Skip to main content
Well PlatformWell Platformby BoostWorks
PrivacyTermsData deletion

Privacy policy

A plain-language account of the data that moves through Well Platform, why it is needed, and the choices available to customers and individuals.

Effective August 28, 2026Applies across the Well Platform product family
On this page
  1. Scope and our role
  2. Information we collect
  3. How we use information
  4. Google, Meta, and connected services
  5. How we disclose information
  6. Cookies and device data
  7. Retention and deletion
  8. Security
  9. Your privacy rights
  10. International processing
  11. Children
  12. Changes and contact

Scope and our role

This Privacy Policy explains how BoostWorks ("BoostWorks," "we," "us," or "our") handles personal information through Well Platform and its products, including EventWell, FieldWell, SuiteWell, and FinWell. It applies to our websites, applications, support channels, and connected services that link to this policy.

A business that uses a Well product generally decides which customer, lead, employee, vendor, event, property, or operational data to place in the service. For that customer data, the business is the controller or business and BoostWorks acts as its processor or service provider. BoostWorks is the controller or business for account administration, billing, security, product analytics, marketing, and our direct business relationships.

If a Well customer collected your information, contact that business first. We support its verified instructions and will not use its customer data for our own independent advertising.

Information we collect

Information you or a customer provides

  • Account and identity details, such as name, email, phone number, role, and login data.
  • Business and workspace details, including company, locations, staff, services, and preferences.
  • Operational records entered into a Well product, such as leads, contacts, notes, appointments, jobs, quotes, invoices, events, documents, and communications.
  • Support messages, feedback, survey responses, and other communications with us.
  • Billing details and transaction records. Payment card data is handled by our payment providers rather than stored in full by us.

Information from connected services

At a customer's direction, we receive data from services it connects, such as Google, Meta, payment processors, calendars, email providers, or other business tools. The data depends on the connection and permissions the customer selects.

Information collected automatically

We collect device, browser, IP address, approximate location derived from IP, session, referral, page interaction, diagnostic, crash, and security-event information when you use the service. We may also create derived information, such as product usage trends, fraud signals, and account health indicators.

How we use information

We use personal information only for legitimate business and service purposes, including to:

  • provide, operate, personalize, maintain, and improve the service;
  • authenticate users, administer workspaces, and provide customer support;
  • sync connected accounts and perform actions a customer requests;
  • process billing, prevent abuse, protect accounts, and investigate security incidents;
  • send service notices and, where permitted, product or marketing communications;
  • measure service performance, troubleshoot errors, and develop new capabilities;
  • comply with law, enforce agreements, and establish or defend legal claims; and
  • create aggregated or de-identified information that does not reasonably identify a person.

Where applicable law requires a legal basis, we rely on performance of a contract, legitimate interests, compliance with legal obligations, or consent. You may withdraw consent at any time, but withdrawal does not affect prior lawful processing.

Google, Meta, and connected services

Google services

When a customer connects Google Ads, Google Business Profile, or another supported Google service, we use OAuth authorization and receive only the account information and data needed to provide the selected feature. Depending on the connection, this may include account identifiers, campaign and performance information, lead-form data, business profile information, and an access or refresh token. Tokens are stored server-side and are not exposed to other customers.

We use Google user data only to provide or improve the customer-facing feature the user requested. We do not sell Google user data, use it for targeted advertising, or permit people to read it except when necessary for security, support with the user's consent, legal compliance, or internal operations consistent with applicable Google policies. Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

Meta services

When a customer connects a Facebook Page or Meta lead form, the customer authorizes the connection through Meta. We may request pages_show_list, pages_read_engagement, pages_manage_ads, pages_manage_metadata, and leads_retrieval. We use those permissions to show pages the user can manage, list lead forms, configure lead delivery, receive leads, and keep the connection working. We store the selected Page and form identifiers, connection evidence, encrypted access credentials, and lead fields submitted through the connected form.

A customer can disconnect Google or Meta from its product's Settings → Sources area. Disconnecting stops future synchronization and revokes or removes the stored connection where supported; it does not automatically erase records previously imported. See our Data Deletion Instructions to delete those records.

Mobile and messaging data

Mobile information, text-message consent, and message-originator data are not sold, rented, or shared with third parties for their own marketing. We disclose them only to service providers and carriers as needed to deliver messages, maintain consent and opt-out records, prevent abuse, and comply with law.

How we disclose information

We may disclose personal information to:

  • The customer and authorized users who control the relevant workspace.
  • Service providers that host infrastructure, process payments, deliver communications, monitor security, provide support, or perform analytics under contractual restrictions.
  • Connected services when an authorized user asks us to send data or perform an action through that service.
  • Professional advisers and authorities when reasonably necessary to comply with law, protect rights and safety, or address fraud or abuse.
  • A transaction counterparty in a merger, financing, acquisition, reorganization, or sale of assets, subject to appropriate confidentiality protections.

We do not sell personal information for money. We also do not share personal information for cross-context behavioral advertising as those terms are defined under California law. If our practices change, we will update this policy and provide legally required choices before the change applies.

Cookies and device data

We use cookies and similar technologies that are necessary to sign users in, remember preferences, protect sessions, balance traffic, and understand whether the service works as expected. Where required, optional analytics or marketing technologies are used only after consent. Browser controls can block cookies, but blocking necessary cookies may prevent sign-in or other core functions.

We do not respond to legacy browser “Do Not Track” signals because there is no uniform industry standard. Where required, we honor legally recognized browser-based opt-out preference signals for processing to which those signals apply.

Retention and deletion

We keep personal information for as long as needed to provide the service, maintain the customer relationship, meet legal and accounting obligations, resolve disputes, enforce agreements, prevent abuse, and preserve security evidence. The period depends on the type of record, customer settings and instructions, legal requirements, and operational need.

When deletion is requested or an account closes, we delete or de-identify covered data from active systems within a commercially reasonable period, subject to verified authority and lawful exceptions. Residual copies may remain in encrypted backups until they cycle out and are not restored except for disaster recovery. We may retain narrow records such as billing, security, legal-hold, and consent or opt-out evidence when required or permitted by law.

Instructions for disconnecting services and requesting deletion are available on our Data Deletion page.

Security

We use administrative, technical, and physical safeguards designed for the nature of the information we process. Measures include access controls, encryption in transit, server-side secret handling, logging and monitoring, provider isolation, backup controls, and incident response practices. No online service can guarantee absolute security. Customers are responsible for protecting their credentials, configuring authorized users, and promptly reporting suspected misuse.

Your privacy rights

Depending on where you live and our role, you may have rights to know or access personal information, correct it, delete it, obtain a portable copy, restrict or object to processing, withdraw consent, or appeal a decision. California residents may also request information about categories of information collected, sources, purposes, recipients, and specific pieces of information. We will not discriminate against you for exercising a privacy right.

Submit a request to support@boostwrks.io. Tell us which Well product and business relationship are involved, the right you want to exercise, and the email or phone number associated with the record. We will verify identity and authority proportionately and respond within the period required by applicable law. An authorized agent may submit a request if it provides proof of authority. You may appeal a denial by replying to our decision with “Privacy Appeal.”

If a Well customer controls the record, we may direct the request to that customer or process it on the customer's verified instruction. EEA and UK residents may also lodge a complaint with their local data-protection authority.

International processing

BoostWorks operates from the United States and uses providers that may process information in the United States and other countries. Privacy laws in those locations may differ from those where you live. Where required, we use recognized safeguards for international transfers, such as contractual commitments and transfer assessments.

Children

Well Platform is a business service and is not directed to children under 18. We do not knowingly collect personal information directly from children. If you believe a child has provided personal information to us, contact us so we can investigate and delete it as appropriate.

Changes and contact

We may update this policy as our services or legal obligations change. We will post the revised policy here, update the effective date, and provide additional notice when a change is material and the law requires it.

Contact BoostWorks

Privacy questions and requests can be sent to support@boostwrks.io or by mail to BoostWorks, 403 Kraft St, San Antonio, TX 78220, United States.

Send a privacy request
Well PlatformOperated by BoostWorks in San Antonio, Texas.
PrivacyTermsData deletionsupport@boostwrks.io