ServiceHQ Privacy Policy
Effective date: April 26, 2026 · Last updated: July 16, 2026
Plain-English summary: We collect only what we need to run dispatch, billing, SMS (incl. STOP-keyword opt-outs), voice calls (when enabled), AI-assisted intake (when enabled), partner GPS location during active jobs (when enabled), CRM data import (when you migrate from another CRM), in-app satellite property measurement (when you draw a polygon), post-completion work-order receipts (when enabled), and -- when prepaid billing is enabled -- the customer's payment via Stripe routed to the dispatching company's own Stripe Connect account. We don't sell your data. We share with the providers required to deliver service (Stripe for payments, Twilio for SMS + voice, Resend for email, Anthropic for AI intake, OpenStreetMap + Esri World Imagery for the dispatcher + measure-tool maps). Customer data your business uploads belongs to you -- we just store and process it on your behalf.
Brand note: The platform was marketed as LockRoute before July 4, 2026 and is now marketed as ServiceHQ across every trade vertical (locksmith, pest control, handyman, pressure washing, and others). It is the same operator, the same platform, and the same policy — references to LockRoute in older communications, receipts, message headers, or URLs (including the lockroute.app domain, which remains in service) refer to ServiceHQ.
1. Who We Are & Scope
"ServiceHQ," "we," "us," or "our" refers to Field Service Ventures LLC, the operator of the ServiceHQ dispatch platform available at lockroute.app and related subdomains. ServiceHQ is a product and trade name of Field Service Ventures LLC. This policy explains how we collect, use, and share information when you visit our website, sign up for an account, or use our services as a Dispatcher Company, Partner, Technician sub-user, or end Customer.
2. Roles & Data Controllership
ServiceHQ operates a multi-tenant Software-as-a-Service platform. The role we play depends on whose data we are handling:
- Dispatcher Companies, Partners, sub-users: We act as a controller of your account data (the information you give us to set up and bill your account).
- End-Customer information (names, phone numbers, addresses, service requests) that a Dispatcher Company collects through ServiceHQ: We act as a processor on behalf of that Dispatcher Company. The Dispatcher Company is the controller and remains responsible for the lawful basis of collection and for honoring end-customer requests.
3. Information We Collect
3.1 Information you give us directly
- Account: name, business name, email, phone, password (hashed), business address.
- Billing: card details handled exclusively by Stripe (we never see or store full card numbers); we retain Stripe customer/subscription IDs and last-4 metadata.
- Bank / payout info: collected by Stripe Connect during partner/dispatcher onboarding and held by Stripe. We never see full bank credentials.
- Identity verification: Stripe may require government-issued ID for Connect onboarding. We do not store these documents.
- Customer data uploaded for dispatching: customer names, phones, emails, addresses, service requests, photos, and free-text notes. Notes can be saved at the job level (specific to one dispatch) or at the customer level (persisted across every future job for that customer — useful for gate codes, pet warnings, payment-method preferences). Customer-level notes are visible to the Dispatcher Company and to the Partner currently assigned to a job for that customer; they are never shown to the customer themselves. Customer-level notes are retained for the life of the customer record and deleted on Dispatcher Company instruction.
- Communications: any messages you send through our contact form, support chat, or email.
3.2 Information collected automatically
- Device/log data: IP address, user-agent, request paths, timestamps. Used for security, abuse prevention, and debugging.
- Authentication tokens: after sign-in, a signed session token is stored in your browser's localStorage (not a tracking cookie) and sent with your requests to keep you logged in. We do not use third-party advertising cookies or cross-site trackers.
- SMS / email delivery logs: timestamps, recipients, status (delivered, failed, undelivered).
- Voice call metadata (when the Voice Add-On is enabled for the Dispatcher Company): masked phone numbers used in the bridge, call timestamps, duration, recording status, billing minutes consumed.
- Voice call recordings & transcripts (when the Voice Add-On is enabled): audio recordings of inbound and outbound calls placed through the platform's masked numbers, retained for the Dispatcher Company's review and dispute resolution. All parties on the call hear an audible disclosure that the call may be recorded. Recorded calls are additionally transcribed to text automatically by our transcription subprocessor (Deepgram, Inc. — see Section 5); the transcript is stored alongside the call log with the same access controls and lifetime as the recording. Recordings and transcripts are accessible only to the relevant Dispatcher Company and ServiceHQ staff investigating support tickets, and are deleted on request or when the underlying job record is deleted.
- AI Receptionist call data (when the AI Receptionist add-on is enabled and active): the speech-to-text transcript of the caller's side of the conversation, the fields the AI extracted (name, address, phone, service type, vehicle), the resulting Job record, and the call recording. The AI's prompt context (company service area, hours, decline list) is included in the AI request to inform the response. Transcripts are stored for diagnostic and prompt-improvement purposes for up to 90 days, then deleted.
- Partner & staff technician GPS location data (when the Live Tracking feature is enabled by ServiceHQ staff for the Dispatcher Company AND a Partner has accepted a job AND the Partner has granted device-level location permission — and, for staff technician Sub-Users, when a dispatcher requests a location fix and the staff member's device has granted location permission): latitude, longitude, accuracy radius, and timestamp, captured periodically (every 30 seconds on Android / desktop, every 5 minutes on iOS Safari) only while the Partner has a job in en_route or on_site status. Pings stop automatically when the job changes to any other status, when the Partner navigates away from the job screen, or when the Partner closes the portal / revokes location permission. Captured location data is retained for up to 30 days, then deleted.
- CRM import data (when a Dispatcher Company migrates from another CRM such as GorillaDesk): CSV exports the Dispatcher Company uploads are temporarily stored in
import_sessions.csv_payload for processing, then automatically cleared from that column once the import is committed. The resulting rows (customers, jobs, invoices, recurring service plans, payments, materials usage history) are stored in the standard production tables as if the Dispatcher Company had entered them natively. We act as a processor; the Dispatcher Company is the controller and is responsible for confirming it has the lawful basis to export and re-upload its End Customer data from the source CRM.
- In-app property measurement data (when a Dispatcher staff member uses the satellite-map measure tool): the polygon coordinates the user drags around the property and the resulting square-footage are stored on the Customer or Site record (
customers.lawn_sqft, customers.property_polygon_geojson, sites.lawn_sqft, sites.property_polygon_geojson). The underlying satellite imagery is loaded from Esri World Imagery tiles; only tile-fetch URLs and the dispatcher's IP traverse Esri (no ServiceHQ account data). Polygons are retained for the life of the Customer / Site record and deleted on Dispatcher Company instruction.
- Work-order receipts (when the Work Orders feature is enabled for the Dispatcher Company): on Job completion, a customer-facing summary page is sent to the End Customer via SMS + email. The page is hosted at a public URL keyed by the Job's existing tracking token. The page renders the Service Type, address, technician name (or anonymized label per the Dispatcher Company's customer-display-mode setting), check-in/check-out times (per company toggle), materials applied (per company toggle), and totals. Per-service-type intro/signoff copy is shown when the Dispatcher Company has authored it. The token is not a secret long-term identifier and is rotateable.
- Materials applications log (when Partners or Dispatchers record materials used on a Job): material name, manufacturer, regulatory ID (EPA reg #, refrigerant Section 608 type, etc.), lot number, quantity, unit, concentration, location applied, target organism, cost, weather conditions, and partner identity. Required by several state pesticide boards for the regulated verticals (pest control); optional and frequently unused for non-regulated verticals (locksmith, handyman). Retained for the regulatory retention window applicable to the Dispatcher Company's vertical (typically 2-7 years for pest; 1 year minimum for other verticals).
- Role template & permissions data (when a Dispatcher Company creates custom user roles): the bundle of permission flags authored by the Dispatcher Company owner and the snapshot of those flags assigned to each Sub-User at the time of invitation. Used by the access-control gates to determine which Sub-Users can view, edit, or delete which records inside the Dispatcher Company. No End Customer data is stored in role templates.
- Derived analytical scores (computed on the Dispatcher Company's own data without external API calls): customer churn-risk score (0-100, recomputed by the nightly cron from existing records), NPS aggregates over the prior 90 days, lifetime-value per customer cohort, and "smart fill" candidate suggestions when a Job cancels. These are computations over data the Dispatcher Company already provided; no new personal information is collected.
- Native push tokens (when a Dispatcher staff member or Partner installs the mobile app and signs in): the device's APNs PushKit token (iOS) or FCM registration token (Android), the platform identifier, and the app version. Stored on the
agents.device_token (Dispatcher staff) or partners.device_token (Partner) row + the voip_devices table (for in-app VoIP call ringing). Used solely to deliver push notifications (job offers, status changes, payment received, incoming calls, voicemails, customer SMS replies); never shared with marketers. Cleared on explicit sign-out and auto-cleared on stale-token detection (Apple / Google reports the device uninstalled the app).
- Sensitive-action audit log (since May 2026): when a Dispatcher Sub-User performs an action with financial consequences — voiding an invoice, marking an invoice paid, reverting a paid invoice to draft, issuing a Stripe refund — we record an append-only audit_log row containing the action type, the Sub-User's email and ID, the source IP (resolved from X-Forwarded-For when present), the user-agent string, the affected record's before / after state, and a timestamp. The log is admin-only (visible to the owning Dispatcher Company's
company_admin / company_manager / owner roles plus ServiceHQ Staff investigating support tickets); regular dispatcher Sub-Users receive 403 when trying to read it. Used solely for forensic review of suspicious activity within a Dispatcher Company.
- Off-Stripe payment method labels (since May 2026): when a Dispatcher Sub-User marks an invoice paid via cash, check, Venmo, Zelle, ACH, or any custom label the Dispatcher Company has configured, we record the chosen label string and an optional short note (e.g., "Check #1234") on the invoice row. No funds move through Stripe or ServiceHQ on this path; we record only the dispatcher-asserted method and note for the Dispatcher Company's own reconciliation. The custom-method label list is configured per-tenant in Settings → Templates and is not visible to End Customers or other tenants.
- Dispatcher UI preferences (browser
localStorage only — never transmitted): map base-layer choice (street vs. satellite), sidebar collapse state, drag-default for recurring-job edits, debug-overlay enable flag, and similar tiny presentation flags. These live on the device and are not synced to our servers or shared with third parties.
- In-app notification center (since June 2026): the Service stores in-app alert rows (job completed, task assigned, customer reply, payment received, and similar lifecycle events) targeted at a specific Dispatcher staff member or Partner inside the same Dispatcher Company. Each row holds a short title/body, a link to the related record, and read/unread state. These are derived from events the Dispatcher Company already generates — no new personal data is collected and nothing is shared with third parties; they mirror the push/SMS the recipient would otherwise receive into an in-app inbox. Cleared with the recipient's account.
- Follow-up campaign enrollment records (since July 2026, when a Dispatcher Company turns a campaign on): when a Dispatcher Company enables an automated follow-up sequence (lapsed-customer win-back, new-customer welcome, missed-appointment re-engage), we store which of that company's customers are enrolled, which step of the sequence they are on, when the next message is due, and why a sequence ended (customer booked again, opted out, sequence finished). Sequences stop automatically when the customer books again or opts out, and messages are only sent to customers of the enrolling Dispatcher Company. Enrollment rows are retained with the customer record and deleted with it.
3.3 Information from third parties
- Stripe: payment status, dispute notifications, payout events.
- Twilio: inbound SMS responses (e.g. STOP, HELP), delivery status callbacks, and inbound voice calls / call audio (when the Voice Add-On or AI Receptionist is enabled).
- Deepgram: speech-to-text transcripts of recorded calls and of AI Receptionist conversations (when the Voice Add-On / AI Receptionist is enabled) — see Section 5.
- Anthropic (when AI Receptionist is enabled): processed responses to extract caller-supplied service-request details. Anthropic does not use API inputs to train its models per their commercial terms.
3.4 Mobile app data (ServiceHQ iOS)
The ServiceHQ iOS app, built on Capacitor, is a thin wrapper around the authenticated web portal. The app collects:
- Push-notification tokens registered with Apple Push Notification service (and, for cross-platform parity, Firebase Cloud Messaging) so we can deliver job-offer, status-change, and payment-received alerts.
- Standard crash-and-diagnostic data the operating system reports to us via Sentry.
- For Solo Operators, the app auto-redirects to
/solo after login, which surfaces the client-side analytics described in §3.5.
- Card capture inside the app uses Stripe.js inside the in-app webview; raw card data does not transit the native app shell or ServiceHQ servers.
The app does not collect device contacts, photos (other than what you intentionally attach to a Job), microphone, or background location. Background location is never collected; foreground location is only collected when the rules in §7C apply.
3.5 Reports tab (Solo)
The Solo home renders revenue, job count, average-ticket, conversion, and top-customer analytics entirely on-device, computed from your own Job records that the app already loaded. No external analytics service receives this data.
3.6 Employee time tracking & payroll data (when time clock is enabled)
When a Dispatcher Company turns on the in-app time clock, we record per-employee clock-in / clock-out timestamps, the elapsed minutes of each shift, and (when the device's location permission is granted) the lat/lng coordinates at clock-in and clock-out for geofence verification. Dispatcher Companies may also store an hourly pay rate per employee, which is multiplied by clocked hours to compute "labor cost" and "gross margin" rollups inside the Reports tab. Hourly rates and computed pay totals are visible only to authenticated Admin/Manager users of the same Dispatcher Company — they are not shared with the employee unless the Dispatcher Company chooses to surface them in the employee's own report views. We do not transmit payroll data to any external payroll processor; export to your accounting / payroll system, if any, is performed by the Dispatcher Company themselves.
4. How We Use Information
- Provide, maintain, and improve the dispatch platform.
- Route jobs to partners, send SMS/email notifications, generate invoices, process payments, and disburse payouts.
- Send transactional service messages (job offers, payment links, password resets, billing alerts).
- Send platform-related operational emails (trial expiring, payment failed, watchdog alerts).
- Authenticate users, prevent fraud, enforce our Terms.
- Comply with tax, accounting, and other legal obligations.
- Aggregate, anonymized analytics about platform usage. Aggregated data does not identify any individual.
We do not sell personal information. We do not use your data to train third-party AI models. We do not run advertising on the platform.
5. Sub-Processors / Service Providers
We share data with the limited set of vendors required to deliver service. Each is contractually bound to use data only for the services they provide to us:
- Stripe, Inc. — PCI DSS Level 1 certified payment processor. Handles card capture, charges, refunds, Connect payouts, the customer billing portal, and stores payment-method details. Card capture happens through Stripe.js / Stripe Elements, which isolates card data inside Stripe's iframe so raw card numbers never reach ServiceHQ servers — including when a Partner enters a customer's card on their phone via the in-portal "Take Card Payment" flow. Stripe Privacy Policy.
- Twilio, Inc. — A2P 10DLC-registered SMS delivery and inbound message routing; voice call bridging, masked-number routing, and call recording (when the Voice Add-On is enabled). Phone numbers, message bodies, call audio, and delivery status are processed by Twilio. Twilio Privacy Notice.
- Deepgram, Inc. — speech-to-text transcription (when the Voice Add-On or AI Receptionist is enabled): audio of recorded platform calls is sent to Deepgram to produce the text transcript stored alongside the call log, and the AI Receptionist's live speech recognition runs through Deepgram. Deepgram processes call audio as our processor and does not retain it for model training under our service configuration. Deepgram Privacy Policy.
- Anthropic, PBC — AI inference for the AI Receptionist (when enabled by ServiceHQ for the Dispatcher Company) and for the optional AI import column-matcher (only when a Dispatcher staff member clicks the "AI match columns" button on an unrecognized import file: the file's column headers plus up to 8 sample rows, truncated, are sent to propose a column mapping; the mapping is reviewed and applied by the human, and the AI never writes data directly), and for optional AI text-message assistance (see Section 7C: when a Dispatcher Company enables AI auto-replies or AI reply drafts, the customer's recent message thread, truncated, plus stored account facts are sent to generate a short reply). Caller speech transcripts and the company's configured prompt context are sent to Anthropic's Messages API to extract structured fields. Anthropic does not retain inputs for training. Anthropic Privacy Policy.
- Resend — transactional email delivery (job notifications, receipts, password resets, billing alerts). Resend Privacy Policy.
- Google LLC — Google Places API for address-autocomplete on the public lead-intake form (when configured). Address fragments typed into the form are sent to Google for suggestion lookup. No persistent identifiers are sent. Google Privacy Policy.
- OpenStreetMap Foundation — free map tile imagery for the dispatcher Live Map (when Live Tracking is enabled). Map tiles are fetched from OpenStreetMap's public tile servers; only generic tile-coordinate requests are sent (no user-identifying data). OpenStreetMap Privacy Policy.
- Railway — application hosting + managed PostgreSQL (US data centers). Railway Privacy Policy.
- Sentry (if enabled) — error monitoring; PII is scrubbed from error reports before transmission.
- Cloudflare — DNS and DDoS protection at the network edge. Cloudflare Privacy Policy.
- Apple Inc. (APNs) and Google LLC (Firebase Cloud Messaging) — push-notification delivery for the ServiceHQ iOS app. Device push tokens and notification payloads (job ID, status, masked customer first name) are transmitted; no card or location data is included. Apple Privacy Policy · Google Privacy Policy.
- Esri (Environmental Systems Research Institute, Inc.) — satellite / aerial map imagery used by (a) the in-app property measurement tool, and (b) the optional Satellite base layer offered on every dispatcher map surface (calendar map, dashboard live map, partner heat map, coverage map) when the dispatcher selects it via the layer switcher in the corner of the map. Only tile-fetch URLs (zoom + x + y coordinates) and the dispatcher's IP traverse Esri; no ServiceHQ account, customer, or job data is included in tile requests. Esri Privacy Statement.
- OpenStreetMap Foundation — street-map tiles, the default base layer on every dispatcher map surface. Same scope as Esri above (tile-fetch URLs + IP, no account data). OpenStreetMap Privacy Policy.
We do not sell, rent, or trade your data to advertisers or marketing brokers. We do not use your data to train third-party AI models.
6. Disclosure of Information
We may disclose information when:
- Required by law (subpoena, court order, lawful government request);
- Necessary to protect the rights, property, or safety of ServiceHQ, our users, or the public;
- Investigating fraud, abuse, or violations of our Terms;
- Required as part of a business transaction (merger, acquisition, sale of assets) — successor will be bound by terms at least as protective as this policy;
- The user has given explicit consent.
7. SMS / TCPA Compliance
7.1 What we send
SMS messages sent through ServiceHQ are transactional / informational in nature. Examples include:
- Job offers sent to Partners: "New job: 2024 Honda Civic — house lockout — Jamaica NY. Reply YES to accept or NO to decline."
- Customer tracking links: "Hi Maria — your locksmith is on the way. Track here: https://lockroute.app/t/abc123. Reply STOP to opt out."
- Payment links: "Your service from ABC Locks is complete — $185.00. Pay here: https://lockroute.app/p/xyz789"
- HTML pay-link emails with a one-click "Pay now" button containing the same prepaid-checkout URL.
- Post-payment receipt and one-question survey, fired automatically when Stripe confirms the charge.
- Post-service surveys (single, optional message after job completion).
- Appointment reminders and confirmation requests ahead of a scheduled visit, on the schedule the Dispatcher Company configures (e.g. 5 days before + day-of). Confirmation messages contain a one-tap link to confirm the appointment.
- Re-engagement / follow-up messages (only when the Dispatcher Company has enabled a follow-up campaign): a short sequence of messages to that company's own current or former customers — e.g. a "we miss you" note to a lapsed recurring customer, a welcome note to a new customer, or a re-booking offer after a missed appointment. These sequences stop automatically when the customer books or opts out.
- Operational alerts to Dispatcher staff (job stuck, partner not responding, etc.).
7.2 Consent & opt-out
By providing a phone number to a Dispatcher Company that uses ServiceHQ, you consent to receive transactional SMS related to your service request. Dispatcher Companies are required by these terms to collect numbers only with valid consent. Recipients may at any time:
- Text STOP (or STOPALL / UNSUBSCRIBE / CANCEL / END / QUIT) to opt out of all further messages. Twilio honors the opt-out at the carrier level immediately, and we mirror it into the customer's record on our side so the opt-out persists even if the Dispatcher Company changes phone numbers later. Text START (or UNSTOP / YES) to re-subscribe.
- Text HELP for contact information.
- For email: every customer-facing email contains a one-click unsubscribe link in the footer. Clicking it stops all future commercial emails from us on that recipient's behalf (receipts and account emails for jobs the recipient books themselves still go through).
- Email [email protected] with a phone number or email to be globally suppressed across all senders on our platform.
Frequency: a typical recipient receives 1-3 messages per service request, plus any appointment reminders on the schedule the Dispatcher Company configures. ServiceHQ itself does not send marketing to consumers and never messages a consumer except on a Dispatcher Company's behalf. Dispatcher Companies may additionally enable limited follow-up sequences to their own current or former customers (win-back, welcome, missed-appointment re-engage — at most a handful of messages per sequence); the Dispatcher Company is responsible for having the appropriate level of consent for those messages (see Terms of Service §7 and §7M), every such message honors STOP immediately, and sequences end automatically when the customer books or opts out.
7.3 Compliance
Message & data rates may apply. We comply with the US Telephone Consumer Protection Act (TCPA), CTIA messaging guidelines, and the A2P 10DLC / Toll-Free Verification framework. Dispatcher Companies are the senders of record for compliance purposes; ServiceHQ provides the technical platform.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent will not be shared with any third parties, excluding aggregators and providers of the text-message delivery services acting on our behalf.
7A. Voice Calls & Recording (when the Voice Add-On is enabled)
The optional Voice Add-On enables masked phone calls and call recording between Dispatcher Company Partners and end Customers via Twilio. When enabled for a Dispatcher Company:
- Two-party consent disclosure: Unless the service company has disabled the disclosure in its settings (in which case that company bears sole responsibility for recording-consent compliance), recorded calls begin with an audible disclosure that the call may be recorded for quality and dispute resolution. Calls are masked so neither party sees the other's real phone number.
- What we record: The audio of inbound calls to the Dispatcher Company's masked number and outbound calls placed by Partners through the platform. Call metadata (timestamps, duration, masked numbers in use, billing minutes consumed). Recorded calls are additionally transcribed to text automatically (via Deepgram, our transcription subprocessor); the transcript is stored on the call log with the same access controls as the recording. We do not record or transcribe calls placed outside the platform.
- Who can access recordings: The Dispatcher Company that owns the masked number, the Partner assigned to the relevant job, and ServiceHQ staff investigating support tickets. Recordings are not exposed to other Dispatcher Companies.
- Retention: Call recordings are retained for the life of the underlying job record, then deleted on Dispatcher Company instruction or 90 days after the job is closed.
- Off-by-default: The Voice Add-On is disabled by default. Dispatcher Companies opt in by purchasing the add-on and provisioning a Twilio voice number through ServiceHQ Staff.
7B. AI Receptionist (when the AI Receptionist add-on is enabled)
The optional AI Receptionist add-on uses an automated voice assistant (powered by Anthropic) to answer inbound calls to a Dispatcher Company's masked number, collect intake information, and book a Job. When enabled by ServiceHQ Staff for a Dispatcher Company:
- What we collect from the caller: Speech-to-text transcripts of the caller's spoken responses (produced by Deepgram, our transcription subprocessor), the structured fields the AI extracts (name, address, phone, service type, vehicle year/make/model when applicable), and the call recording (subject to the Voice Add-On disclosure above).
- What we send to Anthropic: Each caller utterance plus the company-specific prompt context (configured by the Dispatcher Company, e.g. service area, hours, services offered, services declined, brand instructions). Anthropic does not retain or train on these inputs per their commercial terms.
- Human handoff: Callers may at any time say "speak to a human" / "transfer me" / similar, and the AI will transfer the call to the Dispatcher Company's configured handoff number. The handoff is logged.
- Retention: AI call transcripts and extracted fields are retained for up to 90 days for diagnostic and prompt-improvement purposes, then deleted.
- Off-by-default and gated: AI Receptionist is unavailable to a Dispatcher Company unless ServiceHQ Staff has explicitly enabled it for that account.
7C. AI Text-Message Assistance (when enabled by the Dispatcher Company)
Two optional AI text features are available to Dispatcher Companies. Both are off by default:
- AI auto-replies: when a Dispatcher Company turns this on (off / after-hours only / always), an automated assistant answers an inbound customer text message using only the account's stored facts (for example, an upcoming appointment date). The customer's recent message thread (truncated) and those facts are sent to Anthropic (our AI subprocessor) to generate the reply, which is sent automatically on the company's behalf. Replies are length-limited and instructed never to invent prices, dates, or commitments, and never to promise emergency response.
- AI reply drafts: the assistant proposes a draft reply inside the office inbox; a staff member reviews, edits, and sends (or discards) it. Nothing is sent to the customer automatically.
- Retention: the underlying message threads are retained as normal SMS logs (see Section 9). Anthropic does not retain or train on these inputs per their commercial terms.
7C. Live Partner GPS Tracking (when Live Tracking is enabled)
The optional Live Tracking feature lets Dispatcher Companies see Partners' real-time location on a dispatcher map while a job is active. When enabled by ServiceHQ Staff for a Dispatcher Company:
- When location is captured: Only when (a) the Partner has a Job in
en_route or on_site status, AND (b) the Partner has granted device-level location permission, AND (c) the Partner portal is open. Pings stop automatically when the Job changes status, the Partner navigates away, or the portal is closed.
- What is captured: Latitude, longitude, accuracy radius, and timestamp. We do not capture continuous breadcrumbs outside active jobs and we do not collect location for inactive Partners or Partners not currently working a Job.
- Polling cadence: Approximately every 30 seconds on Android and desktop browsers; every 5 minutes on iOS Safari (a battery-saving compromise; iOS pauses Geolocation when the page is not in the foreground).
- Who can see it: The Dispatcher Company the Partner works for can see the Partner's live position on the dispatcher map. In addition, when BOTH the Dispatcher Company's customer-visible-tracking toggle is on AND a job is in
en_route or on_site status, the End Customer for that job only can see the assigned Partner's approximate live position on their tracking page (the same page that shows job status), for the duration of the active visit only. No location history is shown to End Customers, and the tracking page stops showing location the moment the job leaves the active statuses. The Partner can see that their location is being shared via a visible "Sharing location" indicator.
- Partner control: Partners can deny location permission at any time at the operating-system or browser level, ending all GPS sharing. We will not nag or repeatedly request access.
- Retention: Partner and staff technician location pings are retained for up to 30 days, then deleted.
- Off-by-default and gated: Live Tracking is unavailable to a Dispatcher Company unless ServiceHQ Staff has explicitly enabled it for that account.
- One-time location ping (since July 2026): a dispatcher may request a single "where are you right now?" location fix from a Partner or a staff technician Sub-User. The request only reaches the recipient if their portal / app is open (it expires after 10 minutes), the recipient's device asks for / relies on the same operating-system location permission the recipient controls, exactly one fix (latitude, longitude, accuracy, timestamp) is captured per request, and it is stored and purged on the same 30-day schedule as job-tracking pings. Recipients who deny location permission at the device level cannot be pinged. Dispatcher Companies are responsible for providing their employees any workplace location-monitoring notice required in their jurisdiction.
- Partner availability heartbeat: Independent of GPS, the Partner portal sends a small "I'm online" beacon to ServiceHQ every 60 seconds while the portal tab is open. This is used by the routing matcher to skip Partners whose tab has crashed or whose phone has lost connection. Only the timestamp is stored; no location data is included in the beacon.
7D. Prepaid Booking & Customer Card Data (when prepaid billing is enabled)
Some Dispatcher Companies (when ServiceHQ Staff has explicitly enabled the prepaid model for them) charge the End Customer at booking time rather than at job completion. When prepaid is used:
- Card capture: Either the Dispatcher's agent enters the customer's card via Stripe Elements during a live call (PCI-isolated inside Stripe's iframe -- raw card numbers never reach ServiceHQ servers), OR the customer pays via a Stripe Hosted Checkout link sent to them by SMS and email. In both cases card data flows directly to Stripe.
- Funds custody: The PaymentIntent is created against the Dispatcher Company's own Stripe Connect account (
transfer_data.destination). Funds land in the Dispatcher Company's Stripe balance, never in ServiceHQ's platform balance.
- Partner payout: When the Partner marks the job complete, ServiceHQ fires a Stripe
Transfer.create from the Dispatcher Company's Connect account to the Partner's connected Stripe account for the locked partner-payout amount. We never see or hold the customer's payment.
- Refunds: If the Dispatcher Company refunds a prepaid charge (no partner accepted, customer cancelled, etc.), Stripe returns the funds to the customer's original card. Reasons are logged for audit.
- Information walls: The Customer never sees the Partner's payout amount; the Partner never sees what the Customer paid. Pre-acceptance, the Partner also doesn't see the customer's name, phone, email, or street address (only ZIP and any non-PII notes) regardless of billing model.
- What we store: The Stripe PaymentIntent ID, the dollar amounts, timestamps, and refund metadata. We do not store card numbers, CVCs, or expiry dates -- those live in Stripe's vault.
- Card on file (when the End Customer saves a card via the secure card-setup link or a dispatcher-initiated setup): the card is vaulted by Stripe; we store only the Stripe payment-method identifier and display metadata (brand, last four digits). A saved card may be charged off-session for completed jobs and recurring invoices when the End Customer has opted in; it can be replaced or removed on request at any time, and the card-setup page never sends card numbers to ServiceHQ servers.
- Hosted Checkout link expiry: Pay links expire 30 minutes after creation. Unpaid pending bookings older than 30 minutes are auto-deleted from our database.
- Quick Charge with inclusive tax: When the Dispatcher Company has a non-zero
tax_rate_pct configured, Quick Charge will compute and add tax on top of the entered subtotal; both subtotal and tax are stored on the Job, and the tax-inclusive total is what the End Customer is charged. Sales-tax remittance and reporting are the Dispatcher Company's responsibility.
- Off-platform payment recording: When you mark a Job paid via cash, check, Venmo, Zelle, or another off-Stripe method, ServiceHQ records only the amount, method, and timestamp. No funds move through Stripe or ServiceHQ on that path.
- Solo Operator topology: Solo Operators have a single Stripe Connect account that serves as both dispatcher and partner. Customer payments deposit there directly via
on_behalf_of + transfer_data.destination; no separate downstream partner Transfer fires.
8. International Transfers
Our infrastructure is hosted in the United States. If you access the service from outside the US, your data will be transferred to and stored in the US. We rely on standard contractual clauses with our sub-processors when applicable.
9. Data Retention
- Active accounts: Data retained for the life of your account.
- Closed accounts: Operational data deleted within 90 days of cancellation, except for billing records retained for 7 years for tax/accounting compliance, and audit logs retained 1 year for security.
- Customer data uploaded by Dispatcher Companies: Deleted on Dispatcher Company instruction or 90 days after their account closes.
- SMS / email delivery logs: 24 months.
- Voice call recordings: Life of the underlying job, then deleted on Dispatcher Company instruction or 90 days after the job is closed.
- AI Receptionist transcripts & extracted fields: 90 days.
- Recorded-call transcripts (Voice Add-On): same lifetime as the underlying call recording — deleted with the call log row, on request, or when the recording's retention window ends.
- Partner & staff technician GPS location pings: 30 days.
- Sensitive-action audit log: 13 months (1 year + a 30-day grace window for late forensic investigations). Append-only; we do not modify or delete individual rows on request because doing so would defeat the forensic purpose. End Customers seeking to exercise deletion rights against an audit-log entry that names them should contact the Dispatcher Company that performed the action.
10. Security
We implement industry-standard administrative, technical, and physical safeguards including TLS in transit, encryption at rest for sensitive fields, hashed passwords (bcrypt), least-privilege database access, signed-webhook verification for Stripe, audit logging, and regular security reviews. No system is perfectly secure; we cannot guarantee absolute security.
11. Your Rights
Depending on where you live, you may have the right to:
- Access the personal information we hold about you;
- Correct inaccurate information;
- Request deletion (subject to retention requirements above);
- Request a copy of your data in a portable format;
- Object to or restrict certain processing;
- Withdraw consent.
To exercise these rights, email [email protected]. We respond within 30 days. If you are an end customer of a Dispatcher Company using our platform, requests should be directed first to that Dispatcher Company; we will assist them in fulfilling your request.
11A. End-Customer Deletion Requests
If you are an End Customer and want your record (name, phone, address, job history, recordings, and pay-link tokens) deleted, contact the Dispatcher Company that served you; they can erase your record from their tenant in one click, which cascades through Stripe customer deletion and Twilio opt-out. If the Dispatcher Company is unresponsive, email [email protected] with the business name and approximate service date and we will assist within 30 days.
12. California (CCPA) Notice
California residents have additional rights under the California Consumer Privacy Act, including the right to know what personal information we collect, the right to delete, the right to correct, and the right to opt out of sale or sharing for cross-context behavioral advertising. We do not sell or share personal information for cross-context behavioral advertising. Contact [email protected] to exercise California rights. We will not discriminate against you for exercising them.
13. EU/UK (GDPR) Notice
If you are in the European Economic Area or UK, our legal bases for processing are: performance of contract (providing the service), legitimate interests (security, fraud prevention, service improvement), legal obligation (tax/accounting), and consent (where applicable, e.g. SMS opt-in). You can lodge a complaint with your local data protection authority.
14. Children
ServiceHQ is not directed to anyone under 16. We do not knowingly collect information from children. If you believe a child has provided us information, contact [email protected] and we will delete it.
15. Third-Party Links
The platform may contain links to third-party services (Stripe-hosted billing, customer support tools). Their privacy practices are governed by their own policies; we are not responsible for them.
15A. Do Not Track
Some browsers can send a "Do Not Track" (DNT) signal. Because there is no industry-standard consensus on how to interpret DNT, we do not currently respond to DNT signals. Regardless of any DNT setting, we do not track our users across third-party websites and we do not use cross-site advertising or behavioral-tracking cookies (see also §3.2 of this policy).
16. Changes
We may update this policy. The "Last updated" date will reflect the change. Material changes will be announced by email to account owners at least 14 days before taking effect. Continued use after the effective date constitutes acceptance.
17. Contact
Field Service Ventures LLC (operator of ServiceHQ)
Privacy inquiries: [email protected]
General contact: [email protected]