Privacy
Privacy policy
Deskwork is a back-office application for real-estate brokerages. This policy describes what the service collects, where it is kept, what leaves it, and what it does not do. It is written to be accurate about this particular product rather than to be broad enough to cover anything we might do later. If the product changes, this page changes with it.
1. Who is responsible for what
Your brokerage decides what goes into Deskwork and who on its roster may use it. Your brokerage is responsible for those records and for the people it gives access to. We operate the service, host it, and handle those records on your brokerage's instructions.
If you are an agent or staff member at a brokerage that uses Deskwork, your broker or office manager controls your access and can answer questions about the records your office keeps. We will also answer directly; see section 12.
2. Signing in: what Google tells us
Deskwork has no passwords of its own. Signing in uses your brokerage's Google Workspace account.
The application requests three permissions and no others:
openid, email and profile. That is identity only.
- It does not request access to your Gmail, your Drive files, your Calendar, your contacts, or your organisation's Google Admin settings.
- It does not read, send or delete anything in your Google account.
- It stores no password, no password hash, no security question and no reset flow, because there is nothing of that kind to store.
From Google's response we keep the following, and nothing more:
| What | Why |
|---|---|
| Your Google account identifier | To recognise the same person across sign-ins. |
| Your email address | To match you to a row on your office's roster. This is the whole of the check. |
| Your Workspace domain | To confirm you signed in with a work account on an approved domain. |
| Your display name | To show who is signed in, and to name you on your own statement. |
Those four values live in the running server's memory for the length of your session. They are not written to a database of users. Restarting the service ends every session, and the next visit signs in again. Sessions also expire on their own (eight hours, unless your deployment is configured otherwise).
Your browser holds one cookie: a signed session identifier, plus a token used to prove that a save came from the Deskwork page and not from another site. The cookie carries no personal information itself. There are no advertising cookies and no cross-site cookies.
3. Your brokerage's records
The working records your office enters are stored on the server that runs your brokerage's desk. That includes:
- your roster: names, work email addresses, roles, teams, start and departure dates;
- commission plans: splits, caps, flat transaction fees, and each agent's cap year;
- transactions: property address, side, status, the agents on the file, the dates typed against it, sale price, and the parties recorded on it;
- document checklists: which documents a file owes, which have been filed, and the names of the files that were filed;
- closing figures, issued commission statements, referral fees, and office charges;
- any figures your office transcribes from its own commission workbook, kept marked as yours and separate from anything the desk computed.
Deskwork stores no document files. It holds the name of a document and whether it has been filed. The documents themselves stay in your brokerage's own Google Drive, under your own account, and we have no access to them.
Every accepted save keeps a copy of the version it replaced, so a bad save can be undone. Those copies live beside your office's records, are not reachable over the web, and are held under the same rules as the records themselves.
Every accepted save is also written to an append-only history: the time, the account that made it, and which parts changed. The history is kept beside your office's records rather than inside them, so it cannot be rewritten by the same save it records.
4. Who can see your records
- People on your roster. Your office's roster is the server's authority on who may read anything. An account that is not on it is refused, by name, on every screen and every data request.
- Not other brokerages. Each brokerage's records are separate and a sign-in is confined to its own approved domains.
- Us, only when we have to. The people who operate and support the service can reach the server where your records are stored. We look only when your brokerage asks us to, or when we have to in order to keep the service running or to meet a legal obligation.
One limitation stated plainly, because it is real today: a signed-in roster member can read the whole of their own office's records, not only the files assigned to them. Writes are restricted by role — the roster, the commission plans, the issued statements and the recorded referral fees can only be changed by the broker-owner or the office manager — but reads are not yet narrowed. Removing somebody from your roster, or disabling their Google Workspace account, ends their access.
5. Email
Email is off unless your brokerage configures it. When it is on, Deskwork sends exactly two kinds of message and there is not meant to be a third:
| Message | Goes to | When |
|---|---|---|
| A commission statement | The agent it is about, and nobody else | Once per deal per agent, when a closing is paid and archived |
| A deadline digest | The broker-owner and the office manager | At most once a day. A day with no deadline sends nothing |
Messages are sent directly to your brokerage's own mail server. No email vendor sits in the path of an agent's pay — there is no third-party sending service holding a copy of a statement in its own console or retention window. Agents are not sent deadline alerts, and there are no marketing emails, newsletters or product announcements from the application.
6. What the browser contacts
Deskwork's pages make one request outside our own server, and it is not about you: on the listing-search screen, listing photographs are fetched from the MLS image host. Those are public listing photographs. No transaction, agent, client name or commission figure appears in that request.
There is nothing else. Specifically, there is:
- no analytics of any kind, first-party or third-party;
- no advertising pixel, tag manager, session recorder or heatmap tool;
- no web fonts, icon service or content delivery network;
- no social media widget or embedded video;
- no third-party JavaScript at all, in the product or on this website.
This marketing website you are reading now loads its own stylesheet and nothing else. It sets no cookies.
7. Address and listing lookup
Entering a property address is always possible by hand. If your deployment is configured with lookup keys, the address text you type is sent from our server to the address and property-data providers configured for it, and suggestions come back. Only the address text is sent: no agent, no client, no figure and no record identifier. The provider keys are held on the server and never reach your browser. The feature works or does not exist depending on your deployment's configuration; the rest of the product is unaffected either way.
8. What we never do
- We do not sell your records, your agents' details or your clients' details. Ever.
- We do not share them with advertisers or data brokers.
- We do not use your brokerage's records to train machine-learning models, ours or anybody else's.
- We do not build a profile of you across other websites, because we cannot see them.
- We do not read your Google Drive, your Gmail or your Calendar, because we never asked for permission to.
9. How long records are kept
Your office's records are kept for as long as your brokerage uses Deskwork, because a brokerage needs its own closed files for years afterwards. Retained copies of earlier versions are pruned over time. Sign-in sessions end when they expire, when you sign out, or when the service restarts.
When your brokerage stops using Deskwork, you can ask for a copy of your records and ask for them to be deleted from our servers. We will do both. Say so at the address in section 12 and tell us which you want.
10. Security
The service is served only over HTTPS. Sign-in is Google Workspace, so account security — including two-factor authentication and offboarding a departing employee — is handled by your own Google Admin, and disabling somebody there stops them signing in here. Saves are checked against the signed session and the sending page before they are accepted, and are refused if the account's role does not permit that change. No system is perfect; if you believe something is wrong, tell us at the address below and we will treat it seriously.
11. Children
Deskwork is a tool for licensed real-estate professionals and the staff of a brokerage. It is not directed at children, and we do not knowingly collect information from anyone under 18.
12. Contact, and changes to this policy
Questions about this policy, a request for a copy of your records, or a request to delete them: privacy@deskworkapp.com.
If we change what the product does with information, we change this page and move the "last updated" date at the top. A change that materially affects what leaves your office will be told to the brokerages using the product, not left on a page for someone to notice.