Back

Privacy policy

Workbelt Automation Inc. · Last updated July 25, 2026

1. Overview

Workbelt Automation Inc. (the “Company”, “we” or “us”) operates Workbelt, an AI-powered operations and customer engagement platform for small and medium home service businesses, including flooring and coatings, cleaning, plumbing, electrical, landscaping and HVAC.

This policy explains how we collect, use, store, share and protect information. It applies to our website at workbelt.co, to the Workbelt application and to every other service we provide through them (together, the “Service”). It should be read together with our Terms of Use.

By creating an account or submitting information through the Service you agree to this policy. If you have questions before doing so, email us at privacy@workbelt.co.

2. Two kinds of data, two different roles

Workbelt is business software, so it is important to separate two things:

  • Your account data. The information you give us to open and run a Workbelt account. We decide how this is used, and this policy governs it.
  • Your workspace data. The records you put into Workbelt to run your business — your customers, their contact details and addresses, photos of their premises, job histories, quotes, invoices and message threads. This data belongs to you. We hold and process it on your instructions, as your service provider, to deliver the Service to you. You remain responsible for having the right to collect and to message the people whose information you enter, and for answering their privacy requests. We will help you do so.

3. Information we collect

When you create an account and use the Service, we collect:

  • Account information — full name, business name, email address, phone number, profile picture, and the password hash and two-factor settings for your sign-in.
  • Workspace content you upload — customer records, job and scheduling details, pricing, documents, photos of premises, and the content of messages sent and received through the channels you connect.
  • Payment information — subscription and transaction records. Card numbers are entered directly with our payment processor and are never stored on our servers.
  • Technical and security data — IP address, browser and operating system, device identifiers, locale preference, timestamps, and a log of sign-ins and of important actions taken in your workspace. We keep this to secure accounts, investigate incidents and diagnose faults.

You may decline to provide some of this information, in which case parts of the Service may not work.

4. Information we do not collect

We do not buy personal information from data brokers, we do not build advertising profiles, and we do not sell personal information to anyone, under any circumstances.

5. Cookies

Workbelt sets only strictly-necessary cookies. There are no advertising cookies, no cross-site tracking pixels, and no third-party ad networks:

  • Session — keeps you signed in.
  • Device id — recognises trusted devices for new-device sign-in verification.
  • Active workspace & language — remembers what you were viewing.
  • Theme & cookie choice — remembers your light/dark and consent preference.

Your browser can refuse cookies, but the Service cannot keep you signed in without the session cookie. If we ever introduce analytics, we will update this section and ask for consent first.

6. How we use information

We use the information described above only to:

  • provide, operate and support the Service, and deliver the features you use;
  • process payments and issue invoices and receipts;
  • send you service messages — security alerts, billing notices, and changes to the Service or these policies;
  • secure accounts, prevent fraud and abuse, and investigate incidents;
  • diagnose faults and improve the reliability and usefulness of the Service; and
  • comply with our legal obligations.

We may produce aggregated statistics that cannot identify you, your business or any individual, and use them to understand and improve the Service. We do not use your workspace data to advertise to you or to anyone else, and we do not use it to train general-purpose AI models.

7. AI features

Workbelt uses AI to triage incoming leads, draft replies for your approval, and build draft quotes from your price book. To do that, the relevant content is sent to our AI provider for processing: the text of the message being handled, the related job and pricing details, and — where the feature relies on them — a small number of photos your customer sent.

  • Content is sent only when an AI feature runs, and only what that feature needs.
  • We use providers under terms that prohibit using your content to train their models.
  • AI output is a draft. Quotes and customer replies are sent only when a person approves them, except where you explicitly switch on automatic replies.
  • Data obtained from Google APIs is never sent to AI providers.

8. Service providers we share data with

We share information with the providers below strictly so they can perform services for us, under contracts that limit them to that purpose. We do not sell personal information and we do not share it with advertisers.

  • Stripe — payment processing.
  • Twilio — SMS and WhatsApp messaging.
  • Resend — sending and receiving email on your behalf.
  • OpenRouter and the model providers it routes to — the AI features described in §7.
  • Google — sign-in and Google Calendar, if you connect them (see §9).
  • Meta — Facebook Messenger and Instagram Direct, if you connect them as messaging channels.
  • Slack — notifications to your team channel, if you connect it.
  • Our hosting provider — the servers and database that run the Service.

Each of these providers has its own privacy policy, which we encourage you to review. Connecting an optional channel is your choice, and you can disconnect it at any time in Settings.

9. Google account data

Connecting a Google account is optional and is used for exactly two things:

  • Sign in with Google — we receive your name, email address and profile picture, solely to create or match your Workbelt account.
  • Google Calendar — the permission you grant (calendar.events) covers viewing and editing calendar events, but Workbelt only creates and updates the events for jobs you schedule in Workbelt. We do not use your other calendar data, and we never delete your calendars.

From Google we store only an encrypted access token and the email address of the connected account. Data obtained from Google APIs is never sold, never shared with advertisers, never sent to AI providers, never used to train any model, and is not read by our staff except where you ask us for support, where it is necessary for security or to comply with the law, or in aggregated and anonymised form. It is not included in any transfer of our business assets without your consent. You can disconnect at any time in Settings → Integrations, or revoke access directly at myaccount.google.com/permissions — the stored token is destroyed either way.

Workbelt's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.

10. Where your data is stored

Our application servers and database are hosted in Canada, in electronic form on industry-standard infrastructure. Some of the service providers listed in §8 operate outside Canada, principally in the United States, so information necessary for those services — for example a phone number passed to a messaging provider, or the text of a message processed by an AI provider — is transferred to and processed in those countries, and may be subject to the laws there. We use providers that commit to appropriate safeguards for such transfers.

11. Keeping your data secure

We protect the Service with access controls, encryption of credentials and integration tokens, two-factor authentication on accounts, and strict separation between workspaces so no business can reach another's data. We keep a log of sign-ins and of significant actions taken in your workspace.

No system is perfect, and we cannot guarantee absolute security. If personal information is exposed by a breach of the Service, we will notify affected users and the applicable regulators as required by law, and in any event without undue delay.

12. Retention, access and deletion

  • We keep your account and workspace data for as long as your account is active, and only as long as we need it afterwards to meet legal, tax and accounting obligations.
  • You can export your entire workspace at any time from the dashboard, and delete your account and all associated data from Settings. Deletion is permanent and irreversible, and is confirmed by codes sent to your email and phone.
  • You may also ask us to access, correct or delete your personal information by emailing privacy@workbelt.co. We respond within 30 days. Deleting your personal information may require us to close your account.
  • You may withdraw your consent to our processing at any time, subject to legal or contractual restrictions and reasonable notice, and you may complain to your privacy regulator — in Canada, the Office of the Privacy Commissioner or your provincial equivalent.
  • Security and audit logs are retained for a limited period (currently 180 days) and then removed automatically.

13. When we disclose information

Apart from the service providers in §8, we disclose personal information only:

  • with your consent;
  • where we must comply with a law, a court order or a lawful request from a public authority;
  • where necessary to establish or defend legal claims, or to protect the rights, property or safety of our users, the public or us; and
  • in connection with a merger, acquisition or sale of assets, in which case personal information may be one of the transferred assets — we will give you notice, the acquirer remains bound by this policy, and data obtained from Google APIs is excluded unless you consent separately.

14. Use of the Service by minors

The Service is not intended for anyone under 18, and we do not market to children. If we learn that we hold information about a minor, we will delete it.

15. Changes to this policy

We may update this policy as the product and the law change. The updated version takes effect when posted here, and we will notify you by email or in the app of any material change. Continuing to use the Service after that means you accept the updated policy.

16. Contact us

Questions, privacy requests and complaints go to our Privacy Officer at privacy@workbelt.co. We reply to policy questions within 7 days and to formal requests within 30 days.

Privacy policy · Workbelt