DRAFT — pending legal review. This document is not yet legally binding.
The text below is a good-faith description of how CatchBack currently works. It has not been reviewed by a lawyer, and sections marked [TO BE CONFIRMED BY COUNSEL] are open questions rather than commitments.
Privacy Policy
What CatchBack collects, why we collect it, and what happens to the customer list you upload.
Last updated:
In plain English
- You give us two kinds of data: your own account details, and the customer list you upload so we can look for missed follow-ups.
- We use that data to run the audit and show you recovery opportunities. We do not sell it, and we do not use your customer list to advertise to anyone.
- We rely on a small number of outside services to operate: Stripe for payments, Resend for email, and Google if you sign in with a Google account.
- The customer list you upload is about other people. You are the one responsible for having the right to share it with us.
- You can ask us to export or delete your data at any time by emailing privacy@catchback.ai.
1. What this policy covers
This policy explains what CatchBack LLC (“CatchBack”, “we”, “us”) does with information when you use the CatchBack service at catchback.ai.
CatchBack is a revenue-recovery tool for small local service businesses. A business uploads its customer and job list, and our audit engine looks for customers who were never followed up with and surfaces them as recovery opportunities. Almost everything in this policy follows from that one activity.
CatchBack is currently in private beta. The product is still changing, and this policy will change with it.
2. Information we collect
Account information
When you create an account we collect your name, email address, and the business you say you represent. Authentication is handled by better-auth. If you sign in with Google, Google tells us your name, email address, and profile image; we do not receive your Google password.
Customer and job data you upload
This is the core of the product. When you upload a CSV file or point us at a Google Sheet, we ingest whatever that file contains — which in practice usually means customer names, phone numbers, email addresses, addresses, and the history of jobs, quotes, or estimates associated with them.
We do not choose what is in your file. If your list contains additional columns, we ingest those too. Please do not upload information you do not need us to have.
Payment information
Subscriptions are billed through Stripe. Stripe collects and stores your card details directly; we do not receive or store your full card number. We do receive and store limited billing metadata such as your subscription status, plan, and the identifiers Stripe uses to refer to your customer and subscription records.
Usage and technical data
Like any web application, we record basic technical information when you use the service: pages and features accessed, timestamps, IP address, browser and device type, and error diagnostics. We use this to keep the service working and to understand which features are actually used.
3. How we use information
We use the information described above to:
- create and maintain your account, and sign you in securely;
- run the audit — that is, analyse your uploaded customer and job records to identify likely missed follow-ups and score them as recovery opportunities;
- display those results to you in your dashboard and let you act on them;
- take payment, manage your subscription, and send billing receipts;
- send transactional email such as verification links, password resets, and service notices;
- operate, debug, secure, and improve the service;
- comply with legal obligations that apply to us.
We do not sell your data, and we do not sell or rent the customer lists you upload. We do not use your uploaded customer list to market to the people in it.
4. The customer lists you upload contain other people's data
This is the most important section of this policy, because it is the part that is specific to what CatchBack does.
When you upload a customer list, you are giving us personal information about people who are not our users and who have no relationship with us. They are your customers, not ours. In that arrangement you are the one who decides what happens to their data, and we process it on your instructions in order to provide the service.
By uploading a list, you confirm that you have the right to do so — that you collected that information lawfully, and that using a service like CatchBack to analyse it and to prompt follow-up contact is consistent with whatever you told those customers when you collected it.
If one of your customers asks you to delete their information, or asks you what you hold about them, that request is yours to answer. We will help you locate, export, or delete their records within CatchBack — email privacy@catchback.ai and we will assist.
If someone who is not a CatchBack user contacts us directly about data we hold on a business’s behalf, we will normally refer them to that business, and tell the business about the request.
5. Where your data is stored and processed
Account data and uploaded customer records are stored in a PostgreSQL database. A separate Python analytics service reads those records to score them and produce the audit results you see in the dashboard. Both run on infrastructure operated by our hosting providers.
CatchBack LLC is registered in Delaware, United States, and our infrastructure is operated on that basis. If you use CatchBack from outside the United States, your data will be processed in the United States.
We use industry-standard measures such as encryption in transit and access controls on our systems. No service can promise perfect security, and we do not.
[TO BE CONFIRMED BY COUNSEL: formal information-security commitments, incident-notification timelines, and any international data-transfer mechanism]
6. Third-party services we use
We keep this list short on purpose. These are the outside services that receive data in the course of running CatchBack:
- Stripe — processes subscription payments. Stripe receives your billing and card details directly.
- Resend — delivers transactional email. Resend receives the recipient address and the contents of the message we send you.
- Google (Sign in with Google) — used only if you choose to sign in with a Google account, and to read a Google Sheet if you give us a link to one.
- Our hosting and database providers — store and run the application and its database.
Each of these services has its own privacy policy governing what it does with the data it receives.
[TO BE CONFIRMED BY COUNSEL: the specific data-processing terms and sub-processor list to publish for each provider named above]
7. How long we keep information
We keep account data for as long as your account is open, and uploaded customer records for as long as they are needed to show you your audit results. If you delete an uploaded list, we remove it from your workspace.
If you close your account, ask us to delete your data and we will do so, other than records we are required to keep — for example, billing records needed for tax and accounting.
[TO BE CONFIRMED BY COUNSEL: the specific retention period for closed accounts, deleted uploads, backups, and application logs]
8. Your choices and your rights
You can, at any time:
- view and update your account details in your account settings;
- delete an uploaded list from your workspace;
- ask us for a copy of the data we hold about you, or ask us to correct or delete it;
- close your account.
To make any of these requests, email privacy@catchback.ai. We may need to verify that the request really comes from you before we act on it.
Depending on where you live, local law may give you additional rights over your personal information.
[TO BE CONFIRMED BY COUNSEL: which statutory privacy regimes CatchBack is subject to, and the specific rights and response deadlines to state here]
10. Children's data
CatchBack is a tool for businesses and is not directed at children. We do not knowingly collect personal information from anyone under 18 through account signup. If you believe a child has created an account, contact us at privacy@catchback.ai and we will remove it.
11. Changes to this policy
We will update this page when our practices change, and we will update the “Last updated” date at the top. If a change materially affects how we handle your data, we will tell you by email or in the product before it takes effect.
12. How to contact us
For anything about privacy or your data, email privacy@catchback.ai. For help using the product, email support@catchback.ai, or use our contact page.
CatchBack LLC, Delaware, United States.