Legal
Privacy Policy
This policy explains how On it! Workdesk processes information when organizations coordinate maintenance tickets, people, locations, files, and subscriptions.
1. Scope and responsibility
This policy applies to the On it! Workdesk Android application, owner portal, public website, and related services. On it! Workdesk is published under the Google Play developer name Manic trash panda. Questions and privacy requests can be sent to soporte@onitworkdesk.com.
2. Information we process
- Account and profile information, including name, verified email, optional phone number, job details, availability, and workspace memberships.
- Workspace and location information, including business addresses, contacts, equipment, access notes, categories, and responsibility assignments.
- Ticket content, notes, status activity, reminders, expenses, materials, photos, documents, and other files users choose to submit.
- Approximate or precise location when a workspace enables arrival verification and the user grants Android location permission.
- Device and security information, including generated device identifiers, device model, session records, and protected network-address hashes used for abuse prevention.
- Subscription and billing status, purchase references, fiscal profile details, and tax documents. We do not receive or store full payment-card or bank-account numbers.
3. How information is used
We process information to authenticate users, operate and synchronize workspaces, route and audit tickets, provide directory and reporting features, process subscriptions, prevent abuse, support customers, and comply with legal obligations. We do not sell personal information or use workspace information for third-party advertising.
4. Workspace visibility
Workspace information is visible to authorized members according to role, assigned locations, responsibilities, and ticket participation. Workspace owners and supervisors control those permissions. Contact directory fields are optional, but information intentionally added to a workspace directory can be viewed by authorized workspace members.
5. Service providers
We use Cloudflare for hosting, database, object storage, security, and transactional email; Google services for Android distribution, billing, and planned push notifications; and Stripe for web subscription processing. These providers process information according to their own agreements and privacy practices. Payment providers return transaction references and subscription status rather than complete card details.
6. Storage and security
Cloud traffic is encrypted in transit. Access requires verified sign-in and revocable device sessions. Uploaded files are stored in private object storage and retrieved through authorized requests. We use role checks, non-public object identifiers, file validation, rate controls, and audit events to protect workspace data.
Desk Mode may be hosted directly by a paired phone on the same local network. That local connection may use HTTP and should only be used on a trusted Wi-Fi network or private phone hotspot.
7. Location information
Workdesk does not provide continuous live tracking. When enabled by workspace policy, location is collected only for specific operational events such as arrival verification, and only after the Android user grants permission. Workspace owners can configure whether this information is optional or required for their workflow.
8. Retention and deletion
Information is retained while needed to provide an active workspace, satisfy organization-configured retention rules, maintain security, and meet accounting or legal obligations. Users may delete their account in the Android app or through the account deletion page.
Account deletion removes sign-in identity, directory data, memberships, notification tokens, and active sessions. Organization-owned operational records are dissociated from the deleted identity and may remain where needed for audit, security, dispute resolution, or legal obligations. Legally required subscription and fiscal records may be retained for the applicable period.
9. Your choices and rights
Directory details, many attachments, and profile fields are optional. Android asks before accessing location or sending notifications. Depending on applicable law, you may request access, correction, restriction, objection, portability, or deletion of personal information by contacting soporte@onitworkdesk.com. We may need to verify your identity before acting on a request.
10. Children
Workdesk is a business operations service and is not directed to children. Users must have legal capacity to participate in their organization's workspace or be authorized by that organization.
11. Changes to this policy
We may update this policy as the service, providers, or legal requirements change. The effective date above will identify the current version. Material changes will be communicated through the app, website, or account contact when appropriate.