Legal and privacy
WorkMesh Privacy Policy
Effective: 17 July 2026 · Version: 2026-07-17.1
1. Who we are
WorkMesh is operated by Cost Time Risk Pty Ltd trading as WorkMesh, based in Brisbane, Queensland, Australia. In this policy, “WorkMesh”, “we”, “us” and “our” refer to Cost Time Risk Pty Ltd trading as WorkMesh.
We are the controller of personal information used for our public website, enquiries, waitlist, account administration, service security, billing, support and our own business operations. When a customer organisation uses WorkMesh to manage its own records, people, documents, forms, workflows, signatures or other business information, that customer will normally be the controller and WorkMesh will normally act as its processor or service provider.
2. Information we collect
The information we collect depends on how you use WorkMesh and may include:
- your name, business email address, telephone number, company, role and other contact details;
- account, company, licence, permission, authentication and security information;
- waitlist choices, enquiries, support requests and communications;
- business account applications, ABN, selected modules, template choices, subscription, invoice and transaction records, while complete payment-card details are handled by hosted payment providers;
- affiliate business profiles, referral attribution, commission, GST, payout status and agreement records, while payout-account and identity-verification details are handled through Stripe Connect;
- technical information such as browser and device details, IP address or a protected hash, page visits, referring page, security events, audit records and diagnostics;
- cookie and privacy-preference records;
- content entered, uploaded or generated in WorkMesh, which may include workforce, project, supplier, leave, timesheet, payroll, workflow, document and electronic-signature information; and
- information received from services a customer chooses to connect, such as accounting or payroll integrations.
3. How and why we use information
| Purpose | Typical legal basis |
|---|---|
| Responding to enquiries and taking requested steps before a service relationship | Steps before a contract and our legitimate interests in responding to business enquiries |
| Creating and operating accounts, licences, modules, subscriptions, support, billing and integrations | Contract, steps before a contract and legitimate interests in delivering the service |
| Operating the invite-only affiliate programme, calculating commission and managing payouts | Contract, legal and tax obligations and legitimate interests in administering business referrals |
| Preventing referral fraud and payment abuse using business and payment-method indicators | Legitimate interests in protecting WorkMesh and its customers |
| Authentication, fraud prevention, security monitoring, backups, audit and incident response | Contract, legitimate interests and legal obligations |
| Measuring use of the public WorkMesh website with Google Analytics | Your consent |
| Sending launch, product or marketing communications | Your consent where required; you may withdraw it at any time |
| Processing customer content on behalf of an organisation | The customer’s instructions and the legal basis determined by that customer |
| Meeting legal, tax, regulatory and dispute-resolution requirements | Legal obligations and legitimate interests |
We do not make optional analytics or marketing consent a condition of using core WorkMesh services.
4. Website analytics and cookies
Necessary cookies support login, security, trusted-device choices and remembering privacy preferences. With your consent, we use Google Analytics 4, measurement ID G-KY1052LEME, to understand aggregate use of the public WorkMesh website.
Google Analytics is limited to WorkMesh public website pages, including public marketing, pricing, waitlist, privacy, cookie and commercial-terms pages. It is not loaded on app.html, authenticated application screens, login, onboarding, signing, external forms, external approvals, unsubscribe or maintenance pages.
Analytics may process a random browser identifier, browser and device information, page viewed, referring page, general geographic information and interaction timing. We configure Analytics without Google advertising signals or advertising personalisation, do not provide a WorkMesh user ID, do not send form contents, names or email addresses, and remove query strings from the page location sent by our tag. Analytics is not loaded until Analytics consent is granted.
You can accept, reject or manage optional cookies through the banner and can reopen at any time. See our Cookie Policy for the current cookie inventory.
5. Customer content
Customer organisations decide what information they place in WorkMesh, who may access it and how long it should be kept. Customers are responsible for having an appropriate legal basis, providing required notices and configuring licences, roles, permissions and integrations appropriately. We process customer content to provide, secure, support and maintain the service and as otherwise instructed or permitted by the service agreement and applicable law.
6. Who receives information
We limit access according to role and need. Information may be provided to:
- the customer organisation controlling the relevant WorkMesh workspace and its authorised administrators and users;
- cloud hosting, storage, email, security, support, backup and analytics providers used to operate and improve WorkMesh;
- integration providers selected and authorised by the customer, such as Xero;
- Stripe for hosted payment-method verification, subscription billing, customer billing portals and affiliate Connect onboarding and payouts;
- professional advisers, insurers, auditors and transaction advisers subject to appropriate confidentiality; and
- courts, regulators, law-enforcement bodies or others where disclosure is required by law or reasonably necessary to protect rights, safety and security.
Google acts as a service provider for Google Analytics. WorkMesh does not sell personal information to advertisers and does not currently use advertising or retargeting trackers.
7. International processing
WorkMesh is operated from Australia. Our infrastructure, service providers and customer-selected integrations may process information in Australia and other countries. Where applicable data-protection law requires additional safeguards for an international transfer, we take steps designed to apply suitable contractual, technical and organisational protections. Further information about current providers and transfer arrangements may be requested through the privacy request form.
8. How long we keep information
We retain personal information only for as long as reasonably necessary for the purpose for which it was collected, the customer’s instructions, service security and recovery, dispute resolution, or legal and contractual requirements.
- privacy-consent audit records are normally retained for up to three years unless needed for a complaint, investigation or legal obligation;
- marketing subscription and withdrawal records are kept while required to deliver or respect the communication choice;
- enquiries that do not become an active relationship are periodically reviewed and deleted or de-identified when no longer required;
- customer content is retained for the service term and then returned, deleted or retained as agreed, subject to backup cycles and legal holds; and
- security, audit, financial and electronic-signature evidence may be retained longer where needed to protect users, demonstrate transactions or comply with law; and
- subscription, invoice, payment, affiliate attribution, commission, payout, refund, chargeback, tax and contractual acceptance records may be retained for seven years or another legally required period, while operational customer data is subject to the cancellation and export lifecycle.
Google Analytics retention is also controlled through the settings of our Google Analytics property.
9. Security
We use technical and organisational measures designed to protect information, including company-scoped access controls, licence and permission checks, secure session cookies, MFA options, encryption for selected sensitive information and credentials, private file storage, audit logging, backups, monitoring and incident-response processes. No internet service can guarantee absolute security.
10. Your privacy rights
Depending on the law that applies, you may have rights to request access, correction, deletion, restriction, objection and portability, to withdraw consent, and to complain to a privacy or data-protection authority. These rights may be limited where an exemption applies or information must be kept for legal, security or contractual reasons.
Submit requests through the secure WorkMesh privacy request form. We may need to verify your identity and authority before releasing or changing information. Where the request concerns content controlled by a WorkMesh customer, we may refer the request to that customer or assist the customer in responding.
11. Communications and withdrawal of consent
You may unsubscribe from optional marketing communications by using the unsubscribe link in the message or contacting us. You may withdraw Analytics consent through Cookie settings. Withdrawal does not affect processing that was lawful before withdrawal.
12. Automated decisions
WorkMesh provides configurable workflows, reports, calculations and automation tools. WorkMesh does not currently make its own solely automated decisions about individuals that produce legal or similarly significant effects. A customer configuring such processing is responsible for appropriate transparency, legal basis, safeguards and human review.
13. Children
WorkMesh is a business service and is not directed to children. Customers must not use WorkMesh public forms or other features to collect children’s information unless they have assessed and implemented all required legal protections.
14. Questions and complaints
Please use the WorkMesh privacy request form so we can investigate a privacy concern. You may also complain to the privacy or data-protection authority that applies to you. Individuals in the EU or EEA may contact the supervisory authority in the country where they live, work or believe an infringement occurred. Australian individuals may contact the Office of the Australian Information Commissioner where applicable.
15. Changes to this policy
We may update this policy as WorkMesh, our providers, laws or processing practices change. We will update the effective date and version shown above. Where a material change affects consent-based processing, we will request a new choice.
