← Back to the landing page

Privacy Policy

Effective date: August 22, 2026

Werkmester is a registered DBA of Log Cabin Tech LLC, a limited liability company based in Maine, USA. In this policy, "we," "us," and "Werkmester" mean Log Cabin Tech LLC.

Werkmester is software for service businesses — ready-mix plants, precast yards, and similar trades. This policy explains what information the software touches, why, and who can see it.

Two kinds of people this policy covers

Businesses that subscribe to Werkmester. Each one gets its own private workspace. Everything in that workspace belongs to that business.

People whose information a business puts into Werkmester — its customers, employees, and contacts. We hold that information for the business, not for ourselves. The business decides what goes in, who can see it, and how long it stays.

If you are a customer or employee of a business that uses Werkmester and you want to see, correct, or delete your record, contact that business directly. They control it. If you reach out to us, we will point you to them.

What we collect

Account information. For people who log in: name, work email address, phone number, a hashed password (we never store the password itself), the role assigned to them, and the times they signed in. If a business uses phone-based sign-in, we send and briefly store short login codes.

Business records the business enters. Customers and contacts, businesses, employees, addresses, phone numbers, email addresses, quotes and orders, invoices, statements, payments and credits, uploaded files and documents, job and punch-list notes, price sheets, and vehicle records. We do not decide what goes in here — the business does.

Payment information. Payments run through Stripe. Each business connects its own Stripe account. When someone pays an invoice, the card or bank details are typed into fields hosted by Stripe and sent straight to Stripe, which is a PCI-DSS Level 1 service provider. We never receive or store full card numbers, bank account or routing numbers, or security codes. What we keep is the payment record: amount, date, method, Stripe's own reference number, and — so a receipt reads sensibly — the card brand and last four digits. For bank payments, a last-four is held with the receipt record and deleted after 30 days. Werkmester itself is not a card processor and does not claim any PCI certification of its own; the payment pages are built so card details never reach our servers.

Clock-in and location data, when the employer turns it on. The Time Clock feature records when an employee clocks in and out, and the location of each punch — latitude, longitude, accuracy, distance from the assigned work site, and a text address. This is collected at the employer's direction, for their timekeeping. Vehicle location tracking is in development; where a business uses it, truck positions will be collected the same way — on the employer's instruction, for the employer's use. If you are an employer using these features, telling your workers about them is your responsibility.

Technical information. Our servers keep normal web logs. When someone opens a quote, proposal, or public payment page we may record the IP address and browser type, and we use IP addresses to rate-limit abuse and to keep payment attempts from colliding.

When you ask about onboarding. If you fill in the form on our home page we keep the name, business, trade, and contact you give us so we can call you back — nothing else.

Cookies

We use a session cookie so you stay logged in, and an optional "remember me" cookie. That's it. No advertising cookies, no tracking pixels, no ad or analytics networks. On payment pages, Stripe sets its own cookies for fraud prevention — that's part of processing the payment.

How we use it

To run the software, support the businesses that use it, deliver documents (email and text messages), process payments, keep an audit history of who changed what, prevent abuse, and charge for the service.

Who else sees it

What we don't do

We don't sell your information. We don't rent or trade it. We don't hand it to ad networks or use it to build advertising profiles. And one business never sees another business's data — every record is scoped to its own workspace automatically.

How long we keep it

We keep records while an account is active. When someone deletes a record, we mark it removed and keep it for the audit trail rather than erasing it immediately — that's how the history stays trustworthy. Our change log is set to keep about one year of history. Payment and message bookkeeping records used to prevent duplicates are purged on short cycles (roughly 14 to 32 days). Untouched blank drafts are cleaned up after about a week. If a business leaves, we give it a window to export, then delete its data within a reasonable time on request.

How we protect it

Traffic runs over HTTPS. Passwords are stored hashed. Two-factor login is available. Every record is automatically scoped to its own business, and role-based permissions control what each user can open. Uploaded files sit on private storage, off the public web, and are served only after a permission check. Sensitive stored secrets — integration keys, tax account numbers, and webhook signing keys — are encrypted in the database. Payment pages carry tightened content rules so nothing unexpected can load next to a payment form. No online service can promise perfect security, but protecting your records is core to how Werkmester is built.

Children

Werkmester is a tool for running a business. It isn't directed at children under 13, and we don't knowingly collect their information.

Where data lives

Our servers are in the United States.

Changes

We'll update this page when the product changes, and move the effective date. Meaningful changes get a notice to the businesses that subscribe.

Contact

Questions about this policy: hello@werkmester.com