Skip to content
WorbitaSign in

Privacy

Privacy policy

What Worbita stores, why it stores it, who else sees it, how long it is kept, and how to get it back or have it erased.

Draft — pending review

This is a draft. It describes what the product actually does, but it has not been reviewed by a lawyer and it is not final. Do not rely on it as a contract yet.

Effective
[PLACEHOLDER: effective date]
Operated by
[PLACEHOLDER: registered legal entity name]

Who is responsible

Worbita is operated by [PLACEHOLDER: registered legal entity name], at [PLACEHOLDER: registered business address]. This policy takes effect on [PLACEHOLDER: effective date].

For the records inside a client organization's account, that organization decides what is collected and why; we process it for them. For accounts, billing and the waitlist, we decide, and this policy is ours.

What is stored

Every category below is checked against the database itself. A table we store something in that this list does not account for fails our own tests, so the list cannot quietly fall behind the product.

Accounts and organizations
Your name, your email address, your role, and which client organization you belong to. Passwords are stored only as hashes. Signing in creates a session record that holds the IP address and browser user agent the session was created from. Invitations — for colleagues and for end-client viewers — are emailed to the invited address, and store that address and hashes of the invitation's link and code, never the link or code itself.
Work orders and the places they happen
What you asked for, the description you wrote, the priority, the due date, the site and the area inside it, and the on-site contact name and phone number you gave so the vendor knows who to ask for. Sites carry their address and timezone. Money fields — not-to-exceed amounts, approvals, final cost, invoice records — are stored as whole cents.
The timeline on every work order
Every status change, comment, email in or out, attachment and automatic action is appended to the work order as an entry naming who did it and when. This record is append-only: entries are never edited or deleted, which is the point of it. It belongs to the organization rather than to the person who wrote it, so deleting your own account does not remove the entries you filed — your name on them becomes “Deleted user”. Deleting the organization erases the whole record, entries and all. “What happens when something is deleted” below sets out both, exactly.
Your vendor directory
The vendors you add: business name, email address, phone number, the categories they cover, and the language they are written to in. Vendors never have accounts here. Their access to a single work order is a one-off link, stored only as a hash and revoked when it is replaced. Vendors on the paid automation tier can hold an API key, also stored only as a hash.
Email we send and email we receive
Every message we send a vendor on your behalf is recorded: who it went to, what it was, whether it arrived, and what went wrong if it did not. When a vendor replies, we store the reply — sender, recipient, subject, and the original message in object storage — and attach it to the work order it is about. Addresses that hard-bounce or report us as spam are recorded so we stop writing to them.
Files
Photos and documents attached to a work order, by you or by a vendor, are held in object storage and served only to people who can already read that work order. They are always served as downloads, never rendered inside the site.
Keeping the doors from being forced
Sign-in, sign-up, invitation codes, vendor links and the public report form each count recent attempts so a guesser cannot sit there trying. The counter is keyed to the network address the attempt came from, and the counters are short-lived — each one is discarded once its window has passed. Nothing about the attempt itself is kept: not the password, not the code, not the email address tried.
Waitlist requests
If you asked for an invitation, we keep the email address you gave and anything you chose to add — your name, your company, and your note — until we write back or you ask us to remove it.

Vendors, who never signed up for this

A vendor is a person at a business you hired. They have no account here and never created one, so they never agreed to anything with us — you added them, and you are responsible for having a reason to.

What we hold about them is what you entered (business name, email, phone, categories, language), the messages we sent them on your behalf, and the replies they sent back. A reply is stored in full — sender, recipient, subject, and the original message in object storage — and attached to the work order it is about, because the whole point of the record is that both sides can see the same thing.

A vendor who wants their details removed should ask the client organization that added them. If they ask us, we will pass it on and tell them we have.

Printed QR labels are public locators

The code inside a printed label is stored exactly as printed, not hashed, because a peeled sticker has to reprint to the same code. That means it is a locator, not a password: anyone who can read the sticker knows the code.

It is safe because it does almost nothing on its own. Scanning it while signed out shows nothing unless the organization has turned public reporting on; a public report becomes a queued request that one of your people has to accept before it is a work order; reports through one label are rate limited; and a label that has leaked is retired by rotating its code and reprinting it.

What is deliberately not stored

Passwords, vendor links, invitation codes, signup codes and API keys are stored only as hashes. We cannot recover any of them — a lost one is replaced, never retrieved.

Webhook signing secrets are the one exception, and they are stored in plain text of necessity: we sign outgoing payloads with them, and a hash cannot sign. They are per-vendor, rotatable, and a rotation keeps the previous secret for one window so a vendor mid-swap does not miss an event.

There is no analytics, no advertising, no tracking pixel and no third-party script anywhere in this product. The only cookie we set is the one that keeps you signed in.

Who else sees it

We use three sub-processors. Cloudflare and Resend are infrastructure: they hold your data to run the product for us, on our instructions, and are given none of it for their own purposes.

Stripe is not only that, and rounding it off would be the easy thing to do. It processes payments on our instructions, and it is also a controller in its own right over payment data, which it uses for fraud prevention, risk scoring and the financial regulation it is bound by. That is how a payment processor works and it is not something we can switch off on your behalf. What it is given is the payment and the account behind it — your work orders, your vendors and your timelines do not go to Stripe.

Card details are the one thing we deliberately never receive. Payment and subscription changes happen on Stripe's own pages; what we keep is Stripe's identifier for your subscription, never a card number.

  • CloudflareRuns the whole product: the site, the API, the database, file storage, and the mail routing that receives vendor replies.
  • ResendSends the email we send to your vendors, to you, and to the people you invite.
  • StripeTakes payment and runs the subscription. Your billing contact, billing address and card details are held by Stripe; we hold only its identifiers for them, never a card number.

How long it is kept

Records are kept for as long as the organization that owns them has an account, because a work-order timeline is a record of a transaction and losing half of one is worse than keeping all of it.

Deleting an account, or an organization, starts a 30-day grace period. Nothing is erased during it and the request can be cancelled at any point. When the grace passes, erasure runs and is permanent.

The two deletions do not erase the same things, and the next section sets out exactly what each one removes and what it deliberately keeps.

Waitlist entries are kept until we write back or you ask us to remove them.

What happens when something is deleted

Deleting your own account and deleting the whole organization are different operations, and the difference matters more than the word they share: one removes a person, the other removes a company's entire record of its own maintenance. Both lists below describe what the product actually does.

The short version: your account deletion takes everything that identifies you and leaves the work orders you filed standing, credited to a deleted user. The organization's deletion takes the work orders too.

  • Deleting your own account

    Anyone can ask, from their account page inside the product. Asking ends every signed-in session immediately, on every device — so a lost or shared device stops being a way in the moment you ask. You can still sign in during the 30 days, and every page then offers to cancel. An administrator who is the only administrator is refused and has to appoint another one first, or delete the organization instead: an organization with no administrator has no way back to one.

    Erased
    • Your sign-in — your name, your email address and the hash of your password.
    • Every session, on every device.
    • Your membership of the organization.
    • Any invitation or waitlist entry addressed to your email address.
    • Your email address on the record of the invitation code you signed up with. That a seat was taken is still recorded; who took it is not.
    Kept, and why
    • The work orders you filed and everything you wrote on them. They are the organization's record of work it paid for, not your personal data to withdraw, and the timeline is append-only — an entry whose author has been erased is an entry nobody can audit.
    • A row inside that organization holding your former place, with your name replaced by “Deleted user” and your email address replaced by one no mail can ever reach. It exists so those entries still have an author, and it identifies you to nobody.
  • Deleting the whole organization

    Only an administrator, from the same page. Nobody is signed out by it, and any administrator can cancel during the 30 days from a banner shown on every page. Anyone who had already asked for their own account to be deleted is erased along with it, rather than having their request quietly voided.

    Erased
    • Every work order and every entry on its timeline.
    • Every site, area, vendor, routing rule, custom field, invitation and end-client account.
    • Every record of email sent and received for you, and the files behind them — photos, documents and the original vendor messages held in object storage.
    • Every vendor API key, webhook and printed-label code.
    • The organization itself, and everybody's membership of it.
    Kept, and why
    • Everyone's sign-in. Deleting an organization does not delete the people in it — several of whom did not ask for anything. They are left without an organization and can create or join another; anyone who wants their own account gone asks for that separately.
    • The billing records behind what you were charged: your subscription, the payment events that drove it, and the usage counts an invoice was computed from. Accounting retention is the reason — a past invoice has to stay reproducible and disputable after the organization it belonged to is gone, and erasing these would leave money moved with no record of why. They hold opaque identifiers and numbers only: the billing contact's name, address and card live at Stripe rather than with us, which is what makes these rows safe to keep.

Getting your data, and having it erased

You can request deletion of your own account, and an administrator can request deletion of the whole organization, from inside the product — both with the 30-day grace described above, and each erasing what the section above says it erases. For a copy of your data, or for anything the product does not do for you yet, write to support@worbita.app and we will answer.

Depending on where you live you may have rights to access, correct, port or erase your personal data, and to object to some processing. We will honour those requests; where the data belongs to a client organization's account, we will pass the request to them and tell you we have.

Security

Every query is scoped to one organization, and the roles inside an organization are enforced by the server rather than by the interface. Vendor access is one link to one work order, expiring and revocable. Traffic is HTTPS throughout.

No system is perfect, and we would rather say what we do than claim a posture. If you find something wrong, write to us and we will take it seriously.

Children

Worbita is a tool for businesses. It is not directed at children and we do not knowingly collect anything about them.

Changes to this policy

We will post a changed version here and tell account administrators by email before a material change takes effect. Questions go to support@worbita.app.