Who we are
OBG Tools LLC provides OBGTools for business owners and authorized staff. Contact support@obgtools.com about this notice or your information.
A subscribing business decides which customer records, work details and website content its team enters. Its own notice also applies to its relationship with its customers. Connected customer portals have separate customer accounts; they are not staff sign-in accounts.
Information you provide
- Account and access information: email, account identifiers, sign-in and recovery requests, invitations, business memberships and roles.
- Business records: names, email addresses, phone numbers, customer and job addresses, appointments, assignments, work instructions, notes, products, inventory, sales, returns, estimates, invoices and related history. Business Manager records include expense descriptions, categories, amounts, dates and notes, cash or check income, recorded refunds and the account identifiers associated with changes.
- Messages and content: customer messages, website text, selected photos, job photos and captions, and receipt photos attached to expenses. Receipt photos are stored privately for the authorized business; they are not published on its website. Content you publish on a website becomes public.
- Files and work in progress: selected imports, local drafts, saved records and pending requests. Requested exports and PDFs can contain personal or private business information. A business-record export can include financial notes, account attribution and receipt attachment history; a text export does not include the receipt image itself.
- Inquiries and support: business contact information, project details and issue descriptions you send us.
The app does not request your device's location or address book. An address you enter or a contact you import is still part of the saved business record. Choosing a photo does not upload your entire photo library.
How information is used
We use information to sign you in, apply business permissions, save work, coordinate assignments, exchange customer messages, prepare documents, provide requested exports, edit supported websites and respond to support requests.
Operation and access history helps reconcile interrupted requests, prevent unauthorized actions and explain business changes. Hosting and authentication services process technical records such as request times, page or API paths, response status, account identifiers, IP addresses and browser/device information for delivery, security and troubleshooting. Public inquiry abuse prevention uses a hash derived from request information.
We may access relevant records for authorized support, maintenance, security or resolving a request. Do not send passwords, secret keys, full card numbers or unrelated sensitive records in support messages or sales inquiries.
Website editing and payments
The editor loads the supported business website inside the app. Its hosting service receives page and resource requests, including ordinary request information. Website scripts may load business data, images, fonts, video or customer sign-in services. A website's privacy notice applies to its own customer features. The editor is restricted to registered pages; a website link opened outside the app is handled by your browser.
Supported websites may use local browser storage for carts, saved work or customer sessions. The native editor uses a temporary web session and disables shared and third-party cookies. These settings do not prevent a hosting service from receiving requests.
Card entry and merchant setup take place on the payment provider's pages. OBGTools can receive payment status, provider references, amounts and related business history. The current native payment integration is for testing; this notice does not announce live card processing. Provider pages have their own privacy terms.
Who receives information
Authorized business users receive records allowed by their role. Linked customers receive customer-facing information for their own linked account. Services used for the selected feature include:
- Supabase: staff authentication, databases, file storage and server functions. Privacy information.
- Netlify: our website and supported customer websites and server functions. Privacy information.
- OpenAI Sites: hosting for a registered demonstration website. Privacy information.
- Google Firebase / Identity Platform: connected customer-portal sign-in and recovery. Privacy information.
- Resend: staff verification and recovery email through our authentication service, and configured inquiry notifications. Privacy information.
- Expo and Apple / Google notification services: optional new-message alerts on supported app builds. Delivery uses a device push token and account/business/conversation identifiers. The notification contains a generic alert rather than customer names or message text.
- Stripe: external merchant and payment-provider features where configured. Privacy information.
When you share an export or PDF, you choose its destination using your device. The receiving person, app or storage service controls its copy. We cannot recall copies already downloaded or shared.
Our production database is hosted in the United States. Providers may process information in other countries where they and their service providers operate. Their published privacy and data-processing terms explain their locations and applicable transfer safeguards. This notice does not represent that all information stays in one country.
Your device and choices
Where message notifications are available, enabling them registers this device for the selected business. You can turn them off in Inbox or change notification permission in your phone settings. Turning them off does not delete the conversation. Customers using a website portal do not automatically receive native app alerts.
The app encrypts its local draft and retry database with a key held in protected device storage. That protection does not cover every photo, generated file, operating-system cache, shared copy or server record. Selected photos may be copied into app storage, and exports use temporary files.
You choose whether to select files or photos and can manage camera/photo permissions in device settings. Other work remains available without photo permission. Signing out is different from deleting an account. Reinstalling the app or losing its local key can make unsynced work unrecoverable.
How long information is kept
Business records are kept for the active service and its applicable obligations. Removing a membership restricts access but does not erase business history. Service cancellation takes effect at the end of the paid period. Service terms include one export of available data and approximately 30 days for export or reactivation.
Unnecessary personal account information is removed through verified deletion. Records needed by another active owner remain with that business, with unnecessary departing-user profile and contact copies removed. Financial, tax, payout or dispute records are limited to documented obligations with a responsible owner, review date and end condition. They are reviewed at least annually and when the obligation resolves. A deletion request does not waive money owed.
Closed or withdrawn deletion requests keep a minimal receipt and outcome for 12 months. Unnecessary operator text and redundant identity information are minimized earlier. Unresolved requests remain open. A documented legal or incident hold may extend retention of specified records until its end condition is met.
Routine recovery copies controlled by OBGTools expire within 30 days of creation. Existing recovery copies remain protected until verified replacement and restoration checks pass. Any restoration must reapply later deletions before records return to service.
Provider-managed backups and logs follow their own settings and terms. Our current Supabase Pro service provides seven days of accessible logs and daily backups; this is not a deadline for every internal provider security record. Firebase describes logged authentication IP retention of a few weeks and removal of other authentication data from live and backup systems within 180 days after deletion is initiated. Email and website-hosting log retention depends on the provider's service and plan. These periods are separate from our private recovery copies.
Account deletion
In the app, open Account and help → Manage account. Review the account and retained records, then confirm your password and deletion. An owner first reviews the available transfer or closure choice for each business. If ownership or outstanding records prevent that action, submit the in-app deletion review request so we can resolve the requirements. If you cannot access the app, contact support from the email connected to your account.
Where unresolved business or payout records require review, the app saves an acknowledgment and receipt immediately after a successful request. Our acknowledgment commitment is no later than the next business day. The completion target is 30 days from the original request. The receipt shows progress, the target date, any retained-record explanation and whether the request is overdue. A status update does not extend the original target.
You can withdraw a review request until deletion starts. Keep your saved receipt to check progress and recover an interrupted request, including after sign-in removal. Progress and completion are shown in the app; an email notification is not promised. Completion appears only after server and device cleanup are verified. A request that still needs review is not marked complete.
Transferred business records remain with the receiving business. Cleanup removes supported account/contact copies, authored personal content and registered files when eligible. Business transaction history and pseudonymous attribution may remain. Expense descriptions, notes, receipt photos and their change history can require financial-record review before account deletion completes. Unknown or unresolved records require review. Removing files does not recall original photos or copies already shared; temporary links and cached copies require expiry or verified removal.
Privacy questions and requests
Contact support@obgtools.com to ask for access, correction, an available-data export or deletion. Identify the account and business concerned without sending passwords or card numbers. We may verify your identity and authority before providing records or making changes.
We acknowledge support requests by the next business day and explain the next step. That is separate from the time needed to complete an export or resolve retained records. If information belongs to another business's customer relationship, we may need that business to handle or authorize the request. Your location may provide additional privacy rights or a right to contact a data-protection authority; contact us to exercise applicable rights.
Notice changes
The current notice is available here and through Account and help in the app. When this notice changes, its date is updated. Contact support to ask how a change affects your account or a pending privacy request.