Liigu sisu juurde
Tauvio

Privacy Policy

Tauvio has no accounts. Your hours, laps, settings and saved weeks stay in your own browser and are never uploaded, and we do not sell or share personal information. The only thing we store on a server is a countdown page you deliberately publish, and the analytics on this site runs without cookies and without advertising identifiers, which is why there is no consent banner to dismiss.

Who we are

Tauvio (tauvio.com) is a product of Moon Sherpa Labs. Moon Sherpa Labs is the controller of the personal data described in this policy, and this policy covers the Tauvio website and every tool on it.

Questions, and any request to exercise the rights described below, go to support@tauvio.com. There is no account to sign in to and no ticket system behind that address: it is a mailbox a person reads.

What stays in your browser and never reaches us

Every calculation on this site runs on your own device. What you type into a tool is written to that browser's local storage so that a reload does not lose it, and it is not transmitted to us at any point.

That is the whole list: a running or paused stopwatch and its laps; a timer, a countdown and their targets; an alarm time and its label; a pomodoro cycle; the hours calculator's current week, its dated weeks, and your chosen country, default shift and hourly rate; the timesheet's people, their rates and their weeks; your sound settings; your 12-hour or 24-hour preference; the token that records a purchase; and the list of countdown pages this browser has created, with the edit token for each.

You control all of it. The hours calculator and the timesheet each carry one control that exports everything above as a JSON file and another that deletes everything above in a single action, and clearing site data in your browser does the same. We cannot read any of it, we cannot restore any of it, and there is nothing on our side for you to ask us to delete.

The country a calculator opens on, and the one cookie we set

Statutory overtime thresholds differ by country, so the hours calculator has to open on one. Our hosting provider adds a header to each request carrying the two-letter country code it derived from the connection, and we read that code while rendering the page.

We copy it into a cookie named tauvio-geo so that a page reached by a link inside the site, where no server render happens, can still read it. The cookie holds a two-letter country code and nothing else — no identifier, no session, no profile. It expires after six hours, so a traveller is not stuck with last week's country, and it is set to SameSite=Lax, so it is never sent from another site's pages.

That is storage strictly necessary to provide the service you asked for, under Article 5(3) of the ePrivacy Directive, which is why you are not asked to consent to it and why this site has no cookie banner. Your own explicit choice of country always beats it. We do not store the code on a server, we do not log it, and we use it for nothing except deciding which country's rules a calculator opens on.

Analytics, and why there is no consent banner

Two analytics services run on this site. Both are loaded only once your browser has gone idle, so they never compete with the tool for the first paint, and if you block either of them nothing on the site stops working.

Google Analytics 4 is configured with Google Consent Mode v2 set to denied by default for analytics storage, ad storage, ad user data and ad personalisation, and nothing on this site ever grants any of the four. In that state Google Analytics runs cookielessly: it writes no _ga cookie and no other identifier into your browser, it cannot recognise you across visits or across sites, and no advertising or remarketing feature is enabled. What is sent with a page view is the address of the page, its title, the referring address, and ordinary request information such as your browser, operating system, screen size and language. Google receives the request, which necessarily carries your IP address; Google states that Analytics does not log or store IP addresses, and we never see one.

Ahrefs Web Analytics is cookieless by design and also sets no identifier. It records the address and title of the page, the referring address, any campaign parameters in the link you arrived on, and the browser, operating system, device type, language and approximate country or city derived from the request.

Both give us counts: which pages are read, in which languages, from which sources. Neither gives us any way to identify you, and we do not try to combine them with anything else. Because neither stores anything on your device and nothing is ever sold or shared, there is no consent for us to ask for.

Paying for Tauvio Pass or Tauvio Teams

Checkout runs on Stripe's own pages. You enter your email address and your payment details there, on Stripe. Card numbers never reach Tauvio at any point, and we have no way to see one.

After a payment we ask Stripe about that single checkout session and read back three things: which plan it was for, whether it was actually paid, and the email address Stripe recorded. We then mint a signed token and hand it to your browser. The token carries a version number, the plan, the Stripe checkout session id, a SHA-256 hash of the email address — never the address itself — and an expiry. We keep no copy of it and we run no customer database: once the token is handed over, nothing on our side records that you bought anything. Stripe keeps its own record, as a payment processor must.

Restoring a purchase in another browser works the same way. You give an email address, we ask Stripe for the most recent valid purchase for it, and if there is one we send a restore link to that address through Resend, our email provider. The page answers identically either way, so it cannot be used to find out whether an address has ever bought anything. Resend processes the address and the message in order to deliver it and keeps its own delivery log.

Our payment webhook records the type of a Stripe event and the id of the object it refers to. It never records an email address, a name or any payment detail.

Countdown pages: the one thing we store on a server

A published countdown page is the single piece of your content that lives on a server, because a link that only worked on your own device would not be a link.

When you publish one we store, in a Postgres database hosted by Supabase: the title you chose, the target date and time, the name of the time zone you meant, the accent colour and logo address if you set them with a Pass, whether the Tauvio mark is shown, a SHA-256 hash of the edit token (never the token itself), the times the row was created and changed, an optional expiry, and a plain counter of how many times the page has been loaded.

We do not store an IP address, a user agent, an email address or any per-visitor record against a countdown page. The counter is one number with nothing attached to it. When a page is created the address the request came from is used as a rate-limiting counter held in memory for at most an hour; it is never written to the database and never logged.

A countdown page is public by design. Anyone with the link can open it and it can be embedded on other sites, which is the point of it. The address contains twelve random characters, so it is not guessable, but it is not a secret either: do not put anything in the title that you would not put on a public web page.

You can edit or delete the page at any time from the browser that created it, using the edit token that browser holds, and deleting it removes the row. We do not currently delete pages automatically when an expiry passes — an expired page stops being served, but its row remains until it is deleted. If you lose the edit token, by clearing that browser's storage for instance, write to support@tauvio.com with the link and we will delete the page for you.

The companies that process data for us

Vercel hosts the site and serves it from edge locations worldwide. Like every web host it keeps its own request logs, which include the address a request came from, in order to run and secure the platform. We add nothing to those logs and build no profile from them.

Supabase hosts the Postgres database that holds published countdown pages.

Stripe processes payments, including the email address and the payment details you give it at checkout.

Resend delivers the one transactional email this site sends, the restore link.

Google and Ahrefs provide the two analytics services described above.

That is the complete list. We use no advertising network, no data broker, no customer-relationship or marketing platform, no session recorder and no heat map, and we run no newsletter.

Why we are allowed to do this

Where the GDPR or the UK GDPR applies, these are our legal bases.

Performance of a contract, Article 6(1)(b): taking payment for a Pass or a Teams plan, issuing and restoring the token that records it, and publishing, serving and deleting a countdown page you asked us to publish.

Legitimate interests, Article 6(1)(f): running a site that works, opening a calculator on the right country's rules, limiting automated abuse of the page-creation endpoint, and measuring in aggregate which pages are read so that we know what to write next. We have weighed those interests against your rights and kept the processing to the minimum each purpose needs, which is why the analytics is cookieless and why the rate limiter holds an address for an hour and writes nothing down.

Storage on your device, Article 5(3) of the ePrivacy Directive: the tool state and the country cookie described above are strictly necessary to provide the service you requested, so they need no consent. We store nothing else on your device, which is why we ask for no consent at all.

How long anything is kept

On your device: until you clear it. What the tools store and the token that records a purchase stay in your browser's local storage indefinitely, and are removed by the delete-everything control or by clearing site data. The tauvio-geo cookie expires after six hours.

Countdown pages: until you delete them. There is no automatic sweep today, as described above.

With our processors: according to their own retention periods, which we do not set. Stripe keeps payment records for as long as financial regulation requires of it. Google Analytics retains event data for the period configured on the property, within the maximum Google allows. Our host keeps request logs for its own operational window. Resend keeps a delivery log.

On our own servers: nothing else at all. Beyond the countdown-pages table there is no user record, no log of what you calculated and nothing else to expire.

Where the data goes

Moon Sherpa Labs operates from the United States, and the providers listed above are United States companies or operate globally with infrastructure in the United States. Using this site therefore involves data reaching the United States and possibly other countries.

Where personal data is transferred out of the European Economic Area, the United Kingdom or Switzerland, we rely on the transfer mechanisms these providers offer, including standard contractual clauses.

Your rights

If the GDPR or the UK GDPR applies to you, you have the right to ask for access to your personal data, to have it corrected or erased, to have its processing restricted, to receive it in a portable form and to object to processing based on legitimate interests. You may also complain to your supervisory authority, though we would rather you told us first.

If the California Consumer Privacy Act applies to you, you have the right to know what personal information is collected and why, to have it deleted, to have it corrected, and to opt out of the sale or sharing of personal information. We do not sell personal information and we do not share it for cross-context behavioural advertising, as those terms are defined in that Act, and we have not done either in the preceding twelve months. You will never be treated differently for exercising any of these rights: there is no lesser version of this site.

Most of these rights you can exercise without us, and faster than we could act on them, because the data is on your device. The export control gives you portability and the delete-everything control gives you erasure, immediately and completely.

For anything on our side — a purchase, or a countdown page you published — write to support@tauvio.com. We will need enough to find the record and nothing more: the email address you paid with, or the link to the page. We answer as quickly as we can and within the time the applicable law allows, which is one month under the GDPR and forty-five days under the California Act. We may ask you to show that you control the address or the page, because acting on an unverified request would be the privacy failure rather than the fix.

Do Not Track and Global Privacy Control

Some browsers send a Do Not Track header or a Global Privacy Control signal. A Global Privacy Control signal is a request not to sell or share personal information, and we honour it by construction: there is nothing for it to switch off, because nothing is ever sold or shared and no cross-site advertising identifier is set in the first place. This site behaves identically whether you send either signal or not.

Children

Tauvio is not directed at children. We do not knowingly collect personal data from anyone under 13, and in the European Economic Area we do not knowingly collect it from anyone under 16, or under the lower age a member state has set.

There is no account to create and no profile to build here. If you believe a child has nonetheless sent us personal data, through the title of a countdown page for instance, write to support@tauvio.com and we will remove it.

Security

The site is served over HTTPS. The token that records a purchase is signed with HMAC-SHA256 and verified in constant time, so it cannot be forged or edited. The edit token for a countdown page is stored only as a SHA-256 hash, and a wrong token and an unknown page get the same answer, so the endpoint cannot be used to discover which pages exist. The countdown-pages table is unreachable with any public key: row-level security is on with no policies and the default grants are revoked, so only our own server code can read or write it. Card details are held by Stripe and we never see a card number.

No system is perfect and no promise about security is worth more than what it actually does. The most honest thing we can say is structural: the less we hold, the less there is to lose, and we hold almost nothing.

Changes to this policy

The date at the top of this page identifies the version you are reading. If what we process or why it is processed changes, we update this page and move that date, and a material change is described here rather than made quietly.

How to reach us

Moon Sherpa Labs publishes Tauvio, and more about the company is at https://moonsherpa.com.

Write to support@tauvio.com about anything in this policy, including a data-protection request. It is the only address the product publishes, on purpose: a promise split across two mailboxes is a promise one of them will drop.