Privacy Policy
This policy covers Paxworks Track and Paxworks Plan (together, "Paxworks", "we", "us"), operated by Paxworks Ltd. It applies whether you use one product or both — they share the same account, organisation, and billing. (Green Claims is a separate product with its own privacy policy.)
Who this applies to
Paxworks is B2B software: your organisation is our customer, and you (and your team) are the users we have a direct relationship with. If you invite clients into the client portal, your organisation is the data controller for your clients' data — you decide what to add and who to invite, and Paxworks processes it on your behalf as described below. If you're a client using a portal someone else set up, direct data questions to the agency or freelancer who invited you; we don't have an independent relationship with client-portal users.
What we collect
Your team's account data
- Name, email address, and password (stored as a salted hash — we never store or can see your plaintext password).
- Two-factor authentication status, if you enable it (we store a TOTP secret, not your authenticator app's codes).
- Role and permissions within your organisation, login history, and cost rate if your admin sets one.
Data you add about your clients
- Client name and email address.
- If you enable the client portal for a client: a portal login (password or access-token based) and, per client user, their name, email, and the specific permissions you grant them.
Your project and financial data
Projects, milestones, tasks, time entries, invoices, retainers, and any files you attach to a task — the operational content you create in Paxworks to run your work.
Billing data
Subscription and billing are handled by Stripe. We store your Stripe customer ID and subscription status; we never see or store your card details — those are held by Stripe directly, governed by Stripe's own privacy policy.
Optional integrations
- Xero: if you connect Xero, we store the OAuth tokens needed to keep the connection alive, and invoice/payment data syncs to your connected Xero account.
- Slack: if you configure budget-burn alerts, we send the relevant project/milestone/budget details to the Slack webhook URL you provide. No client-portal login data is included in these alerts.
Activity and support data
We keep an internal audit log of significant actions taken in your organisation (who did what, and when) for security and support purposes. We use session cookies to keep you signed in — no third-party advertising or analytics cookies.
What we don't do
We don't sell your data, and we don't use your organisation's data — or anything derived from it — to train or improve any AI or machine-learning model.
Where it's stored
Application data lives in a PostgreSQL database hosted on Railway. File attachments are stored via Cloudflare R2. Both providers act as our subprocessors and don't use your data for their own purposes.
Subprocessors
- Stripe — payment processing and subscription billing.
- Resend — transactional email (invoices, notifications, digests).
- Railway — application and database hosting.
- Cloudflare — file storage.
- Xero, Slack — only if you choose to connect them.
Data retention
We retain your organisation's data for as long as your account is active. If you close your account, we'll delete or anonymise your organisation's data within 90 days, except where we're required to keep records for legal, tax, or accounting reasons (e.g. Stripe-related transaction records). You can request earlier deletion, or ask us about the status of a deletion request, at any time by emailing us.
Security
Passwords are hashed, not stored in plaintext. Two-factor authentication is available for your team, and can be required organisation-wide. All traffic to Paxworks is encrypted in transit (HTTPS). No system is perfectly secure, but we take reasonable technical measures to protect your data and review them as the product evolves.
Your rights
Depending on where you're located, you may have rights to access, correct, export, or delete your data (e.g. under UK GDPR or similar regional laws). Contact us to exercise them. If you're a client-portal user, your rights are generally exercised through the organisation that invited you, since they control what data is added about you.
Children
Paxworks is a business tool and isn't directed at, or knowingly used by, children.
Changes to this policy
We'll update the "last updated" date above if this policy changes, and post the new version at this same URL. Material changes will be communicated via the app or by email.
Contact
Questions about this policy or your data: hello@paxworks.io.