Privacy Policy
Last updated:
Worklane operates a two-sided freelance marketplace with milestone-based escrow. This policy explains what personal data we collect from customers and freelancers, why we collect it, how we use and protect it, and what rights you hold under applicable law. We are committed to handling your data lawfully and transparently.
1. Introduction
Worklane (“we”, “us”, “our”) is the data controller for the personal information processed when you use this platform. We are EU-facing and comply with the General Data Protection Regulation (GDPR) and, where applicable, the UK GDPR and the California Consumer Privacy Act (CCPA).
This policy applies to all users of the Worklane platform — whether you are a customer posting a project, a freelancer submitting a proposal, or simply browsing public content. By using Worklane you acknowledge that you have read this policy.
We do not knowingly collect data from anyone under the age of 18. If you believe a minor has provided us with personal information, please contact us immediately so we can remove it.
2. Data We Collect
We collect information in three ways: directly from you when you register or use the platform, automatically as you interact with our services, and from third-party processors where necessary to operate the platform.
Information you provide
- Account data: name, email address, password (stored hashed), role (customer or freelancer), and any optional profile fields such as country, language level, biography, skills, or portfolio links.
- Project and proposal data: titles, descriptions, budgets, deadlines, and any attachments you upload.
- Messages: the content of communications sent through the platform messaging system.
- Support requests: any information you submit when contacting our support team.
Information collected automatically
- Usage data: pages visited, features used, timestamps, and interactions within the platform (e.g., proposals submitted, bids accepted).
- Device and browser data: IP address, browser type and version, operating system, and referring URL.
- Cookies and similar technologies: see Section 4 and our separate Cookie Policy.
Information from third parties
- Payment processor: our PSP confirms whether a card charge or payout succeeded or failed. We receive a transaction reference and status, not your full card number — card data is captured directly by the payment widget and never passes through our servers.
3. How We Use Your Data
We process your personal data only for the purposes described below and only where we have a lawful basis to do so.
| Purpose | Lawful basis (GDPR) |
|---|---|
| Create and manage your account | Contract performance |
| Match customers with freelancers and facilitate proposals | Contract performance |
| Process escrow payments and release funds | Contract performance |
| Send transactional emails (account verification, payment confirmation, milestone updates) | Contract performance |
| Detect and prevent fraud and abuse | Legitimate interests |
| Improve platform features and fix bugs (aggregate analytics) | Legitimate interests |
| Comply with legal obligations (tax records, anti-money-laundering) | Legal obligation |
| Send promotional communications (newsletter, platform news) | Consent (opt-in) |
We do not use your personal data for automated decision-making that produces legal or similarly significant effects without human review.
4. Cookies & Tracking
We use cookies and local storage to operate the platform (session management, consent preferences, cart state) and, with your consent, to collect analytics data to understand how users interact with Worklane.
Necessary cookies are set automatically. Non-essential cookies (analytics and marketing) are not set until you give explicit consent via the cookie banner. You can change your preferences at any time via the “Cookie Settings” link in our banner or footer. Full details are in our Cookie Policy.
5. Data Sharing & Processors
We do not sell personal data. We share data only with the sub-processors below, each bound by a data processing agreement, and only to the extent necessary to operate the platform.
| Processor | Purpose | Location |
|---|---|---|
| Payment Service Provider (PSP) | Card tokenisation, escrow charges, freelancer payouts | EU / EEA |
| Transactional email provider (Amazon SES) | Account, payment, and milestone notification emails | EU region |
| Hosting infrastructure (RunCloud / DigitalOcean) | Web server, database, and file storage | EU / EEA |
| Analytics provider (if enabled) | Aggregate usage and performance metrics | EU / EEA |
We may disclose personal data to law-enforcement authorities or courts where required by applicable law. We will notify you of such requests where legally permitted to do so.
If we transfer data outside the EEA, we rely on Standard Contractual Clauses or an equivalent adequacy mechanism approved by the European Commission.
6. Your Rights (GDPR & CCPA)
Depending on your location, you hold some or all of the following rights regarding your personal data:
- Access: request a copy of the personal data we hold about you.
- Rectification: ask us to correct inaccurate or incomplete data.
- Erasure (“right to be forgotten”): request deletion of your data, subject to legal retention obligations (e.g., financial records must be kept for the period required by applicable tax law).
- Restriction: ask us to pause processing while a dispute is resolved.
- Portability: receive your data in a structured, machine-readable format.
- Objection: object to processing based on legitimate interests, including for direct marketing.
- Withdraw consent: where processing is based on your consent, withdraw it at any time without affecting the lawfulness of prior processing.
California residents also have the right to know what categories of personal information we collect, the right to opt out of the sale of personal information (we do not sell data), and the right not to be discriminated against for exercising these rights.
To exercise any of these rights, contact us using the details in Section 8. We will respond within 30 days (GDPR) or 45 days (CCPA). We may ask you to verify your identity before fulfilling a request.
You also have the right to lodge a complaint with your local data protection authority. In the EU, a list of authorities is available at edpb.europa.eu.
7. Data Security
We apply technical and organisational measures to protect your personal data against unauthorised access, disclosure, alteration, or destruction. These include:
- All data in transit encrypted via TLS 1.2+.
- Passwords stored using a one-way hashing algorithm (bcrypt) — we cannot recover your password in plain text.
- Card data captured by the PSP’s PCI-DSS-certified widget — it never traverses our servers.
- Database access restricted to application credentials; direct public access disabled.
- Regular security patching of server-side software.
We retain personal data for as long as your account is active or as needed to provide services, resolve disputes, and comply with legal obligations. When data is no longer required it is securely deleted or anonymised. Financial transaction records are retained for the period required by applicable law (typically 7 years).
In the event of a data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and, where required, inform affected individuals without undue delay.
8. Contact
If you have questions about this policy, wish to exercise your data rights, or have a concern about how we handle your information, please reach out to us via our contact page. We aim to respond to all privacy-related enquiries within 30 days.
If you believe we have not addressed your concern adequately, you may escalate to the data protection authority in your country of residence.