Privacy Policy

Last updated: 8/20/2026

1. What we collect

Account details (name, email), your organization's business data (customers, jobs, quotes, invoices, payments), and — only with explicit opt-in — field-staff location during job hours.

When you sign up we also record your IP address and browser user agent. See “Sign-up and abuse prevention” below.

2. How we use it

To provide the Service: scheduling, invoicing, payments, notifications, and reporting. We do not sell your personal information.

3. Cookies

Essential cookies keep you signed in. Optional analytics, marketing, and personalization cookies run only with your consent — manage them anytime via "Cookie settings."

4. Account sessions and device security

To protect your account, we keep a short record of each device you're signed in on - a device label (e.g. “Chrome on Windows”) and when it was last active. We use this to automatically sign out a session after 4 hours of inactivity, to limit an account to 3 signed-in devices at a time, and to end every other session the moment you change your password. This is operational security data, not an activity log: a device's record is deleted as soon as it signs out, is timed out, or is replaced. You can view and end your own active sessions anytime from Settings → Security.

5. Location data

Field-staff location is collected only after individual opt-in, only during active job hours, and is auto-deleted per your organization's retention setting. Staff can turn it off anytime.

6. Sign-up and abuse prevention

When you submit the sign-up form we store what you entered (business name, industry, team size, your name, email, and phone if given) together with your IP address and browser user agent. We use these to create your workspace and to rate-limit sign-ups, which is what stops the form being used to create workspaces in bulk.

If a sign-up is never completed, we delete that record — including the IP address and user agent — after 90 days.

7. Sharing

With processors that run the Service (Stripe, QuickBooks, Twilio, Resend, Facebook, Supabase, hosting). Each is bound to protect your data. No sale of personal information.

When you connect a third-party integration (QuickBooks, Facebook Lead Ads, Stripe, cal.com), you log in directly with that provider using your own credentials - we never receive or store your password for it. We store only the authorization token the provider issues after you approve the connection, scoped to the actions that integration needs, and protected by the same access controls as the rest of your organization's data. You can revoke a connection at any time from Settings → Integrations, which stops all future access immediately.

8. Your rights

Access, export, correct, or delete your data. Owners can self-delete their organization from Settings → Danger Zone.

9. Contact

admin@cloudglobal360.com