Privacy Policy
Effective date: [EFFECTIVE DATE]
Draft. This document has not been reviewed by a lawyer. Every bracketed item below needs to be filled in, and the whole thing should be read by counsel before an outside shop signs up.
This policy explains what information ShopWorks handles, why, and who else touches it. ShopWorks is operated by [LEGAL ENTITY NAME] (we, us). It covers the ShopWorks application at [WEBSITE], including the shop floor screens, the admin area, and the customer portal.
1. Two different kinds of information
It matters which of these we are talking about, because our responsibilities are different.
Your shop's working data — jobs, customers, quotes, material, drawings and photos, invoices, and the hours your crew logs. Your shop decides what goes in and what it is used for. We hold it and process it on your instructions, and for nothing else.
Account and billing data— the shop name, the administrator's name and email, subscription status, and support correspondence. This we handle for our own purposes: running accounts, taking payment, and providing support.
2. What we collect
- People with logins. Name, email address, role (administrator, employee, or customer-portal user), which shop they belong to, and whether the login is active. Passwords are never visible to us — they are stored, hashed, by our authentication provider.
- Work records. Everything your shop enters: jobs, tasks, customers and their contact details, pricing and cost figures, inventory and material records, notes, uploaded photos and drawings, messages between your shop and its customers, and time entries showing which employee worked on what and for how long.
- Technical records. Standard server and application logs — IP address, browser type, pages requested, timestamps, and error details — kept to keep the service running and secure.
- Cookies. ShopWorks sets a session cookie so you stay signed in. That is what it is for. There are no advertising or tracking cookies, and we do not run third-party analytics that follow you across other sites.
We do not ask for and do not want government identifiers, payment card numbers stored in the app, health information, or any other sensitive category of personal information. Please do not put it in job notes.
3. How we use it
- To provide ShopWorks and the features your shop turns on.
- To authenticate people and keep shops separated from each other.
- To send the emails the app depends on — invitations to new users and password resets.
- To diagnose faults, fix bugs, and keep the service secure.
- To bill for the subscription and to answer support requests.
- To send you service notices about outages, changes, or your account.
We do not sell personal information, we do not share it for advertising, and we do not use your shop's working data to build products for anyone else.
4. Who else touches the data
We use a small number of service providers to run ShopWorks. They act on our instructions and are bound to protect the data.
- Supabase — the database, login system, file storage for photos and drawings, and the delivery of invitation and password-reset emails. Data is stored in [REGION].
- Vercel — hosting and delivery of the application itself.
- [PAYMENT PROCESSOR] — subscription payments. Card details go to them directly and are never stored by ShopWorks.
- [EMAIL PROVIDER, IF SEPARATE] — sending application email.
We will also disclose information where the law requires it, and, if our business is ever sold or merged, to the acquirer — in which case this policy continues to apply until you are told otherwise.
One shop never sees another shop's data. Every record carries the shop it belongs to, and the database enforces that boundary on every read and write rather than relying on the application to remember.
5. How long we keep it
- Your shop's working data is kept for as long as the account is active, and for at least [90] days after a subscription ends, so that paying again restores everything.
- Time entries are removed automatically 30 days after the job they belong to has been invoiced. The totals stay on the job; the individual clock-in records do not.
- Technical logs are kept for [30-90] days.
- Account and billing records are kept for as long as the law requires, typically [7] years.
An administrator can delete records inside the app at any time. To have an entire shop's data erased, write to [CONTACT EMAIL].
6. How it is protected
- All traffic to and from ShopWorks is encrypted in transit (HTTPS).
- Data is encrypted at rest by our hosting provider.
- Access rules are enforced in the database itself, per shop and per role, so a mistake in the application cannot expose another shop's records.
- Passwords are stored hashed and are never readable by us.
- Backups are taken automatically, and access to production systems is limited to the people who need it.
No system is perfectly secure. If a breach affects your data, we will notify the affected shop administrators without undue delay and within any period the law requires.
7. If you are an employee or a customer of a shop
If you log in as an employee or through a customer portal, the shop that invited you decides what is recorded about you and why. Requests to see, correct, or delete that information should go to that shop first. If you cannot reach them, write to us at [CONTACT EMAIL] and we will help where we are able to.
Depending on where you live, you may have rights to access, correct, delete, or export your personal information, or to object to certain processing. We honor those rights as the law provides, and we will not treat you differently for exercising them.
8. Children
ShopWorks is a tool for businesses and is not intended for anyone under 16. We do not knowingly collect information from children.
9. Changes to this policy
We may update this policy. If a change materially affects how your information is handled, we will email the account administrator at least [30] days beforehand. The effective date at the top of this page always shows the current version.
10. Contact
[LEGAL ENTITY NAME]
[MAILING ADDRESS]
[CONTACT EMAIL]
See also our Terms of Service.