Privacy Policy
Version of 15 September 2026
1. General provisions
This policy describes how personal data of users of EraTrack, a time tracker with project profitability (the “Service”), is processed: the web application at app.eratrack.eradev.tech and the website eratrack.eradev.tech.
The policy is drawn up in accordance with Federal Law of the Russian Federation No. 152-FZ of 27.07.2006 “On Personal Data” (the “Law”) and is a publicly available document defining the operator’s policy on personal data processing (Article 18.1(2) of the Law).
The operator is Era Developers Studio (the “Operator”). Requests about personal data are accepted via email at support@eratrack.net or Telegram at t.me/eratrack.
By using the Service, the user confirms that they have read this policy. A user who does not agree with it should stop using the Service.
2. What data is processed
The website eratrack.eradev.tech has no forms, does not collect visitor data, does not use analytics and does not set cookies.
The web application processes the following data.
Account:
- email address;
- name;
- password — stored only as an irreversible hash; the Service does not store the password itself;
- settings: interface language, theme, time zone;
- two-factor authentication secret — if the user has enabled it.
Sign-in sessions:
- IP address;
- browser and device information (the User-Agent header);
- time of sign-in, last use and end of the session.
Work data within an organization:
- the member’s role and status in the organization, membership in groups and projects;
- time entries: start, end, task description, “billable” and “private” flags;
- planned load, timesheets and their status, reason a timesheet was returned;
- rates: a member’s hourly cost and the hourly price for the client;
- email addresses of people invited to the organization;
- the organization’s activity log (audit log): who made which change and when.
Information about the organization’s clients (names, details, project terms) is entered by users themselves. If it contains personal data of third parties, the user entering it is responsible for having a legal basis to transfer it to the Service.
Payment data: when paying for a paid plan, card details are entered on the payment system’s side, which processes them under the PCI DSS security standard. They are not passed to the Operator. The Operator receives from the payment system only information about the payment: amount, currency, date, status and transaction ID.
3. Purposes of processing
- registration, sign-in and operation of the account;
- providing the Service’s features: time tracking, load planning, timesheet approval, profitability calculation, reports;
- account protection: two-factor authentication, a list of active sessions that can be ended;
- sending invitations to an organization and service emails related to the Service;
- role-based access control within an organization and recording changes in the activity log;
- accepting payments for paid plans and processing refunds;
- fulfilling obligations imposed on the operator by law.
No marketing emails are sent; data is not used for profiling or targeted advertising.
4. Legal grounds
- conclusion and performance of a contract to which the user is a party — use of the Service under the User Agreement (Public Offer) published on the website (Article 6(1)(5) of the Law);
- consent of the data subject — where it is required (Article 6(1)(1) of the Law);
- fulfilling obligations imposed on the operator by the laws of the Russian Federation (Article 6(1)(2) of the Law).
Data of members whom an organization adds or invites to the Service is transferred to the Service by the organization for its own records. In this part the Operator processes data on behalf of the organization (Article 6(3) of the Law), and the organization is responsible to its members for having a basis for such processing.
6. Data transfer
Personal data is not sold and is not transferred to third parties for their own purposes. Within an organization, members see data within their role: financial information (rates, revenue, cost, profit) is available only to the organization’s owner, administrator and accountant.
To run the Service, data may be processed by authorized persons on behalf of the Operator:
- the hosting provider whose servers host the Service;
- the email delivery provider — for invitations and service emails.
To convert amounts between currencies, the Service obtains exchange rates from an external source. No personal data is transferred in doing so.
Payments for paid plans are processed by the payment system: the user enters payment details on its side, and it processes them under its own rules.
Personal data may be provided to government authorities upon their lawful request in accordance with the laws of the Russian Federation.
7. Retention and deletion
Account data is kept for as long as the account exists. The user can delete the account in the account settings. An owner of an organization that has other active members first transfers ownership to one of them or blocks or archives the other members.
When an account is deleted:
- the email address is removed and replaced with a technical value, freeing the address for a new registration;
- all active sessions are ended;
- organizations in which the user was the only member are closed;
- membership in other organizations is archived: time entries and the name remain in their history, as they are records of those organizations.
Invitations to an organization are valid for a limited time and cannot be used once they expire.
8. Data protection
- the connection to the Service is encrypted (HTTPS);
- passwords are stored only as an irreversible hash;
- two-factor authentication with one-time codes is available;
- the user sees active sessions with device information and can end any of them;
- session keys are stored in cookies that page scripts cannot access;
- access to data within an organization is controlled by roles, and changes are recorded in the activity log;
- private time entries are shown to colleagues without the task and project name.
9. User rights
Under the Law, the user has the right to:
- receive information about the processing of their personal data (Article 14 of the Law);
- demand that data be clarified, blocked or destroyed if it is incomplete, outdated, inaccurate, unlawfully obtained or not needed for the stated purpose;
- withdraw consent to processing, where processing is based on consent;
- appeal the Operator’s actions or inaction to the Federal Service for Supervision of Communications, Information Technology and Mass Media (Roskomnadzor) or in court.
In the account settings, the user can change their name, language, theme, time zone and password, manage two-factor authentication, end sessions and delete the account. Other requests, including changing the email address, are sent via email at support@eratrack.net or Telegram at t.me/eratrack. The Operator responds within 10 working days; this period may be extended by no more than 5 working days with notice of the reasons (Article 20 of the Law).
10. Changes to the policy
The Operator may change this policy. A new version takes effect when published on this page; the version date is shown at the top of the document.
11. Contacts
For any questions about the Service:
- email: support@eratrack.net;
- Telegram: t.me/eratrack.