This Privacy Policy explains how Smart Book collects, uses, shares, protects, and retains personal information when people use the Smart Book service. It also explains how business owners can access, export, and delete business data.
1. Scope and our role
Smart Book is a business-management platform for service professionals. We process information directly about Smart Book account holders and authorized team members to provide accounts, subscriptions, security, and support.
When a service business uses Smart Book to store information about its own customers, workers, jobs, estimates, invoices, payments, photos, or communications, that business generally decides why the information is collected and how it is used. Smart Book processes that information to provide the service on the business’s instructions, subject to this Policy, the Terms of Service, and applicable law.
2. Information we collect
Account and business information. Names, email addresses, authentication identifiers, business name, phone number, business address, role, team membership, subscription status, settings, and account activity.
Client and service information. Customer names, companies, phone numbers, email addresses, service and billing addresses, notes, service locations, recurring schedules, job history, estimates, invoices, customer requests, and communication preferences.
Operational and field-service information. Appointment dates and times, technician assignments, route order, access instructions, job notes, completion records, before/after photos, documents, and other uploaded files.
Payment information. Smart Book stores transaction amounts, payment status, payment dates, processor references, card brand/last-four metadata where available, and Stripe customer/payment-method identifiers. Full payment-card numbers are processed by Stripe rather than stored in Smart Book’s ordinary business database.
Communications, support, and product feedback. Email/SMS recipient information, customer-message content, message templates, notification status, consent/opt-out records, delivery events, customer portal requests, information submitted to Smart Book Support such as name, email, business name, support category, and message, and signed-in product feedback or feature requests such as product area, optional experience score, message, and follow-up preference.
Technical, security, and product-adoption information. Authentication events, access timestamps, audit logs, identifiers needed to enforce business isolation and permissions, error information, optional product-nudge views/clicks/dismissals, detected feature-adoption events, recorded founder follow-up events, and other records reasonably necessary to secure, operate, support, and improve the service.
3. How we use information
We use personal information to provide and operate Smart Book; authenticate users; enforce roles and business separation; schedule and track work; create estimates and invoices; process or reconcile payments; deliver customer portals and communications; respond to support requests; support imports, exports, reporting, and routing; prevent abuse and fraud; troubleshoot errors; maintain audit records; comply with law; and improve the reliability and usability of the service.
Smart Book does not sell business customer data or use a service business’s client list for third-party targeted advertising.
4. How information is shared
We share information only as reasonably necessary to operate Smart Book, at the direction of the business using Smart Book, or as required by law. Providers may include:
- Base44 for application infrastructure, authentication, database functions, and file storage.
- Stripe for Smart Book subscriptions, Stripe Connect merchant onboarding, customer card payments, saved payment methods, and AutoPay where enabled.
- Resend for external customer or team email delivery where configured.
- Twilio for SMS delivery, consent/opt-out processing, and delivery status where a business enables texting.
- Professional advisers, authorities, courts, or other parties when disclosure is reasonably necessary to comply with law, enforce agreements, protect rights and safety, investigate abuse, or complete a corporate transaction.
Independent providers may process information under their own terms, privacy notices, and legal retention obligations.
5. Payments
Smart Book separates the software subscription paid by a service business from payments that business collects from its customers. Smart Book subscription charges are processed through the Smart Book platform Stripe account. Customer invoice payments and saved payment methods are processed through the service business’s connected Stripe account when Stripe Connect is enabled.
Smart Book does not intentionally store complete card numbers or card security codes in its ordinary application records. Stripe may retain payment and identity information as required to provide payment services, handle disputes, prevent fraud, and meet legal obligations.
6. Email and SMS
Customer email is optional and uses an external delivery provider when configured. SMS is optional and requires the business to configure Twilio and maintain appropriate recipient consent. Smart Book records consent and opt-out events to help businesses honor communication preferences.
Recipients may opt out of SMS where supported by replying STOP. A business using Smart Book remains responsible for ensuring it has a lawful basis and any required consent to contact its customers.
7. Data retention
We generally retain active business data while a Smart Book workspace is in use and for as long as reasonably necessary to provide the service, maintain security, resolve disputes, enforce agreements, and comply with legal obligations.
When an owner schedules business deletion, Smart Book provides a 30-day recovery period. If the owner does not cancel the request, Smart Book will attempt to cancel any still-active Smart Book software subscription and purge the business-scoped records from the active application database after the scheduled date.
Some information may remain for a limited period in backups, logs, caches, or provider systems, and certain records may be retained longer where reasonably necessary for security, fraud prevention, billing, tax, legal, dispute, or compliance purposes. Payment processors and communication providers may have their own retention duties. Private-file references are removed from the Smart Book workspace during deletion; underlying infrastructure backups or storage objects may persist temporarily under infrastructure retention practices.
8. Access, correction, portability, and deletion
Smart Book provides account tools that allow authorized business users to review and update many records directly. Owners/Admins can export supported business datasets in CSV or JSON format from Data Management. The owner can schedule deletion of the business workspace from Account & Data settings.
Depending on where you live and which privacy law applies, you may have rights to request access, correction, deletion, a portable copy, or other control over personal information. Requests may be subject to authentication, legal exceptions, and the relationship between Smart Book and the service business that originally collected the information.
If you are a customer of a service business that uses Smart Book, you should generally direct requests about that business’s customer records to the service business first because it controls how those records are used. Smart Book will assist its business customers where reasonably required.
9. Account deletion
Only the verified Smart Book business owner can schedule deletion of the business workspace. The workflow requires the owner to acknowledge data export, type the business name exactly, and then wait through a 30-day recovery period. The owner can cancel the deletion during that period.
When deletion is completed, Smart Book removes the business workspace and business-scoped application records such as client records, jobs, estimates, invoices, payments, service locations, team records, customer portal links, notes, attachments references, communication logs, automation records, notifications, routes, settings, and audit records. Authentication/security records and records held by independent processors may be retained as described above.
10. Security
Smart Book uses role-based access controls, tenant/business identifiers, restricted financial fields, private-file signed URLs, server-side payment operations, audit logging, and other administrative and technical safeguards designed to protect information. No system can guarantee absolute security, and users are responsible for protecting their credentials and devices.
11. Children
Smart Book is a business service and is not directed to children under 13. Account holders must be at least 18 under the Terms of Service. We do not knowingly invite children to create Smart Book business accounts.
12. State privacy rights
Some U.S. state privacy laws provide eligible residents with rights involving access, correction, deletion, portability, and certain opt-outs. The availability and scope of those rights depend on the law, the type of information, the size and activities of the business involved, and applicable exceptions.
Smart Book’s export, correction, communication-consent, and deletion controls are intended to help account holders and their businesses respond to applicable privacy requests even where a specific statute does not apply.
13. Changes to this Policy
We may update this Privacy Policy as Smart Book changes or legal requirements evolve. We will post the current version and effective date here and may provide additional notice for material changes.
14. Contact and privacy requests
Signed-in business owners can use Settings → Account & Data to export or schedule deletion of their Smart Book workspace. Business users can update account and customer information through the normal Smart Book controls. Other privacy questions and requests can be submitted through the public Smart Book Support page at /support/.