Purple Willow Consulting, LLC

Privacy Policy

Willow Workbench handles UKG configuration that belongs to you and your clients. This page explains what we keep, what we don't, and how we protect it.

Last updated 9 October 2026

Credentials sealed

UKG passwords and secrets are encrypted with AES-256-GCM using a key unique to you.

Files not kept

Uploads are read in memory and discarded. We log only a file's name and size.

No tracking

No advertising, no analytics scripts, and we never sell or share your data.

You're in control

Download your personal data at any time, or ask us to delete your account.

Who we are

Willow Workbench is a set of tools for UKG Pro Workforce Management implementers, run by Purple Willow Consulting, LLC ("we", "us"). Accounts are by invitation only: a platform or customer administrator invites you, and your account belongs to that customer organization.

When you use the tools on a client's UKG environment, the client data stays the client's. We process it only to give you the results you asked for.

What we collect

DataWhy we have it
Account details
Name, email, customer organization, role, whether you hold one of its licenses, hashed password, and two-factor settings (your authenticator key, encrypted, and recovery codes, stored only as one-way hashes)
To sign you in, send your invitation and password emails, decide which tools you can open, and email customer administrators reminders when their license is ending.
Billing
For organizations that pay online: your organization's Stripe customer and subscription IDs, plan, number of licenses and renewal date. We send Stripe your organization's name and the subscribing administrator's email. Card details, billing address and tax ID are entered on Stripe's pages and held by Stripe, not by us
To keep your organization's licenses and renewal date in step with what it pays for.
UKG environment settings
Environment name, URLs, app key, client ID, user name, and the encrypted password, client secret and organization
To connect to UKG on your behalf when you run a tool.
Terms acceptance
Which version of the Terms of Service you agreed to, when, your email and IP address at the time
To keep a record of the agreement between us.
Usage log
Which tool you ran, when, on which environment, uploaded file names and sizes, duration, and any error
To support you, fix problems and understand how the tools are used.
Bug reports
What you write, an optional screenshot, the page and tool, your browser and IP address
To investigate and answer the problem you reported.
Technical data
IP address, browser, request times in server logs
To keep the service secure, limit sign-in attempts and diagnose faults.

Your UKG credentials

  • Passwords, client secrets and organization values are encrypted with AES-256-GCM before they are stored.
  • Each user has their own encryption key, and the keys are not stored in the database, so a copy of the database alone can't unlock them.
  • Only the person who added an environment can use it. Secrets are never shown again after you save them, not even to administrators.
  • We only connect to UKG over HTTPS and refuse private or internal network addresses.

Files and client data

Tools read SDM exports you upload, or configuration fetched from the selected UKG environment. That data is processed in memory to build your results. We don't store uploaded files or the configuration we fetch.

Results you can download (such as an Excel workbook) are held in server memory for up to one hour so the Download button works, then discarded. They are cleared sooner if the service restarts.

Usage log

Each tool run is recorded with your user, customer, the tool, the environment name, uploaded file names and sizes, how long it took and whether it succeeded. The log never contains file contents or UKG data.

You can see your own runs on the Usage page. Customer administrators see the runs for their organization, and Purple Willow Consulting's platform administrators can see all runs.

Bug reports

When you use Report a bug, we send what you wrote, any screenshot you attach, and context (your name and email, customer, page, tool, UKG environment name, browser and app version) to our support desk at [email protected], where it becomes a support ticket. Only attach screenshots you're allowed to share with us.

Cookies

We use only the cookies the service needs to work. There are no advertising or analytics cookies.

CookiePurposeLasts
PWCSServer.AuthKeeps you signed in15 minutes after your last activity
PWCSServer.SessionRemembers the UKG environment you selected15 minutes after your last activity
PWCSServer.TwoFactorRemembers that you entered your password while you enter your two-factor code5 minutes
PWCSServer.TwoFactorRememberOnly if you tick "Remember this browser" when signing in: skips the two-factor code in that browser14 days, or until you forget the browser or change your two-factor settings
PWCSServer.TempDataCarries a one-time message, such as a confirmation or your new recovery codes, to the next pageUntil that page is shown, or you close your browser
PWCSServer.DownloadTells the page your file download has started, so the loading indicator can close. It holds only a random code the page made up1 minute
.AspNetCore.Antiforgery.*Protects forms against cross-site request forgeryUntil you close your browser
Cloudflare cookies (such as __cf_bm)Set by Cloudflare to block malicious trafficUp to 30 minutes

Service providers

We don't sell your data or share it for marketing. A few providers handle data so we can run the service:

  • Cloudflare sits in front of the site to provide HTTPS and protect it from attacks. Your traffic passes through its network.
  • Microsoft 365 sends invitation, password and notification emails, and receives bug reports.
  • Stripe processes subscription payments and invoices. When your administrator subscribes or manages billing, they're sent to Stripe's own pages, and Stripe tells us the plan, number of licenses and renewal date.
  • Our help desk, which we host ourselves, holds support tickets created from bug reports.
  • UKG receives the requests our tools make to the environments you connect, under your own credentials.

The application and its database run on infrastructure operated by Purple Willow Consulting.

Security

The site is served only over HTTPS. Sign-in attempts are rate-limited and accounts lock after repeated failures, and you can turn on two-factor authentication with an authenticator app from your account page. Access to each tool depends on your role and your organization's plan. No system is perfectly secure. If a security breach affects your personal data, we will notify you as required by applicable law.

How long we keep data

  • Account details are kept while your account exists.
  • UKG environments are kept until you delete them, or your account is removed.
  • Downloadable results are discarded within one hour.
  • Terms acceptances are kept as a record of what was agreed, including after an account is removed.
  • The usage log is kept to support you and your organization. Entries keep the email address used at the time.
  • Support tickets are kept in our help desk for as long as needed to resolve and follow up on them.

Your choices

You can update your name, email and password, and download a copy of your personal data, from your account's Personal data page. To correct something else, or to have your account and data deleted, contact your organization's administrator or email us. Depending on where you live you may have further rights, such as to object to processing or complain to a regulator; we'll help with any request.

Changes to this policy

We'll update this page when the service changes how it handles data, and change the date at the top. For significant changes we'll let account holders know by email.

Contact us

Questions about privacy or your data? Email [email protected].