Privacy Policy
Last updated: 15 August 2026
This Privacy Policy explains how asktimer.com (“asktimer”, “we”, “us”, “our”) collects, uses, and protects personal data when you use asktimer.com and the services available on it (the “Service”). It is written to comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who we are
asktimer.com (“we”, “us”, “our”) operates the Service described in this policy.
We are the “data controller” for the personal data described in this policy, except where stated otherwise (for example, questions submitted by an event's audience — see section 3).
If you have any questions about this policy or how we handle your data, contact us at privacy@asktimer.com.
2. Personal data we collect
We collect different data depending on how you use the Service.
2.1 If you create an organizer account
- Name and email address — collected when you sign up.
- Login codes— we use passwordless authentication: we email you a temporary 6-digit code instead of storing a password. Codes expire shortly after they're issued and are deleted once used.
- Session data — a session cookie that keeps you signed in. This is strictly necessary for the Service to work and is not used for tracking or advertising.
- Event data you create — event names, speaker names, and timer configurations you set up for your own events.
- Billing data — if you subscribe to a paid plan, our payment processor, Stripe, handles your card details directly; we never see or store your full card number. We store your Stripe customer ID, subscription ID, subscription status, and renewal date so we can show your billing status and keep your account plan in sync.
- Support and contact messages — if you use our contact form, we collect the name, email address, and message you provide, plus your IP address, which we use only to prevent spam submissions (see section 5).
2.2 If you attend an event as an audience member
If you submit or vote on a question through an event's public audience page, we collect:
- The question text you submit.
- A random device identifier generated and stored in your browser (via local storage), used to attribute your questions and votes and to enforce rate limits (e.g. a limit on how many questions you can submit per minute). This identifier is not linked to your name, email address, or any other real-world identity, and we do not ask audience members to sign up or log in.
- Your IP address, used only transiently, combined with your device identifier, to enforce submission and voting rate limits. We do not store IP addresses in our database alongside your questions.
The organizer running the event you're attending controls that event, can see and moderate the questions submitted to it, and is themselves responsible for how they use that data — see section 3.
2.3 Automatically, from everyone
Like most websites, our hosting infrastructure (Cloudflare) automatically processes standard technical data to operate and secure the Service — for example, IP addresses and request metadata used for abuse prevention, rate limiting, and diagnosing technical issues. We do not use this data for advertising, and we do not run any third-party analytics or advertising trackers on asktimer.com.
3. If you're an event organizer: your responsibilities
If you create and run an event, you control the speaker names, timer setup, and audience questions collected for that event. In relation to the personal data of your event's audience (their submitted questions), you act as the data controller and we act as your data processor, processing that data only on your instructions to provide the Service (storing it, displaying it to you, and letting you moderate it).
If your audience members submit anything containing personal data about themselves or others, you are responsible for handling that appropriately — including deciding what to do with it after your event ends, and complying with your own obligations under UK GDPR if applicable to you.
4. How we use personal data, and our legal basis
| Purpose | Data used | Legal basis (UK GDPR Art. 6) |
|---|---|---|
| Creating and securing your account, passwordless login | Name, email, login codes, session cookie | Performance of a contract with you |
| Running your events (storing speakers, timers, questions) | Event data you create | Performance of a contract with you |
| Processing subscription payments and renewals | Billing data, Stripe identifiers | Performance of a contract with you |
| Sending you a summary email after an event ends | Email address, event summary content | Performance of a contract with you |
| Responding to contact form messages | Name, email, message | Legitimate interests (responding to enquiries) |
| Preventing abuse, spam, and rate-limit evasion | IP address, device identifier | Legitimate interests (keeping the Service secure and reliable) |
| Enforcing our Terms of Service | Account and usage data | Legitimate interests / legal obligation |
You can withdraw consent or object to processing based on legitimate interests at any time by contacting us — see section 9.
5. Cookies and similar technologies
We use one strictly necessary cookie to keep you signed in to your organizer account. This cookie is essential for the Service to function and does not require consent under UK cookie law (PECR), since it isn't used for analytics, advertising, or tracking.
Audience members submitting questions are identified by a random ID stored in their browser's local storage, not a cookie, for the reasons described in section 2.2.
We do not use any advertising cookies, third-party analytics cookies, or cross-site tracking technologies.
6. Who we share data with
We share personal data only with the following categories of recipients, and only as needed to run the Service:
- Cloudflare — our hosting provider. Cloudflare hosts our application, database, and email-sending infrastructure, and by necessity processes the personal data described in this policy on our behalf.
- Stripe — our payment processor, for anyone on a paid plan. Stripe processes your payment details directly and shares limited billing status information back with us.
- Law enforcement or regulators, if we're required to disclose data to comply with a legal obligation, court order, or to protect the rights, property, or safety of asktimer, our users, or others.
- A buyer or successor, if asktimer is involved in a merger, acquisition, or sale of assets — in which case we'll ensure any new owner is bound by commitments consistent with this policy.
We never sell personal data, and we never share it with third parties for their own marketing purposes.
7. International data transfers
Our infrastructure providers (Cloudflare and Stripe) operate global networks, which means personal data may be processed outside the United Kingdom, including in the United States and other countries. Where this happens, we rely on appropriate safeguards recognised under UK GDPR, such as the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or the fact that the recipient is certified under an adequacy-recognised framework. You can ask us for more detail on the safeguards in place by contacting us.
8. How long we keep data
- Account datais kept for as long as your account is active, and for a reasonable period afterward in case you wish to reactivate it, after which it is deleted or anonymised — unless we're required to keep it longer (for example, billing records for tax purposes, which we keep for the period required by UK law).
- Login codes are deleted once used, or automatically expire shortly after being issued.
- Event, speaker, timer, and audience question data is kept for as long as your account is active, so you can refer back to past events and their summaries. You can delete individual events, or your whole account, at any time — see section 9.
- Contact form messages are kept only as long as needed to resolve your enquiry.
9. Your rights under UK GDPR
You have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate or incomplete data.
- Eraseyour data (“right to be forgotten”), including by deleting your account.
- Restrict or object to certain processing.
- Data portability — receive your data in a portable format, or have it transferred to another service.
- Withdraw consent at any time, where processing is based on consent.
- Complain to the UK Information Commissioner's Office (ICO)if you believe we've mishandled your data — see ico.org.uk/make-a-complaint or call 0303 123 1113.
To exercise any of these rights, email privacy@asktimer.com. We'll respond within one month, as required by law.
10. Data security
We use industry-standard technical and organisational measures to protect personal data, including encryption in transit, access controls, and reputable infrastructure providers (Cloudflare) with strong security practices of their own. No method of transmission or storage is 100% secure, but we work to protect your data appropriately for its sensitivity.
11. Children's privacy
The Service is not directed at children, and we do not knowingly collect personal data from children under 13. If you believe a child has provided us with personal data, please contact us and we will delete it.
12. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we'll update the “Last updated” date above and, where appropriate, notify account holders by email. Continued use of the Service after an update means you accept the revised policy.
13. Contact us
For any questions about this policy or your personal data:
Email: privacy@asktimer.com
You also have the right to lodge a complaint with the ICO, the UK's supervisory authority for data protection issues: ico.org.uk.