DoneWell

Privacy Policy

Effective August 23, 2026

This policy explains what personal information DoneWell collects, why, who else sees it, and what you can ask us to do about it. It is written to be read, not to be survived — if something here is unclear, write to mail@donewellapp.com and we will explain it in plain words.

1. Two kinds of information, two different roles

This distinction runs through the whole policy, so it comes first. DoneWell holds two very different kinds of personal information, and our responsibility is not the same for both.

  • Account information — the people who sign in to DoneWell: business owners and their staff. We decide what we collect here and why, and we answer to you for it directly.
  • Business records — everything a business enters about its own clients: names, addresses, phone numbers, job history, photos, invoices. We hold this on behalf of that business. They decide what to collect, how long to keep it and who may see it. We act on their instructions and do not use it for our own purposes.

If you are a client of a business that uses DoneWell and you want your records changed or deleted, contact that business — they control those records. If they ask us to act, we do.

2. What we collect

When you create an account: your name, email address, password (stored only as a cryptographic hash — we never see or store the password itself), and optionally a phone number and profile photo.

About your business: company name, address, contact details, tax and pricing settings, and the team members you invite.

Records you enter: your clients and their properties, quotes, jobs, visits, invoices, payments, expenses, photos and files you upload, and messages sent or received through the service.

Automatically, when you use the service: your IP address, browser type, and the times of your requests. We use these to keep the service running, apply rate limits, and investigate abuse.

We do not run advertising or third-party analytics. There are no tracking pixels, no advertising cookies, and no behavioural profiling in DoneWell. We do not sell personal information, and we never have.

3. Cookies

We use a small number of cookies, all of them necessary for the service to work:

  • A sign-in session cookie, so you stay logged in.
  • A client-portal session cookie, scoped to the portal, when a client opens a link you sent them.
  • A referral cookie, set only if you arrive through a referral link, so the code can be applied at signup.
  • A theme preference, so the interface stays in light or dark mode.

None of these are used for advertising or shared with advertisers. Blocking them will stop you from signing in.

4. How we use information

  • To provide the service: showing your schedule, sending quotes and invoices, collecting payments, and keeping your data available to the people you authorised.
  • To communicate with you about your account: security notices, billing, and changes to the service.
  • To keep the service secure: detecting abuse, enforcing rate limits, and investigating incidents.
  • To meet legal and tax obligations, including keeping payment records.
  • To improve the product, based on aggregate usage — not by reading your business records.

We do not use your business records to train machine-learning models, and we do not share them with anyone except the service providers listed in section 6.

6. Who else receives data

We use the service providers below to operate DoneWell. They may process personal information only to provide their service to us, and are bound to keep it confidential.

ProviderDigitalOcean
PurposeHosting and database infrastructure
What it receivesAll service data, stored in the region the servers are located in
ProviderStripe
PurposePayment processing and subscription billing
What it receivesPayment amounts, payer name and email, and card details entered directly into Stripe
ProviderResend
PurposeOutbound and inbound email delivery
What it receivesRecipient addresses and the contents of the emails sent through the service
ProviderGoogle (Places API)
PurposeAddress autocomplete while typing an address
What it receivesThe partial address text typed into an address field
ProviderGoogle (Calendar API)
PurposeWriting scheduled visits into a connected calendar, when a user connects one
What it receivesVisit time, title, address and a link back to the job — for that user only
ProviderCloudflare (Turnstile)
PurposeBot protection on public forms
What it receivesIP address and browser signals at the moment a public form is submitted
ProviderTelegram
PurposeNotification delivery, only for users who connect their Telegram account
What it receivesThe text of the notifications that user chose to receive
ProviderOpenStreetMap
PurposeMap tiles on scheduling and property screens
What it receivesThe map area being viewed; no customer records are sent

Card numbers are entered directly into Stripe’s payment fields and never reach our servers; we store only the outcome of a payment and the last digits Stripe returns to us.

We will also disclose information if we are legally required to — a court order, for example — or to protect the safety of people or the integrity of the service. We do not sell personal information and do not disclose it for advertising.

7. Google user data

If you choose to connect a Google account so that your scheduled work appears in Google Calendar, we request access only to your calendar events. We use it for exactly one thing: writing, updating and removing the visits assigned to you. We do not read your personal events, and connecting a calendar is entirely optional — the service works without it.

DoneWell’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

You can disconnect at any time from your schedule settings in DoneWell, or by revoking access in your Google account. Disconnecting removes the stored access credentials from our systems.

8. How long we keep it

Business records stay for as long as the business keeps them — that is their decision, not ours. The periods we enforce ourselves are:

DataRead in-app notifications
Retention30 days
DataAll in-app notifications, read or not
Retention90 days
DataExpired sign-in, invitation and portal tokens
RetentionPruned daily once expired
DataBusiness records (clients, jobs, invoices, photos)
RetentionKept until the account owner deletes them or closes the account

When an account is closed we delete its data, except records we must keep for legal or accounting reasons — payment history in particular. Ask us and we will tell you what would remain in your specific case.

9. Security

What we do:

  • All traffic is encrypted in transit with TLS.
  • Passwords are stored as bcrypt hashes, never in a recoverable form.
  • Credentials for connected services (payment, messaging and calendar integrations) are encrypted at rest with authenticated encryption, and are never sent back to the browser once saved.
  • Access inside a company is controlled by roles and permissions that the account owner sets; each company’s data is isolated from every other company’s.
  • Sign-in sessions can be revoked, and changing a password signs out other devices.

No system is perfectly secure, and we will not claim otherwise. If we discover a breach affecting your information, we will tell you and the relevant authorities as required by law.

10. Your rights

You may ask us to:

  • Tell you what personal information we hold about you and how it has been used.
  • Correct information that is wrong or incomplete.
  • Delete your account and the personal information tied to it.
  • Export your data in a machine-readable form.
  • Withdraw your consent to our use of your information.

Write to mail@donewellapp.com. We will respond within the time required by applicable law — under Canadian federal privacy law that is thirty days — and we will not charge you for a reasonable request. If you are unhappy with our answer you may complain to the Office of the Privacy Commissioner of Canada.

If your request concerns records held by a business that uses DoneWell rather than your own account with us, we will point you to that business, who can act on them directly.

11. Where data is processed

DoneWell is operated from Canada and our servers are located in Canada. Some of the providers listed in section 6 operate internationally, which means information may be processed outside Canada and may be accessible to courts and authorities in those countries. We choose providers that commit to protecting it, but we cannot exempt them from the laws they operate under.

12. Children

DoneWell is a tool for businesses and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child’s information has reached us, write to mail@donewellapp.com and we will delete it.

13. Changes to this policy

We update this policy when the service changes. The effective date at the top always reflects the current version. If a change materially affects your rights, we will tell account holders by email before it takes effect rather than relying on you to notice the date.

14. Contact

Privacy questions and requests: mail@donewellapp.com
Everything else: support@donewellapp.com

Amazing Canada Inc.
3-635 Marsh Rd NE, Calgary, AB T2E 5B4, Canada

See also our Terms of Service.