CURRENT DOCUMENT
Privacy Policy
This Privacy Policy explains how The Detail Coach handles personal information in the hosted application, Account Launch, and related support.
- Effective date
- August 22, 2026
- Version
- privacy-owner-approved-2026-08-22-r2
1. Scope and roles
This Privacy Policy applies to The Detail Coach’s hosted business-management application, account creation, onboarding, account support, and related application pages (the “Service”). Separate public website pages may collect limited inquiry or analytics information under the notice shown there.
For account, subscription, security, and direct support information, The Detail Coach decides why and how the information is processed. For personal information a business enters about its customers, employees, contractors, vehicles, appointments, and work, the business generally decides the purpose and The Detail Coach processes the information to provide the Service. People whose information was entered by a business should normally contact that business first.
2. Information we collect
- Account information, such as name, email address, authentication identifiers, account status, password-reset activity, and legal-consent version and time. We do not receive your readable account password from the authentication provider.
- Business and onboarding information, such as business name, operating model, location details, time zone, logo, membership, roles, invitations, setup progress, and business settings.
- Business Data, such as customer and vehicle records; Services, Packages, and Add-Ons; appointments and availability; booking requests; estimates; jobs; invoices, expenses, and payment status; notes; forms; documents; photographs; and other uploaded media.
- Communications information, such as recipient, consent and opt-out status, sender identity, channel, purpose, legal version, timestamp, delivery result, provider response, and the content of messages a business directs the Service to send where a supported communication feature is enabled.
- Payment and subscription information, such as plan, billing status, provider customer or account reference, transaction reference, amount, currency, and payment state. Payment providers, not ordinary application forms, handle full card or bank credentials.
- Usage, device, diagnostic, and security information, such as browser and device details, application requests, timestamps, error and delivery results, session or authentication events, and pseudonymous rate-limit or abuse-prevention values derived from IP address or email.
3. Sources of information
We receive information from account holders, invited team members, the businesses that use the Service, people who submit public booking or proposal forms, connected providers, and the devices and browsers used to access the Service. A business may upload or enter information that it collected outside the Service.
4. How we use information
- Create, authenticate, recover, secure, and administer accounts and business workspaces.
- Provide customer, vehicle, scheduling, booking, Service, estimate, job, financial, coaching, training, settings, and media features requested by the business.
- Process invitations, legal consent, onboarding, subscriptions, connected payments, and transactional communications.
- Prevent abuse, enforce rate limits and permissions, investigate errors, maintain availability, and protect users and data.
- Provide support, respond to requests, meet legal obligations, enforce agreements, and improve the reliability and usability of the Service.
6. Service providers and integrations
Supported repository and configuration evidence shows that the Service uses Supabase for authentication, database, and private file-storage services, and Vercel for application hosting and request delivery. Stripe supports platform subscription billing and supported connected payment workflows.
Resend is the approved initial provider for supported transactional email. Stripe is the initial payment provider for platform subscriptions and supported connected payment workflows. Square remains future and disabled at launch. A provider that is configured but not enabled or connected does not receive data through that optional workflow.
No authenticated analytics provider is enabled at launch. We will update this Policy before introducing authenticated-product analytics that materially changes the information described here.
Providers process information under their own privacy notices and our applicable agreements with them. They may process information in countries other than the user’s country.
7. Payment information
Stripe or a connected merchant provider collects and processes full payment-card or bank details presented through its hosted or secured payment experience. The Detail Coach may receive provider references and transaction details needed to show subscription, invoice, payment, refund, dispute, or payout state, but ordinary Service forms are not designed to collect full card numbers or security codes.
A detailing business is responsible for its own customer charges, descriptions, refunds, disputes, and compliance with the connected provider’s requirements.
9. Retention and deletion
We retain information for as long as reasonably needed to provide the Service, maintain account and business records, preserve authorized historical records, secure the platform, resolve disputes, enforce agreements, and meet legal obligations. The approved target for account and workspace data after cancellation or restriction is 90 days where that target already applies. It is a target, not authorization for automatic deletion. Category-specific schedules for financial records, communications, consent, security logs, legal holds, backups, and other operational records remain unresolved until their operational requirements are finalized.
When an account or business asks for closure or deletion, we will evaluate the request against the requester’s authority, other users’ rights, legal and financial recordkeeping duties, security needs, active disputes, provider limitations, and reasonable backup cycles. Information may be deidentified instead of deleted where appropriate and permitted.
10. Security
We use technical and organizational safeguards designed for the nature of the Service, including authenticated access, tenant separation, role-based permissions, protected server operations, private storage controls, bounded requests, rate limiting, and secret or token hashing where supported. No safeguard can guarantee that information will never be lost, misused, or accessed without authorization.
Users should use unique passwords, protect their devices and email accounts, review team access, and contact us promptly about suspected misuse. Do not send passwords, full payment credentials, or sensitive secrets to support.
11. Choices, access, and account closure
Account holders can update certain account, business, customer, and vehicle information through available Service controls. They may contact us to request access, correction, deletion, account closure, or help exercising a privacy right that applies to them. We may need to verify identity and authority before acting.
For information controlled by a detailing business, contact that business first. We will support the business as reasonably required to respond. Some information cannot be deleted immediately when it must be retained for security, legal, financial, fraud-prevention, or record-integrity reasons.
12. Responsibilities of businesses using the Service
Each business is responsible for providing any legally required notice, obtaining any required permission, limiting collection to appropriate information, managing team access, responding to its customers’ requests, and using communications and media lawfully. Internal notes must not be exposed publicly unless the business intentionally uses a supported customer-visible field.
Transactional messages, review requests, and promotional marketing are different purposes. Review requests are permitted only when the business explicitly enables them, with a default delay of one day after completed work that the business may change. Email and SMS must be enabled separately. A business cannot override consent, opt-out, suppression, or applicable messaging law, and Canadian commercial messaging remains disabled until its required safeguards are implemented.
13. Children’s privacy
The Service is designed for businesses and adults and is not directed to children under 13. Account holders must be at least 18. Do not intentionally submit a child’s personal information unless it is necessary for a lawful business purpose and you have the authority and any permission required by law. Contact us if you believe a child’s information was submitted improperly.
14. International processing and legal rights
Public signup launches only for businesses in the United States. The application may contain international-ready foundations for the United States, Canada, United Kingdom, Australia, and New Zealand, but technical readiness does not authorize public signup outside the United States. Canada is planned next and remains disabled until Canadian privacy, tax, messaging-consent, and provincial requirements are completed. The United Kingdom, Australia, and New Zealand remain disabled until separately approved.
The Service and its providers may process information in the United States and other countries where they operate. Privacy rights and transfer requirements vary by location. We will respond to applicable legal rights, but this Policy does not claim certification under or universal compliance with a specific privacy regime.
15. Policy updates
We may update this Privacy Policy when the Service, providers, practices, or law changes. The page will show its version and effective date. We will provide additional notice or request new consent when required by law or when a change materially affects a consent already recorded.
16. Contact
The Detail Coach operates from Clinton, Iowa, United States. Privacy questions, requests, and account-closure inquiries may be sent to support@getdetailcoach.com. We do not publicly display the owner’s home address. A valid business mailing address must be established before any communication workflow that legally requires a postal address is activated.