Privacy policy
Last updated September 04, 2026
What Sundial keeps about you, your team and your clients, why, who else sees it, and how to get it back or have it removed. It covers the website, the app, the emails it sends and the payment pages your clients open.
1. Who we are
Sundial is operated by RI Web Gurus. For the data you put into your account we act on your instructions; for the data about you as a customer of ours, we decide how it is used. Either way, the person to write to is sundial@sundialhq.app.
2. What we collect
- Your account. Your name, email address, a hashed copy of your password, your time zone, and — if you sign in with Google — the identifier and email address Google gives us for you.
- What you put in. Your clients and their contacts, projects, services and rates, time entries and their notes, expenses and receipts, invoices, payments and recurring schedules.
- Your billing with us. The identifiers Stripe gives us for your customer record and subscription. The card itself is held by Stripe and never reaches our servers.
- Your clients' payments. When a client pays through a payment page, Stripe tells us the payment's identifier, the card brand and its last four digits. If a client chooses automatic payment, we also keep a reference to the payment method they saved with Stripe. Card numbers never reach us.
- Technical records. Server logs with the address a request came from, the browser, the page and the time, kept for a few weeks; and error reports, which name the account and the person signed in when something went wrong.
- Cookies. A session cookie to keep you signed in, a remember-me cookie if you tick that box, and a token that protects forms from forgery. No advertising or analytics cookies. On the sign-in, sign-up and password-reset pages, Google reCAPTCHA may run to tell people from automated traffic; it sets its own cookies and is subject to Google's privacy policy and terms.
3. What we use it for
- Running the service: showing your data back to you and your team, generating invoices and reports, and keeping it backed up.
- Billing you for your subscription.
- Sending the email the service needs: invoices, receipts and reminders to your clients on your behalf; invitations and password resets; a note when a timer has been left running all day; and notices about your subscription.
- Keeping the service secure, and finding and fixing faults.
- Meeting a legal obligation, where one applies.
We do not send marketing without asking first, do not sell data, and do not use what you put in to train anything.
4. Who else sees it
These are the services Sundial is built on, and what each one is given.
- Stripe takes your subscription payment, and handles your clients' card payments on your own Stripe account.
- Mailchimp Transactional (Mandrill) delivers the email Sundial sends: the address, the subject and the message.
- Google, if you sign in with it, and for reCAPTCHA on the public pages.
- Intuit QuickBooks, only if you connect it: your invoices, the clients on them and their payments.
- Harvest, only if you import from it: we read your Harvest data and send nothing back.
- Honeybadger receives error reports, so a fault can be fixed before you have to tell us about it.
- Our hosting provider, whose server in the United States runs Sundial, and our backup provider, which holds encrypted copies off that server.
The people who run Sundial can open your account to help you with it. Every such session is recorded — who did it, and when — and we only do it to answer a question you have asked or to fix something you have reported.
5. Your clients and your team
You decide what goes into your account, and we process it on your instructions. Your clients receive invoices, receipts and reminders from Sundial on your behalf, and a client who has set up automatic payment can stop it from the link in every email about it. If someone whose details are in your account asks us about them, we will refer them to you and help you answer.
6. How long we keep it
- For as long as your account exists. A lapsed subscription leaves the account readable rather than deleting it, because the invoices in it are your business records.
- If you ask us to delete your account, we do so within 30 days. Copies in backups age out within twelve months.
- Records of what you paid us, for as long as tax law requires.
7. How it is protected
Every connection is encrypted. Passwords are stored hashed, never as typed. The tokens that let Sundial act on your behalf with Stripe, Google, Harvest and QuickBooks are encrypted at rest. Backups are taken hourly, checked before they leave the server, and kept off it. Access to the server is limited to the people who run the service.
8. Your rights
You can see and correct most of what we hold about you from within the app, and export your time, expenses and invoices from it whenever you like. For anything else — a copy of your data, a correction, deletion, or an objection to how it is used — write to sundial@sundialhq.app and we will answer within 30 days. If you are in the United Kingdom or the European Union you also have the right to complain to your data protection authority.
9. Where it lives
Sundial runs on a server in the United States, and its backups are kept there too. If you use it from elsewhere, your data is transferred to and stored in the United States.
10. Children
Sundial is for businesses. It is not for anyone under 18, and we do not knowingly collect anything from them.
11. Changes to this policy
If this policy changes in a way that matters, we will email the account's owners before the change takes effect. The date at the top says when it last changed.
12. How to reach us
Anything about privacy goes to sundial@sundialhq.app.