Hashoff

Privacy Policy

Last updated 17 September 2026

Hashoff is a leave and time-off tracker for Slack workspaces. This policy explains what we collect, why, and what we do with it. It is written to be read rather than to be impressive.

Who is responsible for your data

When your employer installs Hashoff, they decide what employee data goes into it — they are the data controller. We process that data on their behalf as a data processor. If you are an employee and want your data corrected or removed, ask your employer's Hashoff administrator first; they can act on it directly.

What we collect

  • From Slack, when your workspace installs Hashoff: your name, display name, email address, Slack user ID, profile picture, and whether you are a workspace admin or owner. We use this to create your account and to work out who approves whose leave.
  • Leave records you create: dates, the leave type you selected, whether it is a half day, any note you write, and the decision your manager makes.
  • Configuration your administrator sets: teams, leave policies and allowances, public holidays, and your work location. They may also record your gender and marital status, used when choosing who a leave type applies to. Colleagues do not see these fields.
  • Operational logs: request timestamps and error reports, used to keep the service working.

We do not use tracking cookies, we do not run advertising, and we do not sell or share your data with anyone for marketing.

Leave types can reveal health information

If your workspace has a leave type such as "Sick Leave", then recording it against your name may reveal information about your health. Under the UK GDPR and EU GDPR this is special category data (Article 9).

We treat it accordingly: leave types are never included in messages posted to shared Slack channels, and we keep them out of our operational logs. Your employer decides who inside your organisation can see your leave records — typically you, your manager, and administrators.

Where your data is stored

On servers in the European Union, operated by Hetzner Online GmbH (Helsinki, Finland). Backups are encrypted before they leave the server.

Who else processes it

  • Hetzner Online GmbH (Germany/Finland) — hosting and databases
  • Cloudflare, Inc. — DNS, TLS, and encrypted backup storage
  • Slack Technologies — the workspace Hashoff runs in

We will update this list before adding anyone else who processes personal data.

How long we keep it

Leave history is kept for as long as your employer uses Hashoff, because leave balances are calculated from it. When someone leaves your Slack workspace we deactivate their account rather than deleting it, so their leave history stays attached to the record — but they can no longer sign in.

If your employer stops using Hashoff, we delete their data within 90 days of the account closing, unless they ask us to do it sooner.

Your rights

Depending on where you live you may have the right to access, correct, export, or delete your personal data, and to object to how it is processed. Because we act on your employer's instructions, the fastest route is usually your Hashoff administrator. You can also contact us at the address under Contact below and we will help — though for employee data we may need to involve your employer.

If you are in the EU or UK and believe we have handled your data improperly, you have the right to complain to your local data protection authority.

Security

Traffic is encrypted in transit with TLS. Slack access tokens are encrypted at rest. Each workspace's data is isolated, and access is limited to what is needed to operate the service. No system is perfectly secure, and we will not pretend otherwise — but if we ever become aware of a breach affecting your data, we will notify your employer promptly.

Changes

If we change this policy in a way that materially affects you, we will update the date at the top and tell administrators before it takes effect.

Contact

[email protected]