Privacy Policy
Manage Working Time ("the extension") is a browser extension that augments the Zoho People attendance calendar and helps SmartOSC employees review their working time and log timesheets to the internal SRA (Smart Resource Allocation) system. This policy explains what data the extension accesses, how it is used, and what it is never used for.
1. Data the extension accesses
| Data | Why it is accessed | Where it is stored |
|---|---|---|
| Attendance data (check-in / check-out times, total hours, leave and holiday status) from Zoho People | To render the custom calendar and compute summary statistics shown to you | Read in-page and held in memory only; not persisted by the extension |
| SRA authentication token (Bearer token issued by sra.smartosc.com) | To call the SRA API on your behalf so you can view and log timesheets | Stored locally via chrome.storage.local on your device |
| SRA timesheet / project / allocation data | To show logged vs. allocated hours and let you log missing days | Fetched on demand and held in memory only |
| Your preferences (theme/colors, dark mode, default project, hours, type of work, note) | To remember your settings between sessions | Stored locally via chrome.storage.local on your device |
2. How the data is used
- To display your attendance calendar and working-time statistics.
- To submit regularization requests to Zoho People when you choose to.
- To view and create SRA timesheet entries when you choose to.
- To remember your display preferences across browser sessions.
All processing happens locally in your browser. Network requests are made
only to your employer's own domains — Zoho People
(people.smartosc.com, people.zoho.com,
people5.zoho.com) and SRA
(sra.smartosc.com, sra-api.smartosc.com) — using
the credentials you are already logged in with.
3. Data we do NOT do
- We do not sell or rent your data.
- We do not share your data with third parties.
- We do not send your data to any server controlled by the developer.
- We do not use your data for advertising, profiling, or any purpose unrelated to the extension's single function.
- We do not include or run any remotely hosted code.
- We do not use analytics or tracking tools.
4. Data storage and retention
Everything the extension persists is stored locally on your own device
through the browser's chrome.storage.local API. Nothing is
stored on any external database. You can delete all stored data at any time
by removing the extension, or via the browser's extension settings ("Clear
data"). Uninstalling the extension removes all locally stored data,
including the cached SRA token.
5. Permissions
- storage — to save your preferences and the SRA token locally on your device.
- notifications — to show optional check-in / check-out reminders.
- alarms — to schedule those reminders.
- host access — to read and write data on the Zoho People and SRA pages/APIs listed above. These are the only sites the extension can access.
6. Security
The SRA token is stored only in your browser's local extension storage and
is transmitted only to sra-api.smartosc.com over HTTPS. The
extension does not transmit it anywhere else.
7. Children's privacy
The extension is an internal workplace tool and is not directed to children under 13.
8. Changes to this policy
This policy may be updated to reflect changes to the extension. The "last updated" date at the top will indicate the latest revision.
9. Contact
For any questions about this privacy policy or your data, contact the developer at phuccntttb@gmail.com.