smithworks
Privacy policy
This policy explains how Ecommerce Maven LLC handles information when locksmith businesses and their customers use smithworks.
Scope and responsibilities
This policy applies to the smithworks Android app, smithworks.app, and related support services. A locksmith business decides what customer and job information to enter and is responsible for using it lawfully. Ecommerce Maven LLC operates smithworks and processes that information to provide the service.
Information we process
| Category | Examples and source |
|---|---|
| Account and business | Email address, business name, phone, service area, address, hours, services, prices, and document settings supplied by the account user. |
| Customers and jobs | Names, phone numbers, email addresses, service addresses, vehicle details and VINs, notes, quotes, appointments, invoices, and payment records entered by a locksmith or customer. |
| Optional device data | Foreground location when a user requests nearby addresses or a current driving-time check. smithworks does not request background location. The camera reads a VIN barcode on the device; an image is not uploaded or stored by smithworks. |
| Connected services | Google Calendar free/busy intervals, dedicated smithworks calendar events, and encrypted connection credentials when a user chooses to connect Calendar. |
| Operations and security | Authentication events, network requests, synchronization and delivery state, error details, IP address, timestamps, and provider quota usage generated while operating the service. |
How we use information
- Authenticate users and administer accounts.
- Save, synchronize, and recover authorized business records.
- Schedule jobs and provide address, route, and Calendar features.
- Create and deliver requested invoices, receipts, and reminders.
- Prevent abuse, enforce quotas, troubleshoot, and secure the service.
- Respond to support, privacy, and account-deletion requests.
The current app records payment amounts and methods supplied by the locksmith. It does not collect or process customer card or bank-account credentials. We do not use a locksmith's customer records to market unrelated services to those customers.
Service providers and integrations
We disclose only the information needed for providers to perform these functions. They may process operational metadata under their own terms and privacy commitments.
| Provider | Purpose |
|---|---|
| Supabase | Authentication, database hosting, synchronization, and server functions. |
| Google Maps Platform | Address search, geocoding, and requested route estimates. |
| Google Calendar | Optional free/busy checks and smithworks appointment publishing. |
| Resend | Account, invoice, receipt, confirmation, and reminder email. |
| Expo | Mobile app builds and delivery of compatible app updates. |
When Google Calendar is connected, smithworks reads free/busy time without displaying meeting titles and creates or updates a dedicated smithworks calendar. OAuth credentials are stored encrypted. Our use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.
We do not sell personal information, share it for cross-context behavioral advertising, or use third-party advertising or analytics SDKs in the current app. We may disclose information when required by law or reasonably necessary to protect users, the service, or others.
Storage, security, retention, and deletion
Data is encrypted in transit and protected by authentication, business-access controls, and restricted administrative access. Authorized operators and infrastructure providers can access readable records when necessary to operate, secure, or support smithworks. The service does not provide end-to-end encryption that prevents operator access.
We keep active account and business data while the account is in use. In-app deletion removes the active account and associated smithworks data when the request succeeds. Verified requests submitted through the web are generally completed within 30 days. Limited backups and security or provider logs may remain until overwritten under normal retention schedules, isolated from ordinary product use. We may retain information longer when required for security, fraud prevention, legal compliance, or resolving a dispute.
Events already published to Google Calendar remain in the user's Google account until removed there. See the account deletion page for the exact process and deletion scope.
Your choices and controls
- Edit business, customer, job, and document information in the app.
- Disconnect Google Calendar from Settings.
- Deny optional foreground-location or camera permission.
- Delete the account in Settings or request deletion on the web.
- Ask to access, correct, or delete personal information by emailing [email protected]. We may verify identity before acting on a request.
Children and geographic processing
smithworks is a business tool for adults and is not directed to children under 13. We do not knowingly create accounts for children. smithworks is operated in the United States, and providers may process information in the United States or other locations where they operate.
Policy changes
We may update this policy as smithworks changes. We will update the date above and provide additional notice when a change materially affects how personal information is handled.
Contact us
Privacy questions and requests can be sent to Ecommerce Maven LLC at [email protected].