Privacy Policy
The short version:
- We collect what you put into Work Well Kept (your account email, vehicle info, odometer readings, trips, income, fuel, expenses, receipt photos, and maintenance records) plus basic technical information needed to run and secure the service.
- We use it to run Work Well Kept for you. We do not sell your personal information, and we do not share it for targeted (cross-context behavioral) advertising.
- We don’t track your location.
- Google (Firebase), Stripe, and our web host help us run the service under their own security and privacy commitments.
- You can see, export, correct, and delete your data, and ask us for a free copy anytime. Deleted items sit in a Recycle Bin for 30 days and then are permanently deleted. Backups age out within about 35 days.
- Questions or requests: service@workwellkept.com.
1. Who we are
Work Well Kept is operated by Alspach Deliveries LLC, an Indiana limited liability company doing business as Work Well Kept (“we,” “us”), based in Elkhart, Indiana. This Privacy Policy explains how we handle personal information when you use workwellkept.com, our web app, any future mobile apps, and related emails (the “Service”). The Service is offered only to adults in the United States.
2. Information we collect
Information you give us
| Category | Examples |
|---|---|
| Account information | Email address, password (handled by Google Firebase Authentication; we never see your password), and optionally your name. If you sign in with a Google account, Google shares your name, email address, and profile picture with our sign-in provider (Firebase Authentication), which keeps them with your sign-in record. The app itself uses only your email address: it doesn’t copy your Google name or picture into your records, and the name on your reports is the one you enter in Settings. |
| Vehicle information | Make, model, year, nickname, fuel economy (MPG), and odometer readings you enter. |
| Work records | Trips and mileage, income entries (including which gig platforms you work with), fuel purchases, expenses, maintenance records, notes, categories, and settings you choose (for example, assumptions used for tax estimates). |
| Receipt photos | Images you upload. Receipts can show merchant names, dates, amounts, and sometimes partial card numbers. Please don’t upload documents showing full card, bank account, or Social Security numbers. |
| Communications | Messages you send us, such as support requests by email or in the app (Settings → Message us), and our replies. When you send a message in the app, your name and account email go with it so we can reply. |
Payment information
When you subscribe, you pay through Stripe’s hosted checkout. Your full card number goes directly to Stripe and never touches our servers. Stripe shares limited information with us, such as your Stripe customer ID, subscription plan and status, payment dates and amounts, card brand, last four digits, expiration date, and billing country and ZIP code.
Information collected automatically
- Device and log information: IP address, browser and device type, operating system, pages or features used, date and time of access, sign-in events, and error logs. Our web host and Google keep standard server and security logs.
- Browser storage: see Section 6.
What we don’t collect
- We don’t collect your location. Mileage comes from odometer readings you enter, not GPS. If we ever add optional location-based trip tracking, we’ll ask for your permission first and update this policy before launching it.
- We don’t connect to your gig-platform accounts, and we don’t ask for your Social Security number or bank login.
- We don’t intentionally collect sensitive personal information such as health, racial or ethnic origin, religious beliefs, or biometric data.
3. How we use information
| Purpose | Legal basis (where a law requires one) |
|---|---|
| Providing the Service: storing and syncing your records, generating reports, CSV exports, income statements, estimates, and comparisons | To perform our contract with you |
| Billing and managing subscriptions, including the founding price | Contract; legal obligations (tax and accounting records) |
| Sending service emails: account verification, password reset, receipts, renewal and price-change notices, security alerts, and changes to our terms | Contract; legal obligations |
| Customer support, including in-app messages (Settings → Message us) and emailing you a short notice with our reply when we answer | Contract; legitimate interests |
| Security, preventing fraud and abuse, backups, and troubleshooting | Legitimate interests; legal obligations |
| Improving the Service using aggregated or de-identified information (for example, which features are used) | Legitimate interests |
| Occasional product news emails (you can unsubscribe anytime) | Consent or legitimate interests, as the law allows |
| Complying with law, responding to lawful requests, and protecting rights and safety | Legal obligations; legitimate interests |
We don’t use your records for targeted advertising, we don’t sell them, and we don’t use them to train AI models. We don’t make automated decisions about you that have legal or similarly significant effects. We don’t look through your individual records except when needed to provide support you ask for, keep the Service secure, or comply with the law.
4. How we share information
We share personal information only as described here:
- Service providers that process data for us under contracts that limit their use of it:
- Google (Firebase Authentication, Cloud Firestore, Firebase Storage, and related Google Cloud services): sign-in, database, receipt photo storage, backups, and sign-in emails. Data is stored in the United States.
- Stripe: payment processing, subscription billing, and the customer portal. Stripe also uses payment data for its own fraud prevention and legal compliance under its own privacy policy.
- HostGator (web hosting and email): hosting for our website and server-side code, including standard server logs, and the mail server that sends our emails and receives mail sent to our @workwellkept.com addresses. This includes the notices about in-app support messages (a copy of each new message is emailed to our support inbox, and our replies are emailed to you).
- Google (email inbox): email sent to service@workwellkept.com and contact@workwellkept.com is forwarded to a Google (Gmail) inbox, where we read and answer it.
- At your direction: when you download, print, or send a report, export, or income statement to someone, you control who receives it.
- Legal reasons: if required by law, subpoena, or court order, or when we believe in good faith it’s necessary to protect someone’s safety, prevent fraud, or protect our rights. Where allowed, we’ll tell you before handing over your information.
- Business transfer: if the business that runs the Service is sold, merged, or reorganized, your information may transfer to the new owner, who must honor this policy for information collected under it. We’ll notify you first.
We do not sell personal information, and we do not “share” it for cross-context behavioral advertising (as those terms are used in California and other state privacy laws). We have not done so in the past 12 months.
5. Possible future advertising
We may, in the future, show one or two unobtrusive ads to free-plan users. Pro subscribers won’t see ads. No ads run today, and no advertising network receives your data. Before we turn on any ad network, we will update this Privacy Policy (and notify you) to explain which company serves the ads, what data it receives (which may include cookies, device identifiers, and IP address), and how to opt out, including through Global Privacy Control where required. We will never give advertisers your trip, income, expense, or receipt records.
6. Cookies and browser storage
- Essential storage only. Firebase Authentication stores sign-in information in your browser (using local storage or IndexedDB) so you stay signed in. The app may store your preferences and temporary data on your device so it works smoothly.
- Stripe sets its own cookies on Stripe’s checkout and portal pages for fraud prevention and to make payments work. See Stripe’s privacy and cookie policies.
- No analytics or advertising cookies are used today. If we add any, we’ll update this section first.
- Do Not Track and Global Privacy Control. We don’t track you across other websites, and we don’t sell or share your data for targeted advertising, so there is currently nothing for these signals to turn off. If that ever changes, we will treat a Global Privacy Control signal as a request to opt out of sale and sharing where the law requires.
7. How long we keep information
| Data | How long |
|---|---|
| Your account and records | While your account is open, unless you delete them sooner. |
| Items you delete | Moved to your Recycle Bin for 30 days (so you can restore mistakes), then permanently deleted from our live systems. |
| Backups | We use our providers’ recovery features and may keep backup copies for disaster recovery (for example, point-in-time recovery or scheduled backups of our database, and short-term recovery of deleted receipt photos). Backup copies are kept for no more than about 35 days, then replaced or destroyed, so deleted data ages out of all backups within about 35 days. |
| Deleted accounts | We delete your account and records from live systems within 30 days of a verified request. Copies in backups age out within about 35 days after that. |
| Billing and transaction records | As long as required for tax, accounting, and legal purposes (generally up to 7 years). Stripe keeps its own records under its policies. |
| Records of your consent to our Terms and to automatic renewal | At least 3 years, or 1 year after your subscription ends, whichever is longer, as some state laws require. |
| In-app support messages (Settings → Message us) | Stored with your account so we can provide support and you can see the conversation. Only you and Work Well Kept can read them, and they can’t be edited after sending. They are deleted when your account is deleted (backups age out within about 35 days after that). Copies emailed to our support inbox are kept like support emails (below). |
| Support emails | Up to 2 years after the conversation ends, unless we need them longer for a legal reason. |
| Server and security logs | Typically up to 90 days, depending on the provider. |
If we restore a backup after a technical problem, we’ll re-apply deletions so deleted data stays deleted.
8. How we protect information
- Data is encrypted in transit (HTTPS/TLS) and encrypted at rest by Google.
- Database and storage security rules are designed so that each account can access only its own records.
- Card payments are handled by Stripe, a PCI-DSS certified payment processor. We never store card numbers.
- Access to administrative systems is limited to the business owner and protected with strong passwords and multi-factor authentication. Backup copies are encrypted.
No system is perfectly secure. Please use a strong, unique password and keep your devices secure.
9. Your rights and choices
Wherever you live in the U.S., you can:
- Access and export: view your records in the app. Every plan can download CSVs for the current year, and Pro adds full JSON and CSV exports for all years. On any plan, you can also email us to get a free copy of all the personal information we hold about you, including records from every year and receipt photos.
- Correct: edit your records in the app, or ask us to correct information you can’t change yourself.
- Delete: delete individual items in the app (they go to the Recycle Bin for 30 days, and you can empty it sooner). To delete your entire account, email service@workwellkept.com from your account email address with the subject “Delete my account.” Deleting your account also cancels any subscription. We keep only what we must keep by law (see Section 7).
- Opt out of marketing emails: use the unsubscribe link in any marketing email. We’ll still send service emails such as receipts and legal notices.
- Appeal: if we deny your request, reply to our decision to ask us to reconsider. We’ll respond within 60 days. If you’re still unsatisfied, you can contact your state attorney general.
How we handle requests: we verify requests by confirming they come from your account email address. We respond within 45 days (usually much sooner). We may extend that once when reasonably necessary and will tell you if we do. Requests are free. We won’t treat you differently for exercising your rights. You may use an authorized agent if we can verify the agent has your permission.
10. State privacy laws
Several states, including California, Indiana, and others, have comprehensive privacy laws that apply to businesses above certain size or data-volume thresholds. Based on our current size, we believe we do not currently meet those thresholds. We still offer the rights in Section 9 to all U.S. users, and we will update this policy if those laws begin to apply to us.
California residents: In the past 12 months we collected the categories of personal information described in Section 2 (identifiers such as email and IP address; commercial information such as subscription history; financial-type records you choose to enter, such as income and expenses; internet activity such as log data; and images you upload), from the sources and for the purposes described in Sections 2–3. We disclosed them only to the service providers in Section 4. We do not sell or share personal information and do not use sensitive personal information to infer characteristics about you. California’s “Shine the Light” law: we don’t disclose personal information to third parties for their own direct marketing.
11. Children
The Service is only for adults 18 and older. It is not directed to children, and we don’t knowingly collect personal information from anyone under 13 (or anyone under 18). If we learn that we have, we’ll delete it and close the account. If you believe a child has given us information, contact service@workwellkept.com.
12. If there’s a security breach
If a security breach affects your personal information, we will notify you by email without unreasonable delay and within the time required by law (for example, Indiana law requires notice no later than 45 days after a breach is discovered), and we will notify state attorneys general and other authorities when required. The notice will explain what happened, what information was involved, what we’re doing, and steps you can take.
13. U.S. only
The Service is intended only for people in the United States, and your information is stored and processed in the United States.
14. Changes to this policy
We’ll post any update here with a new “Last updated” date. If we make a material change, such as enabling advertising networks or collecting a new type of data, we will notify you by email or in the app before the change takes effect. Where the law requires your consent to a change, we will ask for it.
15. Contact us
Work Well Kept
Elkhart, Indiana, USA
Email: service@workwellkept.com