TL;DR: We collect data to run the Service, never sell your personal information to third parties, store your workspace data in isolated tenant environments, and give you full control to export or delete your data at any time.
1. Information We Collect
1.1 Account & Registration Data
When you sign up, we collect your name, email address, company name, and password (hashed). This is necessary to create and manage your account.
1.2 Workspace Content
All data you create within QuickWrk — including tasks, tickets, kanban cards, emails, comments, and files — is stored on your behalf. You own this data entirely.
1.3 Billing & Payment Information
We collect billing address and subscription plan details. Full card numbers are handled exclusively by our PCI-DSS-certified payment processor (e.g., Stripe/Razorpay). We store only a tokenized reference and the last 4 digits of your card for display purposes.
1.4 Usage & Log Data
We automatically collect log data including IP address, browser type, pages visited, features used, and timestamps. This helps us diagnose issues and improve the Service.
1.5 Communications
If you contact our support team, we retain those communications to resolve your issue and improve our service quality.
2. How We Use Your Data
- To provide, operate, and maintain the Service
- To process payments and manage subscriptions
- To send transactional emails (invoices, password resets, subscription notifications)
- To send product updates and newsletters (you may opt out at any time)
- To detect, prevent, and address fraud, abuse, or security incidents
- To comply with legal obligations
- To improve product features based on aggregated, anonymized usage patterns
We will never use your Content to train AI models or sell it to advertisers.
3. Payment Data & PCI Compliance
QuickWrk does not store your full payment card numbers, CVV codes, or sensitive authentication data on our servers. All payment transactions are processed through PCI-DSS Level 1 compliant payment processors. By providing payment information, you authorize the payment processor to charge the applicable fees on our behalf. Disputes related to charges should be directed to billing@quickwrk.io.
4. Data Sharing & Third Parties
We do not sell, rent, or trade your personal data. We share data only with:
- Payment processors (e.g., Stripe, Razorpay) — for billing
- Cloud infrastructure providers (e.g., AWS) — for hosting and storage
- Email delivery providers — for transactional emails
- Analytics tools — anonymized, aggregated metrics only
- Law enforcement — only when required by law or valid legal process
All third-party partners are contractually bound to protect your data and may only use it to provide services to QuickWrk.
5. Cookies & Tracking
We use cookies and similar technologies for:
- Essential cookies: session authentication, CSRF protection (cannot be disabled)
- Analytics cookies: understanding how features are used (can be opted out)
- Preference cookies: remembering your UI settings
You can manage cookie preferences through your browser settings. Disabling essential cookies will affect your ability to log in.
6. Data Retention
We retain your account and workspace data for as long as your account is active. After cancellation or termination:
- Your data is retained for 30 days to allow export
- After 30 days, all workspace data is permanently and irreversibly deleted from our systems
- Billing records and legal compliance data may be retained for up to 7 years as required by law
- Anonymized, aggregated analytics data may be retained indefinitely
7. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access: Request a copy of your personal data
- Correction: Request correction of inaccurate data
- Deletion: Request deletion of your account and data ("right to be forgotten")
- Portability: Export your workspace data in machine-readable format
- Objection: Opt out of marketing communications at any time
- Restriction: Request that we limit processing of your data
To exercise any of these rights, email privacy@quickwrk.io. We will respond within 30 days.
8. Security Measures
- TLS 1.2+ encryption for all data in transit
- AES-256 encryption for data at rest
- Multi-tenant isolation — your data is never mixed with other customers' data
- Automated daily encrypted backups with point-in-time recovery
- Role-based access controls with audit logging
- Regular third-party security audits and vulnerability assessments
In the event of a data breach affecting your personal data, we will notify you and relevant authorities within 72 hours as required by applicable law.
9. International Data Transfers
QuickWrk is operated from India. If you access the Service from outside India, your data may be transferred to and processed in India. By using the Service, you consent to this transfer. We ensure appropriate safeguards are in place (including standard contractual clauses where required by GDPR).
10. Children's Privacy
The Service is not directed at children under 18 years of age. We do not knowingly collect personal data from children. If we discover that a child has provided personal data, we will delete it promptly. If you believe a child has provided data, please contact privacy@quickwrk.io.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email and an in-app notice at least 30 days before they take effect. Continued use of the Service after the effective date constitutes acceptance of the updated policy.
12. Contact & Data Controller
The data controller for personal data collected via QuickWrk is:
Bangalore, Karnataka, India
Email: privacy@quickwrk.io
Support: support@quickwrk.io
Have questions about your privacy? We're happy to help.