Privacy Policy
Last updated: June 13, 2026.
What we collect
- Customer account data: business name, user email, role, tenant configuration.
- Location data: addresses, service area, photos, brand assets, CRM sync configuration.
- Customer PII (hashed): emails and phones are SHA-256 hashed at ingest before any storage.
- Outcome events: timestamps, device identifiers, confidence scores. No raw customer identifiers retained.
- Subdomain visitor data: session id, UTM source/campaign, page views, scroll depth, CTA clicks. First-party only.
What we don't do
We do not sell data. We do not share it with third parties for marketing. We do not enrich customer PII beyond the hashed contact lookups needed for verification.
Your rights
You may request export, deletion, or opt-out via /privacy/request. We respond within 30 days, often immediately for tenant-scoped requests.
Cookies
A single first-party session cookie on each location subdomain. No cross-site tracking. No analytics cookies that transmit to third-party DSPs without your tenant's configuration.