Legal
Privacy Policy
Effective September 15, 2026 · Obstin Technologies
This Privacy Policy explains how Obstin Technologies ("Obstin," "we," "us") collects, uses, shares and protects personal information in connection with the Tinds websites (tinds.co, obstin.co), the Tinds web application, progressive web app and iOS app, and related services (the "Services"). It also explains the choices you have. By using the Services you agree to this Policy.
1. Two roles: what we control and what we process for customers
Tinds is sold to companies (each a "Customer") that use it to schedule and track time for their own crews. That creates two different situations:
- Obstin as controller. For visitors to our websites, people who request a demo or contact us, and the administrators who purchase and manage a subscription, Obstin decides how information is used. This Policy applies in full.
- Obstin as processor. Information that a Customer or its crew members put into a Tinds workspace (rosters, contact details, pay rates, schedules, punches, breaks, time off, notes, documents) is "Customer Data." The Customer decides what is collected and why; Obstin processes it on the Customer's instructions to run the Services. The Customer's own privacy notices govern that data, and requests about it should go to the Customer first (see Section 10).
2. Information we collect
Information you give us
- Account and contact information: name, work email, phone number, company name, job title, password (stored hashed by our authentication provider), and any information you send us by email or through a demo, early-access or contact form.
- Billing information: billing contact and address. Card details are collected and stored by our payment processor, not by Obstin.
- Customer Data entered in a workspace: crew member names, email addresses, phone numbers, positions and pay classes, hourly rates, availability, certifications or notes an administrator records, uploaded logos and documents, schedules, shift assignments, clock-in and clock-out times, breaks, time-off requests and their type (for example PTO, sick, bereavement), manager edits and approvals, and audit log entries recording who changed what.
- Time clock PIN: a short code used to clock in and out on a shared device.
Information collected automatically
- Usage and device information: pages and features used, actions taken, timestamps, browser type, operating system, screen size, language, referring URL and IP address.
- Log data: our hosting and database providers keep standard server logs, including IP address and request metadata, used for security and troubleshooting.
- Push notification token: if you turn on notifications in the Tinds iOS app or in your browser, Apple or your browser gives us a device token that we store with your account so we can deliver shift, time-off and message alerts. It is not used for advertising or tracking. Turning notifications off, or asking for your account to be deleted, removes it.
- Local storage: the Tinds app stores workspace data and settings in your browser so it loads quickly and keeps working with a poor connection. See Section 5.
Information from other sources
We may receive information about a company from public sources or business databases when evaluating a demo request, and from payroll or accounting tools a Customer chooses to connect.
We do not intentionally collect government identification numbers, bank account numbers, health information, biometric identifiers, or information about race, religion, or other sensitive categories. Customers should not enter such information in free-text fields. Time-off type (for example "sick") is recorded only as the label the Customer or crew member selects.
3. How we use information
We use information to:
- provide, operate, secure and support the Services, including syncing workspace data between devices and delivering schedules, call sheets and timesheets;
- create and manage accounts, authenticate users and process payments;
- respond to demo requests, questions and support tickets;
- send service communications such as invites, password resets, billing notices, security alerts and material changes to our terms;
- send marketing about Obstin products to Customer administrators and prospects, which you can opt out of at any time;
- analyze usage in aggregate to fix problems and improve features;
- detect, prevent and investigate fraud, abuse and security incidents;
- comply with law and enforce our terms.
We do not sell personal information. We do not use Customer Data to train artificial intelligence models, and we do not use it for our own marketing. We do not send marketing to crew members.
4. How we share information
- Within a workspace. Customer Data is visible to the Customer's administrators and managers according to the permissions the Customer sets. Crew members can see their own profile, schedule, time records and time-off status, and the names and roles of others on shared shifts and call sheets.
- Service providers. We use vendors that process data on our behalf under contract: Supabase (database, authentication and file storage), Netlify (website hosting and form handling), Cloudflare (DNS and email routing), Google Fonts (font delivery), our payment processor, and email delivery providers. They may use the data only to provide their services to us.
- Integrations you choose. If a Customer connects a payroll, accounting or other third-party tool, we share the data needed for that integration with that provider, which then handles it under its own policy.
- Legal and safety. We may disclose information to comply with law, subpoenas or government requests; to enforce our terms; or to protect the rights, property or safety of Obstin, our users or others. Where lawful we will notify the affected Customer of a request for its data.
- Business transfers. If Obstin is involved in a merger, acquisition, financing or sale of assets, information may be transferred as part of that transaction, subject to this Policy.
- Aggregated or de-identified data that cannot reasonably identify you or your company may be shared for any purpose.
5. Cookies and local storage
Our marketing websites use no advertising cookies and no third-party analytics beyond the basic server logs of our hosting provider. The Tinds app uses browser local storage and a service worker to keep your workspace available offline and to remember your login and settings; clearing site data in your browser removes these. Our authentication provider sets a session token so you stay signed in. Because we do not use tracking cookies, we do not respond differently to browser "Do Not Track" signals; there is nothing to turn off.
6. Location data
Tinds does not collect or track your device location. Clock-in and clock-out are recorded by time only. If we add an optional location-verified clock-in feature in the future, it will be off by default, your device will ask for permission at the moment you clock in, and we will update this Policy before it is released.
7. Data retention
- Customer Data is kept for as long as the Customer's subscription is active and for 90 days after it ends so the Customer can export it or reinstate. After that we delete or de-identify it, except backups that roll off on their own schedule (currently up to 30 days) and records we must keep by law.
- Account and billing records are kept for as long as needed to manage the relationship and for up to seven years afterward for tax and accounting purposes.
- Demo, early-access and contact form submissions are kept for up to two years unless you ask us to delete them sooner.
- Server logs are kept by our providers for short periods, generally 30 to 90 days.
A Customer can delete individual crew records or its entire workspace at any time from the app.
8. Security
We use industry-standard measures to protect information: encryption in transit (TLS) and at rest, database access rules that restrict each workspace's data to authenticated users of that workspace, hashed passwords, least-privilege access for our staff, and audit logs of changes to time records. No system is perfectly secure, and you are responsible for safeguarding your credentials and PIN and for the devices you use. If we learn of a breach affecting your personal information we will notify you and any affected Customer as required by law.
9. Your rights and choices
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information, to restrict or object to certain processing, and to not be discriminated against for exercising these rights. Residents of California, Colorado, Connecticut, Virginia and other states with privacy laws may also have the right to opt out of the sale or sharing of personal information and of targeted advertising; Obstin does not sell or share personal information for those purposes and does not engage in targeted advertising.
To exercise a right over information Obstin controls, email hello@obstin.co with the subject "Privacy request." We may need to verify your identity. We will respond within the time the applicable law requires, generally 45 days. You may authorize an agent to make a request on your behalf; we will ask for proof of that authorization. If we decline a request you may appeal by replying to our response.
Marketing email from Obstin includes an unsubscribe link. Service emails (invites, resets, billing, security) are sent as needed while you have an account.
10. Crew members: how to exercise rights
If you are a crew member and want to see, correct or delete information in a Tinds workspace, contact the company that added you. That company controls the workspace and can update or remove your record. Many corrections (your contact details, availability, time-off requests) you can make yourself in the app. If you contact Obstin about Customer Data, we will refer your request to the relevant Customer and assist them in responding, and we will not delete Customer Data without the Customer's instruction, because it may be needed for their payroll and legal records.
11. Children
The Services are not directed to children under 13 and we do not knowingly collect personal information from them. Customers may add crew members who are 16 or older, or the minimum lawful working age in their jurisdiction if higher. If you believe a child under 13 has provided us with information, contact us and we will delete it.
12. Where data is stored
Obstin is based in the United States and our providers store data in U.S. data centers. If you use the Services from outside the United States, you understand that your information will be transferred to and processed in the United States, where privacy laws may differ from those in your country.
13. Changes to this Policy
We may update this Policy. We will post the new version with a new effective date and, for material changes, notify Customer administrators by email or in the app before the change takes effect. Your continued use after that date means you accept the updated Policy.
14. Contact
Obstin Technologies
Stamford, Connecticut
hello@obstin.co · (203) 517-0411