1. Information We Collect
Information You Provide
- Account Information: Name, email address, business name, phone number, and password when you create an account.
- Business Data: Contacts, estimates, invoices, jobs, team members, services, and other business content you enter into the platform.
- Payment Information: Credit card and billing details are processed by Stripe — we do not store card numbers on our servers.
- Communications: Messages you send through the platform, support requests, and feedback.
Information Collected Automatically
- Usage Data: Pages visited, features used, time spent, clicks, and navigation patterns.
- Device Information: Browser type, operating system, screen resolution, and IP address.
- Location Data: Approximate location from IP address. Precise GPS location only when you explicitly use clock-in/out features on a job (with your device's permission).
- Cookies: Session cookies for authentication and optional analytics cookies (see Section 4).
2. How We Use Your Information
We use your information to:
- Provide and maintain the T2Connect platform and all its modules (Email, Social, SMS, Business Ops, Website Hosting, Insights).
- Process payments via Stripe for your subscription and your clients' invoice payments.
- Send transactional emails (account confirmations, invoice notifications, password resets).
- Send marketing communications only if you opt in (you can opt out anytime).
- Generate analytics and reports within your account (Insights, job profitability, etc.).
- Improve the platform based on aggregated usage patterns.
- Comply with legal obligations.
We never sell your data. Your business data belongs to you. We don't sell, rent, or share your contact lists, client information, or business records with third parties for their marketing purposes.
3. Information Sharing
We share your information only in these limited circumstances:
- Service Providers: Stripe (payments), AWS (hosting + storage), Twilio (SMS), and email delivery services — only as needed to operate the platform.
- Your Clients: When you send an invoice, estimate, or public page to your clients, they see the business information you've entered (name, logo, contact info).
- Legal Requirements: If required by law, court order, or governmental regulation.
- Business Transfer: In the event of a merger, acquisition, or sale of assets, your data may be transferred as part of the transaction.
4. Cookies & Tracking
We use the following types of cookies:
- Essential cookies: Required for login, session management, and security. Cannot be disabled.
- Analytics cookies: Google Analytics (if configured on your hosted website) to understand visitor behavior. Optional.
- Preference cookies: Remember your settings (timezone, sidebar state, etc.).
We do not use advertising cookies or retargeting pixels on the T2Connect application. If you configure a Meta Pixel or Google Analytics ID on your hosted public website (Business Plus feature), those are your tracking tools under your own policies.
5. Data Security
We take reasonable measures to protect your data:
- All data transmitted over HTTPS (TLS 1.2+).
- Passwords stored as bcrypt hashes — we cannot read your password.
- Stripe API keys stored with AES-256-CBC encryption.
- Database hosted on private network (not publicly accessible).
- Regular backups with encrypted storage.
- Access limited to authorized personnel on a need-to-know basis.
No system is 100% secure. If we discover a breach affecting your data, we will notify you within 72 hours.
6. Data Retention
- Active accounts: Data retained as long as your account is active.
- Cancelled accounts: Data retained for 90 days after cancellation, then permanently deleted. You can request immediate deletion at any time.
- Backups: Encrypted backups may retain data for up to 30 additional days after deletion.
- Legal holds: Data may be retained longer if required by law or ongoing legal proceedings.
7. Your Rights
Depending on your location, you may have the right to:
- Access: Request a copy of all personal data we hold about you.
- Correction: Request correction of inaccurate data.
- Deletion: Request deletion of your data (subject to legal retention requirements).
- Portability: Request your data in a machine-readable format (CSV export available in-app).
- Opt-out: Unsubscribe from marketing emails at any time via the link in each email.
- Restrict processing: Request that we limit how we use your data.
To exercise any of these rights, contact us at privacy@t2connect.com.
8. Children's Privacy
T2Connect is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, contact us and we will delete it promptly.
9. Third-Party Services
T2Connect integrates with the following third-party services. Each has its own privacy policy:
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we'll update the "Last Updated" date at the top. For material changes, we'll notify you via email or a prominent notice in the application.