Privacy Policy
Last updated: March 29, 2026
1. Introduction
CherryWorks Pro ("Company," "we," "us," or "our") operates the CherryWorks Pro platform (the "Service"). This Privacy Policy explains how we collect, use, disclose, and protect information when you use our Service. By using the Service, you consent to the practices described in this policy.
2. Information We Collect
Account Information. When you register, we collect your name, email address, company name, and password (stored in hashed form only — we never store plaintext passwords).
Business & Financial Information. Through your use of the Service, we process information you provide about your business operations, including: client names and contact details; project details; time entries and work descriptions; invoices, payment records, and financial totals; expense records; and team member/employee information (names, email addresses, rates).
Team Member Personally Identifiable Information (PII). If you use the team member onboarding features, you may provide sensitive data about your team members, including: Employer Identification Numbers (EINs), bank account and routing numbers for ACH payments, Zelle contact information, mailing addresses, and W-9 and team member agreement confirmations. This data is stored to facilitate your payout operations and is accessible only within your organization's account.
Payment Information. Subscription payment information (credit card numbers, billing addresses) is collected and processed directly by Stripe, Inc., our payment processor. We do not store your full credit card number on our servers. We receive and store only the last four digits, card brand, and expiration date for your reference.
Technical Information. We automatically collect technical data including IP addresses, browser type and version, device information, operating system, referring URLs, pages visited, access times, and session identifiers. This data is collected through server logs and session cookies.
3. How We Use Your Information
We use collected information to: provide, operate, and maintain the Service; process your transactions and manage your subscription; send transactional notifications (invoice emails, payment confirmations, account alerts); respond to customer support requests; monitor and improve the security, performance, and reliability of the Service; detect and prevent fraud, abuse, and unauthorized access; comply with legal obligations, including tax and financial reporting requirements; and send product updates and feature announcements (which you may opt out of at any time).
4. How We Share Your Information
We do not sell, rent, or trade your personal information to third parties.
We share information only in these limited circumstances:
Service Providers. We use trusted third-party providers to operate the Service: Stripe, Inc. (payment processing and subscription billing); Microsoft Corporation (email delivery via Microsoft 365/SMTP, and application hosting via Microsoft Azure); and frankfurter.app (currency exchange rate data). Each provider processes only the data necessary to perform their function and is bound by their own privacy policies and contractual obligations.
Legal Requirements. We may disclose information if required by law, subpoena, court order, or government regulation, or if we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others.
Business Transfer. In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity. We will provide notice before your information becomes subject to a different privacy policy.
With Your Consent. We may share information with your explicit consent for purposes not covered by this policy.
5. Data Security
We implement industry-standard security measures to protect your data, including: encrypted connections (HTTPS/TLS) for all data in transit; passwords hashed using bcrypt with salt (never stored in plaintext); secure session management with HTTP-only cookies; role-based access controls ensuring team members can only access their own data; tenant isolation ensuring your data is completely separated from other organizations' data; and regular security monitoring and logging of access to sensitive data.
Important Notice Regarding Team Member Financial Data. Sensitive team member information (EIN, bank account numbers, routing numbers) is currently stored in our database. While access is restricted to authorized administrators within your organization, this data is not encrypted at rest beyond standard database-level protections. We recommend that you limit access to this data to only those individuals within your organization who have a legitimate business need. We are actively working to implement field-level encryption for sensitive financial fields in a future update.
Despite our efforts, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security of your data.
6. Multi-Tenant Data Isolation
CherryWorks Pro is a multi-tenant platform. Each organization's data is logically isolated using organization-scoped database queries. Your data — including clients, invoices, time entries, expenses, payments, team members, and reports — is never visible to or accessible by other organizations using the Service. Each user is associated with exactly one organization and can only access data belonging to that organization.
7. Data Retention
We retain your data for as long as your account is active and your subscription is in good standing. After account termination or cancellation, we retain your data for 30 days to allow you to export it or reactivate your account. After 30 days, your data may be permanently and irreversibly deleted from our systems, including all backups. Financial and transaction records may be retained for up to 7 years as required by applicable tax and accounting regulations, even after account deletion.
8. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal information:
Access & Portability. You may access and export your data at any time using the built-in export features (CSV downloads, PDF invoices, report exports). For a complete data export, contact us at the email below.
Correction. You may update your personal information through your account settings or by contacting us.
Deletion. You may request deletion of your account and associated data by contacting us. Deletion is subject to the retention periods described in Section 7.
Objection & Restriction. You may object to or request restriction of certain processing activities by contacting us.
We will respond to all rights requests within 30 days. There is no fee for exercising these rights.
9. Cookies & Tracking
We use only essential cookies required for the Service to function: session cookies for authentication and login state management, and security cookies for CSRF protection. We do not use advertising cookies, tracking pixels, or third-party analytics services. We do not serve ads within the Service and do not track your activity across other websites.
10. Third-Party Links
The Service may contain links to third-party websites, such as Stripe's payment portal or your clients' websites. We are not responsible for the privacy practices of these external sites. We encourage you to review their privacy policies before providing any information.
11. Children's Privacy
The Service is designed for business use and is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have inadvertently collected data from a child under 18, we will take steps to delete it promptly.
12. International Data
The Service is hosted in the United States. If you access the Service from outside the United States, your information will be transferred to and processed in the United States. By using the Service, you consent to this transfer. We process data in accordance with applicable U.S. federal and state privacy laws.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email to the address associated with your account or through a prominent notice within the Service at least 30 days before taking effect. The "Last updated" date at the top indicates the most recent revision. Continued use of the Service after an update constitutes acceptance.
14. Contact
For questions, concerns, or requests regarding this Privacy Policy or your data, contact us at:
CherryWorks Pro
Use the contact form to reach us.