Skip to content
WorkOrders

Legal

Privacy policy

Last updated 28 July 2026. This policy is written to the New Zealand Privacy Act 2020.

1. Who we are

WorkOrders is operated by Molehill Creations Ltd, Wellington, New Zealand. We are the agency responsible for personal information handled through the service, and we comply with the Privacy Act 2020.

Contact for any privacy question, request or complaint: hello@workorders.div.nz.

2. Two kinds of information, and why the difference matters

Information about our customers. When your business signs up, we collect the details needed to run the account: names, work email addresses, your company name, and billing information.

Information inside your account. Everything your business puts into WorkOrders — your customers' names, addresses, phone numbers, the contents of email you have us ingest, photographs from job sites, technician notes. For this material you are the agency and we act on your instructions. We process it to provide the service and for no purpose of our own. We do not sell it, we do not use it to market to your customers, and we do not use it to train AI models.

3. What we collect, and why

  • Account details — name, email, password hash, role, company name. To create and secure your account.
  • Billing details — company name, billing email, and a customer/subscription reference held at Stripe. We do not receive or store full card numbers.
  • Mailbox content — where you connect a mailbox, the messages in it, their attachments, and their metadata. To create work orders.
  • Operational data — work orders, customers, sites, notes, photos, status history. This is the product.
  • Technical logs — IP address, browser user agent, timestamps, error traces. For security, abuse prevention and fixing faults.
  • Enquiries — if you use the contact form, your name, email, business name, message, and the IP address and browser it came from. Used to reply to you and to filter spam; nothing else.

We do not use advertising or analytics trackers on this website. Cookies are limited to what the application needs to keep you logged in and to protect forms against cross-site request forgery.

4. AI processing of email and attachments

This is the part most people want to understand, so it is stated plainly.

To turn an email into a work order, WorkOrders sends the message — subject, body, and where relevant its attachments — to a third-party AI model provider, which returns a summary, an urgency assessment, extracted details such as a site or contact, and descriptions of images. That content may include personal information about your customers.

  • Providers are used via their API on business/enterprise terms, under which submitted content is not used to train their models.
  • We send only what the task needs, and results are cached so the same message is not submitted repeatedly.
  • The provider is a configurable part of our infrastructure. The provider currently in use is named in our sub-processor list — ask at hello@workorders.div.nz and we will tell you, and we will give notice before changing it.
  • AI output is a suggestion sitting in an editable field. Nothing generated by a model is emailed to your customer without a person acting on it.

If your business cannot have customer email content processed this way, tell us — the ingestion pipeline can run without the AI layer.

5. Google user data — Limited Use disclosure

Where you connect a Gmail mailbox, WorkOrders accesses your Google account data through the Gmail API. This section is the disclosure Google requires, and it governs that data specifically.

What we access, and why

  • We request the gmail.modify scope.
  • Read — to fetch the messages and attachments in the connected mailbox and turn work requests into work orders.
  • Label — to apply a WorkOrders/Processed label to a message we have handled, so it is not ingested twice, and optionally to archive it if you turn that on.
  • We never delete a message, never move one to trash, and never mark one as read. The narrower read-only scope cannot apply the label the system depends on, which is the only reason a broader scope is requested.

Limited Use

WorkOrders' use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, Google user data is:

  • used only to provide and improve the work-order features you connected the mailbox for;
  • never used for advertising, and never sold;
  • never transferred to others except as needed to provide the service, to comply with the law, or as part of a merger or acquisition where we would first obtain your explicit consent;
  • not read by humans, unless you have given explicit consent for specific messages (for example while we help you debug a fault), it is necessary for security or to comply with the law, or the data has been aggregated and de-identified.

Google user data is not used to train generalised AI models. Where a connected Gmail message is processed by the AI features described in §4, it is processed under the same no-training terms set out there, solely to create the work order.

Ending it

Disconnect the mailbox in Settings → Mailboxes, or revoke WorkOrders at myaccount.google.com/permissions. Our stored OAuth tokens are deleted when you disconnect, and access stops immediately either way. Work orders already created stay in your account, because they are your business records — ask us and we will delete those too.

6. Who else handles the data (sub-processors)

We use a small number of providers to run the service. Each handles only what their function requires:

  • Cloud hosting — runs the application and the database.
  • Stripe — payment processing. Stripe receives your billing details and card data directly; we receive only a reference and the subscription's status.
  • Email delivery — sends the messages the system generates, including the status updates to your customers.
  • AI model provider — as described in §4.
  • Google — where you have connected a Gmail mailbox (§5).

Overseas disclosure. Some of these providers store or process data outside New Zealand. Before disclosing personal information to a provider overseas we satisfy ourselves, as Information Privacy Principle 12 requires, that they are subject to comparable safeguards — through their contractual commitments and their published privacy and security terms. A current list of providers and the regions they operate in is available on request.

7. How long we keep things

  • Account and operational data — for as long as your account is open, then 90 days after it closes, so it can be recovered or exported. After that it is deleted from live systems and purged from backups on the ordinary rotation.
  • Ingested email — kept with the work order it created, on the same clock as the rest of your operational data.
  • Billing records — kept for seven years, as New Zealand tax law requires.
  • Technical logs — a short rolling window, then discarded.
  • Contact-form enquiries — until dealt with, then periodically cleared out.

8. Your rights under the Privacy Act 2020

If you are one of our customers, you may ask us to confirm what personal information we hold about you, get a copy of it, and have it corrected if it is wrong. Ask at hello@workorders.div.nz. We respond within 20 working days.

If you are a customer of a business that uses WorkOrders — for example you emailed a plumber and that email became a work order — the business you dealt with holds that information and your request goes to them. If you contact us we will pass it on and help them action it.

You can complain to us first, and we would like the chance to fix it. You can also complain directly to the Office of the Privacy Commissioner.

9. Security, and what happens if it fails

Data is encrypted in transit. Credentials for connected mailboxes are encrypted at rest. Access to production is limited to the people who need it, every account is scoped to a single company, and roles limit what a team member can see — a technician cannot pull the report containing every customer's address.

No system is perfectly secure. If a privacy breach occurs that is likely to cause serious harm, we will notify affected customers and the Office of the Privacy Commissioner as the Privacy Act 2020 requires, and we will tell you what happened rather than the smallest thing we can get away with saying.

10. Children

WorkOrders is a business tool and is not directed at children. We do not knowingly collect personal information from anyone under 16 other than incidentally, where it appears in a request your business received.

11. Changes to this policy

We will update this page when our practices change, and the date at the top will change with it. For material changes — particularly anything affecting how email content or Google user data is handled — we will email account owners before it takes effect.