Privacy Policy
Last updated: July 16, 2026
1. Introduction
Booxt (“we,” “our,” or “us”) operates booxt.io and provides an AI-powered office assistant for contractors and service businesses, delivered over SMS: it drafts and sends estimates and invoices, collects deposits, schedules estimate visits and appointments, coordinates crews, and — when a business connects them — posts to the business’s social pages and syncs records to its accounting software. We are committed to protecting your privacy and handling your data in an open and transparent manner.
2. Information We Collect
Business Information:
- Business name, trade, service area, and contact information
- Phone number for SMS service
- Services, pricing / rate book, and availability
- Payment information (processed securely via Stripe — we never store full card numbers)
- Estimate and invoice content the assistant drafts for you (line items, amounts, job descriptions)
- Photos you text in or upload (job photos, plan/blueprint images for material takeoffs)
- Emails sent and received through your Booxt business email address
Customer Information (collected on behalf of businesses):
- Phone numbers, names, and email addresses (when provided)
- Job and service addresses (geocoded server-side to power maps and routing for the business)
- Estimate, appointment, and job details and preferences
- SMS/MMS conversation history, including photos sent for quotes
Connected-Account Information (only when a business connects them):
- Facebook / Instagram: Page ID and name, linked Instagram business account ID, and page access tokens — stored server-side and used only to publish content the business approves (see “Facebook & Instagram Data” below)
- QuickBooks Online: OAuth tokens and the invoice/customer/payment records the business chooses to sync
- Stripe Connect: the business’s connected-account ID so customer payments go directly to the business
3. How We Use Your Information
- To run your AI assistant: answer customer texts, draft and send estimates and invoices, schedule estimate visits and appointments, and coordinate your crew
- To process deposits and payments (via Stripe, directly to your connected account)
- To send reminders, confirmations, and review requests (with recipient consent; STOP always honored)
- To publish social posts you have approved to your connected Facebook/Instagram pages
- To sync records you approve to your connected QuickBooks company
- To improve our AI conversation quality
- To comply with legal obligations
4. Data Storage and Security
We store data securely using industry-standard encryption. Customer data is partitioned by business and isolated to ensure privacy. We use Cloudflare Workers, Supabase (PostgreSQL and file storage for photos and documents), and Anthropic Claude AI with strict access controls. Connected-account tokens (Facebook/Instagram, QuickBooks) are stored server-side only and are never exposed to browsers or other businesses.
5. Data Sharing
We do not sell your data. We only share data with:
- Twilio: For SMS/MMS delivery
- Stripe: For payment processing and connected-account payouts
- Anthropic: For AI conversation processing (data not used for training)
- Meta Platforms (Facebook/Instagram): Only when a business connects its pages — to publish the posts the business approves
- Intuit (QuickBooks Online): Only when a business connects QuickBooks — to sync the records the business approves
- Resend: For sending and receiving business email (estimates, invoices, supplier orders)
- Google: For server-side geocoding of job addresses (maps and routing) — addresses only, never names or messages
6. Facebook & Instagram Data
If a business connects its Facebook Page (and linked Instagram business account) to Booxt, we store the Page ID and name, the Instagram business account ID, and the access tokens Facebook issues for that connection. We use them for exactly one thing: publishing the posts the business has approved to its own pages. We never read a page’s inbox, followers, or ad data, and we never post without approval.
You can disconnect at any time from the Booxt dashboard or by removing Booxt in your Facebook settings (Settings → Business Integrations). We honor Facebook’s deauthorization callbacks automatically — disconnecting deletes the stored tokens. For full instructions and deletion confirmation, see our Data Deletion page.
7. Your Rights
You have the right to:
- Access your data
- Request data deletion — see the Data Deletion page for how, and what gets removed
- Opt-out of SMS communications (text STOP)
- Export your data
8. SMS Opt-Out
You can opt-out of SMS messages at any time by texting STOP to the Booxt number. For help, text HELP.
9. Contact Us
For privacy questions or data requests, contact us at: [email protected]