Skip to content

Privacy Policy

Last updated: September 15, 2026

Part of a set with the Terms of Service and the Refund Policy. Our processor terms for your clients' data are in the Data Processing Addendum.

1. Information we collect

When you use PaloWorks, we collect:

  • Account information: email, name, and password (hashed).
  • Workspace data: the clients, projects, intake answers, scopes, revisions, change orders, contracts, time entries, and invoices you create — including your clients' names, email addresses, and the briefs they submit through your links.
  • Signing and approval records: when a client approves a scope or change order or signs a contract, we record their typed name, the time, their IP address, their browser's user agent, and a hash of the document text, so the record can be checked later. For new signatures we also retain the document and submission URLs, electronic-signature consent, and approximate city, region and country when supplied by our hosting platform from the network address. This is not GPS location or verified identity. The workspace can download this evidence alongside its signed records.
  • Account text messages: if you add a security phone, we store the number, verification status and your optional event preferences. We track monthly text usage to enforce the account limit. Provider delivery reports and STOP requests help us manage delivery and opt-outs.
  • Usage data: product events (a workspace created, an intake submitted, an invoice sent) and server logs, so we can keep the product working and see which parts are used.
  • Payment information: handled by Stripe. We do not see or store full card numbers.

2. How we use it

  • To run PaloWorks and show your documents to the clients you share them with
  • To process subscriptions and your clients' payments
  • To send essential service mail (sign-in links, invoice and reminder emails you trigger, receipts)
  • To send optional product mail, which you can turn off in Settings → Notifications or from the unsubscribe link
  • To answer support
  • To understand which parts of the product are actually used

3. Who receives data

We do not sell personal information. We share data only with the processors below, each solely to operate PaloWorks, and with authorities when the law requires it or to protect our rights.

  • Vercelhosts the application and serves every page.
  • Supabasestores your account and workspace data.
  • Stripesubscription billing, and card payments from your clients through your own connected Stripe account.
  • Resenddelivers the email the product sends: sign-in links, documents and reminders you send to clients, receipts, and notifications.
  • PostHogproduct analytics. Our servers send it the event name, a timestamp, and your workspace id when something happens in the product (for example “invoice sent”). It never receives the content of a document, a client’s name, or an amount, and no PostHog script runs in your browser.
  • OpenAIthe model provider behind the AI-assisted drafts (draft a scope from a brief, a verdict on a revision request, a payment chase email, a plain-language contract summary). Only when you press one of those buttons, we send the text needed for that draft — which can include your client’s brief and name and the scope or contract text — to OpenAI and show you the result to edit. Nothing is sent automatically, and nothing is sent if you never use those features. OpenAI’s API terms govern its handling of that text.
  • An error-monitoring service (if one is configured)when a page fails on our servers, the error message, the page path with any share token masked, and the time are forwarded so we can fix it. No stack trace, request body, or document content is sent.

If you subscribe a calendar app to your PaloWorks calendar feed, that app's provider (for example Google or Apple) fetches the feed from us: the due dates, amounts, and client names of your unpaid invoices. That happens only after you add the feed, and resetting the feed link in the product stops it.

4. Your clients' data

The people you send links to never need an account. What they type into an intake form, approve on a scope, or sign on a contract is stored in your workspace and shown only to you, your workspace members, and anyone holding that document's link. You are responsible for having the right to put their details into PaloWorks; we process them on your behalf under these terms and the Data Processing Addendum.

When a shared invoice, scope, contract, change order, portal or statement is opened, PaloWorks records that it was opened and when, so the person who sent it can see it. It does not record who opened it or their IP address for this, and repeat opens within 30 minutes count once. Each of those pages says so in its footer.

A client can also sign in, optionally, to see every project and document studios have shared with their email address in one place. There is no password: we email a one-time code that expires after 10 minutes. For this we store the email address, a keyed hash of the code (never the code itself) and of the requesting IP address, and, once they sign in, a keyed hash of the token in their session cookie, their browser's user agent, and when the session was last used. A session lasts 30 days or until they sign out. Expired codes are deleted within 1 day and expired sessions within 7 days. Signing in shows only what your share links already show and gives no access to your workspace.

5. Retention and deletion

We keep your data while the account is open. A project you delete sits in Settings → Recently deleted for 30 days, where you can restore it, and is then purged. When you close your account (Settings → Account → Close account), we delete your personal information and your workspace data within 30 days, except where the law requires us to keep a record — for example invoices tied to processed payments, which Stripe also retains under its own policy. Backups roll off on the same schedule.

Uploaded files are available for download for 12 months from upload. We retain the private storage objects for up to 18 months for operational recovery before scheduled deletion. The additional retention period does not extend download access. File metadata and document-signing records may remain with the project for recordkeeping. Download and keep your own copies before access expires.

Inquiry conversations include messages submitted through private reply links. When an inbound email service is configured, we also process replies addressed to an inquiry-specific address, their sender, message content and provider reference so the studio can continue the conversation. Anyone with a private conversation link can access that conversation; keep these links confidential.

Some records are swept automatically while the account is open:

  • The text of an AI draft — the brief or contract text sent and the draft returned — is erased 30 days after the draft was made; the remaining record (its kind, status, and time) is deleted after 365 days.
  • The email delivery log, which records the address a message was sent to and whether it arrived, is deleted after 90 days.
  • Expired sign-in sessions are deleted 7 days after they expire.

6. Security

Data is encrypted in transit (HTTPS) and at rest by our hosting providers. Passwords are hashed. Share links use long random tokens and can be rotated or revoked from the project. No method of transmission or storage is completely secure, and we will tell you if we learn of a breach affecting your data.

Report a security vulnerability to security@paloworks.com. A person who works on the code reads every report. Please give us a reasonable chance to fix a problem before you disclose it publicly, and do not access, change, or delete data that is not yours while you test. The same contact is published at /.well-known/security.txt.

7. Your rights

  • Update your name and password in Settings → Account
  • Export your workspace data as JSON from Settings → Your data
  • Turn off non-essential mail in Settings → Notifications or with the unsubscribe link in any such email
  • Close your account from Settings → Account → Close account; a workspace owner can close the workspace with it
  • Ask us at support@paloworks.com to access, correct, or delete anything the product does not let you change yourself

8. Cookies

We use essential cookies to keep you signed in and to remember preferences. We do not set advertising or third-party tracking cookies in your browser. Product analytics is sent from our servers to PostHog as described above, not collected by a script on the page.

When you arrive on our public site from a link, we may also set first-party cookies that remember how you found us, so a referral or campaign is credited when you sign up: cr_ref and cr_aref (the page or partner that referred you, 90 days), cr_rcode (a customer's referral code, 90 days), cr_utm (the campaign tags in the link you followed, 30 days) and cr_draft (a draft you started in one of our free tools, 7 days). They hold no name or email, are read only by our own servers, and the sign-up ones are cleared once your workspace is created.

9. Children

PaloWorks is not for people under 18. We do not knowingly collect information from children.

10. International

Your data may be stored and processed in the United States or other countries where the processors above operate. Using PaloWorks means you accept that transfer.

11. Changes

We may update this policy. If the change is material, we will tell you by email or in the product, and the date at the top will change.

12. Disputes

Disputes about this policy are resolved under the Terms of Service, including the binding individual arbitration, jury waiver, class waiver, limitation of liability, and Massachusetts governing law in those terms. This policy does not enlarge our liability.

13. Contact

Questions about this policy: support@paloworks.com. Ferrier Industries LLC is a Wyoming limited liability company. PaloWorks by Ferrier Industries LLC. Write to legal@ferrierindustries.com for the current mailing address.

This policy is provided by Ferrier Industries LLC. It is not legal advice.