Legal

Privacy policy

Last updated · 3 October 2026Applies to · Workeron and all its appsTerms of service

This policy explains what personal data Workeron collects, why, who it is shared with and the choices you have. It covers the Workeron website, the accounts service and every Workeron app on the web and on mobile.

01

Who we are

Workeron is a product of Txtudio Coretech Private Limited (“Workeron”, “we”, “us”). It includes workeron.app, accounts.workeron.app, Workeron HRM, CRM, Forms and Marketing, and the Workeron HRM mobile app.

Two kinds of personal data pass through Workeron. For your own account (your name, email and sign-in details) we decide how the data is used. For the records an organisation keeps in Workeron (its employees, leads, contacts, form responses and campaign recipients) the organisation decides, and we process that data on its behalf and on its instructions.

If you are an employee, customer or contact of an organisation that uses Workeron and want to know what it holds about you, ask that organisation first. We will help it answer.

02

What we collect

Your account

  • Name, email address and whether it is verified, and a hashed password if you set one.
  • Profile details you choose to add: photo, phone number, timezone, email signature and notification preferences.
  • The organisations you belong to, your roles in them, and invitations you send or receive.

Sign-in and security

  • For each signed-in session: the IP address, the browser or device (user agent) and when it was created.
  • One-time codes and links used for email verification, magic-link sign-in and password resets.
  • A log of actions taken by Workeron administrators, including their IP address, when they act on an account for support.

Workeron CRM

  • Leads, contacts and companies: names, email addresses, phone numbers, job titles, addresses, LinkedIn URLs, do-not-email and do-not-call choices, and any custom fields the organisation adds.
  • Deals, activities, notes, quotes, invoices and payment records. Payments are recorded by the organisation; Workeron does not process card or bank payments.
  • If a user connects a Gmail or Microsoft 365 mailbox: the email messages and calendar events that are synced, including senders, recipients, subjects and content. Access tokens for the mailbox are stored encrypted.

Workeron HRM

  • Employee profiles: name, contact details, address, date of birth, gender, nationality, emergency contact, job details and salary.
  • Payroll details: bank account and IFSC, UPI ID, PAN, UAN, PF and ESI numbers, tax regime and payslips.
  • Identity and onboarding documents the organisation asks for, such as PAN and Aadhaar cards.
  • Attendance: check-in and check-out times and, when location is used, the coordinates at that moment and whether they were inside the branch's area.
  • Leave and time requests, work logs and work entries.

Workeron Forms

  • The answers a respondent submits.
  • A salted, one-way hash of the respondent's IP address (never the address itself), their browser user agent and the page they came from, used to stop abuse.

Workeron Marketing

  • Each recipient's name and email address, whether the campaign was sent to them, and when they unsubscribed.
  • When a campaign email is opened, recorded through a small image in the email.

The mobile app

  • Location, only while the app is open and only when you check in or out. It is never collected in the background.
  • Camera and photo library, only when you photograph or upload a document or profile picture.
  • A random installation ID with the app version and phone operating system version, sent at most every 12 hours while you are signed in, so we know which versions are still in use.

The app does not use push notifications, biometrics, contacts or background location.

03

How we use it

  • To provide Workeron: run the apps, keep each organisation's data separate and show people only what their role allows.
  • To sign you in and keep your account secure, including spotting and stopping misuse.
  • To send service email: verification codes, sign-in links, invitations, password resets, notifications and payslips.
  • To send campaign email and sync mailboxes and calendars, only when an organisation sets that up.
  • To support you when you contact us, and to fix problems.
  • To meet legal obligations.

We do not sell personal data, show advertising, or use the data organisations keep in Workeron to train AI models.

04

Cookies and local storage

The Workeron apps set one cookie: a session cookie that keeps you signed in across Workeron's subdomains. It is required for the apps to work.

The apps also keep small items in your browser: your light or dark theme choice, and short-lived values used while you accept an invitation or after a failed page load.

workeron.app, the public website, sets no cookies and runs no analytics or advertising trackers. It loads its typeface from Google Fonts, so your browser contacts Google when you visit.

05

Who we share it with

We share personal data only with service providers that help us run Workeron, under contracts that limit them to that purpose:

  • Cloud hosting providers, for our servers, database and file storage, and a content delivery network for files.
  • An email delivery provider, for service and campaign email.
  • Google and Microsoft, only when a user connects a mailbox or calendar. Workeron then reads and sends mail and manages calendar events through their APIs, with the permissions shown when connecting.
  • Google Maps, to show branch locations and geofences in HRM.
  • Cloudflare Turnstile, when an organisation turns on spam protection for a public form.

An organisation can also send its own data out of Workeron through API keys and webhooks it sets up. That data goes to destinations the organisation chooses and is then its responsibility.

We may disclose data if the law requires it, to protect people's safety or our rights, or as part of a merger or sale of the business, in which case this policy will continue to apply.

06

Where it is stored

Workeron runs on cloud infrastructure, and your data may be stored and processed outside the country where you live. Wherever it is processed, we protect it as this policy describes and use the safeguards the law requires for those transfers.

07

How long we keep it

  • Account and organisation data is kept while the account is active.
  • Deleted CRM records, campaigns and some HRM entries first go to a recoverable state so they can be restored if deleted by mistake, and are permanently removed later.
  • Read HRM notifications are removed after 30 days.
  • Sign-in links and codes expire within minutes to days and cannot be reused.
  • If you ask us to delete your account or your organisation, we do so within 30 days, except for data we must keep by law (for example, tax records). Copies in backups are overwritten as the backups age out.
08

How we protect it

  • Connections are encrypted in transit (HTTPS).
  • Passwords and API keys are stored only as hashes; mailbox tokens and webhook secrets are encrypted.
  • Every record belongs to one organisation, and every request is checked against that organisation and the person's role.
  • Administrator access to an account for support is time-limited and logged.

No system is perfectly secure. If a breach affects your personal data, we will tell you and the relevant authorities as the law requires.

09

Your rights

Depending on where you live, including under India's Digital Personal Data Protection Act, 2023 and the GDPR, you can:

  • Access the personal data we hold about you and correct it. Most of it you can edit yourself in My profile.
  • Export data. CRM leads, contacts and companies, and HRM records, can be exported to CSV or Excel.
  • Ask us to delete your account or your organisation's data.
  • Withdraw consent at any time: disconnect a mailbox, unsubscribe from a campaign, or turn off location for the mobile app in your phone's settings.
  • Nominate someone to exercise these rights on your behalf, and complain to a data protection authority.

To use any of these rights, email grievance@txtudio.com. We reply within 30 days. If your data is kept by an organisation that uses Workeron, we will pass your request to that organisation.

10

Children

Workeron is a business service and is not meant for anyone under 18. We do not knowingly collect children's personal data. If you believe a child's data has been added, contact us and we will remove it.

11

Changes to this policy

When we change this policy we update the date at the top of the page. If a change is significant, we will tell organisation owners by email or in the apps before it takes effect.

12

Contact and grievances

Txtudio Coretech Private Limited is responsible for this policy. For questions, requests or complaints about personal data, write to our Grievance Officer at grievance@txtudio.com. We acknowledge complaints promptly and resolve them within 30 days.

For anything else, write to business@txtudio.com.

Questions about this page: grievance@txtudio.com. Workeron is a Txtudio Coretech Private Limited product.
Book a demo