Privacy notice
Version 14 · Effective September 17, 2026
This notice explains what Spanstead Works collects, why, who it is shared with, and what you can do about it. It covers the web application, the Spanstead Works desktop app, the Spanstead Works and Spanstead Works Crew mobile apps, and the customer self-service portal.
Read it alongside the Acceptable Use policy, which sets what a business may store here, and the Customer Communications and Consent document, which covers messaging.
The English text governs. This document may be shown in Spanish or another language as a courtesy. Where a translation differs from the English, the English controls, as Section 19.1 of the Legal Terms sets out.
1. Read this first: there are two different relationships here
Almost every confusing question about this product and privacy has the same answer, so it goes at the top rather than being buried in a definitions section.
When a business subscribes to Spanstead Works, we hold data about that business: its owner's name and email address, the workspace settings, the billing record, the audit log. For that data we decide what is collected and why. We are the controller.
That business then puts its own records into the platform: its customers, its jobs, its employees, its timecards. We hold that data, but we do not decide what goes into it or what it is used for. The business decides. We are the processor, acting on their instructions.
This matters to you in a specific and practical way:
| If you are | Who to ask about your data |
|---|---|
| The owner or an administrator of a subscribing business | Us. See Section 11. |
| An employee whose timecards or location are in the system | Your employer. They control it and we cannot answer for them. |
| A customer of a business that uses Spanstead Works | That business. |
If you contact us about data we hold as a processor, we will not disclose or delete it at your request. We will tell you which business controls it and, where we can, pass your request on to them. Acting otherwise would mean handing one company's records to whoever asked convincingly.
2. What we collect
2.1 Account and identity
| Data | Why we hold it |
|---|---|
| Name and email address | Signing in, notifications, and addressing you |
| Password hash, passkeys, and two-factor secrets | Authentication |
| Session records and last sign-in time | Keeping you signed in, and detecting unfamiliar access |
| Profile image, if you set one | Display only |
We never store your password itself. Recovery codes and two-factor secrets are stored so that authentication can verify them, and for no other purpose.
2.2 Operational records your business enters
Customers, leads, jobs, schedules, estimates, invoices, payments, inventory, vehicles, equipment, files and photographs, notes, and any custom fields your business defines. We do not inspect this content except as Section 5 describes.
2.3 Employment records
Where a business uses the HR module, the platform holds worker records, employment history, pay periods and timecards, leave and accruals, credentials, training, reviews, safety incidents, and employee-relations cases.
Certain fields are encrypted by the application itself, using a key held outside the database. These are home address, date of birth, and government identity document type and number. A copy of the database on its own does not disclose them.
Every time someone views a confidential HR category, we record that it happened, including who looked and when. Those categories are compensation, identity, medical, accommodation, employee relations, safety, and location.
2.4 Location
Worker location is captured only at specific work moments: clocking in, clocking out, arriving at a job, completing a job, and taking a job photograph. There is no continuous tracking, no route trail, no recording in the background, and no capture while off the clock. Section 2.5 describes the one background behaviour precisely.
Two conditions must both be true before a location can be recorded at all, and the database enforces them rather than the application code. The worker must be on the clock, and the worker must have a current signed acknowledgment of their employer's monitoring policy. A location record missing either one cannot be stored.
Each record holds latitude, longitude, an accuracy radius, the moment of capture, and the date it is due to be deleted. Location is deleted automatically after 90 days. A worker can see their own complete location history, with the accuracy shown beside every position, and can export it.
Withdrawing consent deletes the location history that consent authorised.
Full detail, including what employers must tell workers, is in the Workforce Monitoring Policy your employer provides.
2.5 Device permissions the apps request
| Permission | When it is requested | If you decline |
|---|---|---|
| Location, precise | At the moment you clock in or out, arrive at or complete a job, or take a job photograph | The action still completes. It is recorded without a location, and the screen tells you so. |
| Background location, on the crew app for Android only | Optionally, to offer the arrival prompt described below | You do not get the arrival prompt. You mark arrival by hand instead, exactly as before. |
| Camera | Only when you tap to take a job or checklist photograph | You can still attach an existing image from your library. |
| Microphone | Only while you hold the record button to leave a voice note on a job | You cannot leave voice notes. Type the message instead. |
| Notifications | If you opt in to job and schedule alerts | No push notifications. Everything remains visible in the app. |
Your location is never recorded in the background. Recording only ever happens at the five moments listed above, and each one requires you to tap something.
There is one background behaviour, and we describe it precisely rather than claiming there is none. On the crew app for Android, if you grant background location, the phone itself can notice when you arrive within a short distance of the job you are currently assigned to, and offer you a prompt asking whether you have arrived. That checking happens entirely on your phone. No position it observes is ever sent to us, logged, or stored anywhere. If you ignore the prompt, nothing at all is recorded and nothing about the job changes. Only tapping the prompt records a location, and it records exactly the same thing that tapping "mark arrived" by hand has always recorded.
Because that behaviour uses the background location permission, your phone may show its own background location indicator. That indicator is accurate: the app is using location in the background to decide whether to show you a prompt. It is not recording where you are.
2.6 Collected automatically
Your IP address and browser or device identifier at sign-in and when you accept an agreement, as evidence of who accepted what and from where. The audit log of significant actions taken in a workspace. Technical logs from our hosting provider.
We do not use advertising identifiers, and there is no third-party analytics or advertising software in any of our apps.
2.7 What we do not collect
No advertising or cross-app tracking identifiers. No access to your contacts, call log, or text message inbox. No health or fitness data. No biometric identifiers of any kind.
The microphone is used only for voice notes, and only while you are actively holding the record button. There is no passive or ambient listening, and the microphone is never opened by anything else in the app. Section 2.8 describes what happens to a recording.
The Acceptable Use policy separately prohibits businesses from storing biometric templates, raw payment card numbers, and medical records outside the specific fields provided for them.
2.8 Voice notes
A voice note is a recording you make deliberately, by holding a record button on a job. It is sent to us, stored as a file attached to that job's message thread, and played back by other people in your workspace who can see the job. It is part of the job's record, not a transient message.
If your workspace has switched transcription on, the recording is also sent to OpenAI, which returns the text of what was said. The transcript is stored on the message so the note is searchable and appears in the thread export. Transcription is off unless a workspace owner turns it on, and the recording is not sent anywhere when it is off.
The recording is kept for as long as the job record is kept, and is deleted when the message or the account is deleted. Deleting the message deletes the recording with it.
3. Why we use it
- To provide the product: running your workspace, scheduling jobs, producing invoices, and calculating timecards.
- To authenticate you and protect accounts against unauthorised access.
- To send the messages you or your business asked for. See Section 6.
- To bill for the subscription.
- To keep security and audit records, and to meet legal and tax obligations.
- To investigate abuse and any support request you raise.
We do not sell personal information. We do not share it for cross-context behavioural advertising. We do not use your business's operational data, your customer records, or your employee records to train machine-learning models, whether ours or anyone else's. See Section 5.
4. Who we share it with
We use the following providers, each for one stated purpose. All of them process data on our instructions under contract.
| Provider | Purpose | What reaches them |
|---|---|---|
| Neon | Database hosting | All stored application data |
| Vercel | Application hosting and file storage | Requests, uploaded files and photographs |
| Resend | Transactional and campaign email | Recipient address, message content |
| Twilio | Text messaging and WhatsApp delivery | Recipient number, message content |
| Meta (WhatsApp) | WhatsApp messages, if a business enables them and a customer chooses WhatsApp | Recipient number, message content |
| Stripe and Square | Payment processing | Payment details, entered directly with them |
| OpenAI | Optional AI assistance features | Only what Section 5 describes |
| Cloudflare | Bot protection on public forms | Request metadata |
| QuickBooks | Accounting sync, if a business enables it | Invoices, payments, customer names |
| Shopify | Marketplace sync, if a business enables it | Orders, catalog, inventory, fulfillment |
Meta is the exception to the sentence above the table. It receives WhatsApp messages under its own terms with the business that connected WhatsApp, not on our instructions.
Card numbers are handled by Stripe or Square directly and are never stored on our systems.
We also disclose data where the law requires it, and would transfer it as part of a merger or sale of the business. In that case this notice continues to apply until you are given notice of a replacement.
5. AI features
Where a workspace enables AI assistance, the specific record involved, such as a job description, a message draft, or a summary request, is sent to OpenAI to produce the result. Under our agreement with them, that content is not used to train their models.
Where a workspace enables voice-note transcription, this includes the audio recording itself: the file is sent to OpenAI, which returns the text of what was said. The same agreement applies, and the recording is not used to train their models either. Section 2.8 describes the feature.
Inventory, equipment, and vehicle photo identification send the selected, normalized asset photograph to OpenAI to suggest a name. Crop out people, plates, VINs, serial labels, and confidential information before requesting identification. The photograph is retained with the saved asset under the normal operational-record retention policy.
Inventory product search and equipment/vehicle model search send the search text you submit, your interface language, and, for asset searches, the equipment/vehicle type to OpenAI. OpenAI may reformulate that text and send search queries to its web-search providers. Our application does not automatically include your inventory database, customer records, job records, photographs, or precise location in a product search. Use public product names, brands, or part numbers; do not include personal, customer, employee, or other confidential information in the query.
Unselected product matches are temporary results in the interface. Selecting a match prefills the item or asset form; the chosen details and source/purchase link become operational records only when you save. We keep usage counters for billing and request limits, not a product-search history. We request that these AI responses not be stored as retrievable API responses. This does not disable provider abuse-monitoring or other applicable retention; see OpenAI's API data controls.
Validated web-search matches may be reused from temporary server memory for up to five minutes, separately for each workspace. When a direct supplier catalog integration is enabled and you select that supplier, the search text is instead sent to its API. Amazon or eBay returns product facts, links and reference-image URLs. These direct catalog results are not stored in our web-search cache.
For optional supplier image previews, visible search results and purchase-link fields may trigger our server to request the linked public page and its image from an approved supplier or image host. Those hosts receive our server request and the requested URLs, not your browser cookies, customer records, or account credentials. We resize permitted images into temporary, metadata-free thumbnails for display. Previews are not permanently copied into asset records or sent to an AI provider. Your browser holds preview bytes while displaying them. Supplier permissions and availability may prevent some previews from loading.
Permitted extracted thumbnails may be reused from temporary server memory for up to one minute. Images provided by an enabled Amazon or eBay catalog API are loaded directly from the supplier's image host, which receives your IP address and normal browser request information. We do not download or permanently store these API images. Clicking a reference-image search link opens Google with the displayed product name; it does not automatically import an image.
For supplier-link autofill enabled under an approved retailer arrangement, the product URL is requested from that retailer by our server. Opening a source or purchase link takes you to the retailer's own site, whose terms and privacy practices apply. Spanstead does not send customer or employee records with those lookup requests.
AI features are switched off unless a workspace turns them on. They are limited to the specific record in front of you rather than a sweep of your database, and they never make a decision on their own about pay, discipline, or employment. A person acts on the output, or does not.
6. Messages
Transactional messages, such as password resets, job confirmations, invoices, and schedule changes, are part of the service and are not marketing.
Marketing email and text messages require separate, explicit consent, which we record together with its time and source. Consenting to transactional text messages is never treated as consenting to marketing. Reply STOP to any text or WhatsApp message, or use the unsubscribe link in any marketing email. Both take effect immediately and both are recorded.
Mobile opt-in data is never shared. A phone number collected for text messaging, and the consent recorded alongside it, are not sold, rented, or shared with third parties or affiliates for their own marketing or for any purpose unrelated to sending the messages that were agreed to. They are disclosed only to the messaging carrier that delivers those messages or, for a customer who chose WhatsApp, to Meta, which delivers WhatsApp messages. Opting out of text messages does not require opting out of anything else, and consent to one category of message is never treated as consent to another.
Where a business sends messages to its own customers through the platform, that business is responsible for holding the consent it claims. See Customer Communications and Consent.
7. How long we keep it
| Data | Retention |
|---|---|
| Worker location | 90 days, then deleted automatically |
| Account and operational data | For the life of the account, then as Section 8 describes |
| Voice-note recordings and their transcripts | With the job message they belong to; deleted when that message or the account is deleted |
| Credentials for a connected sales channel | Deleted the moment the channel is disconnected or the app is uninstalled |
| Data brought in from a connected sales channel | Deleted on the schedule that channel requires — for Shopify, when it tells us the store has been removed, two days after uninstall |
| A customer a connected store asks us to erase | The record's personal details are overwritten on request, and we record that we did it |
| Backups | 30 days, encrypted, then they expire |
| Audit logs of changes | Retained for the life of the account as security evidence |
| Records of who viewed personal data | 400 days, then deleted automatically |
| Agreement acceptances | Retained after account deletion, as the record of what was agreed |
| Billing and tax records | As tax law requires, typically seven years |
Data under a legal hold that has not been released is exempt from automatic deletion. Deleting evidence on schedule during a dispute is spoliation rather than privacy hygiene, so retention gives way to the hold until it is released.
8. Deleting your account
You can delete your account from Settings, then Account, in any of our apps, and from the account deletion page on the web without needing an app installed.
If you are the sole owner of a workspace, deleting your account deletes the entire workspace: every customer record, job, invoice, and employment record in it. Because that is irreversible and affects other people, it runs on a grace period. The request is recorded, everyone with access is notified, and the deletion runs once the period ends. Cancelling during that window stops it completely.
If you are one of several members, deleting your account removes your name, email address, password and passkeys, two-factor secrets, sessions, notifications, and workspace access.
We are precise about what that does not remove, because the honest description matters more than the reassuring one. Business records you created, such as invoices, jobs, timecards and approvals, stay with the workspace with your name detached from them. They are your employer's records, several of them are required by law to exist, and an invoice whose creator had vanished would be a broken business record rather than a private one. What you are entitled to have removed is the information that identifies you, not the fact that work happened.
Grace periods. A member deletion runs after 7 days. A workspace deletion runs after 14 days. Nothing is destroyed before then, the exact date is shown to you when you confirm, and you can cancel at any point until it arrives. The longer window on workspace deletion exists so that colleagues who are notified have time to object.
Also kept, and why: agreement acceptance records, as proof of what was agreed on both sides; billing and tax records for the statutory period; and anything under a legal hold. Everything else is removed from live systems, and from backups as those backups age out.
9. Security
We encrypt data in transit everywhere. HR identity fields and stored integration credentials are additionally encrypted by the application, with keys held outside the database. Access is role-based and defaults to the least privilege that works. Two-factor authentication is available to everyone and can be enforced across a whole organisation. We keep an append-only audit log of significant actions, and separate access logs recording who viewed personal data: every view of a confidential HR category, and every screen or export that shows a person's name, contact details or address. The access records include how many records were read at once, so a bulk export is distinguishable from someone opening a single customer.
No system is perfectly secure. If we discover a breach affecting your data we will notify you, and any regulator the law requires, without undue delay.
To report a vulnerability, write to security@spanstead.com.
10. Children
Spanstead Works is a business tool and is not directed at children.
Customer accounts require you to be 18 or older. Worker accounts require you to be 16 or older, because 16- and 17-year-olds are lawfully employed in the trades this product serves.
Employers must not enter records for workers under 16. Before enabling location capture for a worker under 18, an employer must confirm that the parental consent requirements of their state are met. A minor acknowledgment on its own may not be sufficient.
11. Your rights
Depending on where you live, you may have the right to access, correct, delete, or export your personal information, and to appeal a refusal. Several US states also give you the right not to be treated differently for exercising these rights.
Contact privacy@spanstead.com. We will verify who you are before acting. That verification exists to stop someone else from obtaining your data by asking for it.
For data we hold as a processor, as described in Section 1, we will direct you to the business that controls it. That is a limit on what we may lawfully do, not a refusal.
You can exercise two rights without contacting anyone. You can export your own location history from your worker profile, and you can delete your account as described in Section 8.
12. Where data is held
Data is stored and processed in the United States. Spanstead Works is offered to businesses in the United States only and is not directed at the European Union, the United Kingdom, or other jurisdictions.
13. Changes
Material changes create a new version, which account owners are asked to accept before continuing to use the product. The version and effective date appear at the top of this document. Previous versions you accepted are listed in Settings, under Agreements.
14. Contact
| Purpose | Address |
|---|---|
| Privacy requests and questions | privacy@spanstead.com |
| Legal notices | legal@spanstead.com |
| Security reports | security@spanstead.com |
| Support | support@spanstead.com |
| Support telephone | 913-221-6755 |
Written requests and legal notices can be sent to:
Spanstead LLC, 11701 Roe Ave, Ste D PMB 1057, Leawood, KS 66211, United States.
Spanstead LLC is a Kansas limited liability company.