Privacy Policy
AfterWurk is built on a simple principle: your employees' data belongs to your company, not to us. We never sell, share, or monetize personal data.
1. Who we are
AfterWurk is a private employee bonding platform operated by AfterWurk Inc., based in Minneapolis, Minnesota, USA. We help companies build real culture through after-work activities employees actually want to attend.
2. What data we collect
We collect only what's necessary to run the platform:
- Account information โ name, work email address, department, and profile bio
- Activity data โ activities you create, join, or interact with
- Usage data โ how you interact with the platform (anonymized for analytics)
- Communications โ messages sent within activity chat groups
- Ratings and feedback โ post-activity ratings you submit voluntarily
We do not collect government IDs, financial information, health data, or any sensitive personal categories.
3. How we use your data
- To provide and improve the AfterWurk platform
- To show you relevant activities based on your interests
- To enable your company's admin team to manage the platform
- To send you notifications about activities you've joined
- To generate anonymized engagement analytics for your company admin
4. Company data isolation
Every company's data is completely isolated at the database level using row-level security. Employees from Company A can never see data from Company B. Your company's AfterWurk space is entirely private.
5. International data and GDPR
AfterWurk supports teams across multiple countries. For users in the European Economic Area (EEA) and United Kingdom, we process personal data in accordance with GDPR principles:
- We process data only with a lawful basis (legitimate interests or consent)
- You have the right to access, correct, or delete your personal data
- You have the right to data portability and the right to object to processing
- We do not transfer data outside your region without appropriate safeguards
To exercise any of these rights, contact us at dylan@afterwurk.com and we will respond within 30 days.
6. Data sharing
We never sell your personal data. We share data only in the following limited circumstances:
- Your company admin โ your profile and participation data is visible to your company's designated admin account for moderation and safety purposes
- Service providers โ we use Supabase for secure database infrastructure
- Legal requirements โ if required by law or to protect safety
7. Data security
We take security seriously and implement industry-standard protections:
- All data is encrypted in transit (TLS 1.3) and at rest (AES-256)
- Row-level security ensures complete company data isolation
- We are actively pursuing SOC 2 Type II certification
- Access to production systems is strictly controlled and logged
- Enterprise security documentation available on request at dylan@afterwurk.com
8. Data retention
We retain your data for as long as your company's AfterWurk account is active. When a company cancels, we delete all associated employee data within 90 days. Individual employees can request deletion of their personal data at any time.
9. Cookies
We use minimal cookies necessary to keep you signed in and to understand how the platform is used (via Google Analytics). We do not use advertising cookies or sell data to advertisers.
10. Changes to this policy
We'll notify company admins by email of any material changes to this policy at least 30 days before they take effect.
11. Contact us
For privacy questions, data requests, or security concerns:
- Email: dylan@afterwurk.com
- Response time: within 2 business days for general questions, 30 days for formal data requests