Security

A plain-English summary of the security practices we follow today and the responsibilities you keep as a contractor owner.

Data minimization

Collect only what you need. The app's customer and lead forms ask for the basics required to do the job - name, contact info, service location, and the service request. Do not enter Social Security numbers, payment card numbers, bank account numbers, passwords, unrelated medical information, or unrelated sensitive personal information into any field.

Role-based access and account separation

Each contractor account is isolated using database row-level security. A contractor can only see their own leads, customers, follow-ups, estimates, and activity. Admin tools (such as the platform dashboard and demo seeder) are restricted to users that hold the admin role.

Authentication

The app uses managed authentication for email/password sign-in and supported social providers. Passwords are stored and verified by the authentication provider - TradeAnchor Desk never sees raw passwords. We recommend a strong, unique password for your account.

Your responsibilities

  • Keep your login credentials private and use a strong, unique password.
  • Do not share accounts. Each user needs their own login.
  • Sign out on shared or public devices.
  • Report suspicious account activity right away through Contact Support.
  • Do not enter sensitive information that is not needed for the service request.

Incident review and breach notification

If a security incident affects personal information in a way that requires notice, we will review the applicable law and notify affected users as legally required, including Missouri breach notification obligations (Mo. Rev. Stat. § 407.1500) where applicable, and any other state or federal notification requirements that apply.

Backups and security logs

Backups and security/audit logs may be retained for a limited period to support recovery, troubleshooting, and security investigations. These retention windows may exceed the lifetime of a deleted record.

Features not enabled during the beta

  • No real SMS messages are sent in the current beta.
  • No payment processing is connected in the current beta.
  • No subscription billing is processed in the current beta.
  • No call recording is enabled in the current beta.

If any of these features is activated later, the Privacy Policy, Terms of Service, user consent language, and compliance workflows must be updated before that feature is enabled.

Report suspicious activity

To report a security concern, unusual account activity, or a suspected vulnerability, visit Contact Support and choose the "Technical issue" topic. Please include enough detail to reproduce or investigate the issue without including sensitive personal information.

This document is beta template language and should be reviewed by a qualified attorney before public launch. Nothing in this document is legal advice.