Scoro Time App Privacy Policy

1. Introduction

This Privacy Policy explains how Scoro Software OÜ (“Operator”) handles personal data when you use the Scoro Time mobile app (the “App”) on iOS and Android.

Scoro Time is an official Operator’s app for people who already have an account with the Operator. It lets you log time, view your tasks, and manage time entries on your organization’s Scoro site. You cannot create or delete your account in the App.

This privacy policy only applies to personal data processed in the App. It does not describe Operator’s personal data processing on its platform, which can be found here: Scoro Privacy Policy

2. Main definitions

Client: A person operating in the economic and professional activity who has entered into the Contract with the Operator

Operator: Scoro Software OÜ, registry code 10806081, Endla 15, Tallinn, Estonia

Scoro administrator: A person within the Clients organisation who is responsible for managing the accounts 

3. How the App relates to your organization

Most of the data you see in the App — tasks, time entries, calendars, and similar work information — belongs to the Client. For this data, the Client (your employer) is the data controller and the Operator acts as a data processor as defined in the General Data Protection Regulation (EU) 2016/679.

This means that for most requests about your work data (for example, access or deletion), you should contact your organization’s Scoro administrator. For data we handle to run the App itself (such as crash diagnostics), Scoro acts as the data controller, as described below.

4. Data we process

Depending on how you use the App, we process the following:

  • Account and sign-in data — the sign-in credentials issued when you log in, used to keep you securely signed in.
  • Profile data — basic profile information from your account with the Operator, such as your user identifier and profile picture (if you have added a profile picture).
  • Work and time-tracking data — tasks, time entries, calendar events, availability, and time-off information from your site with the Operator, including descriptions and notes you add. 
  • App activity and preferences — settings you choose in the App (such as display and filter options) and information about your active time tracker.
  • Diagnostics — crash and error reports, and basic app and device information (such as app version and operating system), used to keep the App stable and up to date.

All this data is obtained from you or from your account that you have with the Operator. The Operator does not collect personal data from third parties, such as social media or data brokers. 

5. Why we process this data and legal bases

  • To provide the App and let you log time, view tasks, and sync your site with the Operator — this processing is done based on the Operators legitimate interest which is to deliver the service to you. 
  • To keep the App reliable and usable, including offline support and faster loading — Operator’s legitimate interest to provide a well-functioning App.
  • To diagnose crashes and deliver updates — Operator’s legitimate interest to provide a secure, stable App.

Where the Client acts as a data controller, the Client itself decides the purpose and legal basis for that processing.

The Operator does not use the App for advertising and we do not track you across other companies’ apps or websites.

6. Sign-in and security

You sign in using your existing credentials through a secure, industry-standard authentication process. The Operator uses encrypted connections (HTTPS/TLS) for communication with the Operator’s website and supporting services. The Operator stores your sign-in credentials on your device using the operating system’s secure storage.
The Operator applies appropriate technical and organizational measures to protect personal data taking into account the state of the art, costs of implementation, nature, scope context and purposes of processing and the risks posed. Such measures include, but are not limited to, encrypted storage and access controls. 

7. Notifications

The App can show local notifications on your device while a time tracker is running or paused — for example, the task name and its running or elapsed status (how this appears can vary by platform). These are generated on your device and are not delivered through remote push services. You can allow or deny notifications in your device settings.

8. Data stored on your device and logging out

To work smoothly and support brief offline use, the App stores some data on your device, such as your session, a short-lived cache of your tasks and time data, and any time entries you create while offline (until they sync).

When you log out, the App removes your session and your locally stored work data from the device. Some non-identifying app preferences may remain so your settings are kept for next time.

Logging out does not delete your account you have with the Operator or any data on the Clients Scoro site. That data remains subject to the Clients policies.

9. Service providers and data sharing

The Operator relies on a small number of trusted providers to run the App:

  • The Clients Scoro site — stores and processes your work and time data. This is where your data lives; the App simply connects to it.
  • Sentry — crash and error monitoring. The Operator configures it to minimize personal data and to scrub the Clients site name from diagnostic request information. Sentry appears on the Operators sub-processor list.
  • Expo — app infrastructure used for app updates, hosting of supporting sign-in services, and basic app-level usage metrics (such as app version and operating system). Expo does not receive your work or time data.

We do not sell your personal data nor share it with data brokers or third party advertising networks.

10. International transfers

Some service providers may process personal data outside of the European Economic Area (EEA), including the United States. In case personal data is transferred outside of the EEA, the Operator relies on appropriate safeguards for these transfers. These safeguards include the Standard Contractual Clauses adopted by the European Commission. 

11. Data retention

  • On your device — session and cached work data are removed when you log out; the short-lived cache also refreshes automatically over time.
  • On the Operators platform and diagnostics — the Operator retains this data as long as necessary and in accordance with the maximum limitation period for claims arising from a transaction. Logging out of the App does not delete this data.

12. Your rights

Subject to applicable law, you may have rights to access, correct, delete, restrict, or object to the processing of your personal data, and to data portability.

  • For work data on your Scoro site, contact your organization’s Scoro administrator. You can also view and update much of this data by signing in to your employers (the Clients) Scoro website.
  • For data the Operator handles to operate the App, contact us at [email protected].

A full description of your rights is in the Operators Privacy Policy. In case you believe that the Operator infringes your rights you may also lodge a complaint with the Estonian Data Protection Inspectorate (aki.ee). But please contact the Operator before lodging a complaint with the Inspectorate.
The Operator does not sell personal information.

13. Accounts

The App only supports signing in and signing out. Accounts you have with the Operator are not created, managed, and deleted in the App. To delete your account or related data, contact your organization’s Scoro administrator.

14. Children

The App is intended for business use and is not directed at anyone under 18. The Operator does not knowingly process children’s personal data through the App.

15. Data we do not collect

The App does not collect your location, access your camera, microphone, contacts, or photos, show ads, use advertising identifiers, or track you across other apps and websites.

16. Changes to this policy

The Operator may update this policy from time to time. If material changes are made, you will be provided notice as appropriate. The effective date above shows when the current version took effect.

17. Contact

Privacy questions: [email protected]
General product support: Scoro Help Center

Scoro Software OÜ, Endla 15, Tallinn, Estonia.

Effective date: 01.07.2026