Privacy Policy

Last updated 2026-08-08. This policy describes what WorkMayt Software Inc. actually does with data — verified against the source code, not written from a template. Questions or requests: privacy@workmayt.com.

Draft — not yet in force. WorkMayt Software Inc. is being incorporated in British Columbia, Canada. Published in draft so it can be read before it binds anyone.

Who is responsible for what

WorkMayt sits between two relationships, and the law treats them differently:

  • Your account details — the name, email, and password you signed up with. For these, we are the controller.
  • Your work data — hours, schedules, job codes, and everything your employer organizes work with. Here your employer is the controller and we are their service provider. We process that data on their instructions. If you're a worker and you want your hours changed, your employer decides that, not us — though we will always help you reach them, and the erasure rights below are yours regardless.

What we collect

  • Account information — name, email address, and optionally a phone number and avatar.
  • Employment link — which organization you belong to, your role in it, and your pay rate if your employer records one.
  • Time and schedule data — clock-ins and clock-outs, breaks, the jobs, tasks, projects and equipment your time is coded to, timesheet approvals, and scheduled shifts.
  • Content you upload — photos and attachments you add to time entries, and signatures you capture for sign-offs.
  • Push notification tokens — so the app can notify you about your shifts. Deleted with your account.
  • Operational logs and error reports — server logs and crash/error telemetry, captured by a GlitchTip instance we run ourselves.
  • Website analytics — aggregate page views on this website via a self-hosted umami instance. It is cookieless and does not profile you across sites, which is why you are not being asked to dismiss a cookie banner.

What we don't collect

  • No location. No GPS. Ever. Neither app asks for location permission, there is no map, and there is no breadcrumb trail. This is a permanent product decision, not a feature we haven't got to.
  • No biometrics — no face or fingerprint data.
  • No contacts — we never read your address book.
  • No advertising identifiers, and no ad-tech SDKs of any kind.
  • No sale of data. There is no circumstance in which we sell or rent personal data.
  • No card numbers. Payment details go directly to Stripe and never touch our servers. We store only a customer reference and a subscription status.

Who else processes your data

Three companies, and no more. Everything else — analytics, error tracking, the database — runs on infrastructure we operate ourselves.

Sub-processor What for Where
OVH Hosting — the servers the application and database run on Canada
Stripe Billing and payment processing United States
Postmark Transactional email — invitations, password resets, notifications United States

We will update this list before adding a sub-processor, not after.

How long we keep things

Account and work data is kept while the organization's account is open. When a person's account is deleted, personal details are erased immediately — but the employer's underlying business records (the hours worked, the approvals) are retained in de-identified form, because employment and tax law requires an employer to keep them. The next section explains exactly what that means.

Operational logs are kept on a short rolling window and are not used to build a profile of you.

Getting your data, correcting it, or erasing it

You can ask us what we hold about you, correct it, or have it erased. The self-serve path is at Delete your account, and it works from inside the app.

Erasure is real but not indiscriminate. Deleting your account permanently destroys your personal data — name, email, phone, address, emergency contact, pay rate, avatar, login history, push tokens, invitations, and your password. What survives is the employer's record that work happened: the time entries and approvals, with your identity scrubbed. Anyone looking at them afterwards sees "Deleted User" and has no route back to you.

We do it this way because a true hard delete would destroy the employer's payroll records along with your identity, which is the opposite of what the law wants. If you believe you have a case for erasure beyond this, write to privacy@workmayt.com and a human will read it.

Security

Traffic is encrypted in transit. Passwords are stored hashed, never in a readable form. Access to production data is restricted, and deleting an account immediately invalidates every outstanding session for it. No system is perfectly secure and we won't claim ours is.

If there's a breach

If personal data is exposed in a way that creates a real risk of significant harm, we will report it to the Office of the Privacy Commissioner of Canada and notify affected people without undue delay, as PIPEDA requires. Where your employer is the controller, we notify them so they can notify their workers.

Children

WorkMayt is a workplace tool and is not directed at children. Accounts are for people who are of legal working age where they live.

Where your data lives

Application data is hosted in Canada. Two of our three sub-processors (Stripe and Postmark) are US-based and will process the specific data described above there.

Changes

Material changes get an email to the address on your account and a new date at the top of this page. Every version is kept in our source repository.

Contact

Privacy questions and requests: privacy@workmayt.com
WorkMayt Software Inc., British Columbia, Canada

If we haven't resolved your concern, you can complain to the Office of the Privacy Commissioner of Canada.