Privacy Policy
Last updated: March 10, 2026
1. Introduction
Workestra App LLC ("Workestra," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform at workestra.app, including our APIs and related services (collectively, the "Service").
By using the Service, you consent to the practices described in this Privacy Policy.
2. Information We Collect
2.1 Information You Provide
- Account information: Name, email address, phone number, company name, and job title when you register or complete onboarding
- Workspace data: All content you create, upload, or store within your workspace, including contacts, projects, invoices, documents, and communications
- Payment information: Billing details and payment method information, processed securely through our payment processor (Stripe)
- Communications: Messages you send to us via email or support channels
2.2 Information Collected Automatically
- Usage data: Pages visited, features used, actions taken, timestamps, and session duration
- Device information: Browser type, operating system, device type, screen resolution, and language preferences
- Network data: IP address, approximate geographic location, and referring URLs
- Cookies and similar technologies: We use essential cookies for authentication and session management, and optional analytics cookies to improve the Service
2.3 Information from Third Parties
When you sign in using a third-party provider (Microsoft, Google, or GitHub), we receive your name, email address, and profile picture as authorized by you during the OAuth consent process. We do not access any other data from your third-party accounts without your explicit consent.
3. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve the Service
- Create and manage your account and workspace
- Process transactions and send billing-related communications
- Send service notifications (trial reminders, feature updates, security alerts)
- Respond to your inquiries and provide customer support
- Detect, prevent, and address security issues and fraud
- Analyze usage patterns to improve features and user experience
- Comply with legal obligations
We do not sell your personal information to third parties. We do not use Your Data (workspace content) for advertising or profiling purposes.
4. Data Sharing and Disclosure
We may share your information only in the following circumstances:
- Service providers: Trusted third-party providers who assist in operating the Service (hosting, payment processing, email delivery, analytics), bound by contractual obligations to protect your data
- Workspace members: Information you share within a workspace is visible to other members of that workspace, as configured by workspace roles and permissions
- Legal requirements: When required by law, regulation, legal process, or governmental request
- Business transfers: In connection with a merger, acquisition, or sale of assets, with prior notice to affected users
- With your consent: When you explicitly authorize us to share information with a third party
5. Data Storage and Security
Your Data is stored on secure servers provided by our infrastructure partners. We implement industry-standard security measures including:
- Encryption of data in transit (TLS 1.2+) and at rest (AES-256)
- Row-level security (RLS) ensuring workspace data isolation
- Regular security audits and vulnerability assessments
- Access controls and authentication requirements for all team members
- Automated backups and disaster recovery procedures
While we take commercially reasonable measures to protect your information, no method of transmission or storage is completely secure. We cannot guarantee absolute security.
6. Data Retention
We retain your account information and workspace data for as long as your account is active. If you delete your account or workspace, we will delete or anonymize your data within 30 days, except where we are required to retain it for legal, tax, or compliance purposes.
Usage logs and analytics data are retained in aggregated, anonymized form for up to 24 months to help us improve the Service.
7. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal information:
- Access: Request a copy of the personal information we hold about you
- Correction: Request correction of inaccurate or incomplete information
- Deletion: Request deletion of your personal information
- Export: Request a portable copy of your data in a standard format
- Restriction: Request restriction of processing in certain circumstances
- Objection: Object to processing based on legitimate interests
- Withdraw consent: Withdraw previously given consent at any time
To exercise any of these rights, contact us at privacy@workestra.app. We will respond within 30 days.
8. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. When we transfer data internationally, we ensure appropriate safeguards are in place in accordance with applicable data protection laws, including Standard Contractual Clauses where required.
9. Cookies
We use cookies and similar technologies for:
- Essential cookies: Required for authentication, session management, and security. These cannot be disabled.
- Analytics cookies: Help us understand how users interact with the Service. You may opt out of these via your browser settings.
We do not use advertising or tracking cookies.
10. Children's Privacy
The Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected information from a child under 18, we will take steps to delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you via the Service or by email at least 15 days before the changes take effect. Your continued use of the Service after the effective date constitutes acceptance of the updated policy.
12. Contact Us
If you have any questions or concerns about this Privacy Policy or our data practices, please contact us at:
Workestra App LLC
Email: privacy@workestra.app