Chrontic

Privacy Policy

Chrontic Web Application & Browser Extension

Last Updated: July 26, 2026

Overview

Chrontic is a time tracking app for companies to manage employee time, projects, and leave. This policy covers the Chrontic web app (chrontic.com) in Part 1, and our optional Chrome Extension & JetBrains plugin in Part 2 — those only activate once installed and configured with an API key, never just from visiting a page.

For most users, your employer is the data controller and Chrontic is the data processor. Please direct data requests to your employer first; we help them fulfill it. You can also reach us at support@chrontic.com.

Part 1 · Web Application

What We Collect

  • Account: name, email, bcrypt-hashed password, profile picture (if you sign in with Google)
  • Employment data: an employee ID, plus optional fields your employer may fill in such as cost center, payroll code, hire date, or salary/hourly rate
  • Time & leave data: time entries, leave requests and balances, organizational unit, job title
  • Billing (company admins only): billing email/name shared with Stripe; we never see card numbers
  • Optional integrations: if you or your admin connect Jira, Outlook, or Tempo, we read/write ticket info, calendar events, or worklogs from that service

Cookies, Security & Hosting

  • No session cookies — sign-in uses a token stored in your browser's local storage
  • Analytics (Google Analytics) sets cookies only if you accept our cookie banner. If you decline, we still receive an anonymous, cookieless measurement ping that stores nothing on your device and cannot identify you; change your choice anytime via "Cookie Settings" in the footer
  • All traffic is encrypted (HTTPS); servers are hosted in Germany, within the EU

Who We Share Data With

Stripe (billing), Google (sign-in and analytics), and Atlassian/Microsoft/Tempo (only if you connect those integrations). We don't sell your data or share it with advertisers. Some providers may process data outside the EU/EEA under their own safeguards. See our Subprocessors page for the full list.

Legal Basis for Processing

  • Employee time tracking & employment data: Art. 6(1)(b) GDPR — performance of the contract between your employer and Chrontic
  • Billing data: Art. 6(1)(b) GDPR — performance of the contract
  • Analytics cookies (only if accepted): Art. 6(1)(a) GDPR — consent, which you can withdraw anytime via "Cookie Settings" in the footer
  • Cookieless analytics measurement (if you decline): Art. 6(1)(f) GDPR — our legitimate interest in understanding aggregate site usage; no identifier is stored on your device
  • Security & fraud prevention: Art. 6(1)(f) GDPR — our legitimate interest in keeping the Service secure

Retention & Your Rights

We retain personal data for as long as your organization's Chrontic account is active. After the account is closed, employee personal data is deleted or anonymized, except where we're required to keep specific records for longer under applicable law (for example, German commercial and tax record-keeping obligations) — in which case only those records are kept, and only for as long as that legal obligation requires.

You can review and correct your profile directly in the app. For erasure, export, or other GDPR requests, email support@chrontic.com (self-service tools are on our roadmap), or contact your employer if they're the data controller. You may also lodge a complaint with a data protection authority. If you're located in Berlin, the competent authority is the Berliner Beauftragte für Datenschutz und Informationsfreiheit (BlnBDI), www.datenschutz-berlin.de; other locations have their own competent authority.

Chrontic UG (haftungsbeschränkt) is not required to appoint a Data Protection Officer under Art. 37 GDPR / §38 BDSG.

Part 2 · Browser Extension & IDE Plugin

Only Active When Installed & Configured

Our Chrome Extension and JetBrains plugin are optional and collect nothing until you've installed and configured them with a Chrontic API key — visiting chrontic.com, a JIRA page, or using your IDE otherwise triggers no data collection.

Once set up, they read JIRA ticket IDs, page titles, and activity timestamps from pages you view, and store settings/tracking state locally in your browser — never on our servers. Time entries are sent only to the Chrontic server URL you configure. No analytics, tracking, or third-party sharing. They never access passwords, financial data, screenshots, or non-JIRA browsing history.

You can pause tracking, change settings, or uninstall at any time; uninstalling removes all locally stored data.

Children's Privacy & Policy Changes

Chrontic is a workplace product, not directed at children under 16, and we don't knowingly collect their data. We may update this policy from time to time; changes are reflected in the "Last Updated" date above.

Company Information

Chrontic UG (haftungsbeschränkt)
Kolonnenstraße 8, 10827 Berlin, Germany
Managing Director: Abdullah Sohrab Khan
Email: support@chrontic.com