Privacy Policy

What we collect

  • Account data: email, name, authentication identifiers (Google subject id or a password hash — never the password).
  • Organization data your team enters: clients, projects, tasks, rates, time entries, notes.
  • Operational logs (requests, errors) retained briefly for reliability and security; error reports exclude request bodies.
  • Usage analytics via Google Analytics: page views on our marketing site plus two interaction events there (a call-to-action click, and the demo video being played or finished), and in the application a small set of product-milestone events (account created, import completed, checkout started/completed). Analytics never receives your organization’s data — no clients, projects, rates, or time entries.

What we do NOT do

  • No selling or sharing of personal data for advertising.
  • No advertising trackers or ad-network pixels anywhere. Analytics is limited to the Google Analytics events described above.
  • No training of AI models on your organization’s data.

Processors

Infrastructure: Amazon Web Services (hosting, email), Neon (database), Stripe (payments — card data never touches our servers), Google (optional sign-in and analytics), Sentry (error reports). Each processes data solely to provide their service to us.

Accounting connections you choose to make

An administrator may connect the organization’s QuickBooks Online or Xero account so that a recorded billing run can be created there as a draft invoice. Nothing is sent anywhere until that connection is made and an administrator presses the button on a specific run.

When it is used, we send Intuit or Xero only what an invoice needs: client name, project and task names, the period, hours, rates, amounts and the invoice number. We store the connection’s access and refresh tokens encrypted at rest, the identifier of the company you connected, and the identifier of the contact each client is mapped to. We read your customer, account and tax-code lists to offer them as choices. We never read invoices you created yourself, and we cannot send, alter or collect an invoice — only create the draft.

Disconnecting in Settings revokes our access at the provider where the provider supports it and deletes the stored tokens either way. Invoices already created stay in your books, where you control them.

Retention & deletion

Organization data is retained while the organization exists and for 90 days after cancellation (the Exit Guarantee window), then deleted. Account deletion requests: support@winno.ws.

Security

TLS everywhere, passwords hashed with argon2id, TOTP secrets encrypted at rest, tenancy enforced at the query layer, audit logging on sensitive changes.