Privacy Policy
In short
Spatchr stores the business records you enter — your customers, properties, jobs and photos — so they can sync between your devices and your crew. We do not sell them, we do not advertise, and you can export or delete everything.
This policy explains what Spatchr does with information when you use the Spatchr Android app, the Spatchr web app at app.spatchr.com, or this website.
It is written to be read, not to be survived. Where something is genuinely unresolved, it says so rather than hiding behind a broad clause.
Who is responsible
Spatchr is operated by [LEGAL ENTITY — see src/data/legalEntity.ts], at [POSTAL ADDRESS]. That entity is the data controller for the information described here.
For any privacy question, export request, or deletion request, write to privacy@spatchr.com.
What we collect
Information you give us
- Your account. An email address, and a display name if you provide one. If you sign in with Google we receive your email address, name and profile picture from Google — identity only. We do not request access to your Google Drive, contacts, or calendar.
- Your business records. This is the bulk of it, and it is information you type or capture: customers and their contact details, properties and their addresses, measured areas, jobs, visits, line items, prices, catalog services, expenses, time entries, notes, tasks and interactions.
- Photos and files you attach to jobs, along with the file’s own metadata.
- Crew members you invite, by email address, and the role you assign them.
Some of these records describe your customers, who are not our users. You are responsible for having a lawful basis to hold that information; we process it on your behalf.
Information collected automatically
- Device and session data needed to keep you signed in and to sync — an authentication token, a device identifier, and timestamps of what changed so we know what to send.
- Approximate location, only when you use it. Area measurement and property mapping use your device’s location while you are on that screen. Spatchr does not track your location in the background and does not build a location history.
- Error and diagnostic information when something fails, so it can be fixed.
What we do not collect
We do not collect advertising identifiers, we do not run third-party analytics or advertising SDKs in the app, and we do not build behavioural profiles. We do not sell personal information, and we do not share it for cross-context behavioural advertising.
Payment card numbers never reach us. Payments run through Stripe’s hosted checkout, so card details go from you to Stripe directly.
Where your data lives, and who processes it
Spatchr is offline-capable on Android: after your first sign-in, your records live in a database on the phone itself and the app keeps working with no connection. When you have signal, that data syncs to our cloud so it reaches your other devices and your crew. The web app has no local database — it reads and writes your data live over the network.
We use these processors, each for one purpose:
| Processor | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, file storage | United States |
| Render | Application server | United States |
| Cloudflare | Website and app hosting, object storage | Global edge network |
| Stripe | Subscription billing and payment processing | United States |
| Sign-in, and maps for area measurement | United States | |
| OpenAI | The in-app assistant, when you use it | United States |
The assistant only sends what is needed to answer the request you made. It is not used to train external models on your data.
Data is stored and processed in the United States. If you use Spatchr from outside the United States, your information is transferred there.
How your data is separated from everyone else’s
Each business’s records are isolated at the database level by row-level security keyed to membership, not by application code alone. A signed-in user’s queries can only return rows belonging to a business they are a member of. This is enforced by the database on every request.
How long we keep it
- Active accounts: for as long as the account exists.
- Deleted records: items you delete go to a recoverable trash first, then are purged.
- Cancelled or lapsed subscriptions: your data is retained, not destroyed, so you can return to it. Access may become read-only.
- After an account-deletion request: removed within 30 days, except where we must keep something (for example, billing records required by tax law).
Your choices
- Export everything. The app can produce a complete backup of your data, including attached media, to a file you keep.
- Delete your account and data. The process, and what it does and does not remove, is written out at /data-deletion/.
- Correct or access your information. Most of it you can edit directly in the app. For anything you cannot reach, write to privacy@spatchr.com.
- Location. Revoke the location permission in your device settings at any time. Area measurement will stop working; nothing else will.
Depending on where you live, you may have additional rights — to access, correct, delete, or port your information, and to complain to a supervisory authority. We apply these requests to everyone regardless of location. We do not charge for them and we will not degrade your service for making one.
Children
Spatchr is a tool for running a business and is not directed at children. We do not knowingly collect information from anyone under 13. If you believe a child has provided us information, write to privacy@spatchr.com and it will be removed.
Security
Data is encrypted in transit. Access to production systems is limited to those who need it. Credentials for third-party services are held server-side and are never included in the app you download.
No system is perfectly secure, and we are not going to pretend otherwise. If a breach affects your information, we will tell you and the relevant authority as required by law.
Changes
If this policy changes materially, the “last updated” date at the top will change and we will notify you in the app before the change takes effect. Continuing to use Spatchr after that means the new version applies.
Contact
privacy@spatchr.com — [LEGAL ENTITY — see src/data/legalEntity.ts], [POSTAL ADDRESS]