Back to home

Privacy Policy

What we collect, why, and your rights. Last updated July 23, 2026.

1. Who we are

WorkBOS provides a multi-tenant business operating system. For data your organization puts into its workspace (projects, CRM records, HR records, accounting entries, files), your organization is the controller and WorkBOS processes it on the organization’s instructions. For account and website data, WorkBOS is the controller.

2. Data we collect

  • Account data — name, email, password hash, workspace membership and roles.
  • Workspace content — the business records your team creates: tasks, deals, employees, invoices, journal entries, documents, messages.
  • Usage data — feature interactions, device/browser type, approximate region, log and diagnostic events.
  • Billing data — plan, invoices, and payment status. Card details are processed by Stripe and never stored by us.
  • Referral data — if you arrive via a partner link, an attribution code (cookie) for up to 60 days.
  • Support data — messages you send us and feedback you submit.

3. How we use data

  • Provide, operate and secure the Service (including tenant isolation and abuse prevention).
  • Process payments, send transactional email (receipts, invitations, alerts).
  • Power features you invoke — including AI agents, which process your workspace content to draft proposals you approve.
  • Improve the product using aggregated, de-identified usage patterns.
  • Meet legal obligations and enforce our Terms.

We do not sell personal data. We do not use your workspace content to train third-party AI models.

4. AI processing

When you use AI features, relevant workspace content is sent to the configured AI provider (our default provider, or your own key if you bring one) solely to generate the requested output. Agent actions are logged with who approved what and when. Cost ceilings and rate limits apply.

5. Subprocessors

  • Supabase — database, authentication, storage (hosting of workspace data).
  • Vercel — application hosting and delivery.
  • Stripe — payment processing and billing.
  • Resend — transactional email delivery.
  • OpenAI (or your configured provider) — AI feature processing.
  • Cloudmersive — antivirus scanning of uploaded files.

We bind subprocessors to data-protection obligations and review this list as the platform evolves.

6. Cookies

We use strictly-necessary cookies (session, workspace routing), a functional preference store, and an optional partner-attribution cookie. Details and choices: see our Cookie Policy at /legal/cookies.

7. Retention & deletion

  • Workspace data is retained while the workspace is active.
  • Workspace deletion is self-serve: deletion is scheduled with a cancellation window, then permanently removed; archives follow a retention schedule before hard deletion.
  • Trash and soft-deleted records can be restored by admins until purged.
  • Backups roll off on a fixed schedule after deletion.
  • Billing records are kept as required by tax and accounting law.

8. Your rights

  • Access and export — workspace admins can export workspace data; you can request a copy of your account data.
  • Correction — update your profile and records directly in the product.
  • Deletion — delete your account or workspace via the self-serve flow, subject to legal retention.
  • Objection / restriction — contact us to exercise rights under applicable law (e.g. GDPR, CCPA).

To exercise rights, contact privacy@workbos.com. If you are an end user of a workspace operated by someone else (including a reseller’s client), we may direct your request to that workspace’s administrator, who controls that data.

9. Security

Every table is protected by database-enforced row-level security (tenant isolation), with role-based access control on top. Uploads are virus-scanned and fail closed. Secrets are stored encrypted. Payment webhooks are signature-verified. See /legal/security for the full overview.

10. International transfers

Data may be processed in the regions where our subprocessors operate, under appropriate safeguards (such as standard contractual clauses where required).

11. Children

The Service is not directed to children under 16 and we do not knowingly collect their data.

12. White-label workspaces

If your workspace is provided by one of our resellers under their brand, the reseller is your primary point of contact and may act as controller for your relationship with them. This policy governs WorkBOS’s processing as the underlying platform.

13. Legal bases (GDPR/UK GDPR)

  • Contract — providing the Service you signed up for (account, workspace, billing).
  • Legitimate interests — securing the platform, preventing abuse, improving the product with aggregated data.
  • Consent — optional cookies (e.g. partner attribution) and marketing communications; withdrawable any time.
  • Legal obligation — tax, accounting and lawful-request compliance.

14. US state privacy rights (CCPA/CPRA and similar)

  • We do not sell or share personal information for cross-context behavioral advertising.
  • You may request access, correction, deletion and portability of your personal information.
  • We do not discriminate against you for exercising privacy rights.
  • Authorized agents may submit requests with proof of authorization; we verify identity before acting.

15. Retention schedule (summary)

  • Workspace content — life of the workspace + deletion retention window, then purged.
  • Account data — life of the account + up to 90 days.
  • Billing records — 7 years or as required by tax law.
  • Security logs — 12 months.
  • Backups — rolling window; deleted data ages out on schedule.

16. Changes

We will notify you of material changes in-product or by email before they take effect.

17. Contact

privacy@workbos.com