Who we are
Worthy is operated by Esposito Enterprises LLC d/b/a Worthy, based in New York, United States. We build and maintain websites for our clients. For the purposes of this policy, we are the business responsible for the personal information described below.
If you have a question about anything here, or want to exercise any of the rights in this policy, email us at [email protected]. A real person answers.
What we collect
We only collect information you give us, plus the minimum our servers need to run the site securely. We do not buy personal information from third parties.
When you send an enquiry
The contact form asks for your name and email address, and optionally your phone number, company name, project type, budget range, timeline, and the message you write. Everything past your name and email is optional — leave it blank and the form still works.
When you create an account
We store your email address, a display name if you set one, and a hash of your password. We store a hash, not the password itself, so nobody at Worthy can read your password. Signing in always requires a code we email you, so we also store that code — hashed, and only until it is used or expires. If you sign in with Google, we store the identifier that service uses to recognize you. We also record whether you want email about your tickets and projects, which you can turn off in your account settings.
When you open a support ticket
We store the ticket subject, every message on the thread, who wrote it and when, and any files you attach. Attachments are limited to PNG, JPEG and WebP images, PDFs, and plain text files. Please do not attach anything you would not want stored on our servers — do not send passwords, card numbers, or government ID through a ticket.
When we work on a project for you
We keep a project record: its title, a description, its current status, and the agreed amount. This is what lets you and we both see the state of the work in the dashboard.
Automatically
Our servers keep standard operational logs — the request made, the time, the IP address it came from, and technical details such as browser type — which we use to keep the service running and to investigate abuse or errors. If you have an account, we also store the IP address and browser description of each sign-in against that account: it is what lets us show you the list of signed-in devices in your settings, and what lets us email you when your account is used from somewhere it has not been used before. We keep a record of administrative actions taken on the service, which includes the IP address they came from, and we record failed sign-in attempts by IP address so we can shut down brute-force attacks. We do not use any of this to build a profile of you or to track you across other websites — see “Cookies and local storage” below for what we keep on your device.
Why we use it
We use the information above for these purposes and no others:
- To answer your enquiry and give you a quote.
- To create and secure your account, and to sign you in.
- To run support tickets and reply to you.
- To deliver the project you have hired us for, and to invoice it.
- To keep the service secure — detecting abuse, debugging faults, and preventing fraud.
- To email you about your own tickets and projects — replies and status changes. You can turn this off in your account settings. We do not send marketing email.
We do not sell your personal information. We do not share it with advertisers, and we do not use it to build advertising profiles. We run no advertising or cross-site tracking technology on this site at all.
How long we keep it
We keep information for as long as it serves the purpose we collected it for, then delete it.
- Enquiries that do not become projects: kept while we follow up, then deleted.
- Account data: kept while your account is open.
- Tickets and attachments: kept while your account is open, and retained after you close it as the record of work we did, unless you ask us to delete them.
- Project and billing records: kept for as long as tax and accounting law requires us to keep them, even after your account closes.
- Sign-in and security records: session records are removed when the session expires or you sign it out; the record of devices used to sign in is deleted with your account; failed sign-in attempts and administrative audit records are kept for a limited period for security and then deleted.
When you delete your account, we remove your password, unlink any connected sign-in services, and release your email address so it can be used again. Records we are legally required to retain, such as invoices, are kept for the required period and then deleted.
How we protect it
Passwords are stored as hashes, never in plain text. Sessions use signed, expiring tokens. Uploaded files are renamed on arrival so an uploaded file cannot overwrite anything on our servers, and we accept only a conservative set of file types. Access to production data is limited to the people who need it.
No system is perfectly secure, and we will not pretend otherwise. If a breach affects your personal information and creates a real risk to you, we will notify you and any regulator we are required to tell, without undue delay.
Your rights
You can ask us to do any of the following, at any time, by emailing [email protected]:
- Tell you what personal information we hold about you.
- Give you a copy of it.
- Correct anything that is wrong — you can also edit most of it yourself in your account settings.
- Close your account. We remove your password and any linked sign-in service and release your email address; your ticket and project history is retained as described in “How long we keep it”. Ask us and we will delete what we are not legally required to keep.
- Stop sending you email about your tickets and projects — you can also turn this off yourself in your account settings.
We will not charge you for these requests, and we will not treat you differently for making one. We aim to respond within 30 days.
Where we operate
We are a United States business. We offer our services to clients in the United States, and we do not market or target our services outside it. Information you send us is stored and handled in the United States, which may not offer the same legal protections as another country. If you would prefer that we did not hold your information in the United States, please do not send it to us.
If you believe we have mishandled your information, we would like the chance to put it right first — email [email protected]. You may also have the right to complain to the privacy regulator in your state.
If you live in California
The California Consumer Privacy Act gives you the right to know what personal information we collect, to have it deleted, to correct it, and to not be discriminated against for exercising those rights. We do not sell or share personal information as those terms are defined by the CCPA, so there is nothing to opt out of — but the rights above are yours regardless, and the same email address handles them.
Children
This site is for people running businesses, and is not directed at children. We do not knowingly collect personal information from anyone under 13. If you believe a child has given us their information, email [email protected] and we will delete it.
Changes to this policy
If we change how we handle personal information, we will update this page and the date at the top. If a change materially affects your rights, we will tell account holders directly rather than relying on you to notice.