Privacy Policy

✓ Tested & verified Updated:

Who is responsible for your data

  • Operated by: maicrosites.com
  • Established in: Slovakia, European Union
  • Email: info@timerplan.com
  • Site: timerplan.com

There is no data protection officer. The site is run by one person and meets none of the conditions in Article 37 GDPR that would require one, so the address above reaches the person who actually decides what happens to your data — not a queue.

What we process

Every timer, clock and calculator on this site runs entirely in your browser — nothing you type is sent anywhere, and no tool makes a network request while it is working. Settings such as a timer length travel in the address bar so that a link can carry them; nothing is written to your device.

Advertising and cookies

This site shows ads served by Google AdSense. Visitors from the EEA and UK see a consent banner (Google-certified CMP). Change your choices at adssettings.google.com. More: policies.google.com/technologies/partner-sites.

Permissions the browser may ask for

Two tools ask the browser for something, and both only when you use them. A running timer requests a screen wake lock so the display does not sleep, which involves no data at all, and asks for notification permission the first time a timer is started so it can tell you when the time is up. Refusing either costs you that feature and nothing else. Neither is requested when you arrive.

Your rights

Under the GDPR you may access, correct and erase your data — since we store none ourselves, this primarily concerns data processed by Google.

Last updated: August 2026

Accounts and Pro

You can use everything on this site without an account. An account only exists if you make one.

What an account holds. Your email address. That is the whole profile — no name, no password, no address, no phone number. Passwords do not exist here: you sign in with a one-time link we email you.

Why we hold it. To sign you in, to keep the setups you save, and to send the alerts you ask for. The legal basis is performance of the contract you entered into by creating the account (Art. 6(1)(b) GDPR); for the marketing-free service emails we send about your own account, our legitimate interest in operating it (Art. 6(1)(f)).

What else gets stored, and for how long.

WhatWhyKept
Email addressSigning in, alertsUntil you delete the account
Sign-in linksOne-time sign-inHashed; 20 minutes, then deleted
Session cookieKeeping you signed in90 days, or until you sign out
Saved setupsThe feature itselfUntil you delete them or the account
Email alertsThe feature itselfUntil you turn them off
Hashed IP addressRate-limiting the sign-in and reminder formsOne hour
Subscription status and order referenceKnowing what you paid forUntil you delete the account

Sign-in links and session tokens are stored hashed, never in readable form. Somebody who obtained the database still could not sign in as you.

Cookies. The sign-in cookie is strictly necessary and does not need consent. It is HttpOnly, Secure, SameSite=Lax, and it is set only after you sign in. Advertising and analytics cookies are separate and governed by the consent banner.

Payments. We do not process payments and never see your card. Payment is handled by our payment provider Polar, acting as merchant of record; Polar receives your email address, your billing country and your payment details directly, and is the controller for that data. We receive back only: that a payment succeeded, which plan, when it renews, and an order reference.

Sending email. Sign-in links, alerts and reminders go out through ZeptoMail (Zoho), acting as our processor, with servers in the EU. They receive your email address and the message.

Your rights. Access, rectification, erasure, restriction, portability, and objection. Two of them are buttons on your account page, with no need to ask anyone:

  • Download everything — a JSON file with every record we hold about you.
  • Delete account — immediate, permanent, and it really deletes rather than marking a row inactive.

For anything else, write to us. You also have the right to complain to a supervisory authority — in Slovakia, the Office for Personal Data Protection.

International transfers. The database is on a server in the EU. Where a processor is outside the EEA, the transfer runs on the European Commission’s standard contractual clauses.