Effective: September 13, 2026 · Last updated: September 27, 2026
This summary is for orientation only. The sections below are the policy.
WorkMark ("WorkMark", "we", "us", "our") provides a web and mobile application that lets heating, ventilation and air-conditioning contractors — and other trades — carry out equipment inspections, produce reports, send quotes, and track jobs through a sales pipeline. The service is operated from Orange County, California, United States.
This policy explains what information the service handles, why, who else touches it, how long it is kept, and what rights you have. It applies to workmark.app, the WorkMark application at workmark.app/field, the administration console, and the report pages we serve to your customers.
It does not apply to any third-party site or service we link to, or to what a contractor does with a report after they download or print it.
This distinction runs through the whole policy, so it comes first.
| Account Data | Customer Data | |
|---|---|---|
| What it is | Information about the contracting business that subscribes to WorkMark and the people on its team. | Everything a subscriber puts into the app about the homeowners and properties it serves — names, addresses, equipment, photographs, findings, prices. |
| Who decides how it is used | We do. | The subscriber does. Not us. |
| Our role | Business (controller). | Service provider under the California Consumer Privacy Act — we process it only to provide the service, on the subscriber's instructions. |
We do not use Customer Data for our own purposes. We do not sell it, we do not use it to build profiles, we do not use it to train machine-learning models, and we do not combine one subscriber's Customer Data with another's. Every subscriber's data sits in its own area of the database, separated by security rules enforced on the server.
If you are a homeowner and a contractor sent you a WorkMark report, the contractor — not WorkMark — decides what happens to your information. See section 13.
You control all of this. You choose what to record, and you can edit or delete it at any time from inside the app.
When a report link is opened, the app records an event so the contractor knows their customer saw it: the time, which report, whether the page was merely loaded or a person pressed through the cover screen, and whether the viewer appeared to be the contractor's own staff rather than the customer. See section 9.
Subscription payments are handled by Paddle, which acts as the merchant of record. Card numbers, bank details and billing addresses are collected and stored by Paddle, not by WorkMark. We never receive your full card number. We receive from Paddle only what we need to run your subscription: which plan you bought, how many seats, the status of the subscription, renewal dates and the last four digits of the payment method.
Your data is stored in the United States on Google Cloud infrastructure. We engage the following service providers, and only these. Each is bound to use the data solely to provide its service to us.
| Provider | What it does | What it touches |
|---|---|---|
| Google LLC (Firebase Authentication, Cloud Firestore, Cloud Storage, Hosting, Cloud Functions) | Hosts the application, stores the database and photographs, handles sign-in, runs server-side code. | All Account Data and all Customer Data. |
| Paddle.com Market Ltd | Merchant of record — takes payment, charges sales tax, issues invoices. | Billing name, email, payment method, transaction history. No Customer Data. |
| Google Fonts / gstatic.com cdnjs (Cloudflare) | Serve fonts and code libraries to your browser. | Your IP address and browser, as any web request reveals. No account or Customer Data. |
That is the complete list of our service providers. Nothing else is contacted: QR codes for invitations are drawn inside your browser rather than fetched from a third-party image service, and there is no analytics, advertising or error-reporting service of any kind. The exceptions are services that you choose to connect yourself: an AI assistant, described in 5.1, and ReviewTec, described in 5.2.
We will also disclose information if we are required to by law, subpoena or court order; where it is necessary to investigate suspected fraud, a security incident, or a violation of our Terms of Service; or in connection with a merger, acquisition or sale of the business, in which case we will give notice before your data becomes subject to a different privacy policy.
WorkMark can be connected to an AI assistant — currently Anthropic's Claude or OpenAI's ChatGPT. This is optional and off by default: the company owner decides which team members may use it, and each of them connects their own assistant account by signing in to WorkMark and approving the connection. Once connected, when that person asks the assistant a question, the assistant requests the WorkMark records it needs to answer — for example customer names and contact details, inspection reports and quotes, or sales pipeline cards — and WorkMark sends those records to the assistant's provider. Anthropic and OpenAI are not our service providers; they are services you choose, and they handle that data under your own agreement with them and their privacy policies.
The assistant acts only as the person who connected it, with that person's role and permissions. It never receives passwords or sign-in details, billing or payment information, team members' email addresses or phone numbers, security settings, or any other company's data. Anyone can disconnect their assistant at any time in Settings → AI assistants, and the owner can switch it off for the whole company; access stops immediately.
A company can connect its own ReviewTec account (ReviewTec is a review-request service) so that a customer is asked for a review automatically when their job reaches a pipeline stage the company chooses. This is optional and off by default; only the company owner can turn it on, using the company's own ReviewTec keys. When a job reaches that stage, WorkMark sends ReviewTec the customer's name and either their mobile number or their email address, and nothing else. ReviewTec then sends the request, a reminder and a review page on the company's behalf. ReviewTec is not our service provider; it is a service the company chooses, and it handles that data under the company's own agreement with ReviewTec and ReviewTec's privacy policy.
A customer is asked at most once per job and not again within 90 days. The company is responsible for having its customers' permission to contact them by text or email. The owner can switch this off or disconnect ReviewTec at any time in Settings → Reviews; nothing further is sent once it is off.
WorkMark does not sell personal information, and does not share personal information for cross-context behavioural advertising, as those terms are defined by the California Consumer Privacy Act. We have not done so in the preceding twelve months. We do not offer financial incentives in exchange for personal information.
When a report is sent to a homeowner, WorkMark publishes it at a web address containing a long, randomly generated identifier. Anyone who has that address can open the report without signing in. There is no password on it.
This is deliberate: a homeowner should be able to tap a link in a text message and read their report, on any device, without creating an account. The trade-off is that the link is the key.
The identifiers are long and random, so a link cannot be guessed, and we instruct search engines not to index report pages. But a link that is forwarded, posted publicly, or left in a shared inbox gives whoever holds it the same access the homeowner has. Treat a report link the way you would treat the report.
A contractor can delete a published report at any time from the Reports Log, which makes the link stop working.
The contractor who sent a report can see when it was opened. We record the time of the view, which report it was, and whether the visitor pressed through the cover screen — a distinction that exists because corporate email systems fetch links automatically to scan them for malware, and a fetch is not a person reading.
We do not record the viewer's location, and we do not attempt to identify a viewer beyond distinguishing the contractor's own staff from the customer. This information is visible only to the contracting company that sent the report, and to us for support purposes.
The app also includes a "Clear all data" function that removes a company's records from both the device and the cloud. It cannot be undone.
We take security seriously and have built the service accordingly:
No service connected to the internet is perfectly secure, and nobody can promise otherwise. We cannot guarantee that unauthorised access, a flaw in software we depend on, or an attack on a provider we rely on will never happen. What we can do is build carefully, respond quickly, and tell you promptly if something goes wrong.
If we become aware of a breach of security leading to unauthorised access to personal information, we will notify affected subscribers without undue delay and in any event as required by California Civil Code § 1798.82 and other applicable law. Because Customer Data belongs to the subscriber, it is the subscriber who is generally responsible for notifying its own customers; we will give you the information you need to do so.
Much of day-to-day security is in your hands: use strong, unique passwords, do not share accounts, remove team members when they leave, lock the phones and tablets your technicians carry, and be careful where report links end up.
Found a vulnerability? Email contact@workmark.app. We will not pursue legal action against anyone who reports a flaw in good faith, gives us a reasonable chance to fix it, and does not access or destroy other people's data in the process.
If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act, gives you the right to:
To exercise a right, email contact@workmark.app with the word "Privacy" in the subject line. We will acknowledge within 10 business days and respond within 45 days, extendable once by a further 45 days where the request is complex, and we will tell you if we need the extension.
Before we act we have to be reasonably sure you are who you say you are. For an account holder that usually means replying from the email address on the account. For a larger request we may ask for more. An authorised agent may make a request on your behalf with written permission signed by you, and we may still contact you to confirm it.
Categories of personal information collected in the last twelve months, in the statute's own terms: identifiers; customer records information; commercial information; internet or other electronic network activity information; geolocation at the level of a service address you type in, but not device location; and visual information, in the form of photographs taken during an inspection. Sources, purposes and recipients are described in sections 3 to 6.
Your information is in WorkMark because a contracting business put it there. That business decides what is collected, how it is used, how long it is kept and who it is shared with. We hold it on their behalf and may not lawfully change or delete it on our own initiative.
So the fastest route is to contact the company whose name and phone number are printed at the top of your report. If you would rather come to us, email contact@workmark.app and we will pass your request to the company that holds your record, and tell you we have done so.
If you believe you received a report meant for someone else, the report page has a link that says so — pressing it tells the contractor and shows you nothing further.
WorkMark is a tool for businesses. It is not directed to children, and we do not knowingly collect personal information from anyone under 16. If you believe a child's information has reached us, email contact@workmark.app and we will delete it.
Because we do not track users across websites and do not sell or share personal information, there is nothing for a Do Not Track or Global Privacy Control signal to switch off. We honour these signals by not engaging in the practices they are designed to prevent.
WorkMark is offered to businesses in the United States, is hosted in the United States, and is not designed to meet the requirements of the European Union's General Data Protection Regulation or equivalent laws in the United Kingdom or elsewhere. Do not use the service to process the personal data of individuals in those regions.
We may update this policy as the service changes or the law does. The "Last updated" date at the top always reflects the current version. If a change materially reduces your rights or materially expands how we use personal information, we will give subscribers at least 30 days' notice by email or in the app before it takes effect. Continuing to use WorkMark after that means you accept the updated policy.
Questions, requests or complaints about privacy:
contact@workmark.app
We read every message and aim to reply within two business days.