This Privacy Policy describes how Worklane, LLC ("Worklane," "we," "us") collects, uses, and discloses information when you use our websites, applications, and services (together, the "Services"). By using the Services you agree to the terms of this Policy.
Information we collect
Information you provide
- Account information — name, email, password, phone, company, role.
- Business content — the data you import or create in Worklane: contacts, messages, calendars, pipelines, files, website content, forms, and automation definitions.
- Payment information — handled by our payment processor (Stripe). We do not store full card numbers on our servers.
- Communications — support requests, feedback, and correspondence.
Information collected automatically
- Usage data — pages viewed, features used, actions taken, timestamps.
- Device data — IP address, browser type, operating system, device identifiers.
- Cookies and similar technologies — to keep you signed in, remember preferences, and measure usage.
Information from third parties
- Integrations you connect (e.g. Google, Stripe, Twilio, email providers) share data with Worklane at your direction.
- Public sources such as your public website when you ask Worklane to extract brand or service information.
How we use information
- To provide, operate, and improve the Services.
- To generate your CRM, site, booking, inbox, payments, and automations as requested.
- To send transactional messages (account, billing, security) and service announcements.
- To provide customer support and respond to requests.
- To detect, prevent, and address fraud, abuse, and security incidents.
- To comply with legal obligations and enforce our agreements.
Google user data
When you connect a Google account to Worklane (for example, Google Calendar or Google Business Profile), we request only the scopes needed to deliver the specific features you enabled.
What we access
- Google Calendar — your calendar list, free/busy windows, and event create/update/delete on calendars you designate, so Worklane can prevent double-bookings and push Worklane-managed appointments to Google.
- Google Business Profile — your locations and reviews, so Worklane can surface customer reviews and, when you approve a reply, post it back to Google.
- Account identity — your Google account email address, so we can label the connection in your dashboard.
How we use it
- To render availability on your booking pages and assistants.
- To mirror Worklane appointments to the Google calendars you selected for writing.
- To display external busy time you selected for blocking so staff aren't double-booked.
- To show your Google reviews inside Worklane and post operator-approved replies on your behalf.
OAuth scopes we request
When you connect a Google account, we request only the scopes required for the features you enable. You see every scope on Google's consent screen before approving; you can revoke access any time from your Google account or from Worklane.
https://www.googleapis.com/auth/calendar.calendarlist.readonly— list the calendars on your Google account so you can pick which to use with Worklane.https://www.googleapis.com/auth/calendar.freebusy— read busy windows on calendars you designate, so Worklane bookings don't double-book you.https://www.googleapis.com/auth/calendar.app.created— create, update, and delete events only on calendars Worklane creates. We cannot read or modify events on your other calendars.https://www.googleapis.com/auth/business.manage— (Google Business Profile connections only) read reviews and post operator-approved replies on your Business Profile locations.openid,userinfo.email— identify which Google account is connected and show the email on your dashboard.
How we store and retain it
OAuth access and refresh tokens are stored encrypted at rest and are used only by our servers to call the Google APIs listed above. External busy windows are cached for the near-term booking horizon and refreshed on a schedule. Google event details we write remain in Google; we do not build a long-term archive of your Google data on our servers. Disconnecting the integration revokes our tokens and removes the cached busy windows.
What we do NOT do with Google user data
Worklane's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we do not:
- sell Google user data;
- use Google user data for advertising, including retargeting, personalized, or interest-based advertising;
- use Google user data to train generalized or third-party AI / ML models;
- use Google user data for credit-worthiness or lending purposes;
- transfer or use Google user data for any purpose unrelated to providing or improving user-facing features of the Services visible to and requested by the user.
Human access to Google user data is limited to: (a) with your explicit consent, (b) for security investigations, (c) to comply with applicable law, or (d) in aggregated / anonymized form for internal operations.
Revoking access and deleting your Google data
You can disconnect a Google account at any time, in any of these ways:
- In Worklane — Dashboard → your business → Calendars (or Reviews) tab → "Disconnect" next to the connected account. This immediately revokes our tokens and deletes cached freeBusy windows we derived from that account.
- In your Google account — myaccount.google.com/permissions → "Worklane" → Remove access. Google stops honoring our tokens immediately.
- Email request — send any request for deletion or export of Google user data to privacy@worklane.ai. We respond within 7 days and delete within 30 days unless a longer period is required by law.
Calendar events Worklane wrote to Google remain in Google (we don't own them after they're created); delete them from Google Calendar directly if you want them removed.
How we share information
We do not sell personal information. We share it only as follows:
- Service providers — hosting, analytics, messaging, payment processing, error monitoring. Providers are bound by contract to protect your information.
- At your direction — integrations you connect, and recipients of messages sent through Worklane on your behalf.
- Legal and safety — where required by law, to protect rights, or to prevent harm.
- Business transfers — in connection with a merger, acquisition, or sale of assets, subject to this Policy.
Your customers' end-users
When you use Worklane to operate your own business, you are the controller of the data about your customers and end-users. Worklane processes that data as your service provider / processor, under your instructions and the terms of our agreement with you.
Retention
We retain information for as long as needed to provide the Services and for legitimate business or legal purposes. You can delete most content at any time; we delete residual copies on a rolling schedule.
Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, or export your personal information, or object to or restrict certain processing. To exercise these rights, email privacy@worklane.ai. We will verify your request and respond within the time required by applicable law.
California residents (CCPA/CPRA)
California residents may request to know, delete, or correct personal information, and opt out of "sharing" as defined under California law. We do not sell personal information.
EEA / UK residents (GDPR)
Our lawful bases are: performance of a contract, legitimate interests (to operate and secure the Services), consent (where required), and compliance with legal obligations. You may lodge a complaint with a supervisory authority.
Security
We use administrative, technical, and physical safeguards designed to protect your information:
- All traffic between your browser and Worklane is encrypted in transit over TLS 1.2+.
- OAuth access and refresh tokens, and other sensitive secrets, are encrypted at rest in our database.
- Access to production data is role-based, audit-logged, and limited to personnel who need it for operating the Services.
- Database-level row security (Postgres RLS) isolates each tenant's data so one Worklane customer's data is never visible to another.
- Security-relevant changes and administrative actions are recorded in an immutable audit log.
If we discover a security incident that affects your personal information, we will notify you without undue delay and in accordance with applicable law. Report suspected vulnerabilities to security@worklane.ai. No method of transmission or storage is perfectly secure.
Children
The Services are not directed to children under 13 (or the minimum age in your jurisdiction). We do not knowingly collect information from children.
International transfers
Worklane is operated from the United States. If you are accessing the Services from outside the U.S., your information may be transferred to, stored, and processed in the U.S. and other countries.
Changes
We may update this Policy from time to time. Material changes will be posted here with a new "last updated" date and, where appropriate, notified by email or in-product notice.
Contact
Worklane, LLC
Email: privacy@worklane.ai