How we protect your business data, conversations, and wallet balances.
Every BobsWork page serves over HTTPS-only with HSTS preload. Data is encrypted in the database with the same Postgres-encrypted-at-rest offered by Neon. Backups inherit that encryption and a 30-day retention policy.
Every account ships with multi-factor ready out of the box. We recommend turning it on the day you sign in. We never store passwords in plaintext — bcrypt hashing only — and we never email them back.
Workspaces are isolated. Members see only what their role allows, and every permission change is recorded in an append-only audit log your admin can review at any time.
BobsWork never touches raw card numbers. All payment flows run on Stripe Connect in our merchant or marketplace model, with Webhook signatures verified on every Stripe event we accept.
Read the full privacy policy for details on what we collect, how we use it, and how you can export or delete it.
Read the privacy policy →