WorkerSafe ("WorkerSafe," "we," "us," or "our") provides safety management software that helps organizations track incidents, manage compliance, conduct inspections, and protect their workforce (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use the Service or visit our websites at https://www.workersafe.com and https://app.workersafe.com.
This policy applies to our customers (the organizations that subscribe to the Service), the individual users who access the Service on their behalf, and visitors to our website. If you are an employee whose data was entered into WorkerSafe by your employer, please also review your employer's privacy notice, as they control that data.
The Service is offered to organizations located in the United States.
1. Who We Are and Our Role
For most data processed within the Service, our customers (employers and organizations) control the data and WorkerSafe processes it on their behalf and instructions. We process that data only to provide the Service under our agreement with the customer.
For our website, marketing activities, and account administration, WorkerSafe determines how and why personal information is processed.
Contact:
WorkerSafe, Inc.
18881 West Dodge Road, Suite 200W, Elkhorn, Nebraska 68022
compliance@workersafe.com
2. Information We Collect
Account and contact information. Names, business email addresses, phone numbers, job titles, employer name, and login credentials for users who register for the Service.
Safety and operational data. Information your organization inputs into the Service, which may include incident and injury reports, near-miss records, inspection results, hazard assessments, corrective actions, training and certification records, equipment and site data, and related documents, photos, or audio/video attachments.
Sensitive information. Depending on how your organization uses the Service, this may include health or injury details and medical records related to workplace incidents, which may be treated as sensitive information under applicable law. We process this data only as directed by our customer and as needed to provide the Service.
Usage and device data. IP address, browser type, device identifiers, operating system, pages viewed, features used, timestamps, and referring URLs, collected automatically when you use the Service or website.
Mobile app data. When you use our mobile apps for iOS and Android, we may collect device identifiers, app version, and crash and diagnostic logs. With your permission, the app may also access device features such as your camera, photos, microphone, location, and files so you can create and attach content (for example, incident photos). We may send push notifications, which you can control in your device settings. Handling of these permissions is also governed by the applicable app store's terms.
Cookies and similar technologies. See Section 7.
Communications. Records of your correspondence with us, including support requests and feedback.
3. How We Use Information
We use information to:
- Provide, operate, maintain, and secure the Service.
- Authenticate users and manage accounts.
- Process and store the safety and compliance data our customers submit.
- Provide customer support and respond to inquiries.
- Monitor usage, diagnose problems, and improve the Service.
- Send administrative and service-related communications.
- Send marketing communications where permitted (you may opt out at any time).
- Detect, prevent, and address fraud, security incidents, and abuse.
- Comply with legal obligations and enforce our agreements.
For customer-submitted data, we use it solely to provide the Service per our customer's instructions, not for our own independent purposes.
4. How We Share Information
We do not sell personal information. We share information only as described below:
- Service providers / sub-processors who host, support, or help operate the Service under contractual confidentiality and data-protection obligations. These currently include HubSpot (customer relationship management and marketing) and Twilio (communications and messaging). We may update this list from time to time.
- Within your organization, according to the roles and permissions your administrators configure.
- Legal and safety requirements, when required to comply with law, regulation, legal process, or a governmental request, or to protect the rights, property, or safety of any person.
- Business transfers, in connection with a merger, acquisition, financing, or sale of assets, subject to this policy.
- With your consent or at your direction.
5. Data Retention
We retain customer-submitted data for as long as the customer's account remains active. When a customer terminates its account, we purge the associated data upon request, subject to any legal retention requirements. We retain account, billing, and website data as needed for our legitimate business and legal purposes.
6. Data Storage and Processing
We store and process information in the United States. By using the Service, you understand that your information will be processed in the United States.
7. Cookies and Tracking
We and our service providers use cookies and similar technologies (such as pixels and local storage) to operate the Service, remember your preferences, analyze usage, and support security and marketing. The categories we use are:
- Strictly necessary cookies. Required to operate the Service, authenticate users, and maintain security. These cannot be disabled without affecting functionality.
- Preference cookies. Remember your settings and choices to improve your experience.
- Analytics cookies. Help us understand how the Service and website are used so we can improve them.
- Marketing cookies. Set by us or our service providers (for example, HubSpot) to deliver and measure relevant communications.
You can control non-essential cookies through your browser settings, which allow you to block or delete cookies. If you block certain cookies, some features may not function properly. Because handling of browser "Do Not Track" signals is not yet standardized, we do not currently respond to them.
8. Data Security
We maintain administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit and at rest, access controls, and regular security assessments. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
9. Your Rights and Choices
Depending on your state of residence, you may have rights to access, correct, or delete your personal information, and to opt out of certain uses. Residents of states with comprehensive privacy laws may have these rights. California residents have specific rights described in Section 10 below.
Who handles your request depends on the data involved. If your personal information was entered into the Service by your employer (for example, incident, injury, or inspection records), your employer controls that data and you should direct requests to them; we will assist them as their service provider. For personal information we handle as the business in our own right (for example, information collected through our websites, marketing, or account administration), contact us at compliance@workersafe.com. We will not discriminate against you for exercising your rights.
10. California Privacy Rights (CCPA/CPRA)
This section applies to California residents and supplements the rest of this policy. Under the California Consumer Privacy Act, as amended, California residents have the rights described below.
10.1 Our two roles
WorkerSafe interacts with personal information in two distinct capacities, and this determines who is responsible for responding to a request:
- When WorkerSafe is the "business." For personal information we collect and determine the purposes of on our own behalf — such as information from visitors to https://www.workersafe.com, prospects and marketing contacts, and the account and billing contacts of our customers — WorkerSafe is the "business" under the CCPA and responds to rights requests directly.
- When WorkerSafe is the "service provider." For personal information that a customer (an employer) submits to or generates within the Service — such as employee incident reports, injury and medical records, inspection results, and training records — the customer is the "business" and WorkerSafe is a "service provider" processing that data under a written contract and only on the customer's instructions. If you are an employee or other individual whose data was entered by an employer, please submit your request to that employer. If you send such a request to us, we will refer it to the relevant customer and assist them in responding, but we cannot independently grant access to or delete data on a customer's behalf.
10.2 Your rights
Subject to the roles described above, California residents may:
- Know / access. Request the categories and specific pieces of personal information we have collected, the categories of sources, the business or commercial purposes for collecting it, and the categories of third parties to whom we disclose it.
- Delete. Request that we delete personal information we collected from you, subject to legal exceptions (for example, information we must retain to complete a transaction, comply with a legal obligation, or ensure security).
- Correct. Request that we correct inaccurate personal information.
- Opt out of sale or sharing. Direct us not to sell or "share" (for cross-context behavioral advertising) your personal information. We do not sell personal information, and we do not share it for cross-context behavioral advertising.
- Limit use of sensitive personal information. Direct us to limit the use of sensitive personal information to what is necessary to provide the Service. See Section 10.5.
- Non-discrimination. Exercise these rights without receiving discriminatory treatment.
10.3 How to submit a request, and verification
To submit a request for information we handle as the business, email us at compliance@workersafe.com. So that we can respond appropriately, we will take steps to verify your identity before acting on a request to know, delete, or correct. Verification typically involves matching information you provide against information we already maintain; we may request additional information if we cannot verify you with what we have. We use information provided for verification only for that purpose.
You may use an authorized agent to submit a request on your behalf. We may require the agent to provide proof of your written permission and may still ask you to verify your own identity directly.
For data we hold as a service provider on an employer's behalf, submit your request to your employer; we do not verify or act on those requests independently.
10.4 Response timing
For requests we handle as the business, we will acknowledge receipt within 10 business days and respond within 45 calendar days. If we need more time, we may extend by an additional 45 days and will notify you of the extension and the reason.
10.5 Categories of personal information and how we handle them
In the preceding 12 months, for personal information we handle as the business, we have collected the following CCPA categories:
- Identifiers (such as name, email address, phone number, IP address, and online identifiers).
- Customer records / contact information (such as business contact and billing details).
- Commercial information (such as subscription and transaction records).
- Internet or network activity (such as usage and device data described in Section 2).
- Professional or employment-related information (such as job title and employer).
- Sensitive personal information, where applicable — primarily account login credentials, and, within the Service, health or injury information submitted by employers (which we handle as a service provider, not as the business).
For each category, the sources are you, your organization, and your use of the Service and websites; the purposes are those described in Section 3; and the categories of third parties to whom we disclose are our service providers described in Section 4. We do not use or disclose sensitive personal information for purposes beyond those permitted by the CCPA, and we do not use it to infer characteristics about you.
10.6 Opt-out preference signals
Because we do not sell or share personal information for cross-context behavioral advertising, there is nothing to opt out of, and we honor applicable opt-out preference signals (such as Global Privacy Control) consistent with our practices. Do Not Track browser signals are not yet standardized, and we do not currently respond to them.
10.7 Financial incentives
We do not offer financial incentives or price or service differences in exchange for the retention or sale of personal information.
11. Children's Privacy
The Service is intended for use by businesses and is not directed to children under 13. We do not knowingly collect personal information from children. If you believe a child has provided us information, please contact us so we can delete it.
12. Third-Party Links
The Service may contain links to third-party sites or integrations. We are not responsible for their privacy practices, and we encourage you to review their policies.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated version with a revised "Last updated" date and, where required, provide additional notice. Continued use of the Service after changes take effect constitutes acceptance.
14. Contact Us
If you have questions or requests regarding this Privacy Policy or your personal information, contact us at:
WorkerSafe, Inc.
18881 West Dodge Road, Suite 200W, Elkhorn, Nebraska 68022
compliance@workersafe.com