How we protect your money and your data
Everything a buyer, a security team, or a legal team needs to evaluate REWORK Digital in one place: where funds are held, how disputes are resolved, how data is secured, who our subprocessors are, and how we respond to incidents. Every claim links to its authoritative policy.
Payments & escrow
Money moves through regulated payment processors, and project funds sit in escrow until work is approved. REWORK is not itself a payment processor.
- All payments are handled by third-party processors: Stripe as the primary processor and PayPal as a secondary processor. Card and bank details are collected and stored by those processors, never by REWORK directly.
- For project-based work, funds are held in milestone-based escrow. The buyer funds a milestone in advance and the money is held until that milestone is approved.
- Escrow is powered by Stripe Connect, with each payout routed to the expert's connected account on release.
- A flat flat 10% platform fee applies to marketplace transactions - not a tiered or hidden fee ladder.
Who legally holds customer funds
We are precise about this because it matters for your risk assessment.
- Escrowed project funds are held by the Platform as a convenience to facilitate trust between buyer and seller. This does not create a fiduciary relationship, and REWORK is not a bank, trustee, or licensed money-transmitter.
- Your payment credentials (card numbers, bank details) are held by the payment processors (Stripe, PayPal) under their own regulated custody, not by REWORK.
- REWORK may hold, freeze, or return escrowed funds where there is suspected fraud, a policy violation, or a legal requirement.
Payment protection process
The escrow flow is designed so neither side is exposed while work is in progress.
- The buyer funds a milestone up front; the expert can start knowing the money is committed and held in escrow.
- Funds are released to the expert only when the buyer approves the milestone deliverable, or through the dispute process.
- To keep undisputed work from stalling, an approved milestone that the buyer does not act on is auto-released a few days after delivery - so experts are paid for accepted work, and buyers keep a window to review or dispute first.
- On REWORK's marketplace, buyers can request a free working sample before committing, so hiring decisions are made on delivered evidence rather than promises.
Dispute-resolution timeline
There is a clear, staged path for resolving disputes, with defined time windows.
- Informal resolution first: once a dispute notice is raised, both parties have sixty (60) calendar days to resolve it in good faith before arbitration can begin.
- If it is not resolved in that window, either party may proceed to binding arbitration under the rules of the ADR Institute of Canada (ADRIC), seated in Toronto, Ontario (or a mutually agreed body for users outside Canada).
- For user-to-user marketplace and escrow disputes, REWORK may offer mediation at its discretion, but is not obligated to mediate and does not guarantee an outcome or a fixed resolution time.
- Any claim must be commenced within one (1) year of the cause of action, otherwise it is time-barred.
Supported currencies
We are honest about our current scope rather than overstating it.
- Marketplace escrow transactions are processed in US Dollars (USD).
- You are responsible for any taxes, duties, or currency-conversion fees your own bank or card issuer applies when paying in USD from another currency.
- Payout availability follows the countries our payment processors support for connected accounts.
Refund policy
Refund rules differ for platform fees versus the services experts sell.
- Platform fees charged by REWORK are non-refundable.
- Refunds for a seller's or service provider's work are set by that seller - REWORK does not guarantee or process them on the seller's behalf. Paying for a service does not by itself guarantee a specific result.
- Subscription cancellations take effect at the end of the current billing period; there are no prorated refunds for partial periods, and you keep access until the period ends.
- Filing a chargeback before trying our support channels may lead to account suspension; we contest chargebacks on transactions that went through the proper process.
Security policies
We describe the safeguards we actually run. We do not claim certifications we do not hold.
- Encryption in transit: all traffic between your device and our servers is protected with TLS/SSL.
- Encryption at rest: sensitive data in our databases and file storage is encrypted, including AI Copilot conversations.
- Access controls: role-based access limits data to authorized personnel on a need-to-know basis.
- Authentication: identity is managed through Firebase Authentication with support for multi-factor authentication, encrypted session tokens, and OAuth 2.0 sign-in.
- Infrastructure: hosted on enterprise-grade cloud (Google Cloud / Firebase) with DDoS protection, firewalls, and intrusion detection, plus periodic vulnerability scanning.
- Proof-of-work credentials use digital signatures and hash-based integrity checks so verified records cannot be silently altered.
Data retention
We keep personal data only for as long as it is needed, and delete or anonymize it after that.
- Personal data is retained for as long as necessary to provide the service, comply with legal and tax obligations, resolve disputes, and enforce our agreements.
- When data is no longer needed for those purposes, it is deleted or anonymized.
- Records of privacy breaches are retained for at least 24 months, in line with our breach-notification obligations.
- You can exercise access, correction, and deletion rights through our data-rights process, subject to legal retention requirements.
Data-processing agreement (DPA)
Enterprise buyers who need a signed DPA can request one.
- A data-processing agreement is available to business and enterprise customers on request.
- Our transfers to subprocessors are governed by data-processing agreements and, for international transfers, Standard Contractual Clauses.
- To request a DPA, contact legal@reworkdigital.io.
Incident-response policy
We maintain a documented incident-response plan and notify regulators and affected users within the timelines the law requires.
- Every incident is contained and assessed, investigated for scope and cause, remediated to prevent recurrence, and documented for review.
- GDPR: breaches affecting EU/EEA/UK data subjects are reported to the relevant supervisory authority within 72 hours of becoming aware, with affected individuals notified where the risk is high.
- Canada (PIPEDA & Quebec Law 25): breaches posing a real risk of significant harm are reported to the Office of the Privacy Commissioner of Canada and, where relevant, Quebec's Commission d'accès à l'information, with affected individuals notified.
- California (CCPA/CPRA): notifications follow California's breach-notification law, including notice to the Attorney General when more than 500 residents are affected.
- Suspected a vulnerability or breach? Email security@reworkdigital.io.
Subprocessor list
The key service providers that may process personal data on our behalf. Each is bound by a data-processing agreement with appropriate protection and transfer safeguards.
| Provider | Purpose | Region |
|---|---|---|
| Google Cloud / Firebase | Hosting, database, authentication | US / Global |
| Stripe | Payment processing & escrow payouts (Connect) | US / Global |
| PayPal | Secondary payment processing | US / Global |
| Anthropic | AI features (Copilot, content generation) | US |
| Cohere | AI text processing for platform features | US / Global |
| Resend | Transactional & notification email delivery | US / Global |
| Analytics providers | Usage analytics & performance monitoring | US / Global |