Legal
Effective January 1, 2026
This Privacy Policy explains how Production Pay Tracker ("we", "us", "our") collects, uses, and shares information in connection with Production Pay Tracker (the "Service"). By using the Service, you agree to this Policy.
We do not sell your personal information, and we do not use your payroll data for advertising.
We retain account and payroll data for as long as your employer's account is active. If the account is terminated, data is exportable for 30 days, then deleted in the ordinary course (backups may persist for up to 90 additional days). We retain financial records for 7 years to comply with tax law.
Depending on your jurisdiction (including California CCPA/CPRA, Virginia CDPA, Colorado CPA, Connecticut CTDPA, EU GDPR), you may have the right to:
To exercise these rights, email privacy@productionpaytracker.com. We will respond within 30 days. We may need to verify your identity before fulfilling the request.
We use industry-standard measures — encrypted transport (TLS), hashed passwords (bcrypt), least-privilege access controls, and audit logging — to protect your data. No system is 100% secure; you should use a strong unique password and enable device-level protection.
The Service is not intended for individuals under 16. We do not knowingly collect personal information from children. If you believe we have, contact us and we will delete it.
Our servers are located in the United States. If you access the Service from outside the US, your data will be transferred to and processed in the US, which may have different data-protection laws than your country. By using the Service, you consent to this transfer.
We may update this Policy from time to time. If we make material changes we will notify you via email and/or an in-Service notice. Continued use after the effective date of a change constitutes acceptance.
Data protection questions: privacy@productionpaytracker.com
General support: support@productionpaytracker.com
Production Pay Tracker
Richmond, Kentucky, United States
Attorney note: Confirm the state-specific rights list, retention windows, and sub-processor list against your actual vendor stack. If you serve EU/UK users, add a GDPR-specific "Legal basis" section.