Privacy Policy
Last updated June 22, 2026
This Privacy Policy describes how Workback, LLC ("Workback," "we," "us," or "our") collects, uses, and shares information when you use our websites at tryworkback.com and app.tryworkback.com and the services we provide through them (together, the "Service").
Workback is a production calendar platform built for production and agency professionals. It is a business tool, and this policy is written with that in mind.
If you have questions about this policy or your data, contact us at support@tryworkback.com.
1. Information we collect
Information you provide to us
Account information. When you create an account, we collect your first and last name, email address, and a password (stored in encrypted form by our authentication provider). If you sign in with Google, we receive your name, email address, and profile photo from Google instead of a password. You may later add or change a profile photo, set your timezone, and configure notification preferences.
Organization information. Workback accounts belong to organizations (workspaces). We store your organization's name and any logo you upload.
Content you create. The core of Workback is the content you and your team create: projects, folders, calendar events (titles, dates, colors), production details such as parties, stages, and information fields (for example, director, client, agency, post house, editorial, music, finishing), export notes, and images you upload such as organization, client, and agency logos.
Waitlist and contact information. If you join our waitlist on the marketing site, we collect the name and email address you submit.
Communications. If you contact us by email or through the in-app feedback and support widget, we receive the contents of those messages along with your name and email address.
Information we collect automatically
Usage analytics. With your consent, we use PostHog to understand how the Service is used. This includes pages visited, features used, clicks and interactions, browser and device information, IP address, and product events tied to your account (such as creating a project or exporting a calendar). PostHog also records sessions of app usage; in these recordings, all text and media are masked and not captured. PostHog analytics and session replay do not load until you accept optional analytics cookies (see "Cookies and similar technologies" below). Analytics on the marketing site work the same way for visitors.
Error and performance monitoring. We use Sentry to detect and diagnose errors. When an error occurs, Sentry receives technical details about the error along with your IP address and account identifiers (user ID and email) so we can investigate. Sentry also records session replays for diagnostic purposes; these replays load only with your consent, and all text and media in them are masked. We also use Vercel Web Analytics and Speed Insights for aggregate, cookieless measurement of page views and performance; these set no cookies or cross-site identifiers and run as part of operating the Service.
Cookies and similar technologies. We use cookies and similar browser storage in two categories.
Essential (always on). These are required to run the Service and do not track you across other websites:
- Authentication session cookies that keep you signed in. The Service does not work without these.
- Browser storage for your preferences — for example light/dark theme, calendar view settings, and your cookie choice.
- Cloudflare Turnstile, which protects our sign-in, sign-up, and password-reset pages from automated abuse.
- Reliability monitoring — Sentry error reporting and Vercel Web Analytics and Speed Insights — which are cookieless or set no cross-site identifiers, and from which your project content is masked.
Optional analytics (off until you accept). With your consent, we use these to understand how Workback is used so we can improve it. They do not load, set cookies, or collect any data until you accept them in our cookie banner:
- PostHog — product analytics and session replay (all text and media masked).
- Sentry Session Replay — diagnostic session replays (all text and media masked).
Your choice. When you first visit Workback, a banner lets you accept or decline optional analytics, and we remember your choice on your device. You can change it at any time through the "Cookie preferences" control in Settings → Notifications, or in the footer of our sign-in pages. If you withdraw consent, we stop the optional analytics and delete the cookies and storage they created.
Payment information
Billing is not yet enabled on the Service. When it is, payments will be processed by Stripe. We will store identifiers such as your Stripe customer ID and subscription status, but we will never store your full card number — that information goes directly to Stripe and is governed by Stripe's privacy policy.
2. How we use information
We use the information we collect to:
- Provide and operate the Service, including syncing calendar changes to collaborators in real time
- Create and manage accounts, organizations, invitations, and notifications
- Send transactional emails such as invitations, sign-in and password emails, share notifications, and — if you enable it — a daily digest email summarizing your subscribed projects (note that digest emails include project names and event titles)
- Send product update emails, which you can unsubscribe from at any time
- Understand how the Service is used so we can improve it
- Monitor for errors, abuse, and security issues, including rate limiting by IP address and bot protection
- Comply with legal obligations and enforce our Terms of Service
We do not use your content or personal information to train AI models, and we do not sell personal information or share it for targeted advertising.
3. How we share information
Service providers
We share information with vendors that help us run the Service. Each receives only what it needs:
| Provider | Purpose | Data involved |
|---|---|---|
| Supabase | Database, authentication, file storage, real-time sync | Account information and all content you create |
| Vercel | Hosting, plus cookieless web analytics and performance monitoring | Request traffic, server logs, and aggregate page-view and performance metrics |
| PostHog | Product analytics and session replay, with your consent (all text and media masked) | Usage data, IP address, user ID, email, organization ID |
| Sentry | Error monitoring, plus diagnostic session replay (replay with your consent) | Error reports, IP address, user ID, email, masked session replays |
| Resend | Transactional email delivery | Recipient email addresses and email contents (including digest contents) |
| Loops | Product update emails | Name, email address, user ID |
| Upstash | Rate limiting and scheduled tasks | IP addresses and user IDs used for rate-limit counters |
| Cloudflare | Bot protection and DNS | CAPTCHA interaction signals and IP address |
| Sign-in with Google (if you choose it) | OAuth sign-in handshake | |
| Featurebase | Feedback, support, and sales-chat widget (in our app and on our website) | Name, email address, user ID, and messages you submit |
| Stripe (when billing launches) | Payment processing | Payment and billing details |
Our infrastructure and these providers process data in the United States.
A Data Processing Agreement is available on request for customers who require one — contact support@tryworkback.com.
People you collaborate with
Workback is a collaboration tool, and sharing is part of how it works:
- Organization members can see your name, email address, and profile photo, and can see your role in the organization.
- Project collaborators, including collaborators from other organizations who are invited to a project, can see everything within that project: events, production details, information fields, and associated logos. Collaborators from other organizations cannot see your organization's other projects.
- Share link recipients. Anyone who has an active share link to a project can view that project's calendar — including the project name, events, production details, and logos — without creating an account. Share links can be set to expire and can be revoked at any time by the project's editors. Manage your share links carefully; they are the equivalent of handing someone the calendar.
- Uploaded images (profile photos and organization, client, and agency logos) are served from public URLs. The URLs are not guessable, but anyone who has a URL can view the image.
Legal and business transfers
We may disclose information if required by law, to protect the rights, safety, or property of Workback or others, or in connection with a merger, acquisition, or sale of assets — in which case this policy would continue to apply to your information until you are notified otherwise.
4. Data retention
- Active accounts. We keep your information for as long as your account exists.
- Deleted projects are soft-deleted: hidden from the Service but recoverable by contacting support. Events and other items deleted individually are removed immediately.
- Notifications are automatically purged (read notifications after 30 days, unread after 180 days).
- After cancellation. When billing launches, if your subscription ends, we retain your organization's data for 90 days so you can export it or reactivate, after which it becomes eligible for deletion.
- Deletion requests. You can request deletion of your account and personal information at any time by emailing support@tryworkback.com. We will honor verified requests within the timeframes required by applicable law.
5. Your rights and choices
- Access and correction. You can view and update your name, email, photo, and preferences in your account settings.
- Deletion. Email support@tryworkback.com to request deletion of your account and associated personal information.
- Email preferences. Product update emails include an unsubscribe link. The daily digest can be turned off in your settings.
- Cookies. Optional analytics cookies are off until you accept them, and you can change your choice at any time via "Cookie preferences" in Settings or in the footer of our sign-in pages. Strictly necessary cookies cannot be disabled without breaking sign-in.
Depending on where you live, you may have additional rights under laws such as the California Consumer Privacy Act — including the right to know what personal information we hold, to request deletion, and to not be discriminated against for exercising those rights. We do not sell personal information. To exercise any of these rights, email support@tryworkback.com.
6. International users
Workback is operated from the United States, and data is processed in the United States. If you use the Service from outside the US, you understand that your information will be transferred to and processed in the United States, where data protection laws may differ from those in your country.
7. Security
We take security seriously and apply measures appropriate to a production system, including encryption in transit (HTTPS with strict transport security), database-level tenant isolation so each organization's data is segregated, rate limiting, bot protection on authentication pages, and restricted internal access to production systems. No method of transmission or storage is completely secure, so we cannot guarantee absolute security — but we work to protect your information and will notify you as required by law if a breach affects your data.
8. Children
Workback is a business tool intended for users 18 and older. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us information, contact support@tryworkback.com and we will delete it.
9. Changes to this policy
We may update this policy as the Service evolves. We will post the updated policy here and revise the effective date. If a change is material, we will notify you by email or in the app before it takes effect.
10. Contact
Workback, LLC
Illinois, United States
support@tryworkback.com