Legal
Privacy Policy
Last updated
We collect only what we need to run Clientwharf, and we never sell personal data.
1. Who we are
Clientwharf is operated by Goohoost Ltd, trading as Clientwharf, a private limited company registered in England and Wales under company number 17040971, with its registered office at First Floor Office, 3 Hornton Place, London, W8 4LZ, United Kingdom (“we”, “us”). This policy explains how we handle personal data when you visit clientwharf.com, create an account, subscribe, or contact us.
For privacy questions or to exercise your rights, email privacy@clientwharf.com or write to Goohoost Ltd, First Floor Office, 3 Hornton Place, London, W8 4LZ, United Kingdom.
2. When we are controller and when we are processor
We are the controller for personal data we decide how to use: website visitors, account holders and team members, billing and subscription records, support and contact messages, abuse reports, and security logs.
We are a processor for the content our customers put into their workspaces, including files, comments, approvals, requests and documents, and the names and email addresses of the client contacts they invite. Our customer (the freelancer or agency) is the controller of that data and decides what is shared and with whom. Our Data Processing Addendum governs that processing. If you are a client contact and want to exercise your rights over that data, please contact the business that invited you; we will help them respond.
We may also process limited data about client contacts as a controller where needed to keep the Service secure, prevent abuse, and comply with law (for example, sign-in records and security logs).
3. Personal data we collect, why, and our legal basis
The legal bases below come from the EU and UK General Data Protection Regulation (GDPR): performance of a contract, our legitimate interests, compliance with a legal obligation, and consent.
| Data | What it includes | Why we use it | Legal basis |
|---|---|---|---|
| Account data | Name, email address, password (stored only as a secure hash), two-factor settings, workspace memberships and roles, notification preferences. | To create and run your account and workspace, sign you in, and send service emails such as sign-in links and notifications. | Contract |
| Workspace settings | Workspace name, logo, brand color and portal settings you choose. | To provide the branded portals you configure. | Contract |
| Subscription and billing records | Plan, billing interval, subscription status and dates, Paddle customer, subscription and transaction IDs, amounts and currency, refund records. We do not receive or store your full card details. | To give you the features you paid for, show your billing status, handle plan changes and refunds, and keep business records. | Contract; legal obligation (accounting and tax records) |
| Security and usage logs | IP address, browser user agent, sign-in sessions, timestamps, rate-limit counters and audit events for sensitive actions. | To keep accounts and workspaces secure, detect and prevent abuse and fraud, investigate incidents, and keep the Service working. | Legitimate interests (security and abuse prevention) |
| Support and contact messages | Your name, email address, the content of your message and our replies; IP address for contact-form submissions. | To answer your questions and improve our help content. | Legitimate interests; contract where it concerns your account |
| Abuse and copyright reports | Reporter name, email, organization, the reported content, declarations and signature, IP address. | To review and act on reports and counter-notices, and to keep records of what we did. | Legal obligation; legitimate interests (keeping the Service safe and lawful) |
| Website analytics | Aggregated page views with URL, referrer, country, browser, operating system and device type, via Vercel Web Analytics. It does not use cookies and does not identify individual visitors. | To understand which pages are useful and improve the website. | Legitimate interests |
| Customer Content | Files, comments, updates, approvals, requests, documents and client contact details that customers add to their workspaces. | To provide the Service to the customer who controls it. | Processed on the customer's behalf under the DPA |
We do not sell personal data, we do not share it for cross-context behavioral advertising, and we do not use it to make automated decisions that have legal or similarly significant effects on you. We do not send marketing newsletters; if we start, we will ask for your consent where the law requires it, and you will be able to unsubscribe at any time.
If you do not give us the data needed to create an account (such as an email address), we cannot provide the Service to you.
4. Who receives personal data
We share personal data only as needed for the purposes above:
- Paddle, as Merchant of Record. Paddle.com sells our subscriptions as a reseller. When you buy, Paddle collects your payment details, billing address and tax information directly, as an independent controller under its own Privacy Notice (opens in a new tab). Paddle shares order and subscription details with us so we can give you access.
- Service providers (subprocessors) that host, store and deliver the Service for us, under written contracts that require them to protect the data and use it only on our instructions. They are listed below and on our subprocessors page.
- Professional advisers such as lawyers and accountants, under a duty of confidentiality.
- Authorities and others where required by law, for example to respond to a valid legal request, or where necessary to protect the rights, safety or property of our users, the public or us.
- A successor business if we are involved in a merger, acquisition or sale of assets, subject to this policy. We will tell you before your data becomes subject to a different privacy policy.
- Your workspace and clients. Information you add to a workspace is visible to the team members and client contacts who have access to it, as you decide.
| Subprocessor | Purpose | Location | Privacy policy |
|---|---|---|---|
| Paddle.com Market Ltd (and affiliates) | Merchant of Record: checkout, payments, invoicing, sales tax, refunds | United Kingdom / United States | Privacy policy of Paddle.com Market Ltd (and affiliates) (opens in a new tab) |
| Vercel Inc. | Application hosting and content delivery | United States (functions in us-east-1) | Privacy policy of Vercel Inc. (opens in a new tab) |
| Neon Inc. (Databricks) | Managed PostgreSQL database | United States (AWS us-east-1) | Privacy policy of Neon Inc. (Databricks) (opens in a new tab) |
| Cloudflare, Inc. | File storage (R2), DNS, email routing, network security | United States / global network | Privacy policy of Cloudflare, Inc. (opens in a new tab) |
| Resend (Plus Five Five, Inc.) | Transactional email delivery | United States (AWS us-east-1) | Privacy policy of Resend (Plus Five Five, Inc.) (opens in a new tab) |
5. How long we keep data
| Data | Retention |
|---|---|
| Account data and Customer Content | While your account or workspace exists. After a trial or subscription ends, the workspace is kept read-only for at least 30 days; we email the owner at least 14 days before deleting it. When you delete a workspace or account, data is removed from live systems within 30 days. |
| Backups | Our database provider keeps rolling point-in-time backups. Deleted data expires from them within a further 30 days. |
| Subscription and billing records | Six years after the end of the financial year they relate to, as UK company and tax law requires, even after your account is deleted. |
| Security logs and audit events | Up to 12 months, longer only if needed to investigate a specific incident. |
| Sign-in sessions | Until you sign out, or 30 days after your last activity. |
| Support, contact and abuse-report records | Up to 3 years after the matter is closed, so we can handle follow-ups and repeat issues. |
| Data exports | Export files are available to download for 7 days and then deleted. |
| Website analytics | Aggregated only; Vercel discards visitor session identifiers after 24 hours. |
We may keep data longer if the law requires it or to establish, exercise or defend legal claims.
6. Your rights
Depending on where you live, and in particular under the EU and UK GDPR, you have the right to:
- access the personal data we hold about you and get a copy;
- rectification of inaccurate or incomplete data;
- erasure of your data (“right to be forgotten”) in certain circumstances;
- restriction of processing in certain circumstances;
- data portability: receiving data you gave us in a structured, machine-readable format, or having it sent to another provider;
- object to processing based on our legitimate interests;
- withdraw consent at any time where we rely on consent, without affecting processing that took place before; and
- complain to a supervisory authority, in particular in the country where you live or work or where you believe an infringement took place. Our lead authority is the UK Information Commissioner’s Office (ico.org.uk (opens in a new tab)), because Goohoost Ltd is established in the United Kingdom. We would appreciate the chance to address your concern first.
To exercise a right, email privacy@clientwharf.com. We may need to verify your identity first. We respond within one month of receiving your request. If a request is complex or we receive many, we may extend this by up to two further months, and we will tell you why within the first month. Exercising your rights is free unless a request is clearly unfounded or excessive.
You can also update most account details yourself in the app, and workspace owners can export all workspace data at any time.
7. International transfers
Clientwharf is hosted in the United States, and our subprocessors may process data in the United States and other countries. When personal data from the European Economic Area, the United Kingdom or Switzerland is transferred to a country without an adequacy decision, we rely on appropriate safeguards:
- an adequacy decision, including the EU–US Data Privacy Framework and its UK and Swiss extensions where the recipient is certified; or
- the European Commission’s Standard Contractual Clauses, with the UK International Data Transfer Addendum where relevant, plus additional measures where needed.
You can ask for more information about these safeguards, or a copy of the relevant clauses, at privacy@clientwharf.com.
8. How we protect data
We take appropriate technical and organizational measures to protect personal data against loss, misuse and unauthorized access, including:
- encryption in transit (TLS) on every connection, and encryption at rest by our storage and database providers;
- workspace (tenant) isolation enforced in our data layer, so one customer cannot reach another customer’s data;
- files kept in a private storage bucket and downloaded only through signed, short-lived links;
- passwords stored only as secure hashes, optional two-factor authentication, email verification and rate-limited sign-in;
- audit logging of sensitive actions and access to production systems limited to people who need it.
No system is perfectly secure. If a personal data breach is likely to put your rights at risk, we will notify you and the relevant authorities as the law requires. More detail is on our security page. To report a vulnerability, email security@clientwharf.com.
10. Children
Clientwharf is a business tool and is not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, contact privacy@clientwharf.com and we will delete it.
11. Notice for US residents
We do not sell personal information or share it for cross-context behavioral advertising, and we do not use or disclose sensitive personal information for purposes that would give you a right to limit it. Where US state privacy laws give you rights to know, access, correct or delete your personal information, you can exercise them by emailing privacy@clientwharf.com. We will not discriminate against you for doing so.
12. Changes to this policy
We may update this policy to reflect changes in the Service, our providers or the law. The “Last updated” date at the top shows when it last changed. If a change is material, we will email account holders before it takes effect.