Draft template — not legal advice, not reviewed by a lawyer
This document was written to describe what the software actually does. It has not been reviewed by a qualified lawyer, the bracketed placeholders below are unfilled, and it is not a substitute for advice in your operating jurisdiction. It must be reviewed and completed before the Service charges anyone.
Privacy Policy
Last updated August 29, 2026
1. Who this is about
WhoWorksWhen (“the Service”) is a scheduling tool for teams working across timezones. This policy explains what the Service stores, who else touches that data, and how to get it back or get it deleted.
The Service is operated by [legal entity name, registered address and country — fill in before launch]. For anything in this policy, write to support@whoworkswhen.com.
2. What we collect
Your account
Signing in goes through Kinde, our authentication provider. From it we store your email address, your name, and the identifier Kinde issues for you. We never see or store your password.
What you put in a workspace
When you build a team you enter details about other people: names, email addresses, job titles, timezones, pay rates and currency, working patterns, shifts, time-off overrides, announcements and invitations. This is the substance of the product, and it is stored until you delete it or ask us to.
Billing
Payments are processed by Stripe. Card numbers are entered on Stripe’s systems and never reach ours. What we store is the Stripe customer and subscription identifier, which plan you are on, and whether that subscription is active.
Technical data
Our host records standard server logs — IP address, browser user agent, the pages and API routes requested, and when. Your browser also holds a login session cookie from Kinde, plus two local-storage keys the app uses to remember which workspace you had open and to avoid re-checking your session on every page.
3. What we do not do
- We do not sell personal data, and we do not share it for advertising.
- We do not run advertising trackers or third-party ad pixels on the Service.
- We do not read your workspace data except when you ask us for support, or when we have to investigate a fault or a suspected abuse of the Service.
4. People who never signed up
Much of the data in a workspace describes teammates who did not create the account. In that relationship the customer who created the workspace decides what is stored, and we process it on their instructions. If you are a teammate and want your details corrected or removed, ask the person who invited you first — they can do it immediately from inside the app. You can also write to us and we will act on it or pass it on.
5. Why we are allowed to hold it
Where the GDPR or a similar law applies: we process account and workspace data because it is necessary to provide the Service you asked for (contract); we process logs and security data because we have a legitimate interest in keeping the Service working and unabused; and we send product or marketing email only with consent, which you can withdraw at any time.
6. Who else processes your data
These are the only third parties that receive data from the Service today. If we add one, this list changes before it happens.
| Service | Purpose | What it sees |
|---|---|---|
| Kinde | Authentication and login | Email address, name, and the identity-provider profile you sign in with |
| Stripe | Subscription billing | Billing email, card details (entered on Stripe, never on our servers), subscription and customer identifiers |
| Resend | Transactional email (invitations, account email) | Recipient email address and the contents of the message |
| Prisma Postgres | Application database hosting | Everything stored in your workspace: teammates, schedules, roles, announcements, plan state |
| Vercel | Application hosting and request logs | IP address, user agent, request paths and timestamps in operational logs |
These providers operate internationally, so your data may be stored or processed outside your own country — [confirm hosting regions and the transfer mechanism you rely on before launch].
7. How long we keep it
Workspace data is kept while the workspace exists. When you ask us to delete an account we remove it from the live database within 30 days. Backups roll off on their own schedule, so a copy can persist a short while after that. Billing records are kept as long as tax and accounting rules require.
8. Your rights, and how to use them
You can ask for a copy of your data, ask us to correct it, ask us to delete it, or object to a particular use. Email support@whoworkswhen.com from the address on the account and we will answer within 30 days. Deleting a workspace deletes the teammates, schedules and invitations inside it — that is not reversible, so export anything you need first. If you are in the EU or UK you also have the right to complain to your data protection authority.
9. Security
Traffic runs over TLS. Authentication is handled by Kinde rather than by us, and card data is handled by Stripe rather than by us. Access to the production database is limited to the people operating the Service. We are a small operation and make no certification claims: no SOC 2, no ISO 27001, no audited compliance program. If that matters for your use case, take it into account.
10. Children
The Service is a business tool and is not intended for anyone under 16. We do not knowingly collect their data.
11. Changes
If this policy changes materially we will update the date at the top and, for changes that affect how we use existing data, tell account holders by email.