1. Who is responsible
Beforework is currently operated as a pre-launch service by its individual owner, who is responsible for the personal information described here. Privacy questions and rights requests can be submitted through our support form or emailed to valikastrati.vv@gmail.com.
2. Information we process
- Founding access: email address, trade, signup source, and signup time.
- Purchases and licenses: checkout email, Paddle customer and transaction references, amounts, currency, payment status, and license status.
- Support: email address, support category, message, and submission time.
- Product analytics: a random browser-session identifier and a small set of product events. We do not store advertising identifiers or the contents of your change orders in analytics.
- Security and reliability: short-lived, one-way request fingerprints for rate limiting and limited technical error records.
- Remote approvals: recipient name and email, the frozen document revision, invitation and delivery events, review and response times, printed name, drawn signature, consent wording, and limited one-way technical fingerprints used to protect the signing record.
3. Change-order drafts
Draft change orders are stored in your browser's local storage. When a licensed user chooses Save to account, the draft is also stored in Supabase and tied to that user's account so it can be reopened across devices. A saved draft may include job and client details, pricing, a drawn client signature, and the time that signature was confirmed.
When a licensed customer requests a PDF, the draft is sent to the server to generate that file and is not intentionally retained as a separate PDF-generation record. Removing a signature from the editor updates the current draft; previously downloaded PDFs or older copies outside Beforework are not automatically changed.
4. Remote approval links
When a licensed customer sends a change order for remote approval, Beforework stores a read-only revision and creates a private, expiring link for the named recipient. The raw link secret is not stored in the database. The recipient can review, sign, or decline without creating an account. Completed signed PDFs are kept in private storage for the contractor's account and the recipient's temporary receipt.
Signing links act like temporary passwords and may grant access to job and pricing information. Contractors and recipients should not post or forward them publicly.
5. Why we use information
We process information to provide the product and licenses you request, respond to support, keep transaction records, prevent fraud and automated abuse, understand whether the product works, and diagnose failures. These purposes rely on contract performance, legal obligations, and legitimate operational interests, as applicable.
6. Payments and service providers
Paddle acts as merchant of record and processes checkout and payment information under its own terms and privacy notice. Beforework receives the transaction details needed to fulfill and maintain your license. Vercel hosts and delivers the web application. Supabase provides authentication, database, and private document-storage services. Resend delivers support replies and change-order approval emails. We do not sell personal information or use it for third-party advertising.
Review Paddle's privacy notice for its payment processing practices.
7. Analytics choices
Product analytics are first-party and do not use advertising cookies. Beforework respects Global Privacy Control and browser Do Not Track signals by not creating or sending the analytics session identifier when either signal is enabled. You can also clear the identifier through your browser's site-data controls.
8. Retention and security
We retain information only as long as reasonably needed for the purposes above, including legal, tax, fraud-prevention, support, and dispute requirements. Analytics events are automatically pruned after 90 days and operational errors after 30 days. Rate-limit fingerprints expire with their short enforcement window. Access controls, request validation, encryption in transit, and server-side license checks reduce risk, but no internet service can promise absolute security.
9. Your rights
Depending on your location, you may request access, correction, deletion, restriction, objection, or a portable copy of personal information, and may complain to a competent data protection authority. Submit a request through support. We may need to verify your identity before acting.
10. Changes to this policy
Material changes will be posted here with a revised effective date. If a change materially affects existing customers, we will use a reasonable additional notice where practical.