Privacy Policy
Last updated 2026-09-09. If anything here disagrees with how Worknest actually works, the behaviour is the error — tell us at founder@getworknest.com.
Worknest is a software platform operated by PINSKKIY INC ("Worknest", "we", "us"). This policy explains what we collect, why, who else sees it, and how long we keep it. We collect only what the service needs, and we do not sell personal data. Worknest is offered in the United States.
Who the parties are
Two different people use Worknest, and the difference matters throughout this policy.
- A business — a cook or a contractor — has an account with us. We are the data controller for that account.
- A customer buys from that business. The business collects the customer's details through Worknest to fulfil the order; we process them to run the service on the business's behalf.
What we collect
From a business (account holder)
- Name, email address, mobile phone number, business name.
- The business address and pickup location, including map coordinates. If the business publishes a storefront, this is shown publicly on it, because that is what a storefront is for.
- Photos the business uploads: menu items, and (for contractors) work reports.
- Sign-in identity from the method chosen — email and password, Google, or Apple.
- Notification settings and the device tokens needed to deliver push notifications.
- Payment account details are collected and held by Stripe, not by us. We store Stripe's account identifier and the status Stripe reports (whether charges and payouts are enabled).
From a customer placing an order
- Name and mobile phone number.
- For delivery: the delivery address, its map coordinates, the distance we calculate from it, and any delivery instructions given.
- The order itself: items, amounts, pickup or delivery time, and the language the page was read in.
- An optional free-text note. Customers often use this note to state allergies or dietary needs. It is stored with the order and shown to the business so it can act on it. Do not put anything in it you do not want the business to see.
- Whether the customer ticked the box agreeing to order text messages.
- Card details go directly to Stripe. We never see or store a full card number.
Automatically
- IP address, for two narrow purposes: rate limiting (to stop abuse) and counting daily visitors to a shop page. In both cases we store a keyed hash, never the address itself. Rate-limit records are deleted within an hour; visit counts keep only a per-shop, per-day hash.
- Diagnostics — crash and performance reports from the mobile app, which include the account identifier and email of the signed-in business, the device model, the operating system version, and the screens visited before an error.
- Product events — which features are used, recorded against the account, so we can see where the product fails.
Who else receives it
We share personal data only with the service providers that make Worknest work, and only as much as each needs. They act on our behalf and may not use it for their own marketing.
- Stripe — payment details, order amounts, the business's account information. For payments, payouts and disputes.
- Twilio — mobile numbers and message text. For sending transactional SMS.
- SendGrid — email addresses and message content. For sending transactional email.
- Google (Firebase / Google Cloud) — everything stored by the service. For hosting, database, file storage and functions.
- Google Maps / Places — addresses being typed or geocoded. For address autocomplete and distance.
- Sentry — crash and performance reports, including the signed-in account's identifier and email. For finding and fixing failures.
- Expo — device push tokens and notification content. For delivering push notifications.
- Apple / Google — device push tokens and notification content; sign-in identity. For delivering notifications and for Sign in with Apple or Google.
- Cloudflare — requests to a shop's own subdomain, including the visitor's IP. For delivering and protecting those pages.
We also disclose information where the law requires it.
Mobile numbers are never shared with anyone for marketing. Text-messaging opt-in data and consent are never shared with or sold to third parties or affiliates for marketing or promotional purposes.
Cookies and local storage
Worknest sets no cookies of its own. A shop page uses your browser's local and session storage to remember your cart and where you were on the page; that stays on your device. Two providers set cookies of their own on pages where they are used, and both are essential: Stripe at checkout, for payment and fraud prevention, and Cloudflare on shop subdomains, for security. We run no analytics, advertising or session-replay trackers on the storefront or the landing page.
How long we keep things
- Business account (profile, settings, notification preferences) — until the account is deleted.
- Orders, receipts and payment records — kept indefinitely today, because a receipt, a refund, a dispute or a tax question can arrive long after an order. We are reviewing a fixed term with counsel.
- Rate-limiting records (hashed IP) — deleted automatically within one hour.
- Daily shop-visit counts (hashed IP, per shop per day) — kept as counts; the hash cannot be reversed to an address.
- Diagnostics and product events — kept indefinitely today; under review with the same fixed-term question.
- An opt-out from text messages — kept for as long as we operate. An opt-out that expires is an opt-out that fails.
- Backups — daily backups are kept 7 days and weekly backups 5 weeks, so anything deleted can persist in a backup for up to 35 days before it ages out.
Deleting your account
A business can delete its account in the app: Settings → Delete account, then type DELETE to confirm.
Deleted immediately: the sign-in account, the user profile, push tokens and notification settings, team records, and the reservation of the phone number. The storefront is unpublished at once and stops accepting orders. The business's own contact details — phone, email, address — are erased from the company record.
Kept, and why: the order records themselves, including the customer details on them, because a receipt, refund or dispute may still be needed; an internal record that the business existed, with no personal contact details left on it; records Stripe keeps under its own obligations; and our operational logs. Anything deleted may remain in backups for up to 35 days.
One condition: an account cannot be deleted while paid orders are still open — someone has paid for food that has not been handed over. Hand them over, or cancel and refund them, and the deletion goes through. The app says how many are open.
Customers do not have accounts. To ask what we hold about you, to correct it, or to have it deleted, write to founder@getworknest.com; we reply within 30 days. Some records must be kept — a paid order's receipt, for example — and we will say so if that applies.
Your choices
- Reply STOP to any text message to opt out; reply HELP for help. Opting out of texts does not affect an order.
- Turn push notifications off in your device settings, or in the app's notification settings.
- Write to founder@getworknest.com to access, correct or delete your information (see above).
State privacy rights
Residents of some U.S. states have rights to know what personal information a business collects, to have it deleted, to correct it, and not to be discriminated against for exercising those rights. We do not sell personal information and we do not share it for cross-context behavioural advertising. To exercise any right, write to founder@getworknest.com.
Children
Worknest is not directed to children under 13, and we do not knowingly collect their personal information.
Changes
We will update this policy when the service changes. The date at the top is the date of the current version.
Contact
PINSKKIY INC — founder@getworknest.com