Legal
Privacy Policy
This policy explains how On it! Workdesk processes information when organizations coordinate maintenance tickets, people, locations, files, and subscriptions.
1. Scope and responsibility
This policy applies to the On it! Workdesk Android application, owner portal, public website, and related services. The data controller is Israel Mayen Jimenez, RFC MAJI910706GK7, publishing under the Google Play developer name Manic trash panda. Registered domicile: Calle 307 No. 354, Col. Nueva Atzacoalco, Gustavo A. Madero, C.P. 07420, Ciudad de México, México. Questions and privacy requests can be sent to [email protected] or made by telephone at +52 56 3201 5180.
2. Information we process
- Account and profile information, including name, verified email, optional phone number, job details, availability, and workspace memberships.
- Workspace and location information, including business addresses, contacts, equipment, access notes, categories, and responsibility assignments.
- Ticket content, notes, status activity, reminders, expenses, materials, photos, documents, on-site acceptance names, roles, drawn signatures, exception reasons, and other files users choose to submit.
- Approximate or precise location when a workspace enables arrival verification and the user grants Android location permission.
- Device and security information, including generated device identifiers, device model, session records, and protected network-address hashes used for abuse prevention.
- Subscription and billing status, purchase references, fiscal profile details, and tax documents. We do not receive or store full payment-card or bank-account numbers.
3. How information is used
We process information to authenticate users, operate and synchronize workspaces, route and audit tickets, provide directory and reporting features, process subscriptions, prevent abuse, support customers, and comply with legal obligations. We do not sell personal information or use workspace information for third-party advertising.
4. Workspace visibility
Workspace information is visible to authorized members according to role, assigned locations, responsibilities, and ticket participation. Workspace owners and supervisors control those permissions. Contact directory fields are optional, but information intentionally added to a workspace directory can be viewed by authorized workspace members.
5. Service providers
We use Cloudflare for hosting, database, object storage, security, and transactional email; Google services for Android distribution, billing, planned push notifications, and privacy-enhanced YouTube video playback on the public website; and Stripe for web subscription processing. Loading or opening a YouTube video may provide Google with network, device, and playback information under Google's own privacy practices. These providers process information according to their own agreements and privacy practices. Payment providers return transaction references and subscription status rather than complete card details.
6. Storage and security
Cloud traffic is encrypted in transit. Access requires verified sign-in and revocable device sessions. Uploaded files are stored in private object storage and retrieved through authorized requests. We use role checks, non-public object identifiers, file validation, rate controls, and audit events to protect workspace data.
Desk Mode may be hosted directly by a paired phone on the same local network. That local connection may use HTTP and should only be used on a trusted Wi-Fi network or private phone hotspot.
7. Location information
Workdesk does not provide continuous live tracking. When enabled by workspace policy, location is collected only for specific operational events such as arrival verification, and only after the Android user grants permission. Workspace owners can configure whether this information is optional or required for their workflow.
8. Retention and deletion
Information is retained while needed to provide an active workspace, satisfy organization-configured retention rules, maintain security, and meet accounting or legal obligations. After payment suspension, available operational data and uploaded files remain restricted but are preserved for at least three months for reactivation or export. They may remain longer while an authorized deletion or export process is completed, or where security, dispute, backup, or legal requirements apply. Owners should export required records promptly.
A verified account-deletion request begins an enforced 30-day recovery period. During that period the account remains available so the user may request an export of available personal data or cancel the request. Automated cleanup begins after the deadline, normally on the next daily cleanup cycle, and checks workspace ownership again before deletion. Cleanup deletes or irreversibly dissociates sign-in identity, directory data, memberships, notification tokens, and active sessions. Organization-owned operational records may remain in dissociated form for audit and continuity. Payment, tax, fraud-prevention, and dispute records may remain blocked for the legally applicable period; supporting Mexican fiscal documentation is generally retained for five years, and information concerning contractual noncompliance may be retained for up to 72 months where the current law requires it.
Expired sign-in sessions and unverified deletion requests are removed or de-identified on shorter security schedules. We do not automatically delete an active identity merely because the person has not recently signed in.
9. Your choices and rights
Directory details, many attachments, and profile fields are optional. Android asks before accessing the camera or location and before sending notifications. Camera access is requested only when you choose to take a new photo. You may exercise rights of access, rectification, cancellation, or opposition (ARCO), and any additional right provided by applicable law, by contacting [email protected]. State the right you wish to exercise and the information concerned. We will verify identity before acting and respond within applicable legal periods.
10. Children
Workdesk is a business operations service and is not directed to children. Users must have legal capacity to participate in their organization's workspace or be authorized by that organization.
11. Changes to this policy
We may update this policy as the service, providers, or legal requirements change. The effective date above will identify the current version. Material changes will be communicated through the app, website, or account contact when appropriate.