workloop

Privacy policy

Last updated 20 September 2026

Workloop is built for trusted daily business operations. We do not sell personal data, and the current release contains no advertising SDK. Optional website analytics stays off unless you actively accept it.

1. Who this policy covers

Workloop is a trading name of Haani Enterprise Limited. Registered in England and Wales. Company number 15758586. Registered office: 35 Well Lane, Batley, WF17 5HQ, England. This policy explains how we handle personal data when a solo service business owner uses the Workloop app, public profile, early-access list, welcome series, or support channels. Haani Enterprise Limited is the data controller for account administration, service security, diagnostics, Workloop communications and support information. For support and privacy questions, email support@workloop.uk.

2. Data you provide

We process account details, business profile and service information, working hours, client records, bookings, tasks, notes, income and expense records, and support messages. If you join the early-access list, we store your email address, consent time, and the page where you joined so we can send Workloop beta and public-launch updates. If you separately request the optional welcome series, we store your email address, whether you are exploring or using Workloop, the source channel, consent version and confirmation time, and email delivery and opt-out status. We send this nine-part series only after you confirm by email. This separately requested series stays limited to nine emails. For new app accounts, we record the email notice shown at signup, whether you opted out, your verified account, delivery status and recent app activity. Where the customer soft opt-in applies, getting-started help, practical tips, Workloop product updates, referral ideas and limited inactivity emails start automatically after a clear signup opt-out opportunity. Otherwise we rely on consent. Every marketing email includes an unsubscribe link. Older accounts are not retroactively enrolled without a recorded basis. We do not use your clients’ booking details to subscribe them to Workloop marketing. A customer who submits a public booking request provides their name, phone number, email address, requested service or time, and any message. If the business accepts that request, Workloop uses the email address to send the customer a booking confirmation and scheduled reminders on behalf of the business, and retains it with the request and client record. If you use Stripe payment collection, Workloop also stores connected-account and transaction references, amounts, currency, status, receipt links, and refund or dispute status needed to show and reconcile payments. When a customer asks for a payment receipt, the email address you enter is sent to Stripe for receipt delivery and may be associated with the payment record. Workloop does not receive or store full card numbers or card security codes. If you choose a device import, Workloop reads the relevant contacts or calendar events on your device to present a review list, then adds only the records you confirm to your workspace. File imports process only the files you select.

Business documents and receipt reading

Business records can also include quote and invoice details, payment terms and deposits, receipt attachments, mileage journeys and reviewed tax-estimate inputs. Receipt reading takes place on your device. Workloop does not send receipt content to an OCR service or store the raw recognised text. Details you choose to apply become part of the expense record. Saved receipt attachments are uploaded to private workspace storage.

3. How data is used

Data is used to authenticate you, provide and secure your workspace, connect business records into daily workflows, create exports, support public booking requests, send early-access and launch updates you requested, answer support enquiries, prevent abuse, and meet legal obligations. If you accept optional website analytics, limited usage data is also used to understand which pages help people discover Workloop and whether they join the launch list. We do not sell personal data. The current release contains no advertising SDK.

Optional local weather

Local weather is off until you enable it. If you choose “Use my location”, Workloop asks your phone for a foreground location and reduces its precision before sending it over an authenticated connection to our Supabase server function. That function requests a forecast from MET Norway using the reduced-precision coordinates; it does not pass your Workloop identity or device IP address to MET Norway.

Weather locations are not saved in your business workspace or used for advertising, and weather does not track your device in the background. Weather responses are held in temporary caches. MET Norway processes the requests under its privacy policy.

You may instead choose a UK area: the address or postcode query is sent to Google Places, and the area you choose is remembered only on this device, separately for each account, for less than 30 days. Tap the weather beside your Today greeting to change the area or turn weather off. Phone location permission can also be changed in your device settings.

Crash diagnostics

Supported releases use Google Firebase Crashlytics to help us find and fix app failures. Reports include technical crash details, code locations, app version, operating system and device information, and installation or session identifiers. These reports are not fully anonymous. Workloop limits reports from its app code to fixed error categories and code locations rather than original error messages or customer content. Reports collected by native software may contain technical exception details and cannot undergo that same filtering. We do not add Workloop account IDs, client records or a history of screens visited and actions taken to Crashlytics reports. Google processes diagnostics under its Firebase data practices at https://firebase.google.com/support/privacy.

4. Legal bases

Where UK or EU data-protection law applies, processing is based on performing our service contract, legitimate interests in operating and securing Workloop, legal obligations, and consent where a device permission, optional feature, or website analytics asks for it. Device permissions can be changed in your operating-system settings, and website analytics consent can be changed through the Cookie settings control in the website footer.

5. Service providers and sharing

Supabase provides authentication, database, storage, and server functions. Resend processes recipient addresses and email content to deliver account and booking messages, customer reminders and eligible Workloop tips and product updates under Resend’s privacy policy. UK2/Stackmail hosts support@workloop.uk for incoming support and account correspondence. Stripe processes card payments, connected-account verification, payouts, refunds, disputes, and requested receipt delivery when you enable payment collection; Stripe receives payment, identity, and any customer receipt email you supply under Stripe’s privacy policy. Google Places may process an address search query when you use address lookup or choose a weather area. MET Norway provides local forecasts using the reduced-precision coordinates sent by our weather server, subject to its privacy policy. If you accept optional website analytics, Google Analytics processes the limited website usage data described below under Google’s information for sites that use Google services and privacy policy. Apple, Google, or your chosen device app may process information when you deliberately open a contact, calendar, map, email, or file action. We disclose data when legally required or when needed to protect users and the service.

6. Optional website analytics and cookies

Google Analytics is disabled by default on Workloop’s public marketing pages and its script is not loaded unless you select “Accept analytics”. If you accept, it may process page URLs and titles, referral and campaign information, browser and device information, approximate location, page views, scroll completion, outbound-link clicks, early-access button clicks, and a launch-list success event. We do not send email addresses, form contents, client records, or other directly identifying form data to Google Analytics. Google advertising signals and optional account data sharing are disabled.

Your choice is stored in your browser so the website can remember it. You can reopen the choice using “Cookie settings” in the website footer. Declining keeps analytics disabled. Withdrawing a previous acceptance updates consent, removes accessible Google Analytics cookies, and reloads the page with analytics off.

7. Your clients’ information

The business using Workloop decides which client information is entered and how it is used, and remains the data controller for its own client records. Haani Enterprise Limited processes those records on that business’s behalf to provide Workloop. The business remains responsible for having a lawful reason to use the information, keeping it accurate and responding to its clients’ rights. If you are a customer of a business using Workloop, contact that business directly about your booking or its use of your information. Do not store unnecessary sensitive information in free-text fields.

8. Retention and deletion

Workspace data is kept while your account is active and as needed to provide the service. Unconfirmed welcome-series requests are removed after seven days. Confirmed welcome-series records are retained to deliver the requested series and honour opt-outs; you can request deletion. Deleting a Workloop app account removes matching welcome-series records. Every marketing email includes an unsubscribe link that stops the applicable journey. Returning to the app stops pending inactivity prompts. Customer reminder emails have a separate stop link for the sending business; stopping reminders does not cancel the booking. The website records only a recognised source channel for these signups, without setting an attribution cookie. Early-access email data is kept until you unsubscribe, ask us to delete it, or the list is no longer needed. Every marketing email will include an unsubscribe route, and you can also contact support@workloop.uk. You can export your workspace and request account deletion from Settings > Privacy & data. Deletion removes the account and workspace through a protected server process, subject to limited records that must be kept for security, dispute, tax, or other legal reasons and normal backup expiry cycles. See the account deletion page.

9. Security

Workloop uses authenticated access, workspace isolation, database row-level security, encrypted network transport, and protected server functions. No online service can promise absolute security, so use a strong unique password and protect access to your device.

10. Your rights

Depending on where you live, you may ask to access, correct, export, restrict, object to, or erase personal data. You may also complain to your local supervisory authority; in the United Kingdom this is the Information Commissioner’s Office. Contact support@workloop.uk to exercise a right.

11. International processing

Service providers may process data outside your country. Where required, appropriate contractual or legal safeguards are used for international transfers.

12. Children

Workloop is a business product and is not directed to children. It must not be used by anyone under 18 to create an account.

13. Changes

We may update this policy as Workloop changes. Material changes will be communicated in the app or through the account contact details where appropriate.

14. Subscription access

For a Workloop subscription purchased through Apple or Google, we store the store transaction reference, product, expiry, renewal or refund status and its association with your Workloop account to verify access. RevenueCat processes verified Apple purchase receipts, subscription events and your Workloop account identifier to track subscription status, under its privacy policy at https://www.revenuecat.com/privacy. This integration does not send your client records, bookings, business notes or account email to RevenueCat. The store handles billing; Workloop does not receive your full payment-card details. We also keep verified trial dates, subscription reminder records and any lifetime beta-access grant. We use your account email to send service reminders about an upcoming trial renewal.

15. Public-page safety

When you report a public business page, we store the page reference and a copy of its public content, your selected reason, any explanation or contact details you choose to provide, and the report status and operator actions. Reports are private and used to assess abuse, protect visitors and handle appeals. We use a salted hash of the request source to limit abusive submissions; the reporting feature does not store the raw IP address in the report. Blocking a page saves a preference on your device or browser. Publication reviews retain submitted public content and approved copies of public images so unreviewed edits cannot replace reviewed material. Safety records are kept as needed to investigate, handle appeals and protect the service, subject to limited legal or security retention and normal backup expiry. Contact support@workloop.uk about a report or privacy request.