Privacy policy
Version 1.0 · in effect from
Aug 1, 2026
This explains what Orindesk stores, why, who else can see it and how
long it is kept. It is written to be read rather than skimmed past, and it is
specific on purpose: a policy that lists actual fields and actual companies can
be checked, and one that says “certain information may be shared with
selected partners” cannot.
1. Who is responsible for what
Orindesk is operated by Orindesk (“we”, “us”). Correspondence about this policy can be sent
to 6008 Orange Tip Way, Roseville, CA 95747 or to
[email protected].
There are two different relationships here and they are worth separating, because
the answers below differ depending on which one applies:
-
Your account with us. You signed up, you pay us, and we
decide what to store about that. This policy is our policy for it.
-
The records you keep inside the service. Your clients, your
staff, your quotes and invoices. You decide what goes in there and why; we
hold it on your behalf and do not use it for our own purposes. If one of your
clients asks what you hold about them, that question is for you, not for us —
though we will help you answer it.
In plain terms: we look after your account. The information about
your customers is yours, we are just storing it.
2. What we store about you
When you create a workspace we store:
- your company name and the web address you chose;
- your name, email address and, if you give one, a phone number;
- your password, as a one-way hash — we cannot read it, and neither can anyone
who obtains a copy of the database;
- which plan you are on, what you have agreed to pay, and when your trial ends;
- the date you accepted these terms and the version you accepted;
- the last time somebody signed in to your workspace.
We do not store card numbers. Card details are entered on a page
hosted by Stripe and never reach our servers. What we keep is Stripe’s
reference for your customer and subscription, whether the last payment succeeded,
and when the next one is due.
3. What you store about your clients and staff
Each workspace has a database of its own, not a shared one with a column saying
which company a row belongs to. Yours holds whatever you put in it, which the
software is built to include:
- Clients — name, contact name, email, phone, address and any
notes you write;
- Staff — name, job title, email, phone, hourly and overtime
cost, and notes;
- Work — quotes, change orders, invoices, payments, projects,
jobs, appointments, expenses and labour entries;
- Files — photographs and documents you upload, and the PDFs
the system generates;
- An audit log of who did what inside your workspace.
We do not read it, mine it, sell it, or use it to train anything. It is used to
run the service for you and for nothing else.
Worth knowing: notes fields are free text, so whatever you type
into one is stored exactly as typed. If you would not want something in a database,
do not type it into a notes box.
4. What we measure about how the service is used
Once a night an automated job counts things in every workspace so we can see
whether the service is healthy and being used: how many users a workspace has, how
many were active, and how many quotes, invoices, jobs, payments, clients and files
exist. It records counts, not contents. No client name, no
invoice, no note and no file is copied out of your workspace by it.
We also keep a log of account-level events — a workspace being created, a payment
succeeding or failing, a plan changing, a backup failing, and every administrative
action we take. Each entry records the company name, what happened, when, and the
amount where money is involved.
5. The other companies involved
These are all of them. Nothing is sent anywhere not on this list.
-
DigitalOcean — hosts the servers and stores the off-site
copies of the backups. All of it is in the United States.
-
Stripe — takes the payments. They receive your name, email and
card details; the card details go to them directly and not through us.
-
Postmark — delivers email we send on your behalf, such as a
quote or an invoice. They receive the recipient’s address and the content
of the message. If you put your own mail server details into Settings, your
mail goes through yours instead and Postmark is not involved.
-
Cloudflare — sits in front of the site, handling the domain
and filtering abusive traffic. Requests pass through them.
-
Google — only if address autocomplete is switched on. When it
is, what you type into an address box is sent to Google’s Places service
to suggest completions. Nothing else is.
-
Jobber — only if you connect a Jobber account yourself, and
only to import what you ask it to.
There are no advertising networks, no analytics services and no tracking pixels on
this site or in the application. We checked rather than assumed: there is no
Google Analytics, no Facebook pixel and no third-party script of any kind on the
pages you use.
6. Who can look at your data
Your own users, according to the roles you give them. Beyond that, we can — and
the way that works is deliberately visible:
-
Support sign-in. We can sign in to your workspace to help with
a problem. It signs us in as your owner account, so it can see exactly what
that account can see and nothing more. While it lasts, a banner appears across
every page saying a support session is in progress, and a line is written into
your own audit log naming it. The permission that allows it expires after five
minutes and can only be used once.
-
Direct database access. Whoever administers the servers can
technically read any database on them. That is true of every hosted service;
what we can tell you is that it is limited to the people who operate
Orindesk, and that it is not part of anybody’s routine work.
The point of the banner: you should never have to take our word
for it that nobody has been in your account. Look at your audit log.
7. How long everything is kept
-
Your workspace — for as long as you have an account. Switching
an account off does not delete anything; it locks it.
-
Backups of the databases — taken nightly, copied to separate
storage in a different data centre, and deleted after 90 days.
A record you delete today can therefore still exist in a backup for up to
ninety days afterwards, which is what makes it possible to recover from a
mistake.
-
Account events and the nightly counts — two
years, then deleted automatically.
-
After you leave — see the terms for what happens to a deleted
workspace. Deletion removes the database; the backups age out on the schedule
above.
8. Cookies
One cookie, and it only exists to keep you signed in. It holds a session
identifier and nothing else, it is marked HttpOnly so no script can
read it, it is restricted to this site, and it is sent only over an encrypted
connection. There are no advertising or analytics cookies, which is why there is
no cookie banner — there is nothing to consent to.
9. Getting a copy, or getting it deleted
Your data is yours. You can export your records from inside the application at any
time without asking us. If you want the whole workspace deleted, ask us and we
will delete it; the database goes immediately and the backups containing it age
out within ninety days.
Depending on where you live you may have specific legal rights over your personal
information — to see it, correct it, take it elsewhere or have it erased. Write to
[email protected] and we will deal with
it. If a request concerns information one of your clients has given
you, we will pass it to you rather than act on it ourselves, because that
record is yours and not ours.
10. Changes, and how to reach us
If this policy changes in a way that matters, we will tell account holders by
email rather than quietly editing the page. Each version has a number and a date
at the top, and the version you accepted when you signed up is recorded against
your account.
Questions to [email protected], or by
post to 6008 Orange Tip Way, Roseville, CA 95747.
See also the terms of service.