All documents

Privacy notice

Version 14 · Effective September 17, 2026

This notice explains what Spanstead Works collects, why, who it is shared with, and what you can do about it. It covers the web application, the Spanstead Works desktop app, the Spanstead Works and Spanstead Works Crew mobile apps, and the customer self-service portal.

Read it alongside the Acceptable Use policy, which sets what a business may store here, and the Customer Communications and Consent document, which covers messaging.

The English text governs. This document may be shown in Spanish or another language as a courtesy. Where a translation differs from the English, the English controls, as Section 19.1 of the Legal Terms sets out.

1. Read this first: there are two different relationships here

Almost every confusing question about this product and privacy has the same answer, so it goes at the top rather than being buried in a definitions section.

When a business subscribes to Spanstead Works, we hold data about that business: its owner's name and email address, the workspace settings, the billing record, the audit log. For that data we decide what is collected and why. We are the controller.

That business then puts its own records into the platform: its customers, its jobs, its employees, its timecards. We hold that data, but we do not decide what goes into it or what it is used for. The business decides. We are the processor, acting on their instructions.

This matters to you in a specific and practical way:

If you areWho to ask about your data
The owner or an administrator of a subscribing businessUs. See Section 11.
An employee whose timecards or location are in the systemYour employer. They control it and we cannot answer for them.
A customer of a business that uses Spanstead WorksThat business.

If you contact us about data we hold as a processor, we will not disclose or delete it at your request. We will tell you which business controls it and, where we can, pass your request on to them. Acting otherwise would mean handing one company's records to whoever asked convincingly.

2. What we collect

2.1 Account and identity

DataWhy we hold it
Name and email addressSigning in, notifications, and addressing you
Password hash, passkeys, and two-factor secretsAuthentication
Session records and last sign-in timeKeeping you signed in, and detecting unfamiliar access
Profile image, if you set oneDisplay only

We never store your password itself. Recovery codes and two-factor secrets are stored so that authentication can verify them, and for no other purpose.

2.2 Operational records your business enters

Customers, leads, jobs, schedules, estimates, invoices, payments, inventory, vehicles, equipment, files and photographs, notes, and any custom fields your business defines. We do not inspect this content except as Section 5 describes.

2.3 Employment records

Where a business uses the HR module, the platform holds worker records, employment history, pay periods and timecards, leave and accruals, credentials, training, reviews, safety incidents, and employee-relations cases.

Certain fields are encrypted by the application itself, using a key held outside the database. These are home address, date of birth, and government identity document type and number. A copy of the database on its own does not disclose them.

Every time someone views a confidential HR category, we record that it happened, including who looked and when. Those categories are compensation, identity, medical, accommodation, employee relations, safety, and location.

2.4 Location

Worker location is captured only at specific work moments: clocking in, clocking out, arriving at a job, completing a job, and taking a job photograph. There is no continuous tracking, no route trail, no recording in the background, and no capture while off the clock. Section 2.5 describes the one background behaviour precisely.

Two conditions must both be true before a location can be recorded at all, and the database enforces them rather than the application code. The worker must be on the clock, and the worker must have a current signed acknowledgment of their employer's monitoring policy. A location record missing either one cannot be stored.

Each record holds latitude, longitude, an accuracy radius, the moment of capture, and the date it is due to be deleted. Location is deleted automatically after 90 days. A worker can see their own complete location history, with the accuracy shown beside every position, and can export it.

Withdrawing consent deletes the location history that consent authorised.

Full detail, including what employers must tell workers, is in the Workforce Monitoring Policy your employer provides.

2.5 Device permissions the apps request

PermissionWhen it is requestedIf you decline
Location, preciseAt the moment you clock in or out, arrive at or complete a job, or take a job photographThe action still completes. It is recorded without a location, and the screen tells you so.
Background location, on the crew app for Android onlyOptionally, to offer the arrival prompt described belowYou do not get the arrival prompt. You mark arrival by hand instead, exactly as before.
CameraOnly when you tap to take a job or checklist photographYou can still attach an existing image from your library.
MicrophoneOnly while you hold the record button to leave a voice note on a jobYou cannot leave voice notes. Type the message instead.
NotificationsIf you opt in to job and schedule alertsNo push notifications. Everything remains visible in the app.

Your location is never recorded in the background. Recording only ever happens at the five moments listed above, and each one requires you to tap something.

There is one background behaviour, and we describe it precisely rather than claiming there is none. On the crew app for Android, if you grant background location, the phone itself can notice when you arrive within a short distance of the job you are currently assigned to, and offer you a prompt asking whether you have arrived. That checking happens entirely on your phone. No position it observes is ever sent to us, logged, or stored anywhere. If you ignore the prompt, nothing at all is recorded and nothing about the job changes. Only tapping the prompt records a location, and it records exactly the same thing that tapping "mark arrived" by hand has always recorded.

Because that behaviour uses the background location permission, your phone may show its own background location indicator. That indicator is accurate: the app is using location in the background to decide whether to show you a prompt. It is not recording where you are.

2.6 Collected automatically

Your IP address and browser or device identifier at sign-in and when you accept an agreement, as evidence of who accepted what and from where. The audit log of significant actions taken in a workspace. Technical logs from our hosting provider.

We do not use advertising identifiers, and there is no third-party analytics or advertising software in any of our apps.

2.7 What we do not collect

No advertising or cross-app tracking identifiers. No access to your contacts, call log, or text message inbox. No health or fitness data. No biometric identifiers of any kind.

The microphone is used only for voice notes, and only while you are actively holding the record button. There is no passive or ambient listening, and the microphone is never opened by anything else in the app. Section 2.8 describes what happens to a recording.

The Acceptable Use policy separately prohibits businesses from storing biometric templates, raw payment card numbers, and medical records outside the specific fields provided for them.

2.8 Voice notes

A voice note is a recording you make deliberately, by holding a record button on a job. It is sent to us, stored as a file attached to that job's message thread, and played back by other people in your workspace who can see the job. It is part of the job's record, not a transient message.

If your workspace has switched transcription on, the recording is also sent to OpenAI, which returns the text of what was said. The transcript is stored on the message so the note is searchable and appears in the thread export. Transcription is off unless a workspace owner turns it on, and the recording is not sent anywhere when it is off.

The recording is kept for as long as the job record is kept, and is deleted when the message or the account is deleted. Deleting the message deletes the recording with it.

3. Why we use it

  1. To provide the product: running your workspace, scheduling jobs, producing invoices, and calculating timecards.
  2. To authenticate you and protect accounts against unauthorised access.
  3. To send the messages you or your business asked for. See Section 6.
  4. To bill for the subscription.
  5. To keep security and audit records, and to meet legal and tax obligations.
  6. To investigate abuse and any support request you raise.

We do not sell personal information. We do not share it for cross-context behavioural advertising. We do not use your business's operational data, your customer records, or your employee records to train machine-learning models, whether ours or anyone else's. See Section 5.

4. Who we share it with

We use the following providers, each for one stated purpose. All of them process data on our instructions under contract.

ProviderPurposeWhat reaches them
NeonDatabase hostingAll stored application data
VercelApplication hosting and file storageRequests, uploaded files and photographs
ResendTransactional and campaign emailRecipient address, message content
TwilioText messaging and WhatsApp deliveryRecipient number, message content
Meta (WhatsApp)WhatsApp messages, if a business enables them and a customer chooses WhatsAppRecipient number, message content
Stripe and SquarePayment processingPayment details, entered directly with them
OpenAIOptional AI assistance featuresOnly what Section 5 describes
CloudflareBot protection on public formsRequest metadata
QuickBooksAccounting sync, if a business enables itInvoices, payments, customer names
ShopifyMarketplace sync, if a business enables itOrders, catalog, inventory, fulfillment

Meta is the exception to the sentence above the table. It receives WhatsApp messages under its own terms with the business that connected WhatsApp, not on our instructions.

Card numbers are handled by Stripe or Square directly and are never stored on our systems.

We also disclose data where the law requires it, and would transfer it as part of a merger or sale of the business. In that case this notice continues to apply until you are given notice of a replacement.

5. AI features

Where a workspace enables AI assistance, the specific record involved, such as a job description, a message draft, or a summary request, is sent to OpenAI to produce the result. Under our agreement with them, that content is not used to train their models.

Where a workspace enables voice-note transcription, this includes the audio recording itself: the file is sent to OpenAI, which returns the text of what was said. The same agreement applies, and the recording is not used to train their models either. Section 2.8 describes the feature.

Inventory, equipment, and vehicle photo identification send the selected, normalized asset photograph to OpenAI to suggest a name. Crop out people, plates, VINs, serial labels, and confidential information before requesting identification. The photograph is retained with the saved asset under the normal operational-record retention policy.

Inventory product search and equipment/vehicle model search send the search text you submit, your interface language, and, for asset searches, the equipment/vehicle type to OpenAI. OpenAI may reformulate that text and send search queries to its web-search providers. Our application does not automatically include your inventory database, customer records, job records, photographs, or precise location in a product search. Use public product names, brands, or part numbers; do not include personal, customer, employee, or other confidential information in the query.

Unselected product matches are temporary results in the interface. Selecting a match prefills the item or asset form; the chosen details and source/purchase link become operational records only when you save. We keep usage counters for billing and request limits, not a product-search history. We request that these AI responses not be stored as retrievable API responses. This does not disable provider abuse-monitoring or other applicable retention; see OpenAI's API data controls.

Validated web-search matches may be reused from temporary server memory for up to five minutes, separately for each workspace. When a direct supplier catalog integration is enabled and you select that supplier, the search text is instead sent to its API. Amazon or eBay returns product facts, links and reference-image URLs. These direct catalog results are not stored in our web-search cache.

For optional supplier image previews, visible search results and purchase-link fields may trigger our server to request the linked public page and its image from an approved supplier or image host. Those hosts receive our server request and the requested URLs, not your browser cookies, customer records, or account credentials. We resize permitted images into temporary, metadata-free thumbnails for display. Previews are not permanently copied into asset records or sent to an AI provider. Your browser holds preview bytes while displaying them. Supplier permissions and availability may prevent some previews from loading.

Permitted extracted thumbnails may be reused from temporary server memory for up to one minute. Images provided by an enabled Amazon or eBay catalog API are loaded directly from the supplier's image host, which receives your IP address and normal browser request information. We do not download or permanently store these API images. Clicking a reference-image search link opens Google with the displayed product name; it does not automatically import an image.

For supplier-link autofill enabled under an approved retailer arrangement, the product URL is requested from that retailer by our server. Opening a source or purchase link takes you to the retailer's own site, whose terms and privacy practices apply. Spanstead does not send customer or employee records with those lookup requests.

AI features are switched off unless a workspace turns them on. They are limited to the specific record in front of you rather than a sweep of your database, and they never make a decision on their own about pay, discipline, or employment. A person acts on the output, or does not.

6. Messages

Transactional messages, such as password resets, job confirmations, invoices, and schedule changes, are part of the service and are not marketing.

Marketing email and text messages require separate, explicit consent, which we record together with its time and source. Consenting to transactional text messages is never treated as consenting to marketing. Reply STOP to any text or WhatsApp message, or use the unsubscribe link in any marketing email. Both take effect immediately and both are recorded.

Mobile opt-in data is never shared. A phone number collected for text messaging, and the consent recorded alongside it, are not sold, rented, or shared with third parties or affiliates for their own marketing or for any purpose unrelated to sending the messages that were agreed to. They are disclosed only to the messaging carrier that delivers those messages or, for a customer who chose WhatsApp, to Meta, which delivers WhatsApp messages. Opting out of text messages does not require opting out of anything else, and consent to one category of message is never treated as consent to another.

Where a business sends messages to its own customers through the platform, that business is responsible for holding the consent it claims. See Customer Communications and Consent.

7. How long we keep it

DataRetention
Worker location90 days, then deleted automatically
Account and operational dataFor the life of the account, then as Section 8 describes
Voice-note recordings and their transcriptsWith the job message they belong to; deleted when that message or the account is deleted
Credentials for a connected sales channelDeleted the moment the channel is disconnected or the app is uninstalled
Data brought in from a connected sales channelDeleted on the schedule that channel requires — for Shopify, when it tells us the store has been removed, two days after uninstall
A customer a connected store asks us to eraseThe record's personal details are overwritten on request, and we record that we did it
Backups30 days, encrypted, then they expire
Audit logs of changesRetained for the life of the account as security evidence
Records of who viewed personal data400 days, then deleted automatically
Agreement acceptancesRetained after account deletion, as the record of what was agreed
Billing and tax recordsAs tax law requires, typically seven years

Data under a legal hold that has not been released is exempt from automatic deletion. Deleting evidence on schedule during a dispute is spoliation rather than privacy hygiene, so retention gives way to the hold until it is released.

8. Deleting your account

You can delete your account from Settings, then Account, in any of our apps, and from the account deletion page on the web without needing an app installed.

If you are the sole owner of a workspace, deleting your account deletes the entire workspace: every customer record, job, invoice, and employment record in it. Because that is irreversible and affects other people, it runs on a grace period. The request is recorded, everyone with access is notified, and the deletion runs once the period ends. Cancelling during that window stops it completely.

If you are one of several members, deleting your account removes your name, email address, password and passkeys, two-factor secrets, sessions, notifications, and workspace access.

We are precise about what that does not remove, because the honest description matters more than the reassuring one. Business records you created, such as invoices, jobs, timecards and approvals, stay with the workspace with your name detached from them. They are your employer's records, several of them are required by law to exist, and an invoice whose creator had vanished would be a broken business record rather than a private one. What you are entitled to have removed is the information that identifies you, not the fact that work happened.

Grace periods. A member deletion runs after 7 days. A workspace deletion runs after 14 days. Nothing is destroyed before then, the exact date is shown to you when you confirm, and you can cancel at any point until it arrives. The longer window on workspace deletion exists so that colleagues who are notified have time to object.

Also kept, and why: agreement acceptance records, as proof of what was agreed on both sides; billing and tax records for the statutory period; and anything under a legal hold. Everything else is removed from live systems, and from backups as those backups age out.

9. Security

We encrypt data in transit everywhere. HR identity fields and stored integration credentials are additionally encrypted by the application, with keys held outside the database. Access is role-based and defaults to the least privilege that works. Two-factor authentication is available to everyone and can be enforced across a whole organisation. We keep an append-only audit log of significant actions, and separate access logs recording who viewed personal data: every view of a confidential HR category, and every screen or export that shows a person's name, contact details or address. The access records include how many records were read at once, so a bulk export is distinguishable from someone opening a single customer.

No system is perfectly secure. If we discover a breach affecting your data we will notify you, and any regulator the law requires, without undue delay.

To report a vulnerability, write to security@spanstead.com.

10. Children

Spanstead Works is a business tool and is not directed at children.

Customer accounts require you to be 18 or older. Worker accounts require you to be 16 or older, because 16- and 17-year-olds are lawfully employed in the trades this product serves.

Employers must not enter records for workers under 16. Before enabling location capture for a worker under 18, an employer must confirm that the parental consent requirements of their state are met. A minor acknowledgment on its own may not be sufficient.

11. Your rights

Depending on where you live, you may have the right to access, correct, delete, or export your personal information, and to appeal a refusal. Several US states also give you the right not to be treated differently for exercising these rights.

Contact privacy@spanstead.com. We will verify who you are before acting. That verification exists to stop someone else from obtaining your data by asking for it.

For data we hold as a processor, as described in Section 1, we will direct you to the business that controls it. That is a limit on what we may lawfully do, not a refusal.

You can exercise two rights without contacting anyone. You can export your own location history from your worker profile, and you can delete your account as described in Section 8.

12. Where data is held

Data is stored and processed in the United States. Spanstead Works is offered to businesses in the United States only and is not directed at the European Union, the United Kingdom, or other jurisdictions.

13. Changes

Material changes create a new version, which account owners are asked to accept before continuing to use the product. The version and effective date appear at the top of this document. Previous versions you accepted are listed in Settings, under Agreements.

14. Contact

PurposeAddress
Privacy requests and questionsprivacy@spanstead.com
Legal noticeslegal@spanstead.com
Security reportssecurity@spanstead.com
Supportsupport@spanstead.com
Support telephone913-221-6755

Written requests and legal notices can be sent to:

Spanstead LLC, 11701 Roe Ave, Ste D PMB 1057, Leawood, KS 66211, United States.

Spanstead LLC is a Kansas limited liability company.