Privacy Policy
Version 2026-08-11
Effective 11 August 2026 · Last updated 11 August 2026 · previous version
This Privacy Policy (this “Policy”) describes how Phineworks Inc. (“Phineworks”, “we”, “us”, or “our”) collects, uses, discloses, and retains personal information in connection with the Straightbill platform and its related websites and services (collectively, the “Service”). It applies to the businesses that register for or use the Service (“Shops”, “you”, or “your”) and to the individuals whose personal information is processed through it. Capitalized terms have the meanings given to them where they first appear. Questions regarding this Policy may be directed to support@straightbill.com.
1Our two roles
Phineworks processes personal information in two distinct capacities. The distinction determines the party against whom an individual exercises their privacy rights.
Two roles, and the distinction is material.
(a) As controller. With respect to a Shop’s own account information — the identifying, business, billing, and login details of the Shop and its authorized personnel (“Account Information”) — Phineworks is the controller and, under the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA/CPRA”), a “business”. You exercise your rights in respect of Account Information against us, as set out in section 7.
(b) As service provider and processor. With respect to information a Shop enters into the Service about its own customers (“Customer Data”), the Shop is the controller (or “business”) and Phineworks acts solely as the Shop’s service provider and processor. We process Customer Data only on the Shop’s documented instructions and only to provide the Service, and we do not retain, use, disclose, sell, or share it for any purpose other than performing the Service. The Shop is solely responsible for providing all notices to, and obtaining all consents from, the individuals whose Customer Data it submits, and their rights are exercised against the Shop.
The commitments that make the service-provider role binding — to process Customer Data only to provide the Service, and never to sell it, share it for cross-context behavioral advertising, or combine it with information obtained from any other source — are set out in section 8 of the Terms of Service and are incorporated into this Policy by reference.
2Personal information we collect
We collect the following categories of personal information.
Account and Business Information (as controller)
- Identifiers and credentials: your email address and a hashed password. We do not store, and do not have access to, your password in plaintext.
- Business information printed on, or used to calculate, your documents: business name, address, telephone number, license number, tax rate, labor rate, payment terms, and time zone.
- Configuration: the trade packs you have installed, and any prices you have modified.
- Records of agreement: the version of the Terms of Service you accepted, and the date of acceptance.
Customer Data (as processor, because you submit it)
- Your customers’ names, business names, email addresses, telephone numbers, and billing addresses.
- Service addresses, and any notes you associate with them, such as access instructions.
- Estimates, invoices, jobs, materials, labor hours, and payment records associated with them.
Payment Information
Subscription billing, and your customers’ card and bank payments where used, are processed by Stripe, Inc. (“Stripe”). We receive limited billing metadata — such as payment status, method, the last four digits of a card, and Stripe’s reference for the transaction. We do not collect or store full card numbers or bank-account details, which are handled entirely by Stripe on its own payment pages and never reach our servers.
Usage and Technical Data
- Whether, and when, an estimate or invoice link has been opened. This is surfaced to the sending Shop as a feature of the Service.
- Server log data, including IP address, browser and device information, and pages requested, retained on a short-term basis to operate, secure, and diagnose the Service.
We use only strictly necessary cookies and local storage, for authentication and for the functioning of the application. We serve no advertising or analytics trackers and set no tracking cookies. Accordingly, there is no cookie-consent banner, and there is no tracking to which a browser “Do Not Track” signal would apply.
AI Feature Inputs
Where the Service offers artificial-intelligence-assisted features — for example, drafting a line item from a photograph or a spoken note — the input you provide to such a feature (such as an image, an audio recording, or text) is processed to produce that feature’s output, as described in sections 3 and 4. We do not use that input to train foundation models of our own.
Mobile Numbers and Messaging Consent
If you provide a mobile number or enable text messaging, we collect that number together with your opt-in and consent records. This information is used only to send the messages you have requested, and is not sold or shared with any third party or affiliate for its own marketing.
3Purposes for which we process personal information
| Category | Purpose |
|---|---|
| Account Information | To authenticate you, provide the Service, and bill the subscription |
| Business Information | To render your estimates and invoices |
| Customer Data | To produce, send, and manage the documents you direct us to, solely on your instructions |
| Payment records | To reflect payment status on a document, and to maintain your records |
| AI feature inputs | To produce the output of the AI-assisted feature you have used |
| Records of agreement | To evidence which terms were agreed, and when |
| Usage and log data | To secure the Service, and to diagnose faults |
More generally, we process personal information to provide, maintain, secure, and improve the Service; to authenticate users; to process subscriptions; to send transactional and service communications; to provide support; and to comply with legal obligations. We do not sell personal information. We may create and use aggregated or de-identified information — which identifies neither you nor any individual — to operate and improve the Service.
4How we disclose personal information; Subprocessors
We disclose personal information only as necessary to provide the Service, to the categories of recipients set out below, each engaged under a written contract that requires it to protect the information and to use it solely to perform its function on our behalf (each, a “Subprocessor”).
| Recipient | Function | Information processed |
|---|---|---|
| Our database and authentication provider | Storing your records; authenticating users | Everything stored, encrypted at rest |
| Our hosting provider | Operating the application | Requests in transit; server logs |
| Stripe | Processing payments | Card and bank details, payment amounts |
| Our email-delivery provider | Sending your estimates and invoices | Recipient address, subject, the message and its PDF |
| Our AI provider (where an AI-assisted feature is used) | Returning that feature’s output | The input you submit to that feature |
Stripe is identified by name because you contract with it directly: your customers’ payments settle into a Stripe account held in your own name, under Stripe’s own agreement with you. The remaining Subprocessors are described by function rather than by name — the approach data-protection law contemplates, and one that avoids publishing a map of our systems to the public. A current list of our Subprocessors, identified by name, is available to you on request.
Before we engage a new Subprocessor, we will give you notice. We will update the table above and notify you by email at least 30 days in advance, so that you have an opportunity to inquire or to terminate. Where we must act more quickly — because a provider has failed, or a security matter compels it — we will act and notify you promptly afterward.
Legal and business transfers. We may disclose personal information where required to do so by law or valid legal process, to enforce the Terms of Service, or to protect the rights, property, or safety of any person. We disclose information to law enforcement only where we are legally required to, and not as a courtesy, and we will notify you where we are permitted to do so. If Phineworks is involved in a merger, acquisition, financing, or sale of assets, personal information may be transferred as part of that transaction, subject to section 9.
5International processing
The Service is operated in, and personal information is stored in, the United States. Certain requests may be served by infrastructure located closer to the requester, so information may transit other countries. If you access or use the Service from outside the United States, you understand and agree that your information is processed in the United States, whose data-protection laws may differ from those of your jurisdiction.
6Security
We maintain technical and organizational measures designed to protect personal information, including the following.
- Per-tenant isolation. Each Shop’s data is separated at the database layer through row-level security, not merely by application logic. The access rules reside in the database, so one Shop cannot reach another’s records through the application above it.
- Constrained privileged routines. A small, deliberately narrow set of database routines — such as the routine that records a payment confirmed by Stripe — runs with those rules elevated, because it must operate when no user is signed in. Each such routine verifies the caller’s authority for itself and is covered by automated cross-tenant tests, and we keep that set as small as practicable.
- Encryption and credentials. Information is encrypted in transit and at rest. Passwords are hashed and checked against known-breach lists at the time they are set.
- Continuous verification. Our tenant-isolation test suite runs against a live database in continuous integration, and a change that would allow one Shop to reach another’s data does not ship.
No method of transmission or storage is completely secure. If we confirm a security incident affecting your data or your customers’ data, we will notify you within 72 hours of confirming it — stating what we know, what we do not yet know, and what we are doing — and we will do so even where the law does not require it, keeping you informed as the matter develops.
7Data retention
We retain personal information only as long as necessary for the purposes described in this Policy, or as required by law, in accordance with the following schedule.
- While your account is open: for as long as you maintain the account. Estimates and invoices remain accessible by design, as records.
- After cancellation: for 90 days, after which the data is deleted from our live systems and falls out of our encrypted backups as they rotate, within a further 30 days at most. Deletion on request does not wait out this window. Once deleted, the data cannot be recovered.
- Server logs: for 30 days.
- Payment and tax records we are legally required to retain: for the period the law requires, and no longer.
8Your privacy rights
Subject to the limitations below, and to whatever additional rights your state or country affords you, you may exercise the following rights regardless of where you reside. California residents hold these rights under the CCPA/CPRA.
- To know and to access the personal information we hold, the purposes for which we hold it, and the categories of recipients to which it has been disclosed, and to receive a copy in a portable format.
- To correct inaccurate personal information.
- To delete your personal information. We delete rather than deactivate. Two categories cannot be deleted: records we are legally required to retain, such as payment records held for tax purposes; and information subject to a live legal dispute, which we must preserve until it concludes. We will tell you if either applies.
- To opt out of the sale or sharing of personal information. We do not sell personal information, and we do not share it for cross-context behavioral advertising, and we have not done so in the preceding 12 months, so there is nothing to opt out of.
How to exercise a right. Write to support@straightbill.com. We will not ask your reason. We will verify your identity before acting, because disclosing your information to the wrong person would be worse than a delay, and an authorized agent may act on your behalf where you authorize them in writing. We will respond within the period the applicable law requires.
Appeals. If we decline a request, you may appeal by replying to our response. A different person will review the matter and write to you with the decision and its basis.
Non-discrimination. We will not discriminate against you for exercising any privacy right — no denial of service, no different price or rate, and no reduced quality.
Customer Data. Where a request concerns information a Shop holds about its own customers, the Shop is the controller; such requests should be directed to the Shop, and we will assist the Shop in responding. If one of your customers contacts us directly, we will direct them to you.
9Business transfers
If Phineworks is acquired by or merged with another entity, or sells the Straightbill business or its assets, personal information may be transferred as part of that transaction. We will notify you before any such transfer becomes effective, and the acquiring party will remain bound by this Policy until it provides a superseding policy and a reasonable opportunity to decline it.
10Children
The Service is intended for businesses and is not directed to individuals under 18, and we do not knowingly collect personal information from any individual under 16. If you believe we have collected such information, contact us and we will delete it.
11If you received an estimate or invoice
You may be reading this because a trade business sent you a link, and that page noted that we host it. This section addresses you, the recipient, rather than the business.
- The business that dealt with you holds your information, not us. It entered your information and determines what happens to it; we store it and display it to you on its behalf, as its service provider.
- We will not contact you for our own purposes. The only messages you receive through us are the estimates and invoices that business chose to send.
- We do not sell your information, we do not advertise to you, and we set no tracking cookies on the page you were sent.
- If you pay through the link, we never receive your card details. Those are processed by Stripe, and your payment is made to the business you are paying.
- We record that the link was opened, and when, and report that to the business, so that it knows you received it.
To access, correct, or delete the information held about you, contact the business that sent it, as it is that business’s record. If you cannot reach it, write to support@straightbill.com and we will help you reach the right party. We cannot disclose or alter a Shop’s records on your behalf without its authorization.
12Changes to this Policy
We may update this Policy from time to time. Where a change is material, we will notify you before it takes effect, rather than revising the date at the top of this page without notice. Prior versions remain available at their own dated links.
13Contact
support@straightbill.com
Phineworks Inc.