Privacy
Time in Hand holds an email address and the plans on your account — and, if you asked to be told when the paid version is ready, an address for that one message. That is the whole list, and the rest of this page is mostly an explanation of why it is so short.
Last updated 23/09/2026. Time in Hand is the data controller for everything described here. Questions, or anything this page does not answer: [email protected].
What is held, and about whom
There are three ways to use this product and only two of them put anything on our server. There is also one thing you can ask us for, which is described last and is the only case that can apply to somebody with no account at all.
If you never sign in
We hold nothing about you at all. Your plans are saved in your own browser and we cannot see them, read them or delete them — there is no copy on our side to hold. Working out a schedule, importing a route, printing a card and replanning at a control all happen on your device, which is why none of it asks you to make an account. If you clear your browser's storage, those plans are gone, and we cannot get them back for you because we never had them.
If you have a free account
We hold your email address and the plans you have saved to the account, which includes the running record a plan keeps while you are riding it. A free account buys nothing; it exists so that your plans survive a lost phone or a browser that clears itself. You get the same export and the same delete as anybody who has paid.
If you have paid for something
The same two things, plus a record of what you bought, what it cost and when — enough to know what your account is entitled to. Your card details never reach us: the payment happens on Stripe's own pages, and what comes back is that a payment succeeded and which email address made it.
If you asked to be told when the paid version lands
We hold the address you typed into that box, the moment you typed it, and the exact sentence that was next to it when you did. That is all of it: no name, no plans, nothing about what you have been doing on the site. You do not need an account for this and having one changes nothing about it.
It is for one message, once, when the paid version is ready — and the address is deleted as that message goes out. There is no second email, because after the first one there is nothing left to send it to. You can also take the address off at any time before then, from the same box you typed it into, without telling us who you are.
A plan holds what you typed: the brevet, its controls and distances, your speeds, where you mean to sleep, and the times you stamp during the ride. If you imported a GPX file, it holds the route from that file too. It is a planning document about a bike ride, and it is the largest thing here by a wide margin.
Why, and on what basis
Your email address is how you sign in — there is no password, so a code sent to that address is the whole of the mechanism. It is also where a receipt goes. The basis is contract: you asked for an account and an account cannot exist without somewhere to send the code.
Your plans are held because you asked us to keep them, which is the entire function of an account here. Same basis, same reason.
What you bought is held to know what your account can do, and because a payment is a contract. Stripe keeps its own record of the transaction under its own legal obligations, and that record is the one an accountant or a tax authority would be shown.
The address you gave to be told about the launch is held on your consent, which is a different basis from the three above and is the reason it works differently. Consent has to be as easy to take back as it was to give, so there is a way off the list on the same box you used to join it, and a one-click link in the message itself. We record when you gave it and the exact wording you were shown, so that what you agreed to cannot be quietly rewritten later.
Nothing here is used to profile you, and no decision about you is made automatically.
Position, if you switch it on
There is one setting that reads where you are, and it is off until you turn it on. While it is off, nothing is requested — not the permission, not a reading — and if you never touch it you are in exactly the position you would be in if the feature did not exist.
What is read. One coarse position, at most every two minutes, and only while the ride screen is open in front of you. Never high accuracy, and there is no continuous subscription — the app does not follow you between readings. It asks only when an answer could change something: within about ninety minutes of a projected arrival, at a control your plan has coordinates for, and not once the screen it would bring up is already showing. Most of a leg asks for nothing at all, and a plan you typed by hand, with no route file imported, never asks at any point.
What it decides. Whether to show you the approach-to-a-control screen sooner than the projected time alone would. Nothing else. It cannot move any time, pace or deadline the app works out — those come from the times you stamp yourself, and the calculation engine is structurally prevented from seeing a position at all.
What happens to it. It is compared with the next control's coordinates and dropped in the same breath. It is never saved to your plan, never written to your browser's storage, and never sent to us. No trail of any kind is kept anywhere. The app holds the decision — show the screen, and roughly how far away you are — and never the coordinates. So this capability adds nothing to the list at the top of this page: we hold no more than before, because of it we hold nothing at all.
The basis is your consent, and the consent is your phone's own permission prompt. It is explicit, it applies to this site only, and you can withdraw it at any time in your phone's settings. We are saying so here because that prompt asks whether a website may use your location and cannot tell you that nothing is kept.
Turning it off again, or refusing it mid-ride, breaks nothing: the app goes back to deciding from your projected arrival time, with no message and nothing degraded. That is what every rider who declines already gets, and it is the floor rather than the fallback.
Cookies
There are two, both strictly necessary for something you asked for, and there is no banner because there is nothing to ask you about.
- A sign-in cookie, set when you sign in and lasting up to 90 days. Without it you would be signed out on every page. It cannot be read by scripts.
- A checkout cookie, set for 24 hours when you start a payment. Without it we could not tell you, when you come back from Stripe, that your payment landed. It holds a random token, it cannot be read by scripts, and it goes by itself.
Neither is used for advertising, tracking or measurement, and nothing else is stored on your device by us except the plans you save, which are yours and are described above.
Analytics, and error reports
We count page views and a short list of actions — a plan finished, an unlock clicked, a card printed, a route imported — using Umami, which is cookieless. It stores nothing on your device and reads nothing from it, which is why there is no cookie banner: the law about banners is about storing and reading things on your device, and this does neither. Sessions are counted by a one-way hash of your IP address, your browser string and a salt that changes daily, so the same person on two days is two numbers to us and there is no way back to a person from any of it.
Handling your IP address for the moment it takes to compute that hash is covered by our legitimate interest in knowing whether the product is being used, which is assessed as low-impact because nothing identifying is kept and no profile is built.
When something breaks, an error report goes to Sentry so it can be fixed. Reports carry what went wrong and where in the code; they are not asked to carry your email address, and errors on the sign-in path are deliberately written so they cannot.
To stop sign-in codes being used to flood an inbox, the server counts recent requests against the IP address they came from, and those counters currently hold the address itself rather than a hash of it. They are not attached to your account and there is no way back to a person from one, but nothing deletes them either, so they outlast the account whose sign-in wrote them. That is the one thing in this product not yet held to the standard the rest of this page describes, we know about it, and it is being fixed rather than defended.
Who else handles it
Each of these does one job, under a written data-processing agreement, and none of them may use anything for their own purposes.
- Railway runs the application, in Amsterdam.
- Neon runs the database your account and plans live in, in London.
- Resend sends the sign-in codes and the few other emails there are. Sending happens from an EU region; Resend holds message metadata and delivery logs in the United States.
- Stripe takes the payments and holds the card details, which never reach us.
- Umami counts the page views described above.
- Sentry receives the error reports described above.
Where a processor holds anything outside the UK or the EEA, it does so under the standard contractual clauses and the UK addendum to them. We do not sell anything to anybody, and there is nobody else in the list.
How long it is kept
Your account and its plans are kept until you delete them, or until the account has been unused for two years. At two years we email the address on the account to say what is about to happen and give you thirty days; signing in during those thirty days is enough to keep everything, and the two years start again. Otherwise the account and every plan on it are deleted.
A sign-in code lasts ten minutes and is destroyed when it is used. If you start a payment and do not finish it, the plan parked for that payment is deleted within a day — and it carries nothing about you in the first place, only the controls, the route and the speeds.
An address on the launch notice list is kept until that one message is sent, at which point it is deleted — not marked as sent, not archived, deleted — or until you take it off yourself, whichever comes first. Deleting your account takes it off too, even though the two are not otherwise connected.
Records of payments are kept by Stripe for as long as the law requires, and that is where they live. Deleting your account here does not and cannot delete Stripe's copy.
What you can do about it
Two of these you can do yourself, immediately, without asking us — they are on your account page.
- Take a copy. Download everything the account holds as one file: your address, every plan as the app itself stores it, and the record of anything bought. It is a download rather than a transfer — there is nowhere to upload it back to yet.
- Delete the lot. Removes the account, every plan on it, the record of every ride you stamped, any part-finished payment, and your sign-in sessions. It cannot be undone and we cannot recover it afterwards.
You also have the right to have something corrected, to ask us to restrict what we do with it, and to object to the analytics described above. Email [email protected] and you will get an answer within a month.
If you are not satisfied with how we have handled something, you can complain to the Information Commissioner's Office at ico.org.uk. We would rather you told us first, but you do not have to.
What this product does not do
No health data. There is no heart rate, no weight, no sleep tracking and no connection to anything that collects them. The app asks how fast you ride and how much hills slow you down, which is information about a bicycle journey rather than about your health, and it is used for one thing: predicting when you will reach a control.
No location tracking. Nothing here records or transmits where you have been. The optional reading described above is compared and dropped; there is no trail, no map of your ride and nothing to breach, correlate or hand over.
No marketing. There is no newsletter and nothing you are signed up to by buying something, using the planner, or making an account. Every email we send about your account is about your account: a sign-in code, a receipt, or the warning described under retention. Nobody's address is ever given or sold to anybody.
One thing you can ask for, and it is the only one. If you type your address into the box asking to be told when the paid version lands, we send you exactly that: one message, once, and the address is deleted as it goes. It is the only list this product has, you have to put yourself on it, there is a way off it on the same box and a one-click link in the message, and it cannot be used to send you anything else because after that message there is nothing left of it.
No sharing your plan without you. A plan is visible to somebody else only if you create a share link for it yourself, and only for as long as you keep it.
If this page ever disagrees with what the product actually does, the product is wrong and we want to hear about it.