Privacy Policy

Last Updated: May 20, 2026

1. Introduction

WorkManage ("we," "us," or "our") operates the website at workmanage.cloud (the "Service"). This Privacy Policy describes how we collect, use, store, and protect your personal information when you use our Service.

By creating an account or using WorkManage, you agree to the collection and use of information in accordance with this policy.

2. Information We Collect

2.1 Account Information

When you register, we collect:

  • Email address — used for authentication and account communications
  • Name (optional) — used for display purposes and report branding
  • Password — securely hashed using bcrypt with 12 salt rounds; we never store plaintext passwords

2.2 Company Information

Optionally, you may provide:

  • Company name and address — used for branding on reports
  • Company logo — uploaded to cloud storage and used on exported PDF/Excel reports

2.3 Uploaded Business Data

In the course of using WorkManage, you may upload:

  • Supplier price lists (PDF, Excel, CSV, images)
  • Master product lists

These files are processed by our AI engine to extract product and pricing data. The extracted data is stored in our database for comparison analysis and report generation.

2.4 Usage Data

We automatically collect basic usage information including comparison history, plan usage counts, and account activity timestamps. We do not use third-party analytics services, tracking pixels, or advertising cookies.

2.5 Payment Information

Payment processing is handled entirely by Stripe, a PCI-compliant payment processor. We do not store credit card numbers, bank account details, or other payment credentials on our servers. We only store your Stripe Customer ID and Subscription ID for billing management.

3. How We Use Your Information

We use the collected information to:

  • Provide, maintain, and improve the WorkManage service
  • Process your uploaded supplier data using AI extraction
  • Generate price comparison reports branded with your company information
  • Manage your subscription and billing through Stripe
  • Communicate important account and service updates
  • Enforce our Terms and Conditions and protect against abuse

4. Data Storage & Security

  • Database: User data and comparison results are stored in a cloud-hosted database with encryption at rest.
  • File Storage: Uploaded documents and logos are stored in AWS S3 with presigned URLs for secure access.
  • Passwords: All passwords are hashed using bcrypt (12 salt rounds) before storage.
  • Transport Security: All data is transmitted over HTTPS/TLS.
  • Access Control: Authentication is required for all data access. API routes verify user sessions.
  • Input Validation: All inputs are validated and sanitized using Zod schemas to prevent injection attacks.
  • Rate Limiting: Login endpoints have rate limiting to prevent brute-force attacks.

5. Data Sharing

We do not sell, rent, or share your personal information or business data with third parties, except:

  • Stripe: For payment processing only. Subject to Stripe's Privacy Policy.
  • AI Processing: Your uploaded documents are processed through large language model (LLM) APIs for data extraction. The data is sent securely and is not used to train AI models.
  • AWS S3: For cloud file storage. Subject to AWS Privacy Policy.
  • Legal Requirements: If required by law, regulation, or valid legal process.

6. Cookies

WorkManage uses only essential session cookies required for authentication (keeping you logged in). We do not use advertising cookies, tracking cookies, or third-party analytics cookies.

7. Data Retention

We retain your account data and uploaded content for as long as your account is active. If you delete your account, we will delete your personal data and uploaded files within 30 days. Anonymized, aggregated data may be retained for service improvement.

8. Your Rights

You have the right to:

  • Access your personal data stored in our system
  • Correct any inaccurate information via your profile settings
  • Delete your account and associated data by contacting us
  • Export your comparison data via PDF and Excel exports
  • Withdraw consent by closing your account at any time

9. Children's Privacy

WorkManage is a business tool and is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that a child has provided us with personal data, we will take steps to delete it.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify users of any material changes by updating the "Last Updated" date at the top of this page. Continued use of the Service after changes constitutes acceptance of the updated policy.

11. Contact

For questions about this Privacy Policy or your personal data, contact us at [email protected]