Last updated: May 1, 2026
1. Who we are
IronClad Pro Wash, LLC ("we", "us", or "IronClad CRM") provides a CRM and field-operations platform for small service businesses. This Privacy Policy explains what information we collect, how we use it, who we share it with, how we protect it, and the choices you have. It applies to the IronClad CRM mobile application, the ironcladcrmpro.com website, and any related services (the "Service").
2. The data we collect
Account & identity. When you sign up, our authentication provider (Clerk) collects your email address, name (if provided), authentication method (password or OAuth provider such as Google or Apple), and the unique user ID it issues. We mirror your email and Clerk user ID in our database so we can associate you with the data you create in the app.
Business profile. Information you enter about your business, including business name, address, phone, email, license number, default tax rate, and logo image.
Customers and jobs. Information you enter about your customers (name, address, phone, email, job notes), about jobs (title, description, schedule, services, line items, prices, taxes), and about quotes, invoices, payments, expenses, and mileage.
Photos and files. Photos you upload to jobs (which may include images of property, work in progress, before/after pairs, or, incidentally, people), invoice and quote PDFs you generate, and any other files you attach. Photos are stored in our object storage provider.
Team data. If you invite Crew members, we store their account email, role, status, invite code, and the work-related events they generate (clock-in/out times, location pings while on shift, photos, chat messages, job assignments, and approvals).
Location data. If you use clock-in or location-tracking features, we collect periodic GPS location pings from your device while you are clocked in to a job, plus the start and end coordinates of clock sessions. Location is collected from the device's operating system after you grant location permission and stops when you clock out.
Messages. Chat messages you send within the Service (text and any photo attachments), and the conversations you have with the in-app AI help chat ("Ask the AI"). For Ask the AI, the messages you type are sent to a third-party large-language-model provider only for the purpose of answering your question.
Payment data. If you subscribe to a paid plan, our payment processor (Stripe) collects and stores your payment method, billing address, tax ID (if applicable), and transaction history. We receive limited payment metadata such as subscription status, plan tier, trial end date, and the last four digits of the card; we do not receive or store full card numbers.
Device & usage data. When you use the Service we automatically collect technical information such as device type and operating system, app version, IP address, time zone, request URLs and timestamps, error logs, and basic interaction events. This is used for debugging, security, and product improvement.
Cookies and similar technologies. The web version of the Service uses cookies and local storage for authentication, session continuity, and remembering your preferences. We do not currently use third-party advertising or analytics cookies.
3. How we use the data
We use the categories of data above to:
(a) provide, operate, and maintain the Service for you and your team;
(b) authenticate you and prevent unauthorized access;
(c) bill you for paid plans and process refunds, credits, and tax;
(d) generate quotes, invoices, receipts, mileage logs, and tax summaries on your behalf;
(e) sync data across the devices you and your Crew use;
(f) respond to support requests and send service-related notifications;
(g) detect, investigate, and prevent abuse, fraud, or violations of our Terms;
(h) comply with legal obligations including tax, recordkeeping, and law-enforcement requests;
(i) improve the Service through aggregate usage analysis and bug investigation.
We do not sell your personal information. We do not use your customer data, job data, photos, or messages to train any third-party AI model. We do not show you third-party advertising in the Service.
4. Legal bases (for users in the EU/UK)
If you are in the European Economic Area or United Kingdom, we process personal data on the following legal bases: (a) performance of a contract with you (operating the Service you signed up for); (b) our legitimate interests in providing, securing, and improving the Service; (c) compliance with our legal obligations; and (d) your consent where required (for example, certain optional features). You may withdraw consent at any time without affecting prior processing.
5. How we share data
Within your organization. Data you create as a Boss is visible to you and, depending on the feature, to Crew members you invite. Data Crew creates (clock-ins, location pings, photos, chat messages) is visible to the Boss who invited them. We expose this clearly in the app.
Service providers ("processors"). We share data with third parties that help us operate the Service, under written agreements that limit them to processing data on our behalf:
• Clerk — authentication and account management.
• Stripe — payment processing and subscription billing.
• Replit — application hosting, database hosting, and object storage.
• Resend — transactional email delivery (invites, receipts, password resets).
• OpenAI / Anthropic / similar — large-language-model providers used to power the Ask the AI in-app help feature; only the messages you type into that screen are sent.
Legal and safety. We may disclose information when we believe in good faith it is necessary to comply with a law, regulation, subpoena, court order, or government request; to enforce our Terms; to protect the security or integrity of the Service; or to protect the rights, property, or safety of us, our users, or the public.
Business transfers. If we are involved in a merger, acquisition, financing, or sale of assets, your information may be transferred as part of that transaction. We will notify you and provide choices required by law.
With your direction. We may share data when you explicitly direct us to (for example, when you generate an invoice PDF and choose to share it via email or SMS).
6. International data transfers
We are based in the United States and our service providers may store and process data in the United States and other countries. If you access the Service from outside the U.S., you understand your data will be transferred to and processed in the U.S. and other countries that may have different data-protection laws than your country.
7. Data retention
We retain your data for as long as your account is active and as needed to provide the Service. After you close your account, we retain a residual copy for a limited period to comply with legal, tax, and accounting obligations, to resolve disputes, to enforce our agreements, and in encrypted backups until those backups are rotated. After that, your personal data is deleted or anonymized.
Specific examples: account records and invoices are typically retained for at least seven years for tax compliance; photos and chat messages are deleted within 90 days of account deletion unless legally required to be kept longer; Clerk-managed authentication records follow Clerk's retention policy.
8. Your privacy rights
Depending on where you live, you may have the right to:
(a) access the personal data we hold about you;
(b) correct or update inaccurate or incomplete data;
(c) request deletion of your data, subject to legal exceptions;
(d) object to or restrict certain processing;
(e) request a portable copy of your data;
(f) opt out of "sales" or "sharing" of personal information for cross-context behavioral advertising — we do not engage in either;
(g) appeal a denial of any of the above.
To exercise these rights, email ironcladcrmsupport@gmail.com from the email on your account. We will respond within the timeframes required by applicable law (generally 45 days under U.S. state privacy laws and 30 days under UK/EU GDPR). We will not discriminate against you for exercising your rights.
If your data was uploaded by a Boss who invited you (for example, you are a customer whose information your contractor entered into the Service), please contact that Boss directly first; we are typically a processor for that data and will route requests to them.
9. Specific rights for U.S. state residents
California (CCPA/CPRA). California residents have the rights described in Section 8 above. Categories of personal information we have collected in the past 12 months include identifiers, commercial information, internet/network activity, geolocation data, professional or employment-related information, and inferences. We do not sell or share personal information. We do not knowingly collect personal information from minors under 16.
Other states with similar laws (including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Tennessee, and others) provide comparable rights, which we honor on the same terms.
10. Employee monitoring (important for Bosses)
If you invite Crew members and use clock-in or location-tracking features, several states require you to give written notice to your employees before electronic monitoring begins. As of this writing, this includes Connecticut (Conn. Gen. Stat. § 31-48d), New York Civil Rights Law § 52-c, and Delaware Code Title 19 § 705. Other states may have similar or developing rules.
IronClad CRM surfaces clock-in and location features clearly in the Crew interface, but you, the Boss, are responsible for providing any required written notice and obtaining any required acknowledgment. We recommend giving each Crew member a short written disclosure before they accept their invite code.
11. Children's privacy
The Service is intended for business use by adults (18+). We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, contact ironcladcrmsupport@gmail.com and we will delete it.
12. Security
We use industry-standard safeguards to protect your information, including encryption in transit (TLS), authentication via Clerk, hashed and rotated session tokens, scoped database access, and infrastructure hosted with reputable providers. Payment data is handled by Stripe under PCI-DSS Level 1.
No system is perfectly secure. If we ever experience a breach affecting your data, we will notify you and the appropriate regulators as required by law.
13. Third-party links
The Service may link to or integrate with third-party websites and services. Their privacy practices are governed by their own policies, not ours. We encourage you to review them.
14. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top, and for material changes we will provide notice through the Service or by email. Your continued use of the Service after the effective date constitutes your acceptance of the changes.
15. Contact
Questions or requests about this Privacy Policy can be sent to ironcladcrmsupport@gmail.com. General support questions can be sent to ironcladcrmsupport@gmail.com.