DRAFT — requires owner review before publication; not legal advice.
MyLawnBiz Privacy Policy
Effective date: {EFFECTIVE_DATE} Last updated: {EFFECTIVE_DATE}
This policy explains what information {ENTITY_NAME} ("MyLawnBiz," "we," "us") collects through the MyLawnBiz platform at mylawnbiz.com and tenant subdomains (the "Service"), why we collect it, who we share it with, and the choices you have. We're a US-based company operating from Georgia.
The short version: we collect what's needed to run a CRM and website platform for lawn care businesses, we don't sell anyone's data, we don't run ad tracking, and the businesses using our platform own their data.
1. Two kinds of people, two roles
The Service involves two groups, and our role differs for each:
- Tenants — the lawn care operators who sign up for MyLawnBiz. For tenant account data, we are the controller: we decide how it's collected and used, and this policy governs it directly.
- Tenants' customers — the homeowners and clients whose information tenants put into their CRM (names, addresses, photos of their property, and so on). For that data, the tenant is the controller and we are the processor: we store and process it only to provide the Service to the tenant, on the tenant's instructions.
If you're a homeowner whose information is in a lawn care company's MyLawnBiz account: your relationship is with that company. Requests to access, correct, or delete your information should go to them first — they control the account. If you can't reach them, contact us at {SUPPORT_EMAIL} and we'll help route the request.
2. What we collect and why
From tenants (account holders)
| Data | Examples | Why |
|---|---|---|
| Account info | Name, email, password (hashed), business name, subdomain | Create and secure your account; identify your tenant site |
| Business profile | Business address, phone, logo, service offerings, pricing | Power your public website and CRM documents |
| Billing info | Subscription plan, Stripe customer ID, payment status | Charge subscriptions and apply plan limits. We never see or store card numbers — Stripe handles payment details |
| Usage data | Feature usage, AI analysis counts, log data (IP address, browser type, timestamps) | Operate the Service, enforce plan limits, debug problems, prevent abuse |
| Support communications | Emails you send us | Help you |
From tenants' customers (processed on the tenant's behalf)
| Data | Examples | Why |
|---|---|---|
| Contact records | Names, service addresses, emails, phone numbers | The tenant's CRM: leads, customers, scheduling, invoicing |
| Property photos | Photos of lawns and properties uploaded by the tenant or submitted through the tenant's site | Estimates, job records, and AI property analysis when the tenant requests it |
| Service history | Estimates, proposals, jobs, invoices, notes | The tenant's business records |
| Payment tokens | Stripe payment method tokens and transaction records | Let the tenant charge their customers via Stripe Connect. No raw card numbers touch our systems |
We don't intentionally collect data from children, and the Service isn't directed at anyone under 18.
3. AI processing
When a tenant uses an AI feature (such as property photo analysis), the relevant content — uploaded photos and related text — is sent to Anthropic, our AI provider, processed by the Claude model, and the results are returned to the Service.
- Under Anthropic's commercial terms, content sent through the API is not used to train Anthropic's models.
- AI processing happens only when a tenant triggers an AI feature; we don't run AI over stored data in the background.
4. Who we share data with (subprocessors)
We share data only with service providers who help us run the platform, and only what they need:
| Provider | What they do | What they receive |
|---|---|---|
| Stripe | Payment processing — tenant subscriptions and tenant-to-customer payments (Stripe Connect) | Billing details, payment methods, transaction data. Stripe's own privacy policy applies to data it collects as a processor/controller |
| Anthropic | AI analysis (Claude) | Photos and text submitted to AI features, at the moment a tenant uses them |
| {HOSTING_PROVIDER} | Application and database hosting | All Service data, encrypted in transit; stored on US infrastructure |
| {EMAIL_PROVIDER} | Transactional email delivery | Recipient addresses and message content (e.g., invoices, password resets, verification emails) |
We'll update this table before adding a new subprocessor that handles personal data.
Beyond subprocessors, we disclose data only: when required by law (subpoena, court order); to protect the rights, safety, or property of MyLawnBiz, tenants, or others; or as part of a business transfer (merger/acquisition/sale), in which case this policy's protections follow the data.
We do not sell personal data. We do not share personal data for cross-context behavioral advertising. There are no ad networks or third-party analytics trackers on the Service.
5. Cookies
We use cookies for one thing: keeping you logged in. Session and authentication cookies (including a CSRF protection token) are strictly necessary for the Service to work. There are no advertising, tracking, or third-party analytics cookies. Because we only use essential cookies, there's no cookie-consent banner to click through.
6. Email
We send transactional email only: account verification, password resets, billing receipts, plan-limit and service notices, and messages tenants trigger through the Service (like sending an invoice to their customer). We don't send marketing email, and we don't rent or share email addresses.
7. Security
We take reasonable technical and organizational measures to protect data: encryption in transit (HTTPS), hashed passwords, tenant data isolation (each tenant's data lives in a separate database), access controls, and payment handling delegated entirely to Stripe so card numbers never touch our systems. No system is perfectly secure; if we learn of a breach affecting your personal data, we'll notify affected tenants without undue delay, consistent with applicable law.
8. Retention
- Active accounts: we keep data as long as the account is active, since it is the tenant's business record system.
- Deleted accounts: when a tenant deletes their account, we delete the tenant's database — including their customers' data — within {RETENTION_DAYS, e.g., 30} days, except for data in routine encrypted backups (purged on the backup rotation cycle, within {BACKUP_RETENTION_DAYS, e.g., 90} days) and records we must keep longer for legal, tax, or fraud-prevention reasons (e.g., billing records).
- Individual records: tenants can delete individual leads, customers, and photos in-app at any time.
- Stripe retains transaction records under its own retention obligations.
9. Your rights and choices
Tenants
- Access and export: request a full export of your data anytime at {SUPPORT_EMAIL}; we'll deliver a machine-readable copy within a reasonable time (typically 30 days or less).
- Correction: update your account and business info in-app.
- Deletion: delete your account in-app or by emailing {SUPPORT_EMAIL}.
Everyone (US state privacy rights — CCPA/CPRA and similar)
Depending on your state, you may have the right to know what personal information we hold about you, to access it, correct it, delete it, and to opt out of its sale or sharing. Since we don't sell or share personal information for advertising, there's nothing to opt out of — but the other rights stand. To exercise them, email {SUPPORT_EMAIL} with enough information to verify your identity. We won't discriminate against you for exercising privacy rights. You may use an authorized agent where the law allows.
If your data lives inside a tenant's account, we'll typically refer the request to that tenant (the controller) and assist them in fulfilling it — that's how processor obligations work.
If you're in the EU/UK (GDPR)
The Service is US-focused and hosted in the United States. If GDPR applies to you, you have rights of access, rectification, erasure, restriction, portability, and objection, exercisable via {SUPPORT_EMAIL}. Our legal bases are performance of contract (providing the Service), legitimate interests (security, abuse prevention, service improvement), and legal obligation (tax/billing records). By using the Service you understand your data is transferred to and processed in the US.
10. Data location
Service data is stored and processed in the United States.
11. Changes to this policy
We may update this policy as the Service evolves. Material changes will be announced by email or in-app at least 30 days before taking effect, and the "Last updated" date above will change. Earlier versions are available on request.
12. Contact
Privacy questions, requests, and complaints:
{ENTITY_NAME} {ENTITY_ADDRESS} Email: {SUPPORT_EMAIL}