Privacy Policy
Effective date: June 10, 2026
This Privacy Policy describes how Modern Stack Systems LLC ("Modern Stack Systems," "we," "us") collects, uses, and protects information in connection with Modern Stack Systems Time(the "App"), our internal time-tracking and invoicing application available at https://stack.modernstacksystems.com.
The App is an invite-only tool for Modern Stack Systems team members and contractors. It is not offered to the general public.
1. Information we collect
Account information. When an administrator invites you and you sign in, we store your name, email address, and role. If you sign in with Google, we receive your basic Google profile (name, email address, profile picture) solely to authenticate you.
Work data. The App stores the time-tracking data you and your team enter: time entries (project, date, duration, notes), project and client assignments, billing and pay rates, and invoices generated from that data.
Google Calendar data (optional). Described in detail in Section 4.
QuickBooks data (administrators only). If an administrator connects QuickBooks Online, we store encrypted OAuth tokens and exchange invoice and customer data with Intuit QuickBooks to create client invoices.
Technical data. Standard server logs (IP address, browser type, timestamps) and authentication session cookies. We use cookies only for sign-in sessions and security — we do not use advertising or cross-site tracking cookies.
2. How we use information
We use the information above to operate the App: authenticating you, recording and reporting time, generating invoices, and securing the service. We do not sell personal information, and we do not use it for advertising.
3. Sign-in with Google
If you sign in with Google, we request only your basic profile (openid, email, profile) to identify your account. Signing in does not give the App access to your Google Calendar, Gmail, Drive, or any other Google data.
4. Google Calendar integration
The App offers an optional feature that lets a signed-in user connect their own Google Calendar to pre-fill time entries from meetings they attended.
What we access. With your explicit consent, the App requests read-only access to Google Calendar (calendar.readonly). For a day you choose to sync, we read events on your primary calendar — the event title, start time, end time, and attendee information. We never request write access and never modify, create, or delete calendar events.
Why we access it. Calendar data is used solely to suggest time entries (which meeting, how long, which project) inside your own account. It is shown only to you.
What we store. We do not store a copy of your calendar. We store only the meeting title and duration that you explicitly choose to save as a time entry, the Google Calendar event ID of saved meetings (to avoid duplicate entries), and an encrypted Google refresh token used to keep the connection active.
Sharing. We do not sell Google user data and do not share it with third parties, except as needed to host the App (Section 5). Google user data is not used for advertising and is not used to develop, improve, or train generalized artificial intelligence or machine-learning models.
Revoking access. You can disconnect Google Calendar at any time from the Settings page in the App, which deletes the stored token. You can also revoke the App access at https://myaccount.google.com/permissions.
Limited Use.Modern Stack Systems Time's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
5. Service providers
We share data only with the providers that host and operate the App:
- Supabase — database and authentication hosting
- Vercel — application hosting
- Google — sign-in and the optional Calendar integration described above
- Intuit (QuickBooks Online) — invoicing, when connected by an administrator
Each provider processes data on our behalf under its own security and privacy commitments. We do not sell data to, or share data with, advertisers or data brokers.
6. Data security
All traffic is encrypted in transit (HTTPS/TLS). OAuth tokens (Google and QuickBooks) are encrypted at rest with AES-256-GCM. Database access is restricted with row-level security so users can only access data appropriate to their role.
7. Data retention and deletion
We retain account and work data for as long as you have an account and as needed for our business records (for example, issued invoices). When you disconnect Google Calendar, the stored refresh token is deleted immediately. To request deletion of your account or data, contact us at the address below; we will delete personal data not required for legal or accounting obligations.
8. Your rights
You may request access to, correction of, or deletion of your personal data by contacting us. Team members can view and edit their own time entries directly in the App.
9. Changes to this policy
We may update this policy from time to time. Material changes will be communicated to active users. The effective date above reflects the latest revision.
10. Contact
Modern Stack Systems LLC
mac.nosek@modernstacksystems.com
See also our Terms of Service.
Sign in