Privacy Policy

What ScaleITCRM collects, why we collect it, who we share it with, how long we keep it, and the choices you have.

Last updated August 14, 2026 · ScaleITCRM LLC

1. Two different roles

This policy covers two kinds of people, and our responsibilities differ for each.

  • Our customers — the contracting businesses that subscribe to ScaleITCRM and the team members they invite. We decide how their account information is handled, and this policy describes it.
  • Our customers' customers— homeowners and businesses whose details a contractor enters into their workspace. We process that information on the contractor's instructions. The contractor decides what to collect and why. If you want your details corrected or removed from a contractor's records, contact that contractor; if you cannot reach them, write to us and we will help you reach them.

2. What we collect

Account information

Name, email address, password (stored hashed, never in readable form), profile photo if you upload one, your role, your organisation name and trade, and display preferences.

Workspace content

Everything a contractor enters or imports: lead and customer names, phone numbers, email addresses, service addresses, job details, notes, appointment times, estimates, invoices, payment records, and website chat transcripts. This is entered by the contractor, not collected by us from other sources.

Technician location

GPS position, accuracy and timestamp, collected from a technician's device only while a job is marked "En Route". See section 4 — this one gets its own treatment.

Payment information

Subscription billing is handled by Stripe. We never receive or store your card number. We store a Stripe customer reference, your plan, and your subscription status. If you collect card payments from your own customers through Stripe Connect, those card details go directly to Stripe as well; we record the amount, the date and a payment reference.

Technical information

IP address, browser and device type, and log records of requests to our servers, kept for security and troubleshooting. We also keep an internal audit record of destructive and permission-changing actions — who deleted what, and who changed someone's access.

3. Why we use it

  • To provide the service and keep your workspace separated from every other tenant
  • To authenticate you and secure your account
  • To send transactional messages — invitations, password resets, estimates, job notifications
  • To take subscription payment and, if enabled, to route payments to your connected account
  • To provide support when you ask for it
  • To detect abuse, spam and security incidents, and to enforce rate limits
  • To meet legal and tax obligations

We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We do not use the contents of your workspace to train machine learning models.

4. Technician location data

This is the most sensitive thing we handle, so we are specific about it.

  • It is asked for, not assumed. A technician is prompted for location permission the first time it would be used, and can decline. Declining does not prevent them from working a job or updating its status.
  • It runs only between departure and arrival.Tracking starts when a technician marks a job "En Route" and stops when they mark themselves on site or complete the job. It does not run in the background, before a shift, after a shift, or while a job is in progress.
  • A visible indicator is shown while it is active, with a control to stop it.
  • It is not visible to co-workers.A technician can see their own history; an administrator of the same business can see their team's. No one outside that business can.
  • It is deleted automatically after 90 days by a scheduled job.

If you are a technician and want to know what your employer can see, that list is exactly it: position points recorded between "On my way" and arrival, for up to 90 days.

5. AI features

ScaleITCRM includes AI features: an assistant that answers questions about your own workspace, and an optional website receptionist that talks to visitors on your site and files enquiries as leads.

  • These run on Google's Gemini API. To answer a question, relevant workspace content is transmitted to Google for processing and a response is returned.
  • The assistant can only ever see what the person asking is already permitted to see. It cannot read another business's workspace.
  • The website receptionist is deliberately given no workspace data at all — only your business name, trade and intake questions — because the person it is talking to is a stranger.
  • Where an AI feature proposes a change to your records, it is shown to you for confirmation and is never applied on its own.

6. Who we share it with

We use the following providers to operate the service. They process data on our behalf, under contract, and are not permitted to use it for their own purposes.

ProviderPurpose
SupabaseDatabase, authentication and file storage
VercelApplication hosting and delivery
RailwayBackend service hosting
StripeSubscription billing and, if enabled, card payments from your customers
ResendTransactional email delivery
TwilioText message delivery, where messaging is enabled
Google (Gemini API)AI assistant and website receptionist processing
MapboxMap rendering for the crew map
MetaOnly if you connect a Facebook page, to receive your own lead ad submissions
SentryError monitoring and diagnostics

We may also disclose information if required by law, to respond to lawful requests, to protect our rights or someone's safety, or in connection with a merger or sale of the business — in which case we will give notice before your information becomes subject to a different policy.

7. How long we keep it

  • Workspace content — for as long as your account is active. After you close your account we keep it for a limited wind-down period so you can request an export, then delete it.
  • Technician location — 90 days, then deleted automatically.
  • Audit records — up to two years. Note that when a record is deleted, a copy is retained in this audit log so the deletion can be investigated or reversed. This means deleting a record removes it from the application immediately, but a recoverable copy exists for the audit period.
  • Billing and payment records — as long as required for tax and accounting purposes.

8. Security

Data is encrypted in transit. Every table is scoped to a single tenant and enforced at the database level, not only in the interface, so one business cannot read another's data even through the API. Access within a workspace is limited by role. Passwords are hashed. Card numbers never touch our systems.

No system is perfectly secure. If a breach affects your information we will notify you as required by law and tell you what we know.

9. Your choices and rights

You can:

  • Access and correct your account information in the application at any time
  • Export your workspace data
  • Ask us to delete your account and its data
  • Decline location permission, as a technician, without losing access to your work
  • Opt out of text messages by replying STOP — see our SMS Messaging Policy

Depending on where you live — California and several other states, among others — you may have additional rights to know what we hold, to request deletion, to correct it, and not to be discriminated against for exercising those rights. We do not sell personal information or share it for cross-context behavioural advertising, so there is nothing to opt out of on that front. To make a request, write to support@scaleitcrm.com. We will verify your identity before acting.

If your details are in a contractor's workspace and you are not our direct customer, we will pass your request to that contractor, who decides what happens to their records.

10. Children

ScaleITCRM is business software and is not directed at children. We do not knowingly collect information from anyone under 16. If you believe we have, contact us and we will delete it.

11. Changes to this policy

We may update this policy. The date at the top reflects the current version. If a change is material we will give notice by email or in the application before it takes effect.

12. Contact

ScaleITCRM LLC
27 Albe Drive, Newark, DE 19702
support@scaleitcrm.com