Skip to privacy policy

Privacy policy.

How we handle your information, support your choices, and protect the work you entrust to Soffyt.

privacy@soffyt.com

Effective date: September 12, 2026
Last updated: September 23, 2026

1. Who we are and what this policy covers

Soffyt LLC, doing business as Soffyt ("Soffyt," "we," "us," or "our"), provides software for contractors to manage customer relationships, projects, quotes, contracts, scheduling, communications, payments, and field work.

This Privacy Policy explains how we handle personal information through soffyt.com, our web application and organization workspaces, customer portals, mobile applications, and related support and business communications (collectively, the "Services"). Features and integrations vary by account and availability.

Our business address is 7 Sherburne Hills Rd, Danville, CA 94526, United States. You can contact us about privacy at privacy@soffyt.com.

This policy describes our practices; it does not replace a contractor's privacy notice, your organization's policies, or an applicable data processing agreement. Using the Services does not, by itself, constitute consent to every use of personal information described here. We obtain consent separately where required.

2. Our role and your organization's role

For our own account administration, website inquiries, subscription administration, security, and business communications, Soffyt determines why and how personal information is used. Where applicable law uses these terms, we act as a controller or business for that processing.

When a contractor or other organization uses Soffyt to manage its customers, workers, email, projects, and documents, that organization generally determines the purposes of processing. Soffyt processes that information on its behalf, subject to the applicable agreement and lawful instructions. Where applicable, we act as a processor or service provider for that processing.

If your contractor or employer entered your information into Soffyt, contact that organization first about access, correction, or deletion. You may also contact us; we will assist or refer the request as appropriate to our role and applicable law.

3. Information we collect

The information processed depends on the features you or your organization use.

CategoryExamples and sourcesMain purposes
Account and organization informationNames, work email addresses, phone numbers, company details, roles, membership, and authentication records provided by you, your administrator, or an identity providerEstablish accounts, control access, administer the service, and provide support
Customer and job informationCustomer contacts, property and billing addresses, leads, project details, appointments, assignments, notes, checklists, and service records entered by an organization or through its customer interactionsProvide contractor workflows, scheduling, collaboration, and customer service
Documents and field contentQuotes, contracts, invoices, uploaded files, attachments, jobsite photographs, comments, and associated file metadataPrepare, store, share, and retrieve business records and field evidence
Connected communicationsAuthorized mailbox identity, message subjects and bodies, participants, timestamps, thread identifiers, read status, attachments, and access credentials supplied by the email providerConnect mailboxes, synchronize correspondence, send messages, and associate communications with customer records
Signature and portal activitySigner name and email, consent text, signing time, document identifiers and hashes, hashed network identifiers, browser information, and portal viewing or download eventsDeliver documents, record acceptance, support audit trails, and prevent misuse
Payments and commercial recordsInvoice balances, transaction references, payment status, connected payment-account identifiers, refunds, disputes, and payment details returned by a processorAdminister subscriptions where offered, reconcile invoices, and support payments and accounting
Precise location and work timePhone coordinates, accuracy, available speed and heading, timestamps, sharing sessions, shifts, visit timers, and time corrections linked to a user and organizationProvide authorized live dispatch, review recorded work time, and maintain attributed work records; precise location is sensitive personal information under some privacy laws
Fleet recordsVehicle details and VIN, driver assignments, entered mileage, maintenance schedules, and service history provided by authorized usersOrganize vehicles, plan maintenance, and preserve service records
Technical and security informationIP addresses or derived identifiers, browser and device information, request and error logs, session identifiers, and authentication or access eventsOperate, troubleshoot, secure, and maintain the Services
Website and support communicationsInformation you enter in contact, walkthrough, or subscription forms; support requests; and your communication preferencesRespond to inquiries, provide support, and send requested business communications

We receive information directly from you, from your organization and its authorized users, from people communicating with connected accounts or customer portals, from integrations you authorize, and through operation of the Services. Customers are responsible for having an appropriate basis to provide information about other people.

Do not enter passwords, full payment-card details, government identification numbers, health records, or other highly sensitive information into ordinary notes, email, or file fields unless the relevant feature expressly requests it and its use is appropriate. Information you choose to upload may nevertheless contain sensitive information, and is handled as part of that customer content.

4. How we use information

We use personal information to provide the features described above; authenticate users; apply organization permissions; maintain records; process authorized integrations; respond to support requests; deliver service and security notices; investigate fraud, abuse, and technical failures; and meet legal obligations or establish and defend legal claims.

We may use operational information to understand reliability and improve the Services. This does not authorize use of connected Google data beyond the specific limits in Section 5.

Where you request marketing updates or another lawful basis permits them, we may send information about Soffyt. You may unsubscribe using the message's instructions or contact us. Essential service, security, and transaction communications may continue.

We do not sell personal information, rent customer lists, or disclose personal information for cross-context behavioral advertising or targeted advertising. We do not use customer email content or files to train AI or machine-learning models.

5. Google and Microsoft connections

Connecting a mailbox is optional. Google or Microsoft presents an authorization screen describing the access requested. Soffyt receives authorization credentials from the provider; you should not provide your email-account password to Soffyt.

The current Google integration requests account identity and email information together with the Gmail gmail.modify permission. This permission permits broad mailbox access. Soffyt uses authorized access for its email features, including retrieving and synchronizing messages and attachments, sending messages you initiate, and managing supported message state. Information processed by the integration is not necessarily limited to messages mentioning Soffyt or a particular project. Microsoft mailbox access is governed by the permissions presented when you connect it.

Relevant correspondence may be linked to customer records. Workspace access depends on mailbox type, sharing choices, organization permissions, and record associations. Review these settings before connecting a mailbox containing personal or confidential correspondence.

Google Drive and Docs templates

Connecting Google Drive for document templates is optional and separate from connecting a mailbox. This integration requests openid, email, and https://www.googleapis.com/auth/drive.file. It accesses files created through Soffyt or explicitly selected for the app, rather than requesting access to your entire Drive.

We process the connected account identity and authorization credentials; selected document names, identifiers, and modification information; template-folder identifiers; and document content, embedded images, and exported previews. We use this information to create and organize template documents, preview them, and import content when you choose to publish a template to Soffyt. Choosing an existing document through the file picker creates a copy for the template workflow and preserves the original. Published content is stored in Soffyt and used to generate proposals, contracts, and change orders with the applicable customer and project information.

The connection serves one Soffyt organization. Authorized template managers can use its template features; importing existing files through the picker is restricted to the person who connected the Google account. Google separately controls access to editing source documents. Soffyt does not automatically make those documents public or share them with other Google users.

Disconnecting Google Drive removes Soffyt's stored authorization credentials and pending connection requests. It does not delete source files in Google Drive, retained template mappings, published template versions, or previously generated customer documents. To request deletion of eligible Soffyt copies, contact your organization or privacy@soffyt.com. You can separately remove files in Google Drive and revoke access through your Google Account connections.

Google data commitments

Soffyt's use and transfer of information obtained through Google APIs adheres to the Google API Services User Data Policy and the Google Workspace user data and developer policy, including their Limited Use requirements.

We use Google data only to provide or improve the visible email and document-template features you authorize. We do not use it for advertising, data brokerage, creditworthiness or lending decisions, or training general-purpose AI models. We do not permit people to read Google user data except with your affirmative agreement to view specific information, where necessary for security, to comply with applicable law, or for permitted internal operations using aggregated data that has been anonymized.

Transfers of Google data are limited to those permitted by Google's policies, such as necessary feature delivery, security, legal compliance, or a qualifying business transfer with the required explicit consent. These restrictions take precedence over broader sharing or improvement descriptions elsewhere in this policy.

Disconnecting and deleting information

You or an authorized administrator can disconnect a mailbox through Soffyt's email settings. Disconnecting removes Soffyt's stored mailbox authorization credentials and stops future synchronization using that connection. You can also revoke Google access through your Google Account connections, or use Microsoft's account controls.

Disconnecting or revoking access does not automatically erase messages and attachments already stored in Soffyt. They may remain as organization business records. To request deletion of retained copies, contact your organization or privacy@soffyt.com. We handle the request according to our role, applicable instructions, and lawful retention requirements. Deleting Soffyt copies does not necessarily delete the originals held by the email provider or recipients.

6. Payments, maps, and device permissions

Payments. Stripe provides connected-account and online payment services where enabled. Payment information entered into Stripe-hosted payment or onboarding screens is processed by Stripe under its Privacy Policy. Soffyt receives the references and transaction information needed for the relevant workflow. The current hosted checkout integration does not require Soffyt to store your full card number or security code. Your contractor remains responsible for its services, invoices, and payment instructions.

Google Maps. When you use map viewing or address search, Google may receive search text, map interactions, your IP address, and browser information. The address you select can be saved to your organization's record. Google's handling is described in its Privacy Policy; Google Maps features are also subject to the Google Maps/Google Earth Additional Terms. A property address is information about the job location and does not necessarily represent your current device location.

Mobile devices. The mobile app requests camera access when you use jobsite photography. Photographs you submit and associated metadata are stored with the relevant workspace records. You can manage camera permission in your device settings; denying it limits the related feature. App distribution and beta-testing platforms may independently process installation, diagnostic, and feedback information under their own notices.

Live location, dispatch, and time records

When an authorized technician enables automatic location sharing and grants device permission, Soffyt remembers that choice on the device for that technician and company. Sharing starts during an active shift when the technician clocks in or returns to the app while clocked in. During sharing, Soffyt collects the phone's precise latitude and longitude, accuracy, available speed and heading, and observation and receipt times. These records are associated with the technician, organization, shift, and sharing session. Authorized company dispatchers can view the latest location with the technician's identity, current work context, and assigned vehicle. The purpose is to coordinate field work. A vehicle marker follows the assigned technician's phone; it is not a separate vehicle tracker or an automatic mileage reading.

An active location session started while the app is open can continue while the app is in the background or the screen is locked, with a system location indicator or notification and subject to operating-system restrictions. This includes supported active sessions using While Using permission. Force-quitting the app can interrupt sharing; reopen the app to resume an authorized active shift. Updates depend on connectivity, device settings, and location availability and are not guaranteed to be continuous or exact. The live map uses Google Maps; location information used to display the map can be processed by Google as described above.

You can turn automatic sharing off in the app or revoke location permission in your device settings. Turning it off remains in effect for later shifts until you enable it again. Signing out or clocking out ends active sharing without erasing your saved preference. The app stops sending updates when sharing is stopped, you clock out, sign out, or switch organizations. The server accepts new points only for an active, authorized shift and sharing session. If a stop request cannot reach the server, a last received point and an open sharing-session record can remain until the server receives a stop or the shift ends; a stale point is not a current position. Denying location access does not itself prevent recording work time.

The live feed stores the latest received point for a sharing session and replaces it with newer points; it does not build a GPS route history. The latest point is removed when the server processes the end of sharing or the shift. Sharing-session start/end records, shift punches, recorded visits, and attributed time corrections are separate work records. A visit's jobsite address and duration come from the linked work and timer records, not a historical GPS trail. See Section 9 for retention and backup handling.

Your organization is responsible for explaining its workplace location and timekeeping practices, restricting access to people who need it, and providing required notices and obtaining any necessary consent or other lawful basis. A device permission does not replace those obligations. Contact your organization or privacy@soffyt.com about access, correction, or deletion of these records.

7. When information is shared

We disclose information as needed for the following purposes:

  • Your organization and intended recipients: authorized workspace users, people designated in customer portals, and recipients of communications or documents you or your organization choose to send. Access depends on permissions and sharing settings.
  • Service providers: providers supporting application hosting, databases, authentication, private file storage, email delivery, security scanning, and other necessary operations. These include Vercel for hosting, Supabase for database, authentication and storage, Resend for service email delivery, and a file-scanning provider such as Scanii when scanning is enabled. Uploaded content may be transmitted to the configured scanner to detect threats. We disclose information for the relevant service purposes, subject to applicable data-protection obligations.
  • Authorized integrations: Google, Microsoft, Stripe, and other integrations that you or your organization enable, to perform the requested functions. Some providers also act independently for their own services, subject to their privacy notices.
  • Professional advice, law, and safety: professional advisers, authorities, or other appropriate recipients when necessary to meet legal obligations, respond to valid legal process, protect rights or safety, or investigate misuse, subject to applicable restrictions.
  • Business transactions: relevant parties in a proposed or completed merger, acquisition, financing, reorganization, or asset transfer, subject to appropriate confidentiality, purpose limitations, applicable law, and the additional Google-data restrictions above.

We do not make private workspace content public by default. A person who receives a document, email, or access link may retain or redistribute it outside Soffyt; use sharing features carefully.

8. Cookies, local storage, and tracking choices

The Services use cookies and similar device storage for authentication, session security, and saved interface preferences. You can manage browser storage through browser settings, although blocking necessary storage may prevent sign-in or other features from working.

Soffyt does not currently use advertising or marketing trackers, including Google Analytics or Meta Pixel. We do not currently change essential service behavior in response to a browser's Do Not Track signal. Because we do not sell personal information or share it for targeted advertising, there is no such activity for an opt-out preference signal, such as Global Privacy Control, to stop. Necessary session storage and security logging still occur.

Embedded integrations can receive technical information when they load. Their providers' notices explain their own processing. If we introduce nonessential tracking that requires consent or an opt-out mechanism, we will provide the required notice and controls before that tracking occurs.

9. Retention and deletion

We retain personal information for as long as reasonably necessary for the purposes described in this policy, considering the service relationship, customer instructions, the sensitivity of the information, security needs, applicable law, and legal claims. An active subscription does not by itself justify keeping unnecessary information indefinitely.

InformationRetention criteria
Organization records, contracts, projects, files, and correspondenceWhile needed to provide the organization's service and maintain its business records, subject to valid deletion instructions and legal requirements
Latest live locationReplaced by newer points; removed from the live-location store when the server processes the end of sharing or the shift. An undelivered stop can leave the last received point until that server-side end occurs; residual backups follow the backup lifecycle described below
Sharing sessions, work time, and fleet historySeparately retained as organization work records while necessary for the disclosed purpose, applicable recordkeeping duties, and valid instructions; they do not constitute a GPS route history
Individual accounts and profilesWhile the account or relevant memberships are active and as necessary afterward for account administration, security, and required record attribution
Email authorization credentialsTo maintain an authorized connection; Soffyt's stored credentials are removed when that connection is disconnected
Security and technical recordsAs necessary to investigate errors and incidents, prevent misuse, and satisfy applicable security or legal requirements
Support, billing, tax, and legal recordsAs necessary to resolve the matter, maintain required business records, or meet a specific legal obligation or claim

An individual account and an organization's business records have separate lifecycles. An employee's departure does not automatically delete the organization's contracts, invoices, project history, or correspondence. Necessary authorship and audit information may remain with those records. A request concerning one organization membership does not necessarily require deleting other memberships.

To request account closure, an export, or deletion, email privacy@soffyt.com. Identify the account or organization and the information concerned. We review the request, verify identity and authority where appropriate, coordinate with the organization when it controls the information, and delete or de-identify eligible information in accordance with applicable obligations. These requests may require manual processing. Contact us before closing an organization account if you need copies of its records.

Disconnecting a mailbox stops future access through that connection but does not automatically remove previously stored messages or attachments. Request their deletion separately. Archiving is also different from permanent deletion. File purging may be deferred by a retention requirement or legal hold.

Residual copies may remain in backups until overwritten or expired under the applicable backup lifecycle. Such copies are not intended for ordinary ongoing use. Where a backup containing deleted data is restored, applicable deletion instructions must be reapplied. We may retain limited information where necessary for legal obligations, security, dispute resolution, or other lawful exceptions. These exceptions do not justify keeping an entire workspace when only limited records are needed.

We explain applicable limitations or exceptions when responding to a request. The request-response deadlines described below are distinct from the technical timing of backup expiration.

10. Security

We use measures designed to protect personal information, including access controls, organization-based permissions, encrypted network connections, protected credential storage, private file access, and security logging. Security measures must account for the type of information and the risks of processing it. No service can guarantee that all unauthorized access, loss, or misuse will be prevented.

You and your organization help protect information by controlling user access, securing devices and accounts, choosing appropriate sharing settings, and reporting suspected misuse.

11. Your choices and privacy requests

Depending on your location, the applicable law, and our role, you may have rights to access or obtain a copy of information, correct inaccurate information, request deletion, restrict or object to certain processing, withdraw consent, or opt out of certain uses. Some laws also provide rights relating to sensitive information, automated decisions, authorized agents, and appeals from a denied request.

Send requests to privacy@soffyt.com, identifying the account or organization involved and the request. We may ask for information reasonably needed to verify your identity or an agent's authority. Do not send passwords or full payment-card details. We respond within applicable legal time limits and explain a denial or limitation where required. To appeal a decision where that right applies, reply to our response or contact the same address with "Privacy appeal" in the subject.

For organization-controlled records, we may need to involve the relevant organization or act on its instructions. We will not discriminate against you for exercising rights protected by applicable law. You may also contact your competent privacy regulator or other authority.

You can separately update available profile settings, unsubscribe from marketing, manage device permissions, and disconnect integrations. Withdrawing consent does not affect processing that was lawful before withdrawal or processing supported by another applicable legal basis.

12. California and other United States residents

Soffyt LLC is based in California and offers the Services to customers in the United States. This does not mean every provider processes information only within the United States. Provider operations or support may involve processing in other countries.

California and other state privacy laws provide rights when their applicability requirements are met. We also support the privacy-request process described in Section 11 regardless of whether a particular statutory threshold is met.

Where the CCPA applies, California residents may request information about the categories and specific pieces of personal information collected, its sources, purposes, and disclosures; request correction or deletion subject to exceptions; and exercise applicable rights concerning sale, sharing for cross-context behavioral advertising, or certain uses of sensitive personal information. Authorized agents may submit requests subject to verification. We do not discriminate for exercising protected rights.

Soffyt does not sell personal information or share it for cross-context behavioral advertising. We do not use customer content to train AI models. We use sensitive information only as needed for the disclosed service, security, and legal purposes, subject to any additional limits required by law. The information and recipient categories are described in Sections 3 and 7.

Send requests to privacy@soffyt.com or write to Soffyt LLC, 7 Sherburne Hills Rd, Danville, CA 94526, United States. Where the CCPA applies, requests to know, delete, or correct are generally answered within 45 calendar days of receipt; a permitted extension requires timely notice and explanation. Request limits, verification requirements, and lawful exceptions may apply.

Other U.S. residents may have similar or additional rights under applicable state law, including an appeal from a denied request. Contact us as described in Section 11. You may also complain to your state attorney general or the relevant privacy authority.

13. Age eligibility

You must be at least 16 years old to create or use a Soffyt account. Users under 18 must have permission from a parent or legal guardian and authorization from the customer organization where applicable. An account's age eligibility does not establish authority to bind an organization, enter a contract, or sign a commercial document.

The Services are not directed to children under 16, and we do not knowingly collect account-registration information from children under 16. If you believe an underage person created an account or provided personal information directly to us, contact privacy@soffyt.com so we can investigate and take appropriate action. Organizations should avoid uploading information about children unless necessary and supported by an appropriate legal basis.

14. Changes and contact

We may update this policy to reflect changes in the Services, practices, or law. The effective and last-updated dates identify the current version. Where required, we provide additional notice or obtain consent before a material change takes effect. An update does not retroactively authorize uses that require separate consent.

For questions, requests, or complaints, contact:

Soffyt LLC, doing business as Soffyt
Email: privacy@soffyt.com
Mail: 7 Sherburne Hills Rd, Danville, CA 94526, United States
Website: https://soffyt.com