P
Paxworks
← Back to paxworks.io

Privacy Policy

Paxworks Track & Paxworks Plan · Last updated 8 September 2026

This policy covers Paxworks Track and Paxworks Plan (together, "Paxworks", "we", "us"), operated by Paxworks Ltd. It applies whether you use one product or both — they share the same account, organisation, and billing. (Green Claims is a separate product with its own privacy policy.)

Who this applies to

Paxworks is B2B software: your organisation is our customer, and you (and your team) are the users we have a direct relationship with. If you invite clients into the client portal, your organisation is the data controller for your clients' data — you decide what to add and who to invite, and Paxworks processes it on your behalf as described below. If you're a client using a portal someone else set up, direct data questions to the agency or freelancer who invited you; we don't have an independent relationship with client-portal users.

What we collect

Your team's account data

Data you add about your clients

Your project and financial data

Projects, milestones, tasks, time entries, invoices, retainers, and any files you attach to a task — the operational content you create in Paxworks to run your work.

Billing data

Subscription and billing are handled by Stripe. We store your Stripe customer ID and subscription status; we never see or store your card details — those are held by Stripe directly, governed by Stripe's own privacy policy.

Optional integrations

Activity and support data

We keep an internal audit log of significant actions taken in your organisation (who did what, and when) for security and support purposes. We use session cookies to keep you signed in — no third-party advertising or analytics cookies.

What we don't do

We don't sell your data, and we don't use your organisation's data — or anything derived from it — to train or improve any AI or machine-learning model.

Where it's stored

Application data lives in a PostgreSQL database hosted on Railway. File attachments are stored via Cloudflare R2. Both providers act as our subprocessors and don't use your data for their own purposes.

Subprocessors

Data retention

We retain your organisation's data for as long as your account is active. If you close your account, we'll delete or anonymise your organisation's data within 90 days, except where we're required to keep records for legal, tax, or accounting reasons (e.g. Stripe-related transaction records). You can request earlier deletion, or ask us about the status of a deletion request, at any time by emailing us.

Security

Passwords are hashed, not stored in plaintext. Two-factor authentication is available for your team, and can be required organisation-wide. All traffic to Paxworks is encrypted in transit (HTTPS). No system is perfectly secure, but we take reasonable technical measures to protect your data and review them as the product evolves.

Your rights

Depending on where you're located, you may have rights to access, correct, export, or delete your data (e.g. under UK GDPR or similar regional laws). Contact us to exercise them. If you're a client-portal user, your rights are generally exercised through the organisation that invited you, since they control what data is added about you.

Children

Paxworks is a business tool and isn't directed at, or knowingly used by, children.

Changes to this policy

We'll update the "last updated" date above if this policy changes, and post the new version at this same URL. Material changes will be communicated via the app or by email.

Contact

Questions about this policy or your data: hello@paxworks.io.