Privacy Policy
Who is responsible for your data
- Operated by: maicrosites.com
- Established in: Slovakia, European Union
- Email: info@timerplan.com
- Site: timerplan.com
There is no data protection officer. The site is run by one person and meets none of the conditions in Article 37 GDPR that would require one, so the address above reaches the person who actually decides what happens to your data — not a queue.
What we process
Every timer, clock and calculator on this site runs entirely in your browser — nothing you type is sent anywhere, and no tool makes a network request while it is working. Settings such as a timer length travel in the address bar so that a link can carry them; nothing is written to your device.
Advertising and cookies
This site shows ads served by Google AdSense. Visitors from the EEA and UK see a consent banner (Google-certified CMP). Change your choices at adssettings.google.com. More: policies.google.com/technologies/partner-sites.
Permissions the browser may ask for
Two tools ask the browser for something, and both only when you use them. A running timer requests a screen wake lock so the display does not sleep, which involves no data at all, and asks for notification permission the first time a timer is started so it can tell you when the time is up. Refusing either costs you that feature and nothing else. Neither is requested when you arrive.
Your rights
Under the GDPR you may access, correct and erase your data — since we store none ourselves, this primarily concerns data processed by Google.
Last updated: August 2026
Accounts and Pro
You can use everything on this site without an account. An account only exists if you make one.
What an account holds. Your email address. That is the whole profile — no name, no password, no address, no phone number. Passwords do not exist here: you sign in with a one-time link we email you.
Why we hold it. To sign you in, to keep the setups you save, and to send the alerts you ask for. The legal basis is performance of the contract you entered into by creating the account (Art. 6(1)(b) GDPR); for the marketing-free service emails we send about your own account, our legitimate interest in operating it (Art. 6(1)(f)).
What else gets stored, and for how long.
| What | Why | Kept |
|---|---|---|
| Email address | Signing in, alerts | Until you delete the account |
| Sign-in links | One-time sign-in | Hashed; 20 minutes, then deleted |
| Session cookie | Keeping you signed in | 90 days, or until you sign out |
| Saved setups | The feature itself | Until you delete them or the account |
| Email alerts | The feature itself | Until you turn them off |
| Hashed IP address | Rate-limiting the sign-in and reminder forms | One hour |
| Subscription status and order reference | Knowing what you paid for | Until you delete the account |
Sign-in links and session tokens are stored hashed, never in readable form. Somebody who obtained the database still could not sign in as you.
Cookies. The sign-in cookie is strictly necessary and does not need consent.
It is HttpOnly, Secure, SameSite=Lax, and it is set only after you sign in.
Advertising and analytics cookies are separate and governed by the consent banner.
Payments. We do not process payments and never see your card. Payment is handled by our payment provider Polar, acting as merchant of record; Polar receives your email address, your billing country and your payment details directly, and is the controller for that data. We receive back only: that a payment succeeded, which plan, when it renews, and an order reference.
Sending email. Sign-in links, alerts and reminders go out through ZeptoMail (Zoho), acting as our processor, with servers in the EU. They receive your email address and the message.
Your rights. Access, rectification, erasure, restriction, portability, and objection. Two of them are buttons on your account page, with no need to ask anyone:
- Download everything — a JSON file with every record we hold about you.
- Delete account — immediate, permanent, and it really deletes rather than marking a row inactive.
For anything else, write to us. You also have the right to complain to a supervisory authority — in Slovakia, the Office for Personal Data Protection.
International transfers. The database is on a server in the EU. Where a processor is outside the EEA, the transfer runs on the European Commission’s standard contractual clauses.