Last updated: 8/20/2026
Account details (name, email), your organization's business data (customers, jobs, quotes, invoices, payments), and — only with explicit opt-in — field-staff location during job hours.
When you sign up we also record your IP address and browser user agent. See “Sign-up and abuse prevention” below.
To provide the Service: scheduling, invoicing, payments, notifications, and reporting. We do not sell your personal information.
Essential cookies keep you signed in. Optional analytics, marketing, and personalization cookies run only with your consent — manage them anytime via "Cookie settings."
To protect your account, we keep a short record of each device you're signed in on - a device label (e.g. “Chrome on Windows”) and when it was last active. We use this to automatically sign out a session after 4 hours of inactivity, to limit an account to 3 signed-in devices at a time, and to end every other session the moment you change your password. This is operational security data, not an activity log: a device's record is deleted as soon as it signs out, is timed out, or is replaced. You can view and end your own active sessions anytime from Settings → Security.
Field-staff location is collected only after individual opt-in, only during active job hours, and is auto-deleted per your organization's retention setting. Staff can turn it off anytime.
When you submit the sign-up form we store what you entered (business name, industry, team size, your name, email, and phone if given) together with your IP address and browser user agent. We use these to create your workspace and to rate-limit sign-ups, which is what stops the form being used to create workspaces in bulk.
If a sign-up is never completed, we delete that record — including the IP address and user agent — after 90 days.
With processors that run the Service (Stripe, QuickBooks, Twilio, Resend, Facebook, Supabase, hosting). Each is bound to protect your data. No sale of personal information.
When you connect a third-party integration (QuickBooks, Facebook Lead Ads, Stripe, cal.com), you log in directly with that provider using your own credentials - we never receive or store your password for it. We store only the authorization token the provider issues after you approve the connection, scoped to the actions that integration needs, and protected by the same access controls as the rest of your organization's data. You can revoke a connection at any time from Settings → Integrations, which stops all future access immediately.
Access, export, correct, or delete your data. Owners can self-delete their organization from Settings → Danger Zone.