Privacy Policy
Last updated August 26, 2026.
VisitWorks LLC ("VisitWorks", "we", "us") makes Visit.Works, a scheduling and route planning product for field-service businesses such as landscaping, pest control, pool service, and power washing companies. This policy covers the web application at app.visit.works and the marketing site at www.visit.works.
We wrote this in plain English on purpose. If anything is unclear, ask us at help@visit.works.
The short version: we hold data about two different groups of people, and our role is different for each. We do not sell personal information. We do not run advertising trackers. We only share data with the service providers listed below.
1. Two groups of people, two different roles
Our users. These are the owners, office staff, and crew members at the businesses that subscribe to Visit.Works. They have accounts and log in. For their account data, we decide how and why it is processed. In privacy-law terms, we are the "controller" of this data. This policy is our direct promise to them.
Our subscribers' customers. These are the homeowners and businesses that receive service visits: the lawn that gets mowed, the pool that gets cleaned. They never log in. They have no account with us and no direct relationship with us. Their information is uploaded and managed by the business that serves them. We store and process it only on that business's behalf and only on its instructions. In privacy-law terms, that business is the controller and we are the "processor".
If you are a customer of a business that uses Visit.Works and you want your information corrected or deleted, contact that business directly. They control the record. We will help them carry out your request, and if you contact us first we will refer your request to them.
The product has no interface for our subscribers' customers at all. Nothing in Visit.Works is shown to them, and they cannot sign in.
2. Information we hold
About our users (we are the controller):
- Name, email address, and phone number
- Role and permissions inside their workspace
- Password, stored only as a cryptographic hash. We cannot see it.
- Two-factor authentication settings
- Session records and sign-in history, including IP address and timestamps
- Messages you send us when you ask for help, whether by email or through the in-app chat
About our subscribers' customers (we are the processor, the subscriber controls it):
- Names, service addresses, phone numbers, and email addresses
- Free-text notes written by the subscriber's staff
- Photos and documents the subscriber attaches to customers and visits
- The history of service visits
About the subscriber's own business (we are the processor):
- Employee records, including time-off entries and crew assignments
- Business settings such as service areas, working hours, and scheduling rules
Collected automatically: standard server logs (IP address, browser type, pages requested) for security and troubleshooting.
We do not collect precise device location. Map coordinates in the product come from service addresses, not from tracking anyone's phone.
3. How we use information
- To run the product: accounts, scheduling, route planning, and the service-visit calendar
- To secure it: sign-in, two-factor authentication, session management, and abuse prevention
- To communicate: invitations, password resets, receipts, and service notices
- To support subscribers when they ask for help
- To enforce our one-free-trial rule (see Section 7)
Each subscriber's data is isolated from every other subscriber's data. Our database enforces this separation at the row level, so a query for one workspace cannot return another workspace's records.
We do not use your data, or your customers' data, to build advertising profiles. We do not sell personal information, and we have not sold it in the past.
4. Service providers who receive data
We share data only with the providers below, only so they can perform a service for us. Each one is bound by contract to use the data solely to provide that service.
- Anthropic. Powers the in-app help assistant our subscribers' staff can use to ask questions about the product. The text of the question is sent to Anthropic to generate an answer. This assistant is for our users only; it is never exposed to our subscribers' customers.
- Google Geocoding. To plan routes, we convert service addresses into map coordinates. The address is sent to Google's geocoding service; the customer's name and other details are not. A subscriber's workspace may instead be configured to use the public OpenStreetMap Nominatim service.
- Google Cloud Storage. We keep off-site backup copies of our database with Google Cloud Storage so we can recover from a disaster. Each backup is encrypted on our own servers before it leaves them, so it is protected in transit and at rest, and Google receives only encrypted data it cannot read.
- Microsoft. Our outbound email is delivered through Microsoft 365. That covers account and support notices (user invitations, password resets, and the like) and emails a subscriber sends through the product, such as estimates sent to its customers. Message content and recipient addresses pass through Microsoft in transit.
- Stripe (payment processing; not yet active, planned with self-service signup). When live, payment details will go directly to Stripe. We will not store full card numbers on our systems.
- Telnyx (text-message delivery; planned for October 2026). When live, Telnyx will carry the text messages described in Section 6.
- Cloudflare. Provides DNS, content delivery, and hosting for the marketing site. Cloudflare sits in front of our sites and therefore sees visitor traffic, including IP addresses. We also use Cloudflare Web Analytics on the marketing site; it uses no cookies and does not track individuals.
Route calculations run on our own self-hosted routing engine, and help-search indexing runs locally on our servers. Neither sends data to any outside company.
We may also disclose information if the law requires it, or as part of a merger or sale of the company. If a sale happens, this policy continues to apply to data collected under it until you are told otherwise.
For subscribers who need it, we offer a Data Processing Addendum (DPA) covering the customer and employee data we process on their behalf, and we maintain a list of subprocessors available on request. Subscribers can ask to be notified before we add a new subprocessor.
5. Cookies
The app at app.visit.works uses a session cookie to keep you signed in. It is essential to the product, and it is the only kind of cookie the app sets. We do not use advertising or cross-site tracking cookies anywhere.
The marketing site at www.visit.works sets no cookies of its own. Its analytics (Cloudflare Web Analytics) are cookieless and do not identify individual visitors. Cloudflare, which hosts the site, may set a security cookie when it challenges suspicious traffic; that cookie is not used to track anyone. You will not see a cookie consent banner on our sites because there is nothing to consent to.
Some browsers send a "Do Not Track" signal. We do not track visitors across other sites in the first place, so these signals change nothing: there is no tracking to turn off.
6. Text Message Program
This section describes the Visit.Works text messaging program. The full program terms are at our Text Message Program terms page.
What we send. Messages a subscribing business sends to its own customers through Visit.Works: a reminder the day before a scheduled visit, and a notification when the crew is on the way.
Consent. You will only receive messages if you have opted in. The subscribing business is the message sender and is responsible for obtaining your consent before any message is sent. Consent to receive text messages is never a condition of buying any goods or services.
Message frequency varies. Message and data rates may apply. Carriers are not liable for delayed or undelivered messages.
Opting out. Reply STOP at any time to cancel and receive no further messages. Reply HELP for help, or contact us at help@visit.works.
No sharing of mobile opt-in data. No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent will not be shared with any third parties, excluding only the vendors who deliver the messages on our behalf. Opt-in consent is a direct agreement between you and the message sender; it is never transferred or sold.
Phone numbers and opt-in and opt-out records are kept so long as you are subscribed to a message program, and opt-out records are kept afterward so we do not message you again.
7. Data retention
We are deliberate about retention, and we want to describe it honestly.
- Active accounts. We keep data as long as the account is active, because the product's value includes the full history of service visits.
- Photos and documents. File attachments are the exception to the above: they are automatically and permanently deleted after a retention period the subscriber controls, 180 days by default. Anything worth keeping long-term should be exported before that period lapses. Attachments are also removed along with everything else when a workspace is deleted.
- Inactive accounts. When a subscription ends or we close an account, the workspace is marked inactive and its data is held for 180 days. During that hold, the account's Owner can still sign in to export the data, and if the business returns we can restore full access with everything intact.
- Deletion after the hold. Before the hold ends we email the Owner a warning. When the 180 days pass, the workspace and all of its data are permanently and irreversibly deleted. We can pause a deletion in specific cases, but otherwise it happens automatically on that schedule.
- Deletion on request. A subscriber can request deletion of its workspace at any time, and we will carry it out, subject to the exception below.
A deliberate exception: trial-identity records. To enforce our one-free-trial-per-business rule, we keep a small set of identity verification records permanently. These records survive even the deletion of the account they belong to. We keep them because deleting them would let the rule be bypassed by signing up again. This is a fraud-prevention measure, we limit these records to what that purpose needs, and we use them for nothing else.
8. Security
We protect data with measures that include: encryption in transit, passwords stored only as hashes, optional two-factor authentication, role-based permissions inside each workspace, and database row-level security that isolates each subscriber's data from every other subscriber's. No system is perfectly secure, but if we learn of a breach affecting your data we will notify affected subscribers without undue delay, and the DPA sets specific notice commitments.
9. Your choices and rights
If you are a user: you can view and edit your account details in the app. You can ask us for a copy of the personal information we hold about you, ask us to correct it, or ask us to delete it, at help@visit.works. We will verify your identity and respond within 30 days. We will not treat you differently for exercising these rights.
Based on our size and the kind of data we handle, we do not currently meet the applicability thresholds of the California Consumer Privacy Act or the other US state privacy laws. We honor the requests above anyway, as a matter of policy. If a state privacy law does apply to you and to us, we will honor the rights it grants.
If you are a customer of a subscribing business: the business you hired controls your record, so please direct requests to them. We act on their instructions and will support any request they pass to us.
10. Children
Visit.Works is a business tool. It is not directed at children, and we do not knowingly collect personal information from anyone under 16. If you believe a child's data has reached us, contact us and we will delete it.
11. Where data is processed
VisitWorks is a United States company and the product is operated from the United States. Data is stored and processed in the United States. If you use the product from outside the United States, you are sending data to the United States.
12. Changes to this policy
When we change this policy, we will update the date at the top and keep prior versions available. For significant changes, we will notify subscribers by email or an in-app notice before the change takes effect.
13. Contact us
VisitWorks LLC
help@visit.works