Privacy Policy

Last updated: September 16, 2026

Data Roles

Daily TimeCards is owned and operated by ACE Films LLC. Daily TimeCards is a business-to-business production workflow service for film and television productions.

Production companies and their authorized representatives control the production data submitted, uploaded, configured, or collected through Daily TimeCards for their projects. That production data belongs to the production company or customer that controls the project.

ACE Films LLC, operating as Daily TimeCards, processes customer production data as a service provider or processor to provide the Daily TimeCards platform, maintain project access, support production workflows, generate reports, support document handling, provide customer-authorized integrations, and provide related service functionality.

ACE Films LLC separately controls platform operational data, including account information, authentication records, access roles, support communications, billing-related information, feedback, usage records, audit records, security records, system logs, partner-integration administration records, and other information needed to operate, secure, support, bill for, maintain, and improve Daily TimeCards.

Information We Collect and Process

Daily TimeCards may collect or process the following categories of information depending on how a production company, customer, account owner, project administrator, authorized user, public submitter, or integration partner uses the service.

Customer Account Data

Daily TimeCards may collect customer account information, account owner information, billing contact information, company or production-company information, account status, customer identifiers, account role information, and related account administration details.

Authorized User and Authentication Data

Daily TimeCards may collect authorized user names, email addresses, login identifiers, authentication provider information, access roles, project memberships, account memberships, legal acceptance records, login metadata, and related access records.

Users may sign in using supported authentication methods, including email/password, Google login, and Sign in with Apple.

Project Configuration Data

Daily TimeCards may process project setup and configuration information, including project name, production name, production type, shoot dates, project location, time zone, departments, positions, project users, project roles, project settings, submission settings, document settings, Google integration settings, external API connection settings, and related project administration details.

Customer Production Data Processed Through Project Forms

Customer production data may include crew member names, crew member email addresses, optional phone numbers when provided, departments, roles or positions for a given day, work dates, start times, lunch out times, lunch in times, wrap times, meal penalty indicators or calculations when used by the customer, department notes, timecard notes, amendment notes, submission records, and other production-specific information submitted by the production company, its authorized users, or public submitters using project-specific forms.

Union or guild-related project configuration, when used by a customer for timecard or production workflow purposes, is treated as customer production data.

Uploaded Production Documents

Daily TimeCards may process uploaded production documents and related upload metadata. Uploaded production documents may include files submitted through project-specific upload portals or by authorized project users. These documents are customer production data controlled by the production company or customer responsible for the project.

API Partner and Integration Data

When Daily TimeCards evaluates, configures, or operates an external API connection, it may process partner application names, technical contact names and email addresses, optional phone numbers, technical documentation, endpoint information, integration requirements, questionnaire responses, invitation and review status, connection status, delivery records, error records, and related technical or administrative information.

Public partner-intake workflows may also process limited technical or security metadata, such as submission timestamps, browser or user-agent information, and hashed network identifiers where used for security, rate limiting, abuse prevention, or audit purposes. Partner-intake forms are not intended to collect passwords, private keys, access tokens, or other credential secrets.

Operational, Usage, Audit, and System Data

ACE Films LLC, operating as Daily TimeCards, may collect and control operational data needed to run and protect the platform. This may include audit logs, submission logs, integration delivery logs, email delivery logs, system logs, error logs, usage records, access records, security records, device or browser metadata, and other technical information needed for security, troubleshooting, support, compliance, abuse prevention, service operation, and maintenance.

Billing and Payment Data

Daily TimeCards may process billing-related information such as billing contact details, invoice status, customer billing records, payment status, pricing or project-scope information, customer or payment-processor identifiers, and related communications. Payments and invoices may be handled through an external payment processor such as Stripe. Daily TimeCards does not collect full payment card numbers directly through the Daily TimeCards application.

Support and Communications Data

Daily TimeCards may collect information submitted through support requests, access requests, privacy or data requests, email communications, onboarding communications, partner-intake communications, and other customer or user communications.

Google Integration Data

When a customer or authorized project administrator enables Google Drive or Google Sheets integration, Daily TimeCards may process Google account authorization information, project folder references, Google Sheets references, upload log references, folder names, file links, sync metadata, authorization tokens needed to maintain the connection, and related information needed to create, update, organize, and maintain the customer's project-specific Google Workspace workflow.

Feedback and Survey Data

A voluntary feedback submission may include production name, department or production office role, information about how Daily TimeCards was used, ratings, written comments, and any optional name or email address the respondent chooses to provide.

How We Use Information

Daily TimeCards uses information for purposes that include:

  • providing, operating, maintaining, and securing the Daily TimeCards service;
  • creating and administering customer accounts, projects, users, roles, and permissions;
  • processing customer production workflows, timecards, reports, documents, and submissions;
  • supporting customer-authorized Google Workspace and external API integrations;
  • sending service, project, support, security, billing, reminder, and operational communications;
  • processing invoices, payment status, and related commercial records;
  • investigating errors, support requests, fraud, abuse, unauthorized activity, or security events;
  • maintaining audit, compliance, legal, security, and business records;
  • responding to lawful requests and enforcing applicable agreements; and
  • evaluating and improving Daily TimeCards using operational information and voluntary feedback.

Customer production data is processed to provide customer-directed production services and related support. Daily TimeCards does not use customer production data or Google user data for third-party advertising or unrelated marketing purposes.

Google Drive, Google Sheets, and Google User Data

Daily TimeCards may offer customer-authorized Google Drive and Google Sheets integration. When enabled by a customer or authorized project administrator, Daily TimeCards may create and maintain project-specific Google Drive folders, department folders, uploaded-document folders, timecard spreadsheets, upload logs, and related project records.

The integration is intended to support the customer's Daily TimeCards project workflow. Daily TimeCards is not intended to browse, read, or manage unrelated Google Drive content. Daily TimeCards is not intended to read files that a customer independently places in a connected project folder unless access to that file is needed for the documented Daily TimeCards project workflow.

Google login and Google Workspace integration are separate functions. Google login is used for authentication. Google Drive and Google Sheets integration is used only when authorized for project workflow purposes.

Once information is created, copied, or synchronized into a customer-controlled Google Drive or Google Sheets environment, that copy is controlled through the customer's Google environment. Deleting, deactivating, or later removing corresponding information from Daily TimeCards does not automatically delete the customer's Google copy, and Google records may remain after the Daily TimeCards project ends unless the customer removes them.

Daily TimeCards' use and transfer of information received from Google Workspace APIs adheres to the Google User Data Policy, including the Limited Use requirements. Daily TimeCards does not sell Google user data, use Google Workspace user data for advertising, or use Google Workspace user data to train generalized artificial intelligence or machine learning models.

Sign in with Apple

Daily TimeCards allows users to sign in using Sign in with Apple. When a user chooses Sign in with Apple, Apple may provide Daily TimeCards with basic account information such as the user's name, email address, Apple-provided account identifier, and authentication-related information needed to create or access the user's Daily TimeCards login.

Users who sign in with Apple may choose to share their personal email address or use Apple's private email relay feature. If a user chooses Apple's private email relay feature, Daily TimeCards may receive and store a relay email address instead of the user's personal email address. Daily TimeCards may use that relay email address for login, account access, support, security notices, project access communications, and other service-related messages.

Daily TimeCards does not use Sign in with Apple information for advertising or cross-app tracking. Sign in with Apple is used to authenticate users and provide access to Daily TimeCards services assigned to that user.

Customer-Directed External API Connections

A customer or authorized project administrator may choose to enable an external API connection for a project. When a connection is enabled, Daily TimeCards may transmit copies of customer-authorized project information to the selected external application for the downstream production, payroll, accounting, or other business purpose configured for that integration.

Depending on the integration, an authorized delivery may include project identifiers, crew member names and contact information, department or position information, timecard data, work dates, times, notes, submission information, amendment status, and related project data needed for the connected service. Daily TimeCards does not provide external integration partners with direct write access to the Daily TimeCards database.

These transfers occur at the customer's direction. Once information is delivered to a customer-selected external service, that service's handling of the received copy is governed by the customer's relationship with that provider and the provider's own terms, privacy practices, and security controls. Disabling a connection or deleting information from Daily TimeCards does not automatically delete copies already delivered to the external service.

Third-Party Services

Daily TimeCards may use third-party providers to host, operate, secure, authenticate, support, bill, develop, deploy, communicate, and maintain the platform. These providers may process limited customer production data, platform operational data, account data, authentication data, billing-related data, support data, technical data, or system data as needed to provide their services to Daily TimeCards.

Supabase

Daily TimeCards uses Supabase for database hosting, authentication, storage, Edge Functions, access controls, and related backend services. Supabase may process customer production data, uploaded production documents, account data, authentication data, operational records, audit records, security records, and system data as needed to provide the Daily TimeCards platform.

Hostinger

Daily TimeCards uses Hostinger for live website hosting, domain-related services, email hosting, and related infrastructure. Hostinger may process website, hosting, email, technical, and operational information as needed to provide those services.

Google

Daily TimeCards may use Google for optional Google login, Google Drive integration, and Google Sheets integration. Google login is used for authentication. Google Drive and Google Sheets integration is used only when authorized by a customer or project administrator for project workflow purposes.

Apple

Daily TimeCards uses Apple as an optional authentication provider through Sign in with Apple. Apple may process authentication information when a user chooses to sign in with Apple. Apple may also provide a private relay email address when a user chooses to hide their personal email address.

Cloudflare Turnstile

Daily TimeCards may use Cloudflare Turnstile for bot protection and abuse prevention on public forms. Cloudflare may process technical information needed to detect automated traffic and protect public submission surfaces.

Tally (Feedback Survey)

Daily TimeCards uses Tally to host and process its optional feedback survey. Tally may process responses submitted through that survey, technical information needed to display, secure, and operate the form, and basic aggregate form-performance information such as form visits and submissions. Google reCAPTCHA is used within the survey to prevent automated spam and abuse, and Google Sheets is used to store and organize submitted responses.

Stripe

Daily TimeCards may use Stripe as an external payment processor for invoices, payment processing, billing records, payment status, and related billing communications. Daily TimeCards does not collect full payment card numbers directly through the Daily TimeCards application.

GitHub and Lovable

Daily TimeCards uses GitHub and Lovable as part of its development, code custody, build, deployment, and application maintenance workflow. These services may process technical, development, deployment, or operational information as needed to support development and maintenance of the platform.

Email and Communications Services

Daily TimeCards may use email and communication services to send service messages, support replies, access notices, project membership notices, summaries, reminders, security notices, billing communications, and related operational messages.

Feedback and Survey Data

Daily TimeCards offers an optional feedback survey. ACE Films LLC controls information submitted through that survey as operational, support, and product-feedback data. It is not customer production data processed through a production project.

ACE Films LLC may use feedback to evaluate and improve Daily TimeCards, investigate reported issues, understand how the service is used, and respond to a respondent when a response is appropriate.

Sensitive Information and Data Daily TimeCards Does Not Require

Daily TimeCards is not designed to require Social Security numbers, payroll account credentials, bank-account credentials, full payment-card numbers, passwords or authentication secrets, biometric identifiers, precise geolocation, actual wage rates, direct payroll account information, or payroll tax information as standard structured Daily TimeCards inputs.

Project document-upload features may technically allow a customer or authorized user to provide production documents that contain personal or sensitive information. Customers and users are responsible for deciding what information is appropriate, authorized, and reasonably necessary to upload for their production workflow. Users should not upload passwords, authentication secrets, private keys, or financial-account credentials.

Daily TimeCards does not independently review or endorse the contents of every uploaded production document. Production companies, payroll providers, accounting departments, studios, unions or guilds, or other responsible parties determine payroll treatment, wages, overtime, employment treatment, union or guild compliance, tax treatment, and payment obligations.

Daily TimeCards is not currently designed to make AI-generated employment, payroll, or production decisions or to train generalized artificial intelligence models on customer production data.

Cookies and Browser Storage

Daily TimeCards uses cookies, browser storage, authentication technologies, and similar storage or access technologies as described in the Cookie Policy.

The public website and application operate on separate website addresses and therefore maintain separate browser-storage and Cookie Settings records. Daily TimeCards currently does not use Analytics or Marketing technology, and materially new optional technology requires a fresh choice where required.

Security and Access Controls

Daily TimeCards uses project-based access controls, role-based permissions, server-side validation, controlled storage access, authentication controls, audit mechanisms, and administrative safeguards designed to protect customer production data and platform operational data.

Project data is logically separated by project. Access to project records depends on assigned user roles and permissions. Public forms may use bot-protection, rate-limiting, invitation-token, or validation tools. Uploaded documents and private project records are handled through controlled access systems.

No electronic system can be guaranteed completely secure. Daily TimeCards reviews and updates its security practices as the platform, integrations, and risks evolve.

Retention, Limited Post-Wrap Access, and Customer-Controlled Records

Daily TimeCards is a production workflow service, not a permanent archival-storage service. Customer access becomes limited after Full Wrap. Customers are responsible for downloading or exporting records they need before access ends.

Production operational content, including timecards, uploaded production documents, and similar project records, may be retained for a limited post-project period under Daily TimeCards retention practices and may later be deleted, de-identified, or otherwise removed when it is no longer needed. Retention periods may vary by record type and by operational, contractual, legal, security, audit, or dispute-related needs.

Core account, customer, billing, administrative, legal-acceptance, audit, security, and similar business records may be retained for longer periods, including after project access ends, where reasonably needed for business records, security, legal obligations, dispute resolution, fraud prevention, audit integrity, or enforcement of agreements.

Production-owned project records are different from individual user account records. Deleting an individual user account does not automatically delete a production account, project, timecard, uploaded production document, audit record, email-delivery record, customer-controlled Google copy, external API delivery, billing record, or other record that belongs to or supports a production project or business audit history.

Deleting, deactivating, or changing information inside Daily TimeCards does not automatically delete records already exported, downloaded, sent by email, synchronized to a customer-controlled Google environment, or transmitted to a customer-authorized external system.

Access, Export, Correction, and User Account Deletion

Authenticated users can use Profile and Data Settings within the Daily TimeCards application to request an export of available user-level account information and, where eligible, initiate deletion of their Daily TimeCards user account. The user-level export does not include production-owned project records.

User-account deletion removes login access and eligible active memberships but does not delete the production company's account, a production project, or production-owned records that must remain with the project or its audit history. Certain account deletion requests may be restricted where necessary to protect project ownership, account administration, security, legal obligations, or data integrity.

Users may also request access to, correction of, export of, or deletion of personal account data through the Support page by selecting “Privacy or data request.” Requests concerning production-owned data may require coordination with the production company or customer that controls the applicable project.

No Sale of Personal or Production Data

Daily TimeCards does not sell or rent personal information, Google user data, crew data, or customer production data to data brokers or advertisers. Daily TimeCards does not use customer production data or Google user data for third-party advertising or cross-context behavioral advertising.

Customer-directed transfers to a connected Google environment or a customer-selected external API partner are made to provide the integration chosen by the customer and are not sales of data by Daily TimeCards.

Changes to This Policy

Daily TimeCards may update this Privacy Policy as its services, integrations, data practices, or legal obligations change. Changes will be posted on this page with an updated date. When appropriate, Daily TimeCards may provide additional notice through the service or by email.

If a materially new use of information requires a new consent or other affirmative choice, Daily TimeCards will request that choice where required rather than treating an older choice as authorization for the materially new use.

Contact

For privacy or data requests, use the Support page and select “Privacy or data request.” You can also contact us at support@dailytimecards.com.