Back to home

Privacy Policy

What we collect, why, and your rights. Last updated July 23, 2026.

1. Who we are

WorkBOS is a multi-tenant business operating system provided by Shahzad & Rainer LLC (“we”, “us”), doing business as WorkBOS. For data your organization puts into its workspace (projects, CRM records, HR records, accounting entries, files), your organization is the controller and Shahzad & Rainer LLC processes it on the organization’s instructions. For account and website data, Shahzad & Rainer LLC is the controller. Contact us through workbos.com/contact for any request under this policy, including data-subject requests.

2. Data we collect

  • Account data: name, email, password hash, workspace membership and roles.
  • Workspace content: the business records your team creates: tasks, deals, employees, invoices, journal entries, documents, messages.
  • Usage data: feature interactions, device/browser type, approximate region, log and diagnostic events.
  • Billing data: plan, invoices, and payment status. Card details are processed by Stripe and never stored by us.
  • Referral data: if you arrive via a partner link, an attribution code (cookie) for up to 60 days.
  • Support data: messages you send us and feedback you submit.

3. How we use data

  • Provide, operate and secure the Service (including tenant isolation and abuse prevention).
  • Process payments, send transactional email (receipts, invitations, alerts).
  • Power features you invoke, including AI agents, which process your workspace content to draft proposals you approve.
  • Improve the product using aggregated, de-identified usage patterns.
  • Meet legal obligations and enforce our Terms.

We do not sell personal data. We do not use your workspace content to train third-party AI models.

4. AI processing

When you use AI features, relevant workspace content is sent to the configured AI provider (our default provider, or your own key if you bring one) solely to generate the requested output. Agent actions are logged with who approved what and when. Cost ceilings and rate limits apply.

5. Subprocessors

  • Supabase: database, authentication, storage (hosting of workspace data).
  • Vercel: application hosting and delivery.
  • Stripe: payment processing and billing.
  • Resend: transactional email delivery.
  • OpenAI (or your configured provider): AI feature processing.
  • Cloudmersive: antivirus scanning of uploaded files.

We bind subprocessors to data-protection obligations and review this list as the platform evolves.

6. Cookies

We use strictly-necessary cookies (session, workspace routing), a functional preference store, and an optional partner-attribution cookie. Details and choices: see our Cookie Policy at /cookies.

7. Retention & deletion

  • Workspace data is retained while the workspace is active.
  • Workspace deletion is self-serve: deletion is scheduled with a cancellation window, then permanently removed; archives follow a retention schedule before hard deletion.
  • Trash and soft-deleted records can be restored by admins until purged.
  • Backups roll off on a fixed schedule after deletion.
  • Billing records are kept as required by tax and accounting law.

8. Your rights

  • Access and export: workspace admins can export workspace data; you can request a copy of your account data.
  • Correction: update your profile and records directly in the product.
  • Deletion: delete your account or workspace via the self-serve flow, subject to legal retention.
  • Objection / restriction: contact us to exercise rights under applicable law (e.g. GDPR, CCPA).

To exercise rights, contact privacy@workbos.com. We acknowledge a request within 5 business days and respond substantively within 30 days of verifying your identity. Where the law you are relying on allows an extension for complex requests (for example a further 60 days under CPRA, or a further two months under GDPR Art. 12(3)), we will tell you inside the first 30 days why we need it. If you are an end user of a workspace operated by someone else (including a reseller’s client), we may direct your request to that workspace’s administrator, who controls that data.

9. Security

Every table is protected by database-enforced row-level security (tenant isolation), with role-based access control on top. Uploads are virus-scanned and fail closed. Secrets are stored encrypted. Payment webhooks are signature-verified. See /security for the full overview.

10. International transfers

Your workspace data (database records, uploaded files and backups) is stored by Supabase in the ap-southeast-1 (Singapore) region. The web application and its serverless functions run on Vercel, whose primary region for us is iad1 (US East, Northern Virginia), with static assets served from Vercel’s global CDN. Personal data of individuals in the EEA, the United Kingdom and Switzerland is therefore transferred outside those territories in the ordinary course of providing the Service. The transfer mechanism is the European Commission’s Standard Contractual Clauses, together with the UK International Data Transfer Addendum for UK transfers, incorporated into our Data Processing Addendum and mirrored in our contracts with the subprocessors listed at /subprocessors. We do not offer regional data residency today: you cannot currently choose a different storage region. Full detail, including the position under each regulation, is at /compliance.

11. Children

The Service is not directed to children under 16 and we do not knowingly collect their data.

12. White-label workspaces

If your workspace is provided by one of our resellers under their brand, the reseller is your primary point of contact and may act as controller for your relationship with them. This policy governs WorkBOS’s processing as the underlying platform.

13. Legal bases (GDPR/UK GDPR)

  • Contract: providing the Service you signed up for (account, workspace, billing).
  • Legitimate interests: securing the platform, preventing abuse, improving the product with aggregated data.
  • Consent: optional cookies (e.g. partner attribution) and marketing communications; withdrawable any time.
  • Legal obligation: tax, accounting and lawful-request compliance.

14. US state privacy rights (CCPA/CPRA and similar)

  • We do not sell or share personal information for cross-context behavioral advertising.
  • You may request access, correction, deletion and portability of your personal information.
  • We do not discriminate against you for exercising privacy rights.
  • Authorized agents may submit requests with proof of authorization; we verify identity before acting.

15. Retention schedule (summary)

  • Workspace content: life of the workspace + deletion retention window, then purged.
  • Account data: life of the account + up to 90 days.
  • Billing records: 7 years or as required by tax law.
  • Security logs: 12 months.
  • Backups: rolling window; deleted data ages out on schedule.

16. Changes

We will notify you of material changes in-product or by email before they take effect.

17. Contact

privacy@workbos.com