1. Who this policy covers
This policy applies to the public website at upwrks.com and the UPWRKS maintenance job-card service. A company that creates an UPWRKS workspace controls the operational records placed in that workspace. UPWRKS operates the service and processes that data to provide the product, keep it secure, and support its users.
2. Information we handle
- Account and membership information: name, work email address, company, role, sign-in method and account status.
- Maintenance records: job cards, schedules, checklists, notes, time entries, equipment history, photographs, signatures and completion evidence supplied by a customer or its users.
- Security information: encrypted session identifiers, passkey public credentials, sign-in events, invitation and recovery status, and records needed to prevent abuse.
- Support information: messages and details you send when asking for help or a walkthrough.
- Technical information: ordinary server logs, request details and diagnostic information needed to operate and protect the service.
3. How we use information
We use information to provide and secure the service, authenticate users, separate each company's data, create maintenance records and reports, send requested service messages, troubleshoot problems, improve reliability, and comply with applicable obligations.
We do not sell personal information or use customer maintenance records for targeted advertising.
4. Google and Microsoft sign-in
If a company enables organisation sign-in, UPWRKS requests only the basic OpenID Connect scopes needed to sign a person in: identity, email address and profile. We use that information to verify the email address and connect the Google or Microsoft identity to the correct UPWRKS membership.
UPWRKS does not request access to Gmail, Google Drive, Google Calendar or a user's Microsoft files and mail. The service stores the provider, provider account identifier and verified email needed to recognise future sign-ins; it does not retain Google or Microsoft access or refresh tokens after authentication completes.
5. Cookies and local storage
UPWRKS uses essential session cookies to keep users signed in and enforce company access. The public site stores a theme preference on the device. We do not currently use advertising cookies on the public site.
6. Service providers and sharing
We share information only where needed to operate the service, follow a customer's instructions, protect users, or meet a legal obligation. Current infrastructure providers include Railway for application hosting and managed data services, Cloudflare for DNS and email delivery or routing, and Google or Microsoft when a user chooses the relevant sign-in option. These providers process information under their own contractual and security obligations.
7. Retention, security and international processing
We retain account and customer data for as long as the workspace is active or as needed to provide the service, resolve disputes, maintain security and meet applicable obligations. Backup and security records may remain for a limited period after primary data is removed. UPWRKS uses access controls, tenant separation, encryption in transit, hashed or public-key credentials and monitored infrastructure to protect information.
Providers may process information in countries other than the user's own. Where required, UPWRKS and its providers use appropriate safeguards for those transfers.
8. Your choices and rights
Depending on applicable law, a person may ask to access, correct, delete or restrict use of personal information, object to certain processing, or withdraw consent where consent is the basis used. Workspace users should normally contact their company administrator first because that company controls its maintenance records. You can also contact UPWRKS directly.
9. Contact and changes
Send privacy questions or requests to hello@upwrks.com. We may update this policy as the service changes. Material changes will be reflected on this page with a new update date.