1. Overview
This Privacy Policy describes how Fledge Software, a DBA of BuyIt Ventures (“Fledge,” “we,” “us,” or “our”) collects, uses, shares, and protects information in connection with the Fledge Growth Engine— follow-up and reputation automation for small service businesses — whose company site is at fledgesoftware.com and its related services (collectively, the “Platform”).
Read this policy carefully. It applies to all users of the Platform, including:
- Operators— businesses and individuals who subscribe to Fledge to manage their operations, send SMS messages, collect reviews, and process payments.
- End Customers— consumers who receive SMS messages, visit booking pages, make payments, or otherwise interact with an Operator's Fledge-powered touchpoints.
Fledge offers one product, the Growth Engine, and this policy covers all of it.
How your data is organized. Everything Fledge holds about you lives in one database— a single Supabase Postgres project. Your identity (your login, credentials and business profile) and your business's operational data (customers, jobs, quotes, messages, reviews) are held in separate schemas of that one database, each row tagged with your organization and isolated from every other business by row-level security enforced in the database itself, not by application code remembering to filter.
Questions? Contact us at legal@fledgesoftware.com.
2. Definitions
- “Operator” means any business or individual who creates a Fledge account and uses the Platform to manage jobs, customers, and outreach.
- “End Customer” means a consumer whose information has been entered into the Platform by an Operator, or who has directly interacted with a Fledge-powered booking page, SMS campaign, or payment flow.
- “Operator Data” means information Operators provide about themselves and their businesses in the course of registering for and using the Platform.
- “End Customer Data”means information about End Customers that Operators upload, enter, or that Fledge collects on an Operator's behalf through booking pages, SMS flows, and similar features.
- “AI Features” means any Platform functionality involving automated content generation, message drafting, outreach sequencing, or conversation handling powered by artificial intelligence.
- “SMS Services”means review-request messaging, appointment reminders, and AI-powered outreach campaigns facilitated through the Platform via Twilio's A2P 10DLC messaging infrastructure.
- “Connected System” means a third-party field service or CRM account that an Operator chooses to link to the Platform, as described in Section 3.4.
3. Information We Collect
3.1 Operator Information
When an Operator creates a Fledge account and uses the Platform, we collect:
- Identity and contact information: First and last name, business name, business address, email address, and phone number.
- Account credentials: Email and authentication tokens (managed through Supabase Auth, including OAuth sign-in where applicable).
- Business profile data: Service type, service area, business description, pricing information, and other context provided to configure the Platform or AI features.
- Payment information: Subscription billing is processed by Stripe. Fledge does not store raw credit card numbers, card verification codes, or full payment account numbers. We receive and store a Stripe customer ID, last-four digits, card brand, and billing status.
- Communications: Messages or inquiries sent to Fledge support.
3.2 End Customer Information
Operators use Fledge to manage their customer relationships. In doing so, they enter or import End Customer data that may include:
- Customer name and phone number.
- Job or appointment history (dates, services performed, job status, amounts).
- Review request status and review link delivery records.
- Booking information submitted through Fledge-powered booking pages.
- Deposit or payment records processed through Stripe on behalf of the Operator.
- SMS consent records: Including the date, method, and specific consent language at the time an End Customer opted in to receive SMS messages, as well as opt-out requests and suppression timestamps.
3.3 Automatically Collected Information
When any user accesses the Platform, we automatically collect:
- Log data: IP address, browser type, device type, pages visited, referral URL, and timestamps.
- Usage data: Feature usage patterns, campaign performance metrics (delivery rates, reply rates, opt-out rates), and dashboard activity.
- Cookies and similar technologies: Session cookies for authentication, functional cookies to preserve preferences. We do not use third-party advertising cookies.
The authentication session cookie is scoped to the single host you sign in on, and is not shared with any other domain — including this company site, which has no sign-in at all. There is no cross-site session and no account cookie on the sites that host these policies.
3.4 Data from Connected Systems
If you connect a field service or CRM account to Fledge — currently Jobber, Housecall Pro, ServiceM8 or HubSpot— Fledge imports and keeps a copy of the records it needs to do the follow-up work you have asked for:
- Customers— name, phone number, email address, address, and the provider's own record of them.
- Jobs, quotes and leads— what the work was, when it was scheduled and completed, its value and status, and which customer it belongs to.
- The original payload exactly as the provider sent it, so that a record can be checked against its source rather than against our reading of it.
When you first connect an account, Fledge imports up to twelve monthsof history. Imported history is never used to start automated outreach — only work that happens after you connect can trigger a message, so connecting an account cannot text a year of your past customers.
Disconnecting stops processing immediately, and the imported copy is then deleted on the schedule in Section 7. Records Fledge itself created — your message history, review records and SMS consent and opt-out records — are kept, because they are the evidence of what was sent to whom and with whose permission.
4. How We Use Information
4.1 Operator Data — We Use It To:
- Provision, operate, and maintain the Operator's account and subscription.
- Process subscription payments and issue receipts through Stripe.
- Configure AI features with business-specific context (services, tone, target customer, local market).
- Send account-related communications: billing notices, product updates, feature announcements, and security alerts.
- Provide customer support.
- Improve and develop the Platform, including using aggregated and de-identified usage patterns.
- Enforce our Terms of Use and comply with applicable law.
4.2 End Customer Data — We Use It To:
- Deliver the SMS services and operations features the Operator has configured: review request messages, appointment reminders, and outreach campaigns.
- Record and enforce SMS opt-out requests (STOP commands and equivalents) on behalf of the Operator.
- Process payments and deposits submitted through Operator booking pages via Stripe.
- Maintain job history and booking records accessible to the Operator.
- Generate AI-drafted message content directed by the Operator's configuration.
We do not sell End Customer Data. We do not use End Customer Data to serve advertising. We do notcontact End Customers on our own behalf — any SMS message or booking interaction an End Customer receives is initiated by and on behalf of the Operator.
4.3 AI Features — Specific Disclosures
Fledge uses a large language model (LLM) API — currently Claude, from Anthropic — to generate SMS and email message copy, draft outreach sequences, and answer questions about your own business data. If Fledge adds or changes model providers, this section and the table in Section 6 are updated before the change takes effect. When these features are used:
- Operator-provided business context (business name, services, tone guidance, target customer profile) is sent to the applicable AI provider to generate content.
- End Customer data (such as first name, last service date, or general job type) may be included in generation requests for personalized messaging.
- We use Anthropic's API under its data processing terms. Input data sent to that API is not used to train their public models under our current agreement.
- AI-generated content is always sent under the Operator's direction. The Operator is the sender of record for messages to their customers; Fledge is the platform provider.
- Business context you enter during onboarding (services, tone, target customer, local market background) is stored in the Platform and reused to shape the content Fledge generates for you later.
5. SMS Messaging and TCPA Compliance
This section applies to all SMS communications facilitated through the Platform.
5.1 Who Is the Sender
For all outbound SMS messages to End Customers — including review requests, appointment reminders, and outreach campaigns — the Operator is the sender of record. Fledge is the technology platform that routes and delivers those messages via Twilio's A2P 10DLC infrastructure. End Customers receiving messages are interacting with the Operator's business, not directly with Fledge.
5.2 Consent Requirements
Operators are required by our Terms of Use — and by the Telephone Consumer Protection Act (TCPA) — to obtain prior express written consent from End Customers before sending marketing or promotional SMS messages. Consent must:
- Be obtained through a clear and conspicuous disclosure that informs the End Customer they will receive text messages, describes the message frequency, and identifies the sender.
- Include an explicit opt-in action (e.g., checking a checkbox, replying YES, or submitting a form with compliant consent language).
- Be retained in a form that can be produced as evidence of consent.
Fledge provides Operators with compliant consent language templates and maintains opt-in records, including the date and time of consent, the consent method, and the consent language displayed at the time of opt-in.
5.3 Opt-Out Mechanics and Suppression
Fledge's compliance engine automatically processes opt-out requests:
- Any reply containing STOP, QUIT, CANCEL, UNSUBSCRIBE, or END(case-insensitive, including common variations) immediately suppresses that phone number from all future SMS sends within the Operator's account.
- Suppression is logged with a timestamp and retained as a permanent record.
- Opt-out records are maintained for a minimum of four (4) years.
- An Operator cannot override or delete a suppressed contact to resume SMS sends. Suppression is enforced at the platform level.
5.4 Quiet Hours
Fledge enforces quiet-hour restrictions on all outgoing SMS messages. No automated message will be sent outside of 8:00 AM to 9:00 PMin the End Customer's local time zone (or the Operator's time zone where the End Customer's location cannot be determined), consistent with TCPA requirements.
5.5 Message Delivery Infrastructure
All SMS messages are routed through Twilio's platform using A2P 10DLC registered numbers and campaigns. Twilio acts as a sub-processor of End Customer phone numbers and message content for the limited purpose of message delivery. Twilio's use of data is governed by Twilio's Privacy Policy and our data processing agreements.
5.6 CTIA Guidelines
The Platform is designed to comply with CTIA Messaging Principles and Best Practices. Campaigns involving content prohibited by CTIA guidelines — including cannabis, firearms, adult content, and similar categories — are blocked at the platform level and constitute prohibited use under our Terms of Use.
6. Third-Party Service Providers
We share information with the following third-party service providers only to the extent necessary to deliver the Platform:
| Provider | Purpose | Data Shared |
|---|---|---|
| Supabase | Database infrastructure, authentication, and storage (Postgres with row-level security) | All Platform data |
| Vercel | Frontend hosting and delivery | Session data, usage logs |
| Twilio | SMS message delivery (A2P 10DLC) | End Customer phone numbers, message content, delivery metadata |
| Stripe | Subscription billing and AI Overage (Operator); job, invoice and booking-deposit payments taken by the Operator (End Customer) | Operator billing info; End Customer payment details for Operator-initiated charges |
| Resend | Email delivery — review requests, reminders, follow-ups and account email — and verification of an Operator's own sending domain | End Customer names and email addresses, message content, delivery and engagement metadata; Operator email address and sending domain |
| Google Business Profile and Search Console, where an Operator connects them — reading reviews and posting replies, retrieving profile and search-placement data | Operator business profile and location; the content of reviews and the Operator's replies, including the reviewer name Google publishes | |
| DataForSEO | Search-ranking measurement — where an Operator's business appears in local search results | Operator business name, category and the geographic points being measured. No End Customer data. |
| Jobber, Housecall Pro, ServiceM8, HubSpot | Field service and CRM integrations, where an Operator connects one — reading customers, jobs, quotes and leads so Fledge can follow up on them (Section 3.4). Fledge requests read-only access and writes nothing back to these systems. | Whatever that account already holds: End Customer names, phone numbers, email addresses, addresses and job records. The Operator controls the connection and may end it at any time. |
| Cloudflare | Public DNS lookups used to verify domains an Operator asks Fledge to send from or publish a site on | Domain names only. No personal data. |
| Anthropic (Claude) | AI content generation for message drafting, review responses and outreach copy | Operator business context; End Customer first name / job type where applicable. |
We do not sell or rent personal information to any third party for their independent marketing or advertising purposes.
We may disclose information if required by law, regulation, court order, or valid governmental request; to enforce our Terms of Use; or to protect the rights, safety, or property of Fledge, our users, or others.
If Fledge is acquired, merged, or sold, user information may be transferred to the successor entity, subject to the same privacy commitments.
7. Data Retention
| Category | Retention Period |
|---|---|
| Operator account data | Active subscription period + 90 days after cancellation |
| End Customer Data | Duration of Operator's subscription + 90 days after cancellation, unless Operator requests earlier deletion |
| Records imported from a Connected System (Section 3.4) | While the connection is active. Disconnecting stops processing immediately and the imported copy is deleted 30 days later; a deletion request from you or from the provider is actioned without that delay |
| SMS opt-out / suppression records | Minimum 4 years (TCPA compliance) |
| SMS consent records | Minimum 4 years (TCPA compliance) |
| Payment records | 7 years (tax and financial compliance) |
| Usage and log data | 12 months |
After cancellation, Operators have 90 days to export their data. After that window, Operator account data and End Customer Data associated with their account are deleted from active systems. Backups are purged on a rolling 30-day schedule.
Suppression and consent records are retained for their full mandatory period regardless of subscription status.
8. Data Security
We implement industry-standard technical and organizational measures to protect information in our systems:
- All data in transit is encrypted using TLS 1.2 or higher.
- Data at rest is encrypted in Supabase (Postgres) using AES-256.
- Row-level security policies in Supabase ensure that each Operator's data is logically isolated from other Operators' data.
- Supabase Auth manages credential security; Fledge does not store plaintext passwords.
- Stripe's payment vaulting means Fledge never handles raw card data.
- Access to production systems is restricted to authorized personnel.
No system is perfectly secure. If you believe your account has been compromised, contact us immediately at legal@fledgesoftware.com.
9. California Residents — CCPA / CPRA
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):
- Right to Know: You may request disclosure of the categories and specific pieces of personal information we have collected about you, the sources of that information, and the purposes for which it is used.
- Right to Delete: You may request deletion of your personal information, subject to certain exceptions (e.g., information we are required to retain for legal compliance).
- Right to Correct: You may request correction of inaccurate personal information we hold about you.
- Right to Opt-Out of Sale: We do not sell personal information. No opt-out is necessary.
- Right to Non-Discrimination: We will not discriminate against you for exercising any of these rights.
End Customers seeking to exercise CCPA rights with respect to data collected by an Operator using Fledge should direct requests to that Operator. Fledge will assist Operators in responding to verifiable consumer requests in accordance with applicable law.
Operators seeking to exercise CCPA rights may submit a request to legal@fledgesoftware.com. We will respond within 45 days.
10. Children's Privacy
The Platform is designed for use by business operators and is not directed to individuals under the age of 18. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected such information, contact us at legal@fledgesoftware.com and we will delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify Operators by email (to the address on file) and/or by posting a notice on the Platform dashboard at least 14 days before the changes take effect. Continued use of the Platform after the effective date constitutes acceptance of the updated policy.
12. Contact
Fledge Software
legal@fledgesoftware.com
fledgesoftware.com