Security
How we protect TimeOff Manager and the workforce data our customers entrust to us.
Last updated: August 24, 2026
Encryption in transit
Traffic to and from TimeOff Manager is served over HTTPS (TLS). We redirect HTTP requests to HTTPS on our production domain.
Hosting and data location
Production web application, database, and uploaded files (including optional clock-in photos when enabled) are served through Cloudflare (CDN and Tunnel) as the public edge. The application origin runs on infrastructure in Canada.
Encryption at rest
Customer data is stored on our hosting provider's production infrastructure. PositionMySite does not operate a separate customer-managed encryption layer on top of the host.
Backups
Automated backups are not yet configured. We plan to use Cloudflare for backups. Contact security@timeoffmanager.us for questions about backup scope or recovery.
Access to customer data
TimeOff Manager is operated by PositionMySite. Access to production customer data is limited to authorized PositionMySite personnel who need it for hosting, support, security, or engineering work on the service.
Customer administrators control which users inside their organization can view schedules, time punches, leave records, and exports according to role permissions in the product.
Report a security issue
If you believe you have found a security vulnerability or incident involving TimeOff Manager, contact us at security@timeoffmanager.us with enough detail for us to investigate.
Please do not publicly disclose unresolved issues before we have had a reasonable opportunity to respond.