Privacy Policy
Last updated 17 September 2026.
This policy explains what SmartyBuild does with personal information. It covers both the people who use the software — a contractor's staff — and the people whose details appear in it, such as that contractor's clients and subcontractors.
Who holds what. SmartyBuild is business software licensed to a construction company. The information inside an installation — clients, projects, contracts, payments — belongs to that company. They decide what goes in, who sees it and how long it is kept. We provide and maintain the software and act on their instructions.
If your details are in a contractor's SmartyBuild installation because you are their customer or their subcontractor, contact that company first. They control the record. We will help them respond, and we will pass on any request that reaches us directly.
What is collected
From the people who use the software
- Name, work email address, phone number and job role.
- Sign-in information, including the Google account used to sign in.
- A record of actions taken in the system — who sent a document, who approved a payment, who changed a setting — which exists so a company can audit its own operations.
Entered by a company about its own contacts
- Clients: name, address, email, phone, property details, documents, signatures and payment records.
- Subcontractors: business and contact details, contracts, tax forms including W-9, and payment records.
- Recordings and transcripts of business calls, and copies of text messages, where the company has enabled those features.
Collected automatically
- Ordinary server logs: IP address, timestamps and which pages or endpoints were requested.
- Whether and when a client opened a document that was sent to them, which is what tells a contractor their proposal was received.
Data received from Google APIs
Staff sign in with Google, and a company may connect further Google services. This section describes each permission, what is done with it, and what is stored.
| Permission | Why it is requested | What is stored |
|---|---|---|
userinfo.email, userinfo.profile |
To sign a person in and match them to their staff account. | Email address, name and profile picture URL on the staff record. |
calendar.events |
To create and update an appointment on the assigned staff member's own calendar when one is booked or moved in SmartyBuild. | The identifier of the event SmartyBuild created, so it can be updated or removed later. Other calendar entries are not read or copied. |
contacts.readonly |
To import a company's existing contacts, at an administrator's request, so they can be worked from inside the system. | Name, email, phone, address, photo and a Google identifier, held in the installation's own contacts records. |
chat.spaces.create, chat.memberships, chat.messages,
chat.messages.create, chat.bot |
To deliver internal notifications to the company's own Google Chat — a contract signed, a payment matched — and to create the space those notifications go to. | The space identifier and a record that a message was sent. Conversations in Chat are not read or stored. |
admin.directory.user.readonly |
To let an administrator pick from their own organisation's users when creating staff accounts. | Nothing beyond the staff account the administrator chooses to create. Read-only, and limited to the administrator's own Workspace domain. |
webmasters.readonly |
To show a company its own Google Search Console performance alongside the leads it produced. | Aggregate query, click and impression figures for the company's own site. |
Limited Use. SmartyBuild's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- Google user data is used only to provide or improve the features described above.
- It is not used for advertising, and is not sold or transferred for advertising purposes.
- It is not used to develop, improve or train generalised artificial intelligence or machine learning models, and is not sent to any third-party AI provider. SmartyBuild's assistant feature can read leads, proposals, projects, invoices and commission figures only; calendar, contacts, Chat, directory and Search Console data are outside what it can reach.
- Humans do not read it, except with the company's explicit permission to resolve a specific support issue, where required by law, or on data that has been aggregated and de-identified.
Access can be withdrawn at any time from your Google account permissions page. Withdrawing it stops the connected features and does not delete the records a company has already created.
How information is used
- To run the software: producing documents, sending them, taking payments, calculating balances and commissions.
- To communicate on a company's behalf with their own clients and subcontractors, by email and — with consent — by text message.
- To keep the service secure and working, including diagnosing faults.
- To meet legal and tax obligations.
Personal information is not sold. It is not used for advertising or profiling, and it is not used to train AI models.
Who it is shared with
SmartyBuild uses the following providers, each for one job. They receive only what that job requires.
| Provider | Purpose |
|---|---|
| Render | Application hosting and the database |
| Cloudflare | File and document storage, DNS |
| Helcim | Card and bank payment processing |
| Plaid | Connecting a company's bank account to read transactions |
| Twilio | Text messages and calling |
| Sign-in, calendar, contacts, Chat, Search Console | |
| Anthropic | The in-app assistant and drafting help, over business records only |
| Deepgram, OpenAI | Call transcription, where a company has enabled recording |
| Mapbox | Maps and addresses |
Information may also be disclosed where the law requires it, or to establish or defend a legal claim. If the business changes hands, information may transfer with it; you would be told before that changed how it is handled.
Text messages
Text messages are sent only to people who have consented — by ticking a box, or by signing a document that states plainly that signing includes agreement to be texted. The exact wording shown is recorded with the consent. Message frequency varies, and message and data rates may apply. Reply STOP to any message to opt out, or HELP for help. Opting out is honoured immediately and does not affect anything else.
How long it is kept
Business records — contracts, payments, commissions — are kept for as long as the company that owns them needs them, and at least as long as tax and limitation rules require. Server logs are kept for a short operational period. When a company ends its use of SmartyBuild, their data is made available to them for export and then deleted on the timetable in their agreement.
Security
Data is encrypted in transit. Access inside an installation is governed by per-role permissions set by that company, and every significant action is written to an audit log. Payment card numbers and bank credentials are never stored by SmartyBuild — they are handled by the payment and banking providers named above. No system is perfectly secure, and we do not claim otherwise.
Your rights
Depending on where you live you may have the right to see what is held about you, correct it, delete it, or object to how it is used. Where your details sit inside a contractor's installation, ask that contractor — they control the record. You can also write to us and we will help.
Children
SmartyBuild is business software and is not directed at children. We do not knowingly collect information from anyone under 16.
Changes
If this policy changes materially, the date at the top changes and customers are told before it takes effect.