Privacy Policy
Effective August 23, 2026
This policy explains what personal information DoneWell collects, why, who else sees it, and what you can ask us to do about it. It is written to be read, not to be survived — if something here is unclear, write to mail@donewellapp.com and we will explain it in plain words.
1. Two kinds of information, two different roles
This distinction runs through the whole policy, so it comes first. DoneWell holds two very different kinds of personal information, and our responsibility is not the same for both.
- Account information — the people who sign in to DoneWell: business owners and their staff. We decide what we collect here and why, and we answer to you for it directly.
- Business records — everything a business enters about its own clients: names, addresses, phone numbers, job history, photos, invoices. We hold this on behalf of that business. They decide what to collect, how long to keep it and who may see it. We act on their instructions and do not use it for our own purposes.
If you are a client of a business that uses DoneWell and you want your records changed or deleted, contact that business — they control those records. If they ask us to act, we do.
2. What we collect
When you create an account: your name, email address, password (stored only as a cryptographic hash — we never see or store the password itself), and optionally a phone number and profile photo.
About your business: company name, address, contact details, tax and pricing settings, and the team members you invite.
Records you enter: your clients and their properties, quotes, jobs, visits, invoices, payments, expenses, photos and files you upload, and messages sent or received through the service.
Automatically, when you use the service: your IP address, browser type, and the times of your requests. We use these to keep the service running, apply rate limits, and investigate abuse.
We do not run advertising or third-party analytics. There are no tracking pixels, no advertising cookies, and no behavioural profiling in DoneWell. We do not sell personal information, and we never have.
4. How we use information
- To provide the service: showing your schedule, sending quotes and invoices, collecting payments, and keeping your data available to the people you authorised.
- To communicate with you about your account: security notices, billing, and changes to the service.
- To keep the service secure: detecting abuse, enforcing rate limits, and investigating incidents.
- To meet legal and tax obligations, including keeping payment records.
- To improve the product, based on aggregate usage — not by reading your business records.
We do not use your business records to train machine-learning models, and we do not share them with anyone except the service providers listed in section 6.
5. Consent, and marketing sent through DoneWell
Under Canadian privacy law we rely on your consent to collect and use personal information, and you may withdraw it at any time by closing your account or contacting us. Some information we must keep even after you withdraw consent — payment records, for example, carry legal retention requirements.
DoneWell lets businesses send email campaigns and automated reminders to their own clients. Two things follow from that, and they are the responsibility of the business sending them, not ours:
- Consent to receive those messages must be obtained by the business, in line with anti-spam law. DoneWell records a consent flag per client and honours it: automated reminders and campaigns are not sent to a client who has opted out.
- Text messages sent from DoneWell go through the sending business’s own telecom account, under their own agreement with that provider.
Documents a client explicitly asked for — an invoice, a quote, a receipt, a portal link — are sent regardless of marketing preferences, because they are the transaction itself rather than outreach.
7. Google user data
If you choose to connect a Google account so that your scheduled work appears in Google Calendar, we request access only to your calendar events. We use it for exactly one thing: writing, updating and removing the visits assigned to you. We do not read your personal events, and connecting a calendar is entirely optional — the service works without it.
DoneWell’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
You can disconnect at any time from your schedule settings in DoneWell, or by revoking access in your Google account. Disconnecting removes the stored access credentials from our systems.
8. How long we keep it
Business records stay for as long as the business keeps them — that is their decision, not ours. The periods we enforce ourselves are:
When an account is closed we delete its data, except records we must keep for legal or accounting reasons — payment history in particular. Ask us and we will tell you what would remain in your specific case.
9. Security
What we do:
- All traffic is encrypted in transit with TLS.
- Passwords are stored as bcrypt hashes, never in a recoverable form.
- Credentials for connected services (payment, messaging and calendar integrations) are encrypted at rest with authenticated encryption, and are never sent back to the browser once saved.
- Access inside a company is controlled by roles and permissions that the account owner sets; each company’s data is isolated from every other company’s.
- Sign-in sessions can be revoked, and changing a password signs out other devices.
No system is perfectly secure, and we will not claim otherwise. If we discover a breach affecting your information, we will tell you and the relevant authorities as required by law.
10. Your rights
You may ask us to:
- Tell you what personal information we hold about you and how it has been used.
- Correct information that is wrong or incomplete.
- Delete your account and the personal information tied to it.
- Export your data in a machine-readable form.
- Withdraw your consent to our use of your information.
Write to mail@donewellapp.com. We will respond within the time required by applicable law — under Canadian federal privacy law that is thirty days — and we will not charge you for a reasonable request. If you are unhappy with our answer you may complain to the Office of the Privacy Commissioner of Canada.
If your request concerns records held by a business that uses DoneWell rather than your own account with us, we will point you to that business, who can act on them directly.
11. Where data is processed
DoneWell is operated from Canada and our servers are located in Canada. Some of the providers listed in section 6 operate internationally, which means information may be processed outside Canada and may be accessible to courts and authorities in those countries. We choose providers that commit to protecting it, but we cannot exempt them from the laws they operate under.
12. Children
DoneWell is a tool for businesses and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child’s information has reached us, write to mail@donewellapp.com and we will delete it.
13. Changes to this policy
We update this policy when the service changes. The effective date at the top always reflects the current version. If a change materially affects your rights, we will tell account holders by email before it takes effect rather than relying on you to notice the date.
14. Contact
Privacy questions and requests: mail@donewellapp.com
Everything else: support@donewellapp.com
Amazing Canada Inc.
3-635 Marsh Rd NE, Calgary, AB T2E 5B4, Canada
See also our Terms of Service.