1. Who we are
Chronos is operated by Half Five Ltd, a company registered in England and Wales (company number 17245763) with its registered office at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. Half Five Ltd is the data controller for the personal data described in this policy. For anything privacy-related, email privacy@chronos.sh.
2. What we collect
- Account data: your name, email address and password. Passwords are stored hashed; we never see them in plain text.
- Service data: the schedules, jobs and endpoint URLs you create, job payloads you attach, and execution history (timings, statuses, retry attempts, response codes, and any result or error details your handlers report back).
- Billing data: when paid plans launch, payments will be handled by Stripe. Your card details go directly to Stripe and never touch our servers. We keep your plan, subscription status and invoicing records.
- Technical data: IP addresses, browser user agent and request logs, collected when you use the dashboard, website or API. We use these for security and debugging.
- Preferences: whether you opted in to product update emails.
We do not run analytics or advertising trackers on the website or the dashboard.
3. A note on job payloads
Chronos triggers your code; it does not run it or read your business data. The exceptions are job payloads and execution results: if you put data in a payload, we store it so we can deliver it to your handler when the job runs, and if your handler reports a result or error back, we store that as part of the execution history. Treat both as configuration and diagnostics, not as a datastore. Where you can, send an identifier and look the record up in your own system rather than embedding personal data in payloads or results. If they do contain personal data about your own users, you are the controller of that data and we process it only to deliver your jobs and show you their history.
4. How we use your data
- To provide the Service (contract): running your schedules, delivering jobs, showing execution history, account management.
- To send transactional email (contract): email verification, password resets, and alerts when a job fails or an execution times out.
- To send product updates (consent): only if you ticked the optional box at signup. Every email includes an unsubscribe link, and you can change the preference in your account settings at any time.
- To keep the Service secure (legitimate interests): rate limiting, abuse prevention, debugging with request logs.
- To meet legal obligations: tax and accounting records for payments.
We do not sell your data, and we do not share it with anyone for advertising.
5. Who we share data with
We use a small number of service providers (subprocessors) to run Chronos. They process data only on our instructions:
| Provider | Purpose | Data involved |
|---|---|---|
| Resend | Sending transactional and opt-in product emails | Email address, name, email content |
| Stripe | Payment processing (paid plans) | Billing details, card data (held by Stripe, not us) |
| Cloudflare | Content delivery, DNS and hosting of the dashboard | IP addresses, request metadata |
| OVH | Server hosting for the API | All service data listed above |
The website loads fonts from Fontshare and Google Fonts, which receive your IP address when the font files are fetched. We update this list when our infrastructure changes; the version on this page is always current.
Beyond subprocessors, we disclose data only if the law requires it, or as part of a sale or restructuring of the business (in which case this policy continues to apply to your data).
6. International transfers
Some of our providers process data outside the UK. Where they do, we rely on UK adequacy regulations or the appropriate safeguards under UK GDPR, such as the International Data Transfer Agreement or standard contractual clauses with the UK addendum.
7. Cookies
The marketing website (chronos.sh) sets no cookies. The dashboard (app.chronos.sh) uses only essential cookies for signing you in and protecting against request forgery. There are no analytics, advertising or third-party tracking cookies, which is why you do not see a cookie banner.
8. How long we keep data
- Account data: for as long as your account is active.
- Execution history: according to your plan's retention window (7 to 180 days depending on tier), after which it is deleted automatically.
- Request logs: up to 90 days, for security and debugging.
- After account closure: we delete your account and service data within 30 days, except records we must keep for legal reasons (such as invoices, kept for 6 years under UK tax rules).
9. Security
All traffic to and from Chronos is encrypted in transit with TLS. Passwords are stored hashed, API keys can be rotated at any time, and access to production systems is restricted. No system is perfectly secure; if we become aware of a breach affecting your personal data, we will notify you and the ICO as UK GDPR requires.
10. Your rights
Under UK GDPR you have the right to:
- access the personal data we hold about you;
- correct inaccurate data;
- have your data deleted;
- restrict or object to processing;
- receive your data in a portable format;
- withdraw consent at any time (for example, unsubscribing from product updates).
To exercise any of these, email privacy@chronos.sh. We respond within one month. If you are unhappy with how we handle your data, you can complain to the UK Information Commissioner's Office at ico.org.uk.
11. Children
The Service is not directed at children and we do not knowingly collect data from anyone under 18. If you believe a child has created an account, contact us and we will delete it.
12. Changes to this policy
We may update this policy as the Service evolves. For material changes we will notify you by email or in the dashboard. The date at the top of this page shows when it last changed.
13. Contact
Privacy questions and requests: privacy@chronos.sh, or by post to Half Five Ltd, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom.