Privacy Policy
WorkWright LLC
Effective 22 September 2026
The short version
WorkWright builds and hosts software for businesses. The data our software handles belongs to the client that engaged us. We process it to run the software they hired us to run, and for nothing else. We do not sell it, we do not use it for advertising, and we do not send it to any AI or machine-learning service.
Each Application has its own page describing exactly what it reads, what it writes and what it keeps. This policy covers what is true of all of them.
- Daily Entry Automation — hotel and restaurant night reports into QuickBooks Online
1. Who we are
WorkWright LLC, 561 S 50 W Circle, Saint George, UT 84770. Contact us at [email protected].
For business data processed inside an Application, WorkWright acts as a processor (or "service provider"): our client decides what the data is for, and we act on their instructions. Our client is the controller. For information about our own website visitors and prospective clients, WorkWright is the controller.
2. Two kinds of information
Client business data. Whatever the Application handles — the records it reads from a client's systems, and the records it creates in them. What this consists of varies by Application and is described on that Application's page.
Account and contact information. The names and business email addresses of the people at a client organization who use an Application, receive its reports, or administer its connections.
Operational records. Logs of what our software did: which files it processed, which calls succeeded or failed, and error detail when something went wrong. These are kept to run and repair the service.
3. What we do not collect
Unless an Application's own page says otherwise:
- We do not collect payment card numbers, bank account numbers, or government identification numbers.
- We do not collect consumer or end-customer personal data. Our Applications read business and accounting records, not customer records.
- We do not use cookies, trackers or analytics inside an Application to profile the people using it.
- We do not send client data to any large language model or AI service. Where our software extracts information from documents, it does so with deterministic code — fixed rules written for each document type — not with a model.
4. Why we process it
Only to provide the service: to run the Application, to keep it working, to investigate and fix faults, to communicate with the people at the client organization who use it, and to meet our legal obligations.
We do not use client business data to develop products for other clients, to build general-purpose datasets, or for marketing of any kind.
5. Where it lives, and who else touches it
We host on infrastructure operated by other companies. These are our subprocessors, and each has access only to what its role requires:
| Provider | Role | Location |
|---|---|---|
| Railway | Application hosting and compute | United States |
| Supabase | Database and file storage | United States |
| n8n Cloud | Scheduling and workflow orchestration | Provider-managed |
| Resend | Sending the emails an Application produces | United States |
Individual Applications also connect to systems chosen by the client — an accounting platform, a mailbox, a point-of-sale system. Those are the client's own vendors under the client's own agreements, and each Application's page names the ones it uses.
We do not sell, rent or trade data to anyone, and we do not disclose it to third parties other than the subprocessors above, except where the client directs us to, or where we are required to by law. If we are ever compelled to disclose client data by legal process, we will tell the client unless we are prohibited from doing so.
We will give clients advance notice before adding a subprocessor that handles their data.
6. How long we keep it
Retention is set per Application and stated on its page. As a default:
- Records an Application creates — the log of what it did and what it posted — are kept for the life of the engagement and then for seven years, because they support accounting records the client is themselves required to retain.
- Source documents are not retained by our Applications unless an Application's page says otherwise.
- Operational and error logs are kept for as long as they are useful for diagnosis, typically weeks rather than months, and are pruned automatically.
- Account and contact information is kept for the life of the engagement.
A client may ask us to delete their data at any time, and we will do so except where we are required to retain it by law. Write to [email protected].
7. Security
- Databases run with row-level security enabled and no public access policies. Anonymous and client-side keys can read nothing.
- Credentials — API keys, access tokens, service keys — are held in the hosting provider's encrypted environment configuration and in the orchestration platform's credential vault. They are never committed to source control and never written into project documentation.
- Access tokens for connected systems are stored encrypted at rest and are used only by the server-side service.
- Data is encrypted in transit (TLS) everywhere, and at rest by our infrastructure providers.
- Access to production systems is limited to WorkWright personnel who need it.
No system is perfectly secure. If we become aware of a breach affecting a client's data, we will notify that client without undue delay and tell them what we know, what we are doing about it, and what we recommend they do.
8. Your rights
Where an Application processes personal data, we act on our client's instructions, so requests from individuals should normally go to the organization that holds the relationship. If you contact us directly, we will forward your request to that organization and assist them in responding.
Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your personal information, or to object to or restrict its processing. We do not sell personal information and we do not share it for cross-context behavioural advertising. Exercising any of these rights will not cause us to treat you differently.
9. Where data is processed
Our infrastructure is located in the United States, and client data is processed there. Clients outside the United States should be aware that their data will be transferred to and processed in the United States.
10. Children
Our software is business software. It is not directed at children, and we do not knowingly collect information from anyone under 18.
11. Changes
We may update this policy. The effective date at the top shows when the current version took effect. Material changes will be communicated to clients before they take effect, and prior versions are available on request.
12. Contact
WorkWright LLC
561 S 50 W Circle
Saint George, UT 84770
[email protected]

