SERVPROWorkbench
EULAPrivacy Policy

Workbench Privacy Policy

Effective date: July 20, 2026 Applies to: Workbench, the internal staff application operated at workbench.servproteamolson.com

Who we are

Workbench is a private, internal business application operated by Olson Finance, LLC ("we," "us"). Workbench is not a public service: accounts are provisioned only for our staff and authorized contractors, and the application is used solely to run our own business operations.

If you have questions about this policy or the data Workbench holds, contact legal@servproteamolson.com.

What Workbench is for

Workbench centralizes internal business operations: staff directory and org structure, job titles and role acknowledgements, business unit and franchise information, a knowledge base, operational job data, and financial reporting data. It exists so our teams can stop juggling spreadsheets and manual exports.

Information Workbench processes

Staff information (about our employees and contractors):

  • Directory and profile data: name, work contact information, job title and title history, department, business unit, reporting relationships, start dates, and profile details staff choose to provide (e.g., bio and interview-style profile responses).
  • Professional photos ("headshots"), including photos ingested from our photography vendor.
  • Account and authentication data: work email, hashed authentication credentials and session tokens (managed by our authentication provider), role/permission assignments, and standard security logs.
  • Workplace records such as title acknowledgements and signed documents.
  • Feedback staff submit through the app.

Business and customer information:

  • Operational job data imported from our job-management systems (e.g., Coatality DASH), which can include customer names, job addresses, job status, and invoice information for our restoration and construction work.
  • Financial accounting data imported from our QuickBooks Online company files (see the QuickBooks section below), which can include transaction descriptions and payee/customer names as they appear in our general ledger.
  • Historical financial and job records we have migrated into Workbench for reporting.

Usage data:

  • Standard web logs and privacy-respecting aggregate analytics (page performance and usage via Vercel Analytics). We do not run advertising trackers.

How we use information

  • To operate the application: directory, org management, knowledge base, dashboards, and reporting.
  • To run our business: financial analysis, job and revenue reporting, staffing and organizational planning.
  • To communicate with staff: transactional email (e.g., welcome emails, notifications) sent through our email provider; delivery events are logged.
  • To provide AI-assisted features (see below).
  • To secure the application: authentication, role-based access control, and audit logging.

We do not sell personal information, use it for advertising, or share it with third parties except the service providers listed below.

AI features

Some Workbench features (assistant chat, knowledge-base drafting, profile synthesis) send relevant text to Anthropic's Claude models via API to generate responses. These requests are made under our API agreement with the provider; we do not permit our data to be used to train the provider's models. Prompts and responses may be logged internally for quality and debugging. Do not paste sensitive customer financial details into free-form AI features unless the task requires it.

Workbench also offers an authorized connector that lets approved staff use Claude (Anthropic's assistant) against Workbench data through a scoped, role-gated interface. Access is limited to elevated roles and is governed by the same permissions as the rest of the app.

QuickBooks Online integration

With an administrator's explicit authorization through Intuit's OAuth consent flow, Workbench connects to our own QuickBooks Online company file(s) to import accounting data (via Intuit's Accounting API, read-only in practice: reports and transaction-level general ledger detail).

  • What we access: financial report data — accounts, transaction dates/types/amounts, and the customer/vendor names and descriptions that appear on general ledger lines.
  • Why: internal financial reporting and analysis, replacing manual exports.
  • Credentials: Intuit-issued OAuth tokens are stored encrypted at rest (AES-256-GCM) and are never exposed to browsers, logs, or third parties.
  • Control: an administrator can disconnect QuickBooks at any time from Workbench's settings (which revokes the connection with Intuit); access can also be revoked from Intuit's own account portal.
  • Sharing: QuickBooks data is used only inside Workbench for our own reporting. It is not sold or shared, other than being stored with the infrastructure providers below.

Service providers (subprocessors)

Workbench runs on a small set of infrastructure and service providers, each processing data only to provide their service to us:

ProviderPurpose
VercelApplication hosting and aggregate analytics (US)
SupabaseDatabase, authentication, and file storage (AWS us-west-2, US)
AnthropicAI model API for assistant features
ResendTransactional email delivery
Intuit (QuickBooks Online)Source of our accounting data, connected at our direction
Coatality (DASH)Source of our operational job data
CapturelyStaff photography vendor (headshot delivery)

Data is stored in the United States.

Retention

  • Staff records are retained while the person is associated with our business and thereafter as required for business and legal purposes.
  • Financial and job records are retained as business records per our record-keeping obligations.
  • QuickBooks OAuth tokens are deleted or invalidated when a connection is disconnected.
  • Backups and logs roll off on our providers' standard schedules.

Security

Access requires authentication; permissions are role-based, and administrative functions (including the QuickBooks connection) are restricted to admins. Financial credentials are encrypted at rest. Database access from outside the application layer is blocked (row-level security). Transport is encrypted (HTTPS).

Your choices

Staff may review and update their profile information in the app, or contact legal@servproteamolson.com to ask what information Workbench holds about them, request corrections, or — subject to our legal retention obligations — request deletion. Depending on where you live, you may have additional rights under applicable law (e.g., state privacy laws); we honor verified requests consistent with those laws.

Changes

We will update this policy when the application's data practices change and note the new effective date above. Material changes will be communicated to staff internally.

© SERVPRO Team Olson · Return to sign in