Privacy Policy
Last updated: September 2, 2026
1. Introduction
WorkAura CRM ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, retain, and safeguard information when you use our CRM platform and services.
WorkAura CRM may integrate with third-party services, including Google services, to provide features requested and authorized by users. When a user connects a Google account, we access only the Google data necessary to provide the requested functionality.
2. Information We Collect
Personal Information
We collect information you provide directly, such as your name, email address, phone number, company information, and payment details when you register or use our services.
Usage Data
- IP address and browser/device information
- Pages visited and session activity
- CRM interactions and operational logs
Location Information
WorkAura CRM may collect precise and approximate location data from employee devices when using our mobile applications.
Location access may include foreground and background location access depending on the operational requirements of your organization.
Background location access is used strictly for legitimate business purposes including:
- Employee Safety Monitoring: Monitoring field employee locations during active work assignments for safety and emergency support.
- Attendance & Geofencing: Detecting employee arrival and departure at work sites.
- Task Allocation: Assigning nearby jobs and optimizing operational efficiency.
- Route Optimization: Improving travel routes and reducing operational delays.
- Emergency Situations: Assisting with emergency response and employee recovery situations.
Location tracking is performed only for authorized business activities and may continue in the background during active work sessions when permitted by the employee and organization policy.
Camera & Media Access
Our applications may request access to the device camera and media storage for work-related functionality.
- Capturing installation and work-site photos
- Uploading job completion evidence
- Scanning QR codes or barcodes
- Uploading profile or verification images
- Document and invoice capture
Camera access is only used when initiated by the user or required during authorized operational workflows.
Notification Permissions
We may request notification permissions to provide:
- Job assignment alerts
- Emergency notifications
- Attendance reminders
- Status and workflow updates
3. Google User Data
WorkAura CRM offers optional integrations with Google services. Users may choose to connect their Google account to enable Google Ads and Gmail functionality within WorkAura CRM.
Google Account Information
When you connect a Google account, WorkAura may receive basic Google account information such as your Google account identifier, name, email address, and profile information. This information is used to identify the connected Google account, associate it with the appropriate WorkAura organization or mailbox, and provide the requested Google integration.
Gmail Data
When you explicitly connect a Gmail mailbox to WorkAura CRM, the application may access and process Gmail mailbox data necessary to provide the integrated email functionality. Depending on the features you use, this may include email messages, message metadata, message threads, labels, folders/mailbox categories, drafts, sent messages, attachments, and other mailbox information that is available through the authorized Gmail connection.
How Gmail Data Is Used
Gmail data is used only to provide and operate the email features that the user explicitly enables in WorkAura CRM. These features include:
- Connecting and authenticating a user's Gmail mailbox.
- Displaying mailbox folders and categories such as Inbox, Sent, Drafts, Trash, Spam, and other available Gmail labels.
- Reading and displaying email messages and their associated metadata inside WorkAura CRM.
- Searching, opening, and managing email messages as supported by the connected mailbox functionality.
- Composing and sending emails from the user's connected Gmail account when initiated by the user.
- Creating and managing drafts as supported by the email integration.
- Deleting email messages by moving them to the Trash mailbox when initiated by the user.
- Permanently deleting email messages from Trash when the user explicitly chooses the permanent deletion action. This action permanently removes the selected message from the connected Gmail mailbox rather than retaining it in Trash.
- Supporting other mailbox actions exposed by the WorkAura email interface when authorized and initiated by the user.
Gmail Message Deletion
WorkAura provides user-initiated Gmail message deletion as part of its integrated mailbox experience. When a user chooses to delete an email, WorkAura can move the selected message to the Gmail Trash mailbox.
WorkAura also provides a separate permanent deletion action for messages that are already in Trash. When the user explicitly chooses to permanently delete a message, WorkAura performs the deletion against the connected Gmail mailbox so that the selected message is permanently removed rather than remaining in Trash.
These deletion actions are initiated by the user through the WorkAura mailbox interface. WorkAura does not permanently delete Gmail messages for unrelated purposes or use message deletion to modify or remove Gmail data without an authorized user action.
Google user data is not used for advertising, marketing, profiling, or unrelated analytics. Google user data obtained through Google APIs is used only to provide or improve the Google-enabled functionality requested by the user.
Google Ads Data
If a user connects Google Ads to WorkAura CRM, Google Ads data is used to provide the requested advertising-management and reporting functionality within WorkAura CRM. Google Ads data is not used for unrelated purposes.
Google API Permissions
WorkAura requests Google OAuth permissions only when they are necessary for the Google features being enabled. The permissions requested are presented to the user through Google's OAuth consent process, and the user may choose whether to authorize the connection.
Google User Data Sharing
WorkAura does not sell Google user data. We do not transfer Google user data to data brokers or use Google user data for advertising. Google user data is not disclosed to third parties except where necessary to provide the requested service, comply with applicable law, protect our rights, or as otherwise authorized by the user.
Google User Data Retention
WorkAura retains Google integration data only for as long as necessary to provide the connected Google functionality and to maintain the user's authorized CRM configuration, subject to applicable legal and contractual requirements. Gmail messages and mailbox data accessed through WorkAura remain subject to the user's mailbox actions and the connected Gmail account's state.
OAuth access tokens and refresh tokens used to maintain an authorized Google connection are stored securely using encryption and access controls. We do not store a user's Google account password.
Disconnecting Google Services
Users can disconnect their Gmail or Google Ads account from WorkAura CRM through the applicable integration settings. When a Google integration is disconnected, WorkAura stops using the corresponding OAuth authorization for future access, subject to processing that is required to complete an already initiated operation or comply with applicable legal requirements.
Google Limited Use
WorkAura's use and transfer of information received from Google APIs will comply with the Google API Services User Data Policy, including the Limited Use requirements. Google user data will not be used or transferred for purposes that are unrelated to providing or improving the user-facing functionality of the WorkAura integration.
WorkAura does not use Google user data to develop, train, or improve generalized or foundational artificial intelligence or machine learning models. Google user data is not transferred to third-party AI/ML services for model training.
4. How We Use Your Information
- Provide and improve our CRM services
- Process payments and manage subscriptions
- Send service updates and marketing communications
- Analyze usage patterns and optimize performance
- Comply with legal obligations
- Enable location-based features for employee safety and field operations
- Monitor field staff locations for emergency response and operational efficiency
The general uses listed above apply to WorkAura account and CRM data. Google user data is subject to the specific Google User Data provisions in Section 3 and is not used for unrelated marketing, advertising, or profiling.
5. Data Sharing
We do not sell your personal information. We may share information with:
- Service providers (hosting, payment processors)
- Business partners with your consent
- Legal authorities when required
- Emergency services in case of safety incidents (location data only)
For Google user data, WorkAura limits access and disclosure to what is necessary to provide the requested Google integration and to meet legal or security obligations. Google user data is not sold, rented, or used for targeted advertising.
6. Data Retention and Deletion
We retain your personal information only for as long as necessary to fulfill the purposes described in this policy, comply with our legal obligations, resolve disputes, and enforce our agreements.
Retention Periods
- Account Information: While your account is active and for up to 30 days after account closure, to allow for reactivation or data export.
- Location Data: Raw location data is retained for 90 days for operational and safety purposes. Aggregated analytics may be kept longer for business insights, but without personally identifiable information.
- Job & Attendance Records: Retained for 7 years to comply with tax and employment regulations.
- Usage Logs: Kept for 12 months for debugging and performance analysis.
- Marketing Data: Until you opt out or request deletion.
- Google Integration Data: Retained only as long as necessary to provide the connected Google functionality and maintain the authorized integration, subject to applicable legal requirements.
User Data Deletion Requests
You have the right to request permanent deletion of your personal data. To do so:
- Contact us at privacy@workaura.com.au with the subject “Data Deletion Request”.
- You will be required to verify your identity before processing.
- We will respond within 30 days and, where feasible, delete your data unless we are required to retain it for legal or legitimate business purposes.
Google Data Deletion and Disconnection
If you disconnect a Google integration or request deletion of associated Google integration data, WorkAura will delete or disconnect the applicable stored Google integration data in accordance with the user's request, our retention obligations, and applicable law.
Disconnecting a Gmail mailbox from WorkAura stops the application from using the OAuth authorization for future mailbox access. Disconnecting WorkAura does not, by itself, delete messages from the user's Gmail account.
Gmail message deletion is a separate user-initiated mailbox action. When a user selects Delete for a Gmail message, WorkAura moves the message to Trash. If the user subsequently selects Permanent Delete for a message in Trash, WorkAura permanently removes that selected message from the connected Gmail mailbox. These actions are performed only when explicitly initiated by the authorized user.
What We Delete
Upon verification, we will delete all personal information associated with your user account, including name, email, phone number, location history, and job records. Some aggregated or anonymised data may be retained for analytics.
For connected Gmail mailboxes, disconnecting the integration removes WorkAura's authorized connection and stops future mailbox access. Disconnecting the integration does not automatically delete the user's Gmail messages. Gmail messages are deleted from the connected Gmail account only when the user explicitly performs the applicable Delete or Permanent Delete action through the WorkAura mailbox.
What We Cannot Delete
We may be unable to delete information that is subject to a legal hold, necessary for fraud prevention, or required for financial auditing (e.g., transactional records). In such cases, we will inform you and restrict access to the data.
7. Your Rights
- Access, correct, or delete your personal data
- Opt-out of marketing communications
- Request data portability
- Withdraw consent at any time
- Disconnect authorized third-party integrations, including Google services
- Disable location tracking (except where required for safety compliance)
8. Data Security
We implement industry-standard security measures including encryption, access controls, and regular security audits to protect your data. Location data is particularly safeguarded with additional encryption layers and strict access controls.
Google OAuth credentials and tokens used by WorkAura are protected using encryption and access controls. WorkAura does not request or store Google account passwords.
9. Permissions Used By Our Mobile Applications
- Camera Permission: Used for capturing work-site photos, documents, QR codes, and job verification images.
- Foreground Location Permission: Used for employee attendance, geofencing, and active job tracking.
- Background Location Permission: Used to support field employee safety monitoring and operational tracking during active work sessions.
- Notification Permission: Used for job alerts, reminders, status updates, and emergency notifications.
- Storage / Media Access Permission: Used for uploading and managing work-related photos and files.
- Internet Access: Required for syncing data, receiving updates, and accessing cloud services.
These permissions are used strictly for authorized operational activities, employee safety, attendance management, and field service workflows.
10. Contact Us
For privacy concerns, support requests, Google data questions, or data deletion requests, please contact us at:
privacy@workaura.com.au