WorkTool Privacy Policy
Last updated: August 1, 2026
This Privacy Policy for The Worktool, Inc., a Delaware corporation (“WorkTool,” “we,” “us,” or “our”), describes how and why we may access, collect, store, use, and share (“process”) your personal information when you use our services (the “Services”), including when you:
- Visit our website at https://worktool.com, or any website of ours that links to this Privacy Policy;
- Download and use our mobile application (WorkTool), or any other application of ours that links to this Privacy Policy;
- Use WorkTool features such as the social feed, professional profiles, people search, business pages, CRM, Connections, chat, the Toolbox (including Crew Timesheet), premium subscriptions, and Payouts; or
- Engage with us in other related ways, including sales, marketing, or events.
The Services are open to businesses, sole proprietors, freelancers, and individual professionals across any industry — construction and the skilled trades are a primary but non-exclusive focus. This Privacy Policy applies to everyone who uses the Services, whatever your industry. Where this Policy uses words such as “trade,” “job,” “crew,” or “on-site,” read them as referring to your own industry, engagement, team, or place of work.
Questions or concerns? Reading this Privacy Policy will help you understand your privacy rights and choices. If you do not agree with our policies and practices, please do not use the Services. If you have questions, contact us at office@theworktool.com.
Summary of Key Points
- What we collect. Account and profile information you provide (including resume-style professional details you choose to publish), content you post, messages you send, business records you create (CRM, timesheets, recorded payments), and technical information collected automatically. Details in Section 1.
- Payments and payouts. Payments are processed by Stripe, not by us. We never receive or store full card numbers or bank credentials, and we never hold payout funds. Stripe collects identity-verification information directly from workers who enroll in Payouts. Details in Sections 1 and 4.
- Public content is public. Your professional profile, posts, and other content you share to public areas of the Services can be viewed by other users and may be visible outside the Services.
- Connections. If a business invites you to connect and you explicitly accept, we release your email address and phone number to that business. We do not release your contact details without that acceptance. Details in Section 4.
- Data you enter about other people. Businesses can store their customers’ and workers’ contact details in the CRM (including by CSV import). The business, not WorkTool, is responsible for having the right to use that data. Details in Section 1.
- Not a WorkTool user? If someone stored your information in WorkTool (for example, a business’s CRM import or a Connections invitation), you can still ask us about it or request deletion — email office@theworktool.com. Details in Sections 1.2 and 9.
- Minors. The Services are for adults 18 and older only. We do not knowingly collect data from anyone under 18.
- Your rights. Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your personal information. Details in Sections 9 and 11.
- How to exercise your rights. Email us at office@theworktool.com. We will act on requests in accordance with applicable data protection laws.
1. What Information Do We Collect?
1.1 Personal information you provide to us
We collect personal information that you voluntarily provide when you register, use the Services, or contact us. Depending on how you use the Services, this may include:
- Account information: name, username, email address, phone number, password, and authentication data.
- Profile information: the professional details you choose to add to your public profile, such as your industry or trade, skills, licenses and certifications, work history, job title, photo, and business affiliation. Your profile is designed to be public.
- Content you create: posts, photos, videos, comments, likes, business-page content, and messages you send through chat. Public content is visible to other users (see Section 4).
- Business records you create: CRM contacts, jobs, and notes; Crew Timesheet entries (worker names and hours); and “recorded payments” — bookkeeping entries a business creates to record payments it made outside the app (for example, cash or check). WorkTool executes no money movement for recorded payments; they are ledger entries only.
- Billing information for subscriptions: if you purchase a premium subscription, our payment processor Stripe collects your payment card details directly. We receive limited information from Stripe (such as subscription status and the last four digits of your card) but never your full card number.
- Device contacts (only with your permission): if you grant the app access to your device’s contacts list (for example, to help you invite people or share content), the contacts you allow us to access are uploaded to our systems. This can include the names, phone numbers, and email addresses of people in your address book who are not WorkTool users (see Sections 1.2 and 9 for how those people can exercise rights over that data). You can decline the contacts permission, or revoke it at any time in your device settings, and the app will continue to work.
- Payouts information: see Section 1.4.
All personal information you provide must be true, complete, and accurate, and you must notify us of any changes.
Sensitive information. We do not process sensitive personal information such as racial or ethnic origin, religious or philosophical beliefs, health data, or biometric data. Two categories that California law treats as sensitive personal information are necessarily part of the Services: your account log-in credentials, and precise device location where you grant the location permission. We use both only to provide the Services — to sign you in and to show nearby businesses and tag work photos with a city — and never to infer characteristics about you. Identity-verification information collected during Stripe payout enrollment (see Section 1.4) is collected by Stripe directly, not by us.
1.2 Information you provide about other people
Some features let you enter personal information about people other than yourself:
- CRM data: businesses can store customer and worker contact details (names, phone numbers, email addresses, job records, notes), including by CSV import.
- Connections invitations: a business can invite a person to connect by providing that person’s contact information.
- Timesheets: businesses record workers’ names and hours.
- Device contacts: if you allow the app to access your device’s contacts, information about the people in your address book is uploaded to our systems (see Section 1.1).
If you enter personal information about another person, you represent that you have the right to do so and that you will use it lawfully. For customer data a business stores in its CRM, the business is responsible for that data; WorkTool processes it on the business’s behalf to provide the Services.
If someone else’s information about you is in WorkTool. You do not need a WorkTool account to have rights over your personal information. If you believe a WorkTool user has stored your information in the Services — for example, a business imported your details into its CRM, recorded you on a timesheet, sent you a Connections invitation, or a user uploaded your details from their device contacts — see Section 9 (“If you are not a WorkTool user”) for how to ask us about it or request deletion.
1.3 Information collected automatically
We automatically collect certain information when you visit, use, or navigate the Services:
- Log and usage data: IP address, device information, browser type and settings, date/time stamps, pages and features used, searches, error reports, and system activity.
- Device data: device model and manufacturer, operating system and version, device and application identifiers, mobile carrier or Internet service provider.
- Push notification tokens: if you enable push notifications, we collect a device push token (via Firebase Cloud Messaging) to deliver notifications about your account and activity. You can turn notifications off in your device settings.
- Location data: with your permission, we may collect device location to show professionals and businesses near you on the map, filter the directory by your area, and tag on-site photos with the city they were taken in. A city tag applied to an on-site photo is displayed publicly with that photo — do not enable this if you do not want the city where you took a photo shown alongside your content. You can disable location access in your device settings; some features may not work without it.
- Advertising identifier (only with your permission): on iOS, if you allow tracking when the system prompt appears, we may access your device’s advertising identifier to understand how people discover the app and to improve it. If you decline the prompt, we do not access the advertising identifier. You can change your choice at any time in your device’s privacy settings. See also Section 5.
- Photo and video metadata: photos and videos you upload may contain embedded metadata (such as EXIF data, which can include GPS coordinates). For our planned verified on-site work media feature (available for work of any kind, not only construction), media will be watermarked and EXIF/GPS metadata will be stripped before the media is posted publicly.
We also use cookies and similar technologies on our website (see Section 5).
1.4 Payments and Payouts (Stripe)
Payment processing for the Services is performed by Stripe, Inc. (“Stripe”), not by WorkTool:
- Subscriptions: Stripe collects your card details directly when you purchase a premium subscription.
- Payouts (businesses): a business that uses Payouts provides its bank account details to Stripe to fund ACH payments to its workers. WorkTool does not receive or store bank credentials.
- Payouts (workers): a worker who enrolls in Payouts creates a Stripe Express connected account. During Stripe’s onboarding, Stripe collects identity-verification information (which may include date of birth, address, and government identifiers) directly from the worker. WorkTool does not receive this identity-verification information; we receive account status information from Stripe (for example, whether onboarding is complete and whether payouts are enabled).
- Transaction records: we maintain records of payout amounts, timesheet hours, statuses, fees, and related events to operate the Services, meet our legal and financial recordkeeping obligations, and support tax reporting by the parties responsible for it (see the Terms of Use — the hiring business is responsible for Form 1099-NEC; Stripe may issue a Form 1099-K).
Stripe processes personal information under its own privacy policy, available at https://stripe.com/privacy. This is one of the limited situations where we receive information about you from a third party: Stripe sends us account, verification-status, and transaction-status information needed to run Payouts.
1.5 Google API
Our use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
2. How Do We Process Your Information?
We process your personal information for the following reasons, depending on how you interact with the Services:
- To create and manage user accounts and authenticate you.
- To deliver the Services, including displaying your profile and content to other users, powering people and business search, operating the CRM, timesheets, chat, business pages, and the Toolbox.
- To operate Payouts and subscriptions: initiating payment instructions to Stripe, tracking payout status, applying our application fee (approximately 1% per payout), enforcing payout-release gating, and maintaining transaction records.
- To operate the Connections feature, including releasing your email address and phone number to a business only after your explicit acceptance.
- To export data at your direction, such as QuickBooks invoice export (see Section 4).
- To send administrative information, such as changes to our terms and policies.
- To send push notifications you have enabled.
- To respond to inquiries and provide support.
- To send marketing communications in accordance with your preferences (you can opt out at any time — see Section 9).
- To protect the Services, including fraud monitoring, abuse prevention, and security.
- To identify usage trends and improve the Services.
- To comply with law, including financial recordkeeping and tax-reporting support obligations.
- To save or protect an individual’s vital interest, such as preventing harm.
3. What Legal Bases Do We Rely On to Process Your Information?
If you are located in the EU or UK, this section applies to you. The General Data Protection Regulation (GDPR) and UK GDPR require us to explain the legal bases we rely on to process your personal information: your consent; performance of a contract; our legitimate interests (such as improving and securing the Services), where those interests are not outweighed by your rights; compliance with legal obligations; and protection of vital interests. You may withdraw consent at any time (see Section 9).
If you are located in Canada, this section applies to you. We process your information with your express or implied consent, and in the limited additional situations permitted by applicable Canadian law (for example, investigations and fraud prevention, or where disclosure is required by subpoena or court order). You may withdraw consent at any time.
4. When and With Whom Do We Share Your Personal Information?
We may share your personal information in the following situations:
- Other users. Your professional profile is public by design. Content you share to public areas of the Services (posts, photos, videos, comments, business pages) may be viewed by all users and may be visible outside the Services — including any city tag applied to an on-site photo using your device location (see Section 1.3). Other users can see descriptions of your activity, communicate with you within the Services, and view your profile.
- Connections contact release. When a business invites you to connect and you explicitly accept the invitation, we release your email address and phone number to that business and link your accounts. This happens only on your explicit acceptance. Once released, the business’s use of your contact information is governed by the business’s own practices and applicable law, not by this Privacy Policy.
- Service providers. We share information with vendors who perform services for us under contract, including: Stripe (payments, subscriptions, and Payouts — see Section 1.4); Google (Firebase, including Cloud Messaging for push notifications and related app infrastructure); Amazon Web Services (AWS) (cloud hosting and infrastructure, storage of uploaded photos, videos, and other media on Amazon S3, and delivery of transactional email — such as account and service notices — via Amazon Simple Email Service (SES), our email provider); and our other hosting and analytics providers. Service providers are permitted to use personal information only to provide services to us.
- QuickBooks export. If a business uses the QuickBooks invoice export feature, we transmit the selected invoice data to Intuit QuickBooks at that business’s direction. Intuit’s handling of that data is governed by Intuit’s privacy policy.
- Within a business account. Information you enter in a business’s workspace (CRM records, timesheets, jobs, notes) is visible to authorized users of that business account.
- Business transfers. We may share or transfer your information in connection with any merger, sale of company assets, financing, or acquisition of all or part of our business.
- Legal obligations and safety. We may disclose information where required by law, subpoena, or court order, or where necessary to protect the rights, property, or safety of WorkTool, our users, or others.
- Affiliates. We may share your information with our affiliates, who must honor this Privacy Policy.
We do not sell your personal information for money, and we do not share it with third parties for cross-context behavioral advertising. If you permit tracking on iOS, we use your device’s advertising identifier only to understand how people discover the app (see Sections 1.3 and 5), not to serve you third-party ads.
5. Do We Use Cookies and Other Tracking Technologies?
We may use cookies and similar tracking technologies (such as web beacons and pixels) on our website to keep the Services secure, prevent crashes, fix bugs, save your preferences, and support basic site functions. We may use analytics tools to understand how the Services are used. Most web browsers let you remove or reject cookies; doing so may affect certain features.
In the mobile app, if you allow tracking when the iOS system prompt appears, we may use your device’s advertising identifier to understand how people discover the app and to improve it (see Section 1.3). If you decline, we do not access it, and you can change your choice at any time in your device’s privacy settings.
6. How Long Do We Keep Your Information?
We keep your personal information only as long as necessary for the purposes set out in this Privacy Policy, unless a longer retention period is required or permitted by law. In general, we retain personal information for as long as you have an account with us.
Financial and payout records are an exception. Records of payouts, subscription transactions, fees, and related tax-relevant data are retained after account closure for as long as required by tax, accounting, financial-recordkeeping, and other legal obligations, even if you request deletion of your other data.
When we have no ongoing legitimate business need to process your personal information, we will delete or anonymize it, or, if that is not possible (for example, because it is stored in backup archives), we will securely store it and isolate it from further processing until deletion is possible.
7. How Do We Keep Your Information Safe?
We have implemented appropriate and reasonable technical and organizational security measures designed to protect the personal information we process. However, no electronic transmission over the Internet or information storage technology can be guaranteed to be 100% secure, so we cannot promise or guarantee that hackers, cybercriminals, or other unauthorized third parties will not defeat our security and improperly collect, access, steal, or modify your information. Transmission of personal information to and from the Services is at your own risk. You should only access the Services within a secure environment.
8. Do We Collect Information From Minors?
The Services are for adults 18 years of age and older only. We do not knowingly collect data from, solicit data from, or market to anyone under 18, and we do not permit minors to use the Services. At signup you must confirm that you are at least 18. If we learn that we have collected personal information from a person under 18, we will deactivate the account and take reasonable measures to promptly delete such data from our records. If you become aware of any data we may have collected from anyone under 18, contact us at office@theworktool.com.
9. What Are Your Privacy Rights?
Depending on your state of residence in the US, or your location in regions such as the European Economic Area (EEA), United Kingdom (UK), Switzerland, or Canada, you may have rights under applicable data protection laws, which may include the right to: (i) request access to and obtain a copy of your personal information; (ii) request rectification or erasure; (iii) restrict processing; (iv) data portability, if applicable; and (v) not be subject to automated decision-making. In certain circumstances you may also have the right to object to processing. To make a request, contact us using the details in Section 13. We will consider and act on any request in accordance with applicable data protection laws.
If you are located in the EEA or UK and believe we are unlawfully processing your personal information, you have the right to complain to your Member State data protection authority or the UK data protection authority. If you are located in Switzerland, you may contact the Federal Data Protection and Information Commissioner.
Withdrawing your consent. If we rely on your consent to process your personal information, you may withdraw it at any time by contacting us using the details in Section 13. Withdrawal does not affect the lawfulness of processing before withdrawal. Note that withdrawing consent to the Connections release does not retract contact information already released to a business before withdrawal.
Opting out of marketing. You can unsubscribe from marketing communications at any time by contacting us using the details in Section 13, or by using the unsubscribe link where one is included in the email. We may still send you service-related messages necessary for the administration of your account.
Account information. You may review or change your account information at any time by logging in to your account settings. Upon your request to terminate your account, we will deactivate or delete your account and information from our active databases, except that we may retain some information to prevent fraud, troubleshoot problems, assist with investigations, enforce our legal terms, and comply with legal requirements — including the financial and payout records described in Section 6.
If you are not a WorkTool user. You do not need an account to exercise rights over your personal information. WorkTool may hold information about you even though you never signed up — for example, if a business imported your contact details into its CRM (including by CSV), recorded you on a timesheet, created a recorded-payment entry naming you, sent you a Connections invitation, or a user uploaded your details when granting the app access to their device contacts. To ask whether we hold information about you, or to request access to, correction of, or deletion of that information, email office@theworktool.com with enough detail for us to locate the information (such as the email address or phone number you believe was stored). We will verify your identity before acting on the request. For data a business stores in its workspace (such as CRM records and timesheets), WorkTool processes that data on the business’s behalf: we will forward your request to the business, assist it in honoring your request, and, where the business directs us or applicable law requires, delete the information from our systems, subject to the retention obligations described in Section 6. We honor these requests in accordance with applicable data protection laws.
If you have questions or comments about your privacy rights, email us at office@theworktool.com.
10. Controls for Do-Not-Track Features
Most web browsers and some mobile operating systems and applications include a Do-Not-Track (“DNT”) feature or setting. No uniform technology standard for recognizing and implementing DNT signals has been finalized, and we do not currently respond to DNT browser signals or other mechanisms that automatically communicate your choice not to be tracked online. If a standard we must follow is adopted, we will inform you in a revised version of this Privacy Policy. California law requires us to disclose how we respond to DNT signals; because there is no standard, we do not respond to them at this time.
11. Do United States Residents Have Specific Privacy Rights?
If you are a resident of a US state with a comprehensive consumer privacy law (including California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Tennessee, Texas, Utah, or Virginia), you may have the right to request access to and details about the personal information we maintain about you and how we have processed it, correct inaccuracies, obtain a copy, or delete your personal information, and to withdraw consent to processing. These rights may be limited in some circumstances by applicable law.
Categories of personal information we collect
We have collected the following categories of personal information in the past twelve (12) months:
| Category | Examples | Collected |
|---|---|---|
| A. Identifiers | Name, alias, postal address, phone number, unique personal identifier, online identifier, IP address, email address, account name | YES |
| B. Personal information as defined in the California Customer Records statute | Name, contact information, employment, employment history, and financial information | YES |
| C. Protected classification characteristics under state or federal law | Gender, age, date of birth, race and ethnicity, national origin, marital status | NO |
| D. Commercial information | Transaction information, purchase history, and payment information (subscription and payout transaction records) | YES |
| E. Biometric information | Fingerprints and voiceprints | NO |
| F. Internet or other similar network activity | Browsing history, search history, interactions with our Services | YES |
| G. Geolocation data | Device location | YES |
| H. Audio, electronic, sensory, or similar information | Images and audio or video recordings created in connection with our business activities | YES (photos/videos you upload) |
| I. Professional or employment-related information | Industry or trade, skills, licenses, work history, job title, business contact details | YES |
| J. Education information | Student records and directory information | NO |
| K. Inferences drawn from collected personal information | Profiles reflecting preferences and characteristics | NO |
| L. Sensitive personal information | Account log-in credentials (your password and authentication data) and precise device location | YES |
We may also collect other personal information outside these categories where you interact with us in person, online, or by phone or mail (for example, customer support, surveys, and delivery of the Services).
We use and retain the collected personal information as needed to provide the Services, generally for as long as you have an account with us, except for financial and payout records retained as described in Section 6.
Sources, use, and disclosure
Sources of personal information are described in Section 1. How we use personal information is described in Section 2. We disclose personal information to service providers under written contracts, and in the other situations described in Section 4 — including the Connections contact release, which occurs only on your explicit acceptance. We may use personal information for our own business purposes, such as internal research and technological development, which is not considered “selling.”
We do not sell personal information for money and do not share personal information for cross-context behavioral advertising, and we will not do so in the future. If you permit tracking on iOS, we use your device’s advertising identifier only to understand how people discover the app (see Sections 1.3 and 5).
Your rights
Subject to legal limits, you may have the right to: know whether we are processing your personal data; access it; correct inaccuracies; request deletion; obtain a copy; not be discriminated against for exercising your rights; and opt out of processing for targeted advertising, sale, or profiling in furtherance of decisions that produce legal or similarly significant effects. Depending on your state, you may also have rights to obtain lists of the categories or specific third parties to which we have disclosed personal data, and to limit use of sensitive personal data.
How to exercise your rights
Contact us by emailing office@theworktool.com or using the contact details in Section 13. You may designate an authorized agent to make a request on your behalf; we may deny a request from an agent who does not submit proof of valid authorization.
Request verification. We will verify your identity to confirm you are the person about whom we hold information, using the personal information already maintained by us. If we cannot verify your identity, we may request additional information solely for verification, security, and fraud-prevention purposes.
Appeals. If we decline to act on your request, you may appeal by emailing office@theworktool.com. We will inform you in writing of the action taken or not taken, with reasons. If your appeal is denied, you may submit a complaint to your state attorney general.
California “Shine The Light.” California Civil Code Section 1798.83 permits California residents to request, once a year and free of charge, information about categories of personal information (if any) we disclosed to third parties for direct marketing purposes and the names and addresses of those third parties in the preceding calendar year. Submit such a request in writing using the contact details in Section 13.
12. Do We Make Updates to This Policy?
Yes. We may update this Privacy Policy from time to time. The updated version will be indicated by an updated “Last updated” date at the top. If we make material changes, we will notify you by prominently posting a notice or by sending you a direct notification (such as email or an in-app notice), and where required we will ask you to affirmatively accept the updated policy before continuing to use the Services. We encourage you to review this Privacy Policy frequently.
13. How Can You Contact Us About This Policy?
If you have questions or comments about this Privacy Policy, email us at office@theworktool.com or write to:
The Worktool, Inc.
131 Continental Drive, Suite 305
Newark, DE 19713
United States
14. How Can You Review, Update, or Delete the Data We Collect From You?
You have the right to request access to the personal information we collect from you, details about how we have processed it, correction of inaccuracies, or deletion of your personal information, and you may have the right to withdraw consent to our processing. These rights may be limited in some circumstances by applicable law — including our obligation to retain financial and payout records as described in Section 6. To submit a request, email office@theworktool.com.
These rights are not limited to account holders. If you are not a WorkTool user but believe your personal information is stored in the Services (for example, in a business’s CRM, on a timesheet, in a Connections invitation, or from another user’s uploaded device contacts), you may submit a request the same way — see Section 9 (“If you are not a WorkTool user”) for how we handle it.
This Privacy Policy should be read together with our Terms of Use.
