Privacy Policy
Last updated September 14, 2026
Automatico provides lead generation and appointment booking software to home
service businesses (our "clients"). This policy explains what we collect, why,
and what we do not do with it.
Who this covers
Two groups: our business clients, who sign in to the Automatico dashboard and
app, and consumers who submit a form or book an appointment on a landing page we
host for one of those clients.
What we collect
- From consumers: name, phone number, email address, service address,
and the answers given in a booking form, along with the advertising
campaign the visit came from.
- From clients: business details, contact information, and the account
identifiers needed to connect their tools (such as calendar or advertising
accounts).
- Automatically: basic technical data such as IP address and browser
type, and advertising measurement data where a client has enabled it.
How we use it
To deliver the service the client hired us for: passing leads to that client,
scheduling appointments, sending notifications, and reporting on results. We do
not sell personal information, and we do not use it to build advertising profiles
for anyone other than the client whose customer it is.
Google user data
If a client connects their Google Calendar, we request a single permission,
calendar.events, and use it in exactly two ways:
- Writing: adding appointments booked through Automatico to their
calendar.
- Reading: checking when they are already busy, so our booking page
does not offer a time they have already committed. We read only the start
and end times needed to determine availability.
Limited Use. Automatico's use and transfer of
information received from Google APIs adheres to the
Google API Services User Data Policy,
including the Limited Use requirements. We do not use Google user data for
advertising, we do not sell it, we do not transfer it to third parties except
as needed to provide the feature the client asked for or where required by law,
and we do not allow humans to read it except with the client's explicit
permission, for security purposes, or to comply with applicable law.
We do not use Google user data to train any generalized artificial
intelligence or machine learning model. A client can disconnect their calendar at
any time in their Automatico settings, which deletes the stored authorization
token immediately and ends all access.
Sharing
We share information with the client the data belongs to, and with the service
providers that run our platform on our behalf, including hosting, email delivery,
telephony, and advertising measurement. Those providers may only use it to
provide their service to us. We may also disclose information where required by
law.
How we protect sensitive data
Google user data (calendar events and availability) and consumer contact details are treated as sensitive data. These are the specific protections in place:
- Encryption in transit. Every connection to Automatico, and every call Automatico makes to Google or to any other provider, uses HTTPS with TLS 1.2 or newer. Plain HTTP is not served.
- Encryption at rest. All stored data, including Google authorization tokens, lives in our hosting provider's managed database (Cloudflare D1), which encrypts data at rest. Application secrets and API keys are kept in the provider's encrypted secret store, never in source code.
- Least privilege with Google. We request one Google scope only,
calendar.events. We read only event start and end times to compute availability; event titles, attendees, descriptions and locations are never stored. Availability is checked on demand and is not retained after the check.
- Token handling. The Google authorization token is stored against the client's account only, is used solely by the server to perform the two functions above, is never exposed to browsers, staff screens, logs or third parties, and is revoked at Google and deleted from our systems the moment the client disconnects the calendar or closes their account.
- Access control. Every internal system sits behind single sign-on (Cloudflare Access with Google Workspace accounts, including two-factor authentication) plus role-based permissions inside the application. Access to production data is limited to the staff who need it to operate the service, and is reviewed when roles change.
- Monitoring and logging. Requests to our systems are logged with the authenticated identity. Failed calendar syncs are recorded and surfaced to administrators so problems are found and fixed quickly.
- Secure development. Changes are version-controlled, reviewed and deployed through an automated pipeline. Dependencies and hosting components are kept current.
- Retention and deletion. Consumer and appointment records are kept while the client's account is active and are deleted or anonymized within a reasonable period after it closes. Google tokens are deleted immediately on disconnect. Clients and consumers can request deletion at any time (see Your choices).
- Incident response. If we become aware of a breach affecting personal or Google user data, we will investigate, contain it, and notify affected clients and, where required, authorities without undue delay and within 72 hours of confirmation.
- Sub-processors. Data is processed only by the providers needed to run the service (hosting and database, email delivery, telephony, advertising measurement), each under their own security commitments and only for the purpose of providing their service to us.
Retention and security
We keep lead and appointment records for as long as the client's account is
active, and delete or anonymize them within a reasonable period afterwards.
Authorization tokens are stored encrypted and are removed as soon as an
integration is disconnected. Access to production systems is restricted and
authenticated.
Your choices
To request access to, correction of, or deletion of personal information, or
to ask a question about this policy, email
[email protected]. If you are a consumer
whose data reached us through one of our clients, we will work with that client
to honor the request.
Children
Our services are for businesses and are not directed to children under 13, and
we do not knowingly collect their information.
Changes
If we make a material change to this policy we will update the date above and,
where appropriate, notify clients directly.