Timezones.in — Stay In Sync

Privacy notice

Version 2026-09-05

This notice explains what personal data Timezones.in collects, why, and what you can do about it. It is written to be read, not skimmed past. The short version: most of the site works with no data about you at all; an account is only an email address; analytics runs only if you say yes.

Who is responsible

The data controller is Boffin Coders Pvt Ltd, trading as Boffin Coders, of C 201-202(B), Cyber Cube, Phase 8B, Industrial Area, Mohali, Punjab 160055, India. Contact: info@boffincoders.com, or the data request form. We have not appointed a Data Protection Officer because we are not required to; the contact above handles all privacy matters.

What we collect, and why

1. Nothing, for most visits

Converting times, using the map, the planner and the city pages needs no account and stores nothing on our servers about you. Your selected clocks are kept in your own browser’s storage and in the page URL so you can share them; we do not receive them.

2. Server logs (legitimate interest — keeping the service secure and working)

Our web server records the requested URL, the time, the response status, your browser’s user-agent string and your IP address. Logs are kept for 14 days and then deleted. They are used only to diagnose faults and block abuse.

3. Analytics (consent)

If you click “Allow analytics” in the cookie banner, we load Google Analytics 4 with IP anonymisation and Google Consent Mode set so that advertising storage is always denied. It tells us which pages are used and from which country. If you do not consent, the analytics script is never loaded — not blocked, not loaded. You can change your mind at any time from the cookie policy page. Google processes this data under its own terms; data may be transferred to the United States under Google’s Data Privacy Framework certification and Standard Contractual Clauses.

4. Accounts (contract — providing the features you asked for)

If you sign in we store: your email address; an optional name; your saved clock sets, meeting plans and daylight-saving alert subscriptions; API keys (as a hash — we cannot read them back); sign-in sessions (a random token hash, the time, a hashed IP and your user-agent); and an audit log of security events on your account (sign-in, key created, export, deletion). There are no passwords and no third-party sign-in. Sign-in links are single-use and expire after 15 minutes.

5. Emails we send (contract)

Sign-in links, daylight-saving alerts you subscribed to, and receipts for privacy requests. Nothing else. There is no newsletter and no marketing email. They are delivered by a transactional email provider acting as our processor — currently Brevo (Sendinblue SAS, Paris, France), which stores the address and delivery logs in the EU.

6. Consent receipts (legal obligation — proving consent was given)

Each time you make a choice in the cookie banner we record: a random identifier generated in your browser, the policy version, your choice, a hashed IP and your user-agent. If you have an account the receipt is linked to it until you delete the account, after which the link is removed but the anonymous receipt is kept.

7. Data requests (legal obligation)

If you use the request form we keep your email, the request type and message, and our reply, for 3 years so we can show we handled it.

What we do not do

  • We do not sell or share personal data for advertising, and we do not use advertising cookies. (For California residents: we do not “sell” or “share” personal information as defined by the CCPA/CPRA.)
  • We do not profile you or make automated decisions about you.
  • We do not collect precise location. The map guesses your timezone from your browser’s settings, in your browser.
  • We do not knowingly collect data from children under 16; if you believe a child has created an account, contact us and we will delete it.

Where data is stored

Our server is hosted by DigitalOcean in its Bengaluru, India region. Data is therefore processed in India. For visitors in the UK and EEA this is a transfer to a country without an adequacy decision; we rely on Standard Contractual Clauses with our hosting provider and the minimal nature of the data (an email address and timezone preferences) to protect it. Google Analytics, if you consent, processes data in the EU and the US.

How long we keep things

  • Server logs: 14 days
  • Sign-in links: 15 minutes, then a further 24 hours as used/expired records for abuse detection
  • Sessions: until you sign out, or 30 days of inactivity
  • Account data: until you delete the account. Accounts unused for 24 months are deleted after a warning email.
  • Consent receipts: 5 years
  • Data request records: 3 years
  • Backups: encrypted daily backups are kept for 30 days; deleted data leaves backups within that window.

Your rights

Wherever you are, you can ask what we hold about you, get a copy, correct it, delete it, or object to how we use it. Under the GDPR and UK GDPR you also have the rights to restrict processing, to data portability, and to withdraw consent at any time; under India’s Digital Personal Data Protection Act 2023 you have the rights to access, correction, erasure, grievance redressal and to nominate someone to exercise your rights; under the CCPA you have the right to know, delete, correct and to non-discrimination; under the Australian Privacy Act you have the rights of access and correction.

You do not need to write to us for most of this. Account holders can download everything or delete the account instantly. For anything else, use the request form. We answer within 30 days (or sooner where local law requires), free of charge. We may ask you to confirm you control the email address in question.

If you are unhappy with our answer you can complain to your supervisory authority: in the EU, the authority in your member state; in the UK, the Information Commissioner’s Office; in India, the Data Protection Board; in Australia, the OAIC. We would appreciate the chance to resolve it first.

Security

All traffic is encrypted with TLS. There are no passwords to leak. Sign-in tokens and API keys are stored only as SHA-256 hashes. IP addresses in our own records are stored as salted hashes. Access to the server is by SSH key from named devices only. If a breach affects you we will tell you and the relevant regulator within the legally required time.

Changes

When this notice changes materially we bump the version number at the top and the cookie banner asks for your choice again. Older versions are available on request.