Payweek.

Payweek — Privacy Policy

Last updated 29 July 2026

Payweek is an hours and pay tracker for agency workers. This policy explains what the app stores, where it is stored, and how to get it deleted. Payweek contains no advertising, no analytics or tracking SDKs, and does not sell or share your data with anyone.

Who is responsible

Payweek (“we”) is the data controller for the information described below. Contact: privacy@payweek.app.

What Payweek stores

Data Why Legal basis (UK GDPR)
Your email address To create your account, confirm it, and let you reset your password if you forget it. Performance of a contract
Your username To identify your account and let you sign in without typing your email address. It is not shown to anyone else. Performance of a contract
Agencies and pay rules you enter — agency name, base rate, pay cycle, rate rules, notes To calculate your expected pay. Performance of a contract
Shifts you log — date, start and end time, break, any manual rate, notes To show hours worked and expected earnings. Performance of a contract
Payslip figures you enter — period and gross/net amounts To compare what you were paid against what was expected. Performance of a contract
Your settings — display name, week start, holiday accrual % To match the app to how you are paid. Performance of a contract

Everything above is entered by you. Payweek does not collect your location, contacts, photos, device identifiers, or advertising IDs, and does not track you across other apps or websites.

Where it is stored

Your data is held in a Postgres database hosted by Supabase in the United Kingdom (London region), and is kept private to your account by database row-level security — no other user can read your rows. Traffic between the app and the server is encrypted with HTTPS, and Supabase encrypts stored data at rest. Supabase acts as our data processor; we use no other third-party processors.

Checking your password against known breaches

When you choose a password, Payweek checks whether it has appeared in a public data breach, using the Have I Been Pwned Pwned Passwords service. A password that is already in a breach list is not secret any more, and reusing one is the most common way people lose an account.

Your password is never sent anywhere. The check works by taking a SHA-1 hash of the password on your device and sending only the first five characters of that hash. The service replies with every breached hash sharing those five characters — several hundred of them — and the comparison happens on your device. The service cannot tell which password was being asked about, and never receives your password, your full hash, your email address or your username.

If the service cannot be reached, the check is skipped and your password is accepted. Nothing about this check is stored.

The app also keeps a copy of your data on your device so it works without a signal. Shifts you log offline are stored on the device until your connection returns, then sent to the server. Signing out or uninstalling the app removes this local copy.

How long we keep it

Your data is kept until you delete it or ask us to close your account. Deleting an agency in the app also deletes its shifts and rate rules. When an account is deleted, all rows belonging to it are removed.

Your rights

Under UK GDPR you can request a copy of your data, correct it, delete it, or object to how it is used. Most of these you can do yourself in the app at any time:

For anything else, email privacy@payweek.app and we will respond within 30 days. You can also complain to the UK Information Commissioner’s Office at ico.org.uk.

Children

Payweek is intended for adults in paid work. It is not directed at anyone under 18, and we do not knowingly collect data from under-18s.

Changes

If this policy changes, the date at the top will be updated and the current version will always be available at this address.