Privacy policy
A plain-language account of the data that moves through Well Platform, why it is needed, and the choices available to customers and individuals.
Scope and our role
This Privacy Policy explains how BoostWorks ("BoostWorks," "we," "us," or "our") handles personal information through Well Platform and its products, including EventWell, FieldWell, SuiteWell, and FinWell. It applies to our websites, applications, support channels, and connected services that link to this policy.
A business that uses a Well product generally decides which customer, lead, employee, vendor, event, property, or operational data to place in the service. For that customer data, the business is the controller or business and BoostWorks acts as its processor or service provider. BoostWorks is the controller or business for account administration, billing, security, product analytics, marketing, and our direct business relationships.
If a Well customer collected your information, contact that business first. We support its verified instructions and will not use its customer data for our own independent advertising.
Information we collect
Information you or a customer provides
- Account and identity details, such as name, email, phone number, role, and login data.
- Business and workspace details, including company, locations, staff, services, and preferences.
- Operational records entered into a Well product, such as leads, contacts, notes, appointments, jobs, quotes, invoices, events, documents, and communications.
- Support messages, feedback, survey responses, and other communications with us.
- Billing details and transaction records. Payment card data is handled by our payment providers rather than stored in full by us.
Information from connected services
At a customer's direction, we receive data from services it connects, such as Google, Meta, payment processors, calendars, email providers, or other business tools. The data depends on the connection and permissions the customer selects.
Information collected automatically
We collect device, browser, IP address, approximate location derived from IP, session, referral, page interaction, diagnostic, crash, and security-event information when you use the service. We may also create derived information, such as product usage trends, fraud signals, and account health indicators.
How we use information
We use personal information only for legitimate business and service purposes, including to:
- provide, operate, personalize, maintain, and improve the service;
- authenticate users, administer workspaces, and provide customer support;
- sync connected accounts and perform actions a customer requests;
- process billing, prevent abuse, protect accounts, and investigate security incidents;
- send service notices and, where permitted, product or marketing communications;
- measure service performance, troubleshoot errors, and develop new capabilities;
- comply with law, enforce agreements, and establish or defend legal claims; and
- create aggregated or de-identified information that does not reasonably identify a person.
Where applicable law requires a legal basis, we rely on performance of a contract, legitimate interests, compliance with legal obligations, or consent. You may withdraw consent at any time, but withdrawal does not affect prior lawful processing.
Google, Meta, and connected services
Google services
When a customer connects Google Ads, Google Business Profile, or another supported Google service, we use OAuth authorization and receive only the account information and data needed to provide the selected feature. Depending on the connection, this may include account identifiers, campaign and performance information, lead-form data, business profile information, and an access or refresh token. Tokens are stored server-side and are not exposed to other customers.
We use Google user data only to provide or improve the customer-facing feature the user requested. We do not sell Google user data, use it for targeted advertising, or permit people to read it except when necessary for security, support with the user's consent, legal compliance, or internal operations consistent with applicable Google policies. Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Meta services
When a customer connects a Facebook Page or Meta lead form, the customer authorizes the connection through Meta. We may request pages_show_list, pages_read_engagement, pages_manage_ads, pages_manage_metadata, and leads_retrieval. We use those permissions to show pages the user can manage, list lead forms, configure lead delivery, receive leads, and keep the connection working. We store the selected Page and form identifiers, connection evidence, encrypted access credentials, and lead fields submitted through the connected form.
A customer can disconnect Google or Meta from its product's Settings → Sources area. Disconnecting stops future synchronization and revokes or removes the stored connection where supported; it does not automatically erase records previously imported. See our Data Deletion Instructions to delete those records.
Mobile and messaging data
Mobile information, text-message consent, and message-originator data are not sold, rented, or shared with third parties for their own marketing. We disclose them only to service providers and carriers as needed to deliver messages, maintain consent and opt-out records, prevent abuse, and comply with law.
Retention and deletion
We keep personal information for as long as needed to provide the service, maintain the customer relationship, meet legal and accounting obligations, resolve disputes, enforce agreements, prevent abuse, and preserve security evidence. The period depends on the type of record, customer settings and instructions, legal requirements, and operational need.
When deletion is requested or an account closes, we delete or de-identify covered data from active systems within a commercially reasonable period, subject to verified authority and lawful exceptions. Residual copies may remain in encrypted backups until they cycle out and are not restored except for disaster recovery. We may retain narrow records such as billing, security, legal-hold, and consent or opt-out evidence when required or permitted by law.
Instructions for disconnecting services and requesting deletion are available on our Data Deletion page.
Security
We use administrative, technical, and physical safeguards designed for the nature of the information we process. Measures include access controls, encryption in transit, server-side secret handling, logging and monitoring, provider isolation, backup controls, and incident response practices. No online service can guarantee absolute security. Customers are responsible for protecting their credentials, configuring authorized users, and promptly reporting suspected misuse.
Your privacy rights
Depending on where you live and our role, you may have rights to know or access personal information, correct it, delete it, obtain a portable copy, restrict or object to processing, withdraw consent, or appeal a decision. California residents may also request information about categories of information collected, sources, purposes, recipients, and specific pieces of information. We will not discriminate against you for exercising a privacy right.
Submit a request to support@boostwrks.io. Tell us which Well product and business relationship are involved, the right you want to exercise, and the email or phone number associated with the record. We will verify identity and authority proportionately and respond within the period required by applicable law. An authorized agent may submit a request if it provides proof of authority. You may appeal a denial by replying to our decision with “Privacy Appeal.”
If a Well customer controls the record, we may direct the request to that customer or process it on the customer's verified instruction. EEA and UK residents may also lodge a complaint with their local data-protection authority.
International processing
BoostWorks operates from the United States and uses providers that may process information in the United States and other countries. Privacy laws in those locations may differ from those where you live. Where required, we use recognized safeguards for international transfers, such as contractual commitments and transfer assessments.
Children
Well Platform is a business service and is not directed to children under 18. We do not knowingly collect personal information directly from children. If you believe a child has provided personal information to us, contact us so we can investigate and delete it as appropriate.
Changes and contact
We may update this policy as our services or legal obligations change. We will post the revised policy here, update the effective date, and provide additional notice when a change is material and the law requires it.
Contact BoostWorks
Privacy questions and requests can be sent to support@boostwrks.io or by mail to BoostWorks, 403 Kraft St, San Antonio, TX 78220, United States.