Last updated: August 7, 2026

Privacy Policy

Last updated: August 7, 2026 — Solo Sidekick ("Company," "we," "us," or "our")

This Privacy Policy explains how we collect, use, and protect information through our software platform (the "Service"). It applies to two distinct groups, addressed separately where relevant:

  • Subscribers — the business owners (e.g., electricians, plumbers, HVAC contractors) who create an account and use the Service directly.
  • End Customers — the Subscriber's own customers, whose contact information a Subscriber uploads into the Service in order to send quotes, invoices, and review/referral requests. End Customers do not create accounts and have no direct relationship with us.

1. Information We Collect

From Subscribers directly:

  • Account information: name, business name, email, phone, password (hashed, never stored in plain text)
  • Billing information: processed by our payment provider (Stripe) — we do not store full payment card numbers
  • Usage data: how you interact with the Service, log data, device/browser information

About End Customers (uploaded by Subscribers, not collected from End Customers directly):

  • Name, phone number, email address, service address
  • Job history, quotes, invoices, and communications sent through the Service
  • Review and referral interaction data (e.g., whether a review request email was opened or clicked)

Important note on End Customer data: we do not independently verify that a Subscriber had a lawful basis or valid consent to upload an End Customer's information. That responsibility belongs to the Subscriber, as described in our Terms of Service. If you are an End Customer and want your information removed, see Section 7.

2. How We Use Information

We use collected information to:

  • Provide, operate, and maintain the Service
  • Send automated communications on a Subscriber's behalf (quotes, invoices, review/referral requests) to that Subscriber's End Customers
  • Process subscription billing
  • Monitor for abuse, fraud, and Terms of Service violations
  • Improve the Service based on aggregate usage patterns
  • Comply with legal obligations

We do not use End Customer data for our own independent marketing purposes, and we do not sell personal information to third parties.

3. How Information Is Shared

We share information with the following categories of service providers ("subprocessors"), each solely to the extent necessary to operate the Service:

ProviderPurposeData Involved
SupabaseDatabase hosting, authenticationAll account and application data
StripePayment processing (subscription billing and Subscriber-to-End-Customer invoicing via Stripe Connect)Billing information; Stripe, not us, handles and stores payment card data
ResendTransactional email deliveryEnd Customer email addresses, message content
Make.comWorkflow automation (triggers communications, does not independently store data long-term)Job/customer data necessary to execute a given automation
LovableApplication hostingApplication code and, incidentally, data in transit

We do not sell personal information. We may disclose information if required by law, subpoena, or to protect the rights, safety, or property of the Company or others.

4. Payment Information

Full payment card details are never transmitted to or stored on our servers. Subscription billing and Subscriber-facing invoicing are handled entirely through Stripe, which is independently PCI-DSS compliant. When a Subscriber uses invoicing features, funds from their End Customers are routed directly to the Subscriber's own connected Stripe account — we do not hold, custody, or have visibility into individual payment card numbers.

5. Data Retention

We retain account and application data for as long as an account remains active, plus a reasonable period afterward for legal, accounting, or dispute-resolution purposes [specific retention period, e.g. 90 days post-cancellation, to be finalized]. Subscribers may request deletion of their account and associated data at any time, subject to Section 7.

6. Data Security

We use industry-standard safeguards, including encryption in transit (TLS), and database-level row-level security policies that isolate each Subscriber's data so that one Subscriber cannot access another's records. No system is completely secure, and we cannot guarantee absolute security of information transmitted to the Service.

7. Your Rights and Choices

For Subscribers: You may access, correct, or request deletion of your account data at any time through account settings or by contacting us at support@solosidekick.io.

For End Customers: If you received a communication from a business using this Service and want your information removed, you may click the "unsubscribe" link included in any email, or contact us directly at support@solosidekick.io with the business name and your contact information, and we will remove your data from our systems within [timeframe, e.g. 30 days], except where retention is required by law.

California residents (CCPA/CPRA): You have the right to know what personal information is collected about you, request deletion, correct inaccurate information, and opt out of the "sale" or "sharing" of personal information. We do not sell personal information. We will not discriminate against you for exercising these rights. Requests can be submitted to support@solosidekick.io. [Placeholder — verify current CCPA/CPRA disclosure requirements and add a "Do Not Sell or Share My Personal Information" link if applicable to your data practices before publishing.]

Other states: Residents of states with comparable privacy laws (e.g., Virginia, Colorado, Connecticut) have similar rights, which we honor on request. [To be finalized with counsel based on where End Customers are located.]

8. Cookies and Tracking

[Placeholder — update this section based on what analytics/tracking tools are actually implemented on the marketing site. If none are in use yet, state that plainly rather than describing tracking that doesn't exist. If analytics are added later, disclose the specific tool (e.g., a named analytics provider) and whether it uses cookies.]

9. Children's Privacy

The Service is not directed at, and we do not knowingly collect personal information from, individuals under the age of 18. If we become aware that we have collected such information, we will delete it.

10. International Users

The Service is intended for use by businesses operating in the United States. If you access the Service from outside the United States, your information will be processed in the United States, which may have different data protection laws than your country of residence.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated to active Subscribers with reasonable notice. Continued use of the Service after changes take effect constitutes acceptance of the revised policy.

12. Contact Us

Questions about this Privacy Policy, or requests under Section 7, can be sent to support@solosidekick.io.

Placeholders requiring finalization before publishing: [Business Name], [DATE], [CONTACT EMAIL], specific data retention periods, the cookies/tracking section (Section 8), and CCPA/state-law disclosure specifics (Section 7). This draft has not been reviewed by an attorney.