. Bokio processes what you send as your own accounting provider, under your agreement with them.

Bokio access tokens are encrypted before storage using AES-256-GCM. Disconnecting deletes our stored tokens; Bokio keeps its own record of the authorization, which you can remove in Bokio's settings, and drafts already created remain in Bokio.

6. How We Use Your Data

We use your data to authenticate you, store and display the time records you create, produce the reports and exports you request, send transactional messages such as account deletion notices, take payment for paid plans, and keep the Service secure. We do not use your data for advertising and we do not sell it.

7. Recipients and Sub-Processors

We share data only with providers that operate the Service on our behalf, under contract and on our instructions:

  • Supabase - database and authentication. Your data is stored in the European Union.
  • Vercel - application hosting and content delivery.
  • Brevo - transactional email, such as account deletion notices and confirmations of a money-back request.
  • Google - sign-in, and the Calendar API if you connect a calendar.
  • Bokio - at your direction only, if you connect it: your chosen billing data (see section 4) is sent to your own Bokio company when you create a draft invoice. Bokio is your accounting provider, not our sub-processor - it processes what you send under your agreement with Bokio.
  • GitHub - sign-in, if you use it.
  • Stripe - payment processing, applied if you buy a paid plan. Checkout is hosted by Stripe, so your card details go directly to them; we never see or store them. We keep the resulting invoice and payment identifiers so we can answer questions about your own purchases and meet our bookkeeping obligations.
  • PostHog - product analytics, only if you allowed it in the cookie banner. Hosted in the European Union. Receives feature-usage counts, page views and error reports keyed to a pseudonymous account identifier - never your entries, project or client names, notes, or absence types.

We do not sell personal data and we do not share it with advertisers or data brokers. We may disclose data where legally required.

8. International Transfers

Your account and time data are stored in the European Union. Some of our providers are based in the United States and may process data there in the course of delivering their service. Those transfers rely on the European Commission's Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework, together with technical measures such as encryption in transit and at rest.

9. Security

Access to your data is enforced at the database level: every record is bound to your account, and the database rejects any read or write of another account's data rather than relying on application code to filter it. Traffic is encrypted in transit. Google Calendar and Bokio tokens are encrypted with AES-256-GCM before being stored. No system is perfectly secure, but we design for the assumption that application code will eventually contain bugs.

10. Data Retention

We keep your data for as long as your account exists. You control most of it directly: entries, projects, tags, clients, and organisations can be deleted at any time.

Profile history. When you change your name or phone number we keep the previous value alongside the new one, so that a document you produced earlier can still be reproduced with the details it was issued under. We keep these earlier versions for the life of the account and delete them with everything else when the account is erased. We do not use them for any other purpose.

Email delivery records. Our email provider keeps a record of each message we send you, including the message itself, for six months, so that we can investigate a message that did not arrive. If you delete your account we ask for those records to be erased straight away, without waiting for that period.

When you request account deletion, the account is scheduled for erasure after a 30-day grace period, during which you can reactivate it. After that, your account record, your time data, and the deletion history itself are permanently deleted from the Service. We also revoke your Google Calendar access token and ask our email provider to erase your address from its delivery records.

What remains afterwards, and for how long. Deletion removes everything we hold about you in our own database, with one exception the law requires: purchase records for paid plans, described at the end of this section. A small amount of technical data also survives briefly in the systems our providers run for us, because it is written by their infrastructure rather than by wallticker:

  • Database backups. Our current hosting plan does not include restorable database backups, so no backup copy of your data is kept for us. If we move to a plan that does, this policy will state the retention period.
  • Authentication logs recording sign-in events. We delete these from our own database as part of the erasure; copies retained by Supabase’s logging platform expire on its own schedule.
  • Server request logs held by Vercel, which record IP addresses and requested pages, and expire on Vercel’s schedule.
  • Email delivery records at Brevo, until our erasure request finishes processing.

None of it is used for any purpose after your account is gone; it exists only because backups and logs are written automatically. We do not retain it deliberately and we cannot use it to reconstruct your account.

Accounting records for paid plans. Swedish accounting law (bokföringslagen) requires us to keep a record of each purchase - the invoice reference, amounts and VAT, including their value in Swedish kronor - for seven years after the end of the calendar year it was booked in. If you delete your account, these records are kept for that period but are immediately unlinked from you: what remains contains no name, email address or other contact details, and we cannot connect it to you afterwards. The invoice itself is also retained by our payment processor under its own legal obligations. Each record is deleted automatically when its retention period ends.

Analytics events are kept by our analytics processor for at most 12 months. Deleting your account also deletes the analytics profile and its events, and withdrawing consent stops collection and removes the analytics identifiers from your browser.

11. Cookies and Local Storage

wallticker sets strictly necessary cookies, stores some display preferences on your device, and - only with your consent - uses analytics cookies and storage from PostHog. The cookie banner asks before anything non-essential is stored, and you can change your answer at any time under Cookie settings in the footer or in your account settings. The full list is in our Cookie Policy.

12. Children

wallticker is not intended for anyone under 18 and we do not knowingly collect their data. If you believe a minor has created an account, contact us and we will delete it.

13. Your Rights

Under the GDPR you have the right to:

  • Access your data - use "Download my data" in Settings to get everything we hold in one machine-readable file.
  • Rectify inaccurate data - you can edit your records directly.
  • Erase your data - delete your account from Settings. See “Data Retention” above for what this removes and what briefly remains in our providers’ backups and logs.
  • Restrict or object to processing based on legitimate interests.
  • Data portability - the same export covers this.
  • Withdraw consent at any time, including consent for health data and for the calendar connection.

Most of these you can exercise yourself in the app, immediately. For anything else, contact us.

14. Right to Lodge a Complaint

If you believe we have handled your data unlawfully, you can complain to the Swedish Authority for Privacy Protection, Integritetsskyddsmyndigheten (IMY), Box 8114, 104 20 Stockholm, Sweden. You may also complain to the supervisory authority in your own country of residence.

15. Changes to This Policy

We may update this policy as the Service changes. The version and date at the top of this page always reflect the current version. For material changes we will give notice through the Service or by email.

16. Contact

For any question about this policy or your data, reach us through our Discord community, linked from our Contact page. Postal correspondence: Luwall AB, org. nr 559359-5993, Sweden.