Privacy Policy

Last updated: 27 August 2026

Pausr is time-off management software for engineering teams. This policy explains what we collect, why we collect it, who we share it with, and how you get it back or delete it. It applies to usepausr.com and the Pausr application.

Who controls your data

Pausr is used by organizations. When your employer creates an organization, they decide who is invited, what roles people hold, and what time-off data is recorded. Your employer is the controller of that data and Pausr processes it on their behalf. Requests to correct or remove data may need to go through your organization admin.

What we collect

Account information. Your name, email address, and profile picture, supplied by Google when you sign in with Google, or by your organization when they invite you. We also store your role, your organization, and any teams you belong to.

Time-off data. Requests you submit and their dates, type, duration, any notes you add, approval status, who approved or declined them, and the reason given. Also your allowance, balance, and carryover.

Invitations. The email address, name, role, and team an admin enters when inviting someone, held until the invitation is accepted, withdrawn, or expires.

Operational data. Sign-in timestamps, and error reports used to keep the service working.

We do not collect payment card numbers. Card details are entered directly with Stripe and never reach our servers.

Google user data

Pausr requests access to your Google account for two separate purposes, and you can use the product with either, both, or neither.

Signing in. We request your email address and basic profile so we can create your account and match you to the organization that invited you. We do not receive or store your Google password.

Google Calendar. If you or an admin connects a calendar, we request calendar access in order to list the calendars available to you so you can choose one, and to create, update, and delete the calendar events that represent approved time off. We store the calendar identifiers you select, the identifiers of events Pausr itself created, and an access token so we can keep doing this. We do not read the content of your other calendar events, and we do not use calendar data for anything besides keeping the time-off entries in sync.

You can disconnect a calendar at any time from the admin calendar settings, which stops further access and discards the stored token. You can also revoke access directly at myaccount.google.com/permissions.

Limited use of Google user data

Pausr’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we do not sell Google user data, we do not use it for advertising, we do not transfer it except as necessary to provide the features described here or to comply with the law, and we do not allow humans to read it except with your explicit consent, to resolve a support issue you have raised, for security purposes, or where required by law. We do not use Google user data to develop, improve, or train generalized artificial intelligence or machine learning models.

How we use what we collect

To run the product: authenticate you, show your team’s calendar and capacity, route requests to the right approver, calculate balances, enforce notice periods and freeze periods, send the notifications your organization has enabled, and bill the organization for its plan. We do not sell personal data, and we do not use it for advertising.

Who we share it with

Inside your organization, time-off data is visible to you, to your approver, and to managers and admins. Outside it, we use these subprocessors:

  • Supabase — authentication and database hosting
  • Resend — transactional email such as invitations and request notifications
  • Stripe — subscription billing and payment processing
  • Google — sign-in, and Calendar if connected
  • Slack — only if your organization connects a workspace

We may also disclose data where we are legally required to, or to protect the security of the service.

Retention and deletion

Account and time-off data is kept while your organization’s account is active, because time-off history is a record your employer relies on. Invitations expire fourteen days after they are sent, and can be withdrawn by an admin before that.

You can request a copy of your data or deletion of your account from your profile page. An admin deleting an organization deletes its time-off data and member accounts. Backups are cycled out on a rolling basis after deletion.

Security

Data is encrypted in transit. Access between organizations is separated at the database level so one organization cannot read another’s data. Access tokens for connected services are stored server-side and are never exposed to the browser. No system is perfectly secure, and we will notify affected organizations of a breach that puts personal data at risk.

International transfers

Our subprocessors may process data outside your country, including in the United States. Where required, transfers rely on the standard contractual clauses or an equivalent safeguard.

Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal data, or to object to how it is processed. Contact us at the address below, or your organization admin, and we will respond within the period the applicable law allows.

Changes

If we change this policy materially we will update the date at the top and notify organization admins by email.

Contact

Questions about this policy or about your data: privacy@usepausr.com