Privacy Policy

Last updated: March 2026

1. Information We Collect

When you use ServiceReach, we collect the following categories of information:

  • Account information: Name, email address, phone number, business name, and home base address when you register.
  • Booking information: Customer names, email addresses, phone numbers, and service addresses submitted through your booking page.
  • Payment information: Billing details are collected and processed directly by Stripe. We do not store your credit card numbers, bank account details, or other payment credentials on our servers. We receive only a transaction reference, subscription status, and billing email from Stripe.
  • Usage data: How you interact with the platform, including pages visited, features used, and scheduling preferences.
  • Analytics data: We use Google Analytics (GA4) to collect anonymized usage statistics, including pages visited, session duration, referral sources, browser type, device type, and approximate geographic location (country/region level). Google Analytics uses cookies and similar technologies to collect this data. See Section 9 (Cookies & Analytics) for details.
  • Google user data: If you choose to connect your Google Calendar, we collect the data described in Section 7 (Google Calendar Integration & Google User Data).

2. How We Use Your Information

We use the information we collect to:

  • Provide and maintain the ServiceReach scheduling platform.
  • Calculate location-aware slot scoring and savings badges.
  • Send appointment confirmations, reminders, and status updates via email and SMS.
  • Process payments and manage your subscription through Stripe.
  • Improve our algorithms, features, and user experience.
  • Communicate with you about your account, product updates, and service-related notices.
  • Detect and prevent fraud, abuse, and security incidents.

3. Legal Basis for Processing (EEA/UK Users)

If you are located in the European Economic Area (EEA) or the United Kingdom, we process your personal data under the following legal bases:

  • Contract performance: Processing necessary to provide the ServiceReach platform and fulfill our obligations under the Terms of Service (account data, booking data, appointment management).
  • Legitimate interest: Processing necessary for our legitimate business interests, such as improving the platform, preventing fraud, and sending service-related communications, where those interests are not overridden by your rights.
  • Consent: Where you explicitly grant permission, such as connecting your Google Calendar or opting in to marketing communications. You may withdraw consent at any time.
  • Legal obligation: Processing required to comply with applicable laws, such as tax reporting and fraud prevention.

4. Data Sharing

We do not sell your personal data. We share information only with the following categories of recipients, solely to provide and support the service:

  • Cloud infrastructure: Amazon Web Services (AWS) hosts our servers, database, and file storage in the United States.
  • Payment processing: Stripe processes subscription payments. Stripe receives your billing email and payment details directly.
  • Email delivery: Amazon Simple Email Service (SES) delivers transactional emails such as appointment confirmations and reminders.
  • SMS delivery: Amazon Simple Notification Service (SNS) delivers SMS messages such as appointment reminders and status updates. Phone numbers are shared with AWS solely for message delivery.
  • Mapping services: Google Maps receives service addresses to calculate travel distances for our scheduling algorithm.
  • Analytics: Google Analytics receives anonymized usage data (see Section 9).
  • Your customers: Business name, provider names, and appointment details are shared with customers who book through your booking page.

We do not share your data with data brokers, advertising networks, or any other third parties not listed above. We may disclose your data if required by law, court order, or government request, or to protect the rights, safety, or property of ServiceReach, our users, or the public.

5. International Data Transfers

ServiceReach is hosted on Amazon Web Services in the United States. If you are located outside the United States, your data will be transferred to and processed in the United States. For EEA/UK users, we rely on the EU-U.S. Data Privacy Framework and Standard Contractual Clauses (SCCs) as approved by the European Commission to ensure adequate data protection for international transfers. By using the service, you acknowledge and consent to the transfer of your data to the United States.

6. Data Security

We protect your data using industry-standard security measures, including:

  • Encryption in transit: All data transmitted between your browser and our servers is encrypted using TLS (HTTPS).
  • Encryption at rest: Sensitive data such as Google OAuth tokens is encrypted using AES-GCM with keys managed through AWS Secrets Manager. Database storage is encrypted at the infrastructure level via AWS RDS encryption.
  • Authentication: User accounts are secured via Amazon Cognito with OAuth 2.0 and OpenID Connect (OIDC).
  • Access controls: Role-based access controls restrict data access to authorized users (Admin, Provider, Client roles).
  • Payment security: Your payment information is processed directly by Stripe (a PCI DSS Level 1 certified provider) and is never stored on our servers.

7. Google Calendar Integration & Google User Data

ServiceReach offers an optional Google Calendar integration that allows service providers to sync their schedules. This section describes how we handle Google user data in compliance with Google's API Services User Data Policy, including the Limited Use requirements.

7.1 Google User Data We Access

When you connect your Google Calendar, we request the following OAuth scopes:

  • calendar.readonly — to read your calendar's free/busy information and list your writable calendars.
  • calendar.events — to create, update, and delete ServiceReach appointment events on your selected calendar.

The specific Google user data we access includes:

  • Calendar list: Names and IDs of your writable Google Calendars so you can select which calendar to sync with.
  • Free/busy periods: Start and end times of existing events on your selected calendar (we access only the time blocks, not event titles, descriptions, attendees, or other event details).
  • Google account email: The email address associated with your Google account, used to identify the connected account.

7.2 How We Use Google User Data

We use Google Calendar data exclusively for the following purposes:

  • Preventing double-booking: We read free/busy periods from your Google Calendar to identify when you are already occupied, so those times are excluded from available booking slots.
  • Appointment syncing: When appointments are created, updated, or cancelled in ServiceReach, we create, update, or delete corresponding events on your Google Calendar so your schedule stays current.
  • Calendar selection: We list your writable calendars so you can choose which calendar receives ServiceReach events.

We do not use Google Calendar data for any other purpose.

7.3 Google User Data Sharing and Transfer

We do not share, transfer, sell, or disclose your Google user data to any third party. Google Calendar data is used only within the ServiceReach platform to provide the scheduling features described above. The only data transmission is between ServiceReach servers and Google's API servers to perform the calendar operations you have authorized.

7.4 Google User Data Storage and Protection

  • OAuth tokens: Your Google access and refresh tokens are encrypted using AES-GCM encryption with keys managed through AWS Secrets Manager. Tokens are encrypted before storage and decrypted only when needed to make authorized API calls on your behalf.
  • Free/busy data: Cached in memory for up to 10 minutes to reduce redundant API calls. This cache contains only time ranges (start/end timestamps) and no event content. Cached data is automatically purged after the cache period expires.
  • Event IDs: We store the Google Calendar event ID for each synced appointment so we can update or delete the correct event. No other event content from Google is stored.
  • Google account email: Stored alongside your connection record to display which Google account is connected.

We do not store Google Calendar event titles, descriptions, attendee lists, attachments, or any event content beyond the free/busy time ranges and the event IDs of appointments that ServiceReach itself created.

7.5 Google User Data Retention and Deletion

When you disconnect your Google Calendar from ServiceReach:

  • Your encrypted OAuth tokens are deleted immediately from our database.
  • All cached free/busy data is purged.
  • You may choose to have ServiceReach remove all synced appointment events from your Google Calendar during disconnection.
  • Your Google access is revoked by calling Google's token revocation endpoint.
  • The stored Google Calendar event IDs are cleared from your appointment records.

You can also revoke ServiceReach's access at any time from your Google Account permissions page.

7.6 Limited Use Disclosure

ServiceReach's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We do not sell Google user data to third parties.
  • We do not use Google user data for advertising, retargeting, or serving ads.
  • We do not use Google user data to assess creditworthiness or for lending purposes.
  • We do not use Google user data for training artificial intelligence or machine learning models.
  • We do not transfer Google user data to any third party except as necessary to provide or improve user-facing features that are prominent in the requesting application's user interface, as required by law, or as part of a merger/acquisition with prior user notice.
  • Our use of Google user data is limited to the practices explicitly disclosed in this privacy policy.
  • We allow humans to read Google user data only when we have your affirmative consent (e.g., for a support request), when necessary for security purposes, to comply with applicable law, or when the data is aggregated and anonymized for internal operations.

7.7 Changes to Google User Data Practices

If we change the way we use Google user data, we will update this privacy policy and notify you via email or an in-app notice before making use of your data in any new way. You will be prompted to consent to the updated policy before the new practices take effect. If you do not consent, you may disconnect your Google Calendar integration.

8. Data Retention

We retain your data for as long as your account is active and as needed to provide the service. Specifically:

  • Account and booking data: Retained for the duration of your active account. If you close your account, we delete your data within 30 days, except where retention is required by law (e.g., tax records, legal obligations).
  • Google Calendar data: OAuth tokens are deleted immediately upon disconnection. Cached free/busy data expires automatically within 10 minutes. See Section 7.5 for full details.
  • Analytics data: Google Analytics retains anonymized usage data according to Google's own retention policies.
  • Backup retention: Encrypted database backups may retain deleted data for up to 35 days as part of our disaster recovery process, after which they are automatically purged.

9. Cookies & Analytics

We use the following cookies and tracking technologies:

  • Essential cookies: Required to maintain your login session and remember your authentication state. These cookies are strictly necessary for the platform to function and do not require consent.
  • Google Analytics (GA4): We use Google Analytics to collect anonymized usage statistics about how visitors interact with our marketing site. Google Analytics uses cookies (such as _ga and _ga_*) to distinguish unique users and track session information. This data helps us understand traffic patterns and improve the user experience. Google Analytics data is processed by Google LLC in the United States. You can opt out of Google Analytics by installing the Google Analytics Opt-out Browser Add-on.
  • AWS CloudWatch Real User Monitoring (RUM): The ServiceReach portal application uses AWS CloudWatch RUM to monitor application health and performance. CloudWatch RUM uses cookies to collect data including JavaScript errors, page load performance metrics, and HTTP request telemetry. This data helps us identify and resolve technical issues to maintain a reliable user experience. CloudWatch RUM data is processed by Amazon Web Services in the United States. You can decline CloudWatch RUM data collection via the cookie consent banner presented when you first visit the application.

We do not use third-party advertising cookies, retargeting pixels, or social media tracking scripts.

10. Children's Privacy

ServiceReach is not directed at children under the age of 16. We do not knowingly collect personal data from children under 16. If you become aware that a child under 16 has provided us with personal data, please contact us at hello@servicereach.app and we will take steps to delete that information promptly.

11. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Request correction of inaccurate or incomplete personal data.
  • Deletion: Request deletion of your personal data, subject to legal retention requirements.
  • Portability: Request your data in a structured, commonly used, machine-readable format.
  • Restriction: Request that we restrict processing of your data in certain circumstances.
  • Objection: Object to processing of your data based on legitimate interests.
  • Withdraw consent: Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, contact us at hello@servicereach.app. We will respond to your request within 30 days. If you are in the EEA or UK, you also have the right to lodge a complaint with your local data protection authority.

12. California Privacy Rights

If you are a California resident, the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) provide you with the following additional rights regarding your personal information:

  • Right to know: You have the right to request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources from which the information was collected, the business or commercial purpose for collecting the information, and the categories of third parties with whom we share the information.
  • Right to delete: You have the right to request deletion of your personal information, subject to certain exceptions permitted by law (such as data necessary to complete a transaction, detect security incidents, or comply with a legal obligation).
  • Right to opt-out of sale: ServiceReach does not sell your personal information. We do not sell, rent, or trade your personal data to third parties for monetary or other valuable consideration. Because we do not sell personal information, there is no need to opt out.
  • Right to non-discrimination: We will not discriminate against you for exercising any of your CCPA rights. We will not deny you goods or services, charge you a different price, or provide a different quality of service because you exercised your privacy rights.

To exercise your right to know or right to delete, contact us at hello@servicereach.app. We will verify your identity before processing your request and respond within 45 days as required by law. You may also designate an authorized agent to make a request on your behalf.

13. Data Processor vs. Data Controller

ServiceReach acts as a data controller for the personal data of account holders (business owners, admins, and providers) — we determine the purposes and means of processing your account data.

ServiceReach acts as a data processor for customer data that businesses enter into the platform (customer names, contact details, service addresses). The business using ServiceReach is the data controller for their customers' data and is responsible for ensuring they have a lawful basis to collect and process that data through our platform.

14. Changes to This Policy

We may update this policy from time to time. We will notify you of material changes via email or an in-app notice at least 30 days before they take effect. If the changes involve how we handle Google user data, we will prompt you to consent to the updated policy before making use of your data in any new way. Your continued use of the service after the effective date constitutes acceptance of the updated policy.

15. Contact

Questions about this policy? Email us at hello@servicereach.app.