Privacy Policy
Effective date: July 3, 2026
Workstone Tools (“Workstone,” “we,” “us,” or “our”) provides the Workstone deal management platform (the “Service”) to real estate developers, operators, and general contractors, and to the investors and limited partners those customers invite to a portal within the Service. This Privacy Policy explains what data we collect, why we collect it, who we share it with, and the choices available to you.
1. Information We Collect
We collect the following categories of information:
- Account and contact information — name, email address, phone number, and role, provided when your organization invites you to the Service (team members) or when a customer invites you to their investor portal.
- Deal and financial data — information your organization enters into the Service to run its business, including deal and asset details, budgets, contracts, invoices, vendor records, and, for investor users, positions, capital calls, distributions, and related documents.
- Bank account and transaction data (Plaid) — see Section 2 below.
- Field timecard data — clock-in and clock-out timestamps, notes, cost codes, break minutes, and optional GPS coordinates if a field user allows location capture for a punch. GPS is requested for recordkeeping but is not required to submit a timecard.
- Usage and log data — information about how the Service is accessed and used, such as login timestamps and general application activity, used for security, troubleshooting, and product improvement.
2. Bank Account Data Through Plaid
Workstone offers an optional bank feed reconciliation feature. If you choose to use it, Workstone uses Plaid Inc. (“Plaid”) to let you connect a bank account. When you connect an account, Plaid provides Workstone with certain information from your bank, such as account and routing details, account balances, and transaction history, so that Workstone can display and reconcile that activity against your organization’s books.
This connection is established only through Plaid Link, which requires you to actively select your institution and authorize the connection directly with Plaid — Workstone never receives or stores your bank login credentials. By connecting an account through Plaid Link, you also agree to Plaid’s End User Privacy Policy, which describes how Plaid itself collects, uses, and shares information.
Disconnecting a bank account. You can disconnect a linked bank account at any time from the Bank Feeds settings within the Service. When you disconnect an account, Workstone stops syncing new activity for that connection; previously imported transaction records already used for reconciliation are retained in accordance with the retention terms in Section 6, since they may already be reflected in posted financial records subject to our audit trail. Removing the underlying access Plaid uses to pull your data (an “Item”) can be requested at any time by contacting support@workstone.io; data Plaid itself holds is governed by Plaid’s own privacy policy, linked above, not by Workstone.
3. How We Use Information
- To operate, maintain, and provide the features of the Service.
- To process and reconcile financial activity, including bank feed data where you’ve chosen to connect an account.
- To provide customer support and respond to inquiries.
- To send transactional emails (e.g. invitations, investor updates, capital call notices).
- To maintain the security and integrity of the Service.
4. How We Share Information
We do not sell personal information. We share information with the following categories of service providers, each engaged only to the extent needed to operate the Service:
- Supabase — database, authentication, and file storage.
- Vercel — application hosting.
- Stripe — subscription billing for Workstone customers.
- Resend — transactional and outbound email delivery.
- Anthropic — optional AI-assisted document parsing (e.g. invoice or pricing extraction), used only when a user explicitly uploads a document for parsing.
- Plaid — bank account linking and transaction data, as described in Section 2, only when a user chooses to connect a bank account.
We may also disclose information if required by law, or to protect the rights, property, or safety of Workstone, our customers, or others.
5. Security
The Service enforces row-level security on every database table, so an organization’s data is scoped and isolated at the database layer, not only in application logic. Data is encrypted in transit (TLS/HTTPS with HSTS enforced) and at rest. Financial and investor-facing records are protected by an append-only, immutable audit trail. Further detail is available in our Information Security Policy upon request to support@workstone.io.
6. Data Retention and Deletion
We retain account and organization data for as long as the account or organization remains active. Upon account or organization closure, we retain data for 90 days — to allow for recovery of an accidental closure and to wind down related processing — after which it is deleted or anonymized, except where continued retention is required for legal, audit, or financial recordkeeping obligations. Because Workstone maintains an immutable audit trail on financial and investor records, certain historical transaction records may be retained in that audit trail beyond account closure as part of our recordkeeping obligations, even where the underlying account data has been deleted. GPS coordinates on timecards are retained for no more than two years and then removed from the timecard record.
7. Your Rights and Choices
You may request access to, correction of, or deletion of your personal information by contacting support@workstone.io. Team members and investor users are invited to the Service by an organization administrator; if you no longer wish to have an account, you or your organization administrator can remove your access.
8. Children’s Privacy
The Service is intended for business use by adults and is not directed at children under 13. We do not knowingly collect personal information from children under 13.
9. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will update the effective date above and, where appropriate, notify affected organizations.
10. Contact Us
Questions about this Privacy Policy can be sent to support@workstone.io.