BACK-BONE · Legal
Privacy Policy
Operated by BECON Industries LLC. Effective .
BACK-BONE is business software for service companies. A company — our “customer” — uses it to run their jobs, their schedule, and their own client records. This page says what we hold, why we hold it, and what we will not do with it.
Who the data belongs to
Nearly all the information in BACK-BONE is entered by our customer, or by the people they employ, and it is about their business and their clients. We hold it on their behalf. They decide what goes in, who may see it, and when it is removed. We do not sell it, rent it, or share it with anyone outside the providers named below.
What we hold
- Account information — the name, email address and role of each person who signs in.
- Business records — jobs, estimates, invoicing amounts, schedules, notes, photos, and the contact details of the customer's own clients.
- An activity log — a durable record of what happened and who did it. Deliberately append-only, so a business can answer questions about its own history later.
- Integration credentials — where a customer connects an outside service such as QuickBooks Online or Google Calendar, the access credential that service issues. See below.
What we do with it
We use it to operate the product for the customer who entered it: showing it back to them, sending the messages they have configured, helping them import records they already have, and keeping it available and backed up. That is the whole list.
We do not sell personal information, use it for advertising, or use our customers' business data to train machine-learning models.
Google Calendar
A customer may connect a Google account so that jobs they schedule in BACK-BONE appear on a calendar they already use. Authorisation happens through Google's own sign-in — we never see or store a Google password.
The permissions we ask for, and why
https://www.googleapis.com/auth/calendar.events- To create, update and remove the calendar events BACK-BONE itself writes for scheduled jobs. Scheduling a job creates an event; moving it moves that event; cancelling the job removes it.
https://www.googleapis.com/auth/calendar.calendarlist.readonly- To list the names of the calendars on the account, so the owner can choose which one their jobs should appear on. Read-only, and over the list of calendars — not their contents.
What this connection does not do
- It only ever writes. BACK-BONE does not read, index, store or analyse the events already on a customer's calendar. Nothing from a Google Calendar is copied into BACK-BONE, shown to anyone else, or used to build a profile.
- We ask for the narrowest permissions that do the job. We do not request the broader Google Calendar permission, which would also allow creating, sharing and deleting whole calendars.
- The credential Google issues is held in Google Secret Manager, not in our application database.
- A customer may disconnect at any time from Settings in the console, or from their Google account's own connected-apps list. Disconnecting revokes our access immediately and destroys the stored credential. Events already on the calendar are left alone — they are the customer's own records.
BACK-BONE's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.
QuickBooks Online
If a customer connects QuickBooks Online, they authorise BACK-BONE through Intuit's own sign-in — we never see or store their QuickBooks password. With that authorisation BACK-BONE may read and write accounting records such as customers, estimates and invoices, to keep their books and their job records in step.
- We request the accounting permission only.
- The credential Intuit issues is held in Google Secret Manager, not in our application database.
- We store the identifiers QuickBooks uses for a record, so the two systems can refer to the same invoice or customer.
- A customer may disconnect at any time. Disconnecting stops all further access immediately.
Where it lives, and who processes it
BACK-BONE runs on Google Cloud Platform and Firebase in the United States. Our service providers are:
- Google Cloud / Firebase — hosting, database, and secret storage.
- Google — where a customer has connected Google Calendar.
- Intuit — where a customer has connected QuickBooks Online.
- Resend — delivery of email a customer has configured their account to send.
- Anthropic — the spreadsheet import described below.
Each is used to deliver the product, and none is given data for its own purposes.
Importing a spreadsheet, and the one place we use AI
When a customer uploads a spreadsheet of their existing client list, BACK-BONE asks a language model — Anthropic's Claude — to work out which column is which: which one holds a name, which a phone number, which an address. This is the only place in the product where a model sees customer information.
- What is sent: the column headings, and at most three example values from each column. Never the file, and never whole rows. That limit exists to keep the data sent as small as the job allows.
- What comes back is a suggestion, not an action. A person reviews the proposed mapping and accepts it before a single record is created. Nothing is applied automatically.
- No connected-service data is ever sent. Nothing read from a customer's accounting system, and nothing from a calendar, goes to a model.
- The request is made by our server, never the browser, and the API key is held in Google Secret Manager.
- This data is not used to train models, ours or anyone else's.
How long we keep it
For as long as the customer's account is active. When an account is closed we delete its data within 90 days, except where we are required to keep something longer by law.
Security
Access is restricted to the business a person belongs to, enforced on the server rather than in the app. Integration credentials are held in Google Secret Manager. Data is encrypted in transit and at rest by our hosting provider. No system is perfectly secure, and we do not claim otherwise; if we discover a breach affecting a customer's data we will tell them.
Your choices
If you are an employee or a client of a business that uses BACK-BONE, that business controls your record — please contact them first, and they can correct or remove it. You may also write to us at the address below and we will help, or pass the request on.
To ask what we hold about you, to correct it, or to have it deleted, contact us at the address below.
Changes
If we change this policy we will update the date at the top, and tell account administrators about anything material.
Contact
BECON Industries LLC
admin@beconindustries.com