Legal
Privacy Policy
- Effective
- Last updated
SmartOrderCapture is built so that the sensitive part — what is on your screen — never leaves your phone. This policy explains what we do hold, why, for how long, and what you can do about it.
If you only read one section, read Accessibility Service data: it covers the permission that makes automation possible and the two ways data can deliberately leave your device.
1.Scope and who we are
This Privacy Policy explains how SmartOrderCapture, the business operating the smartordercapture.com website and the SmartOrderCapture Android application (“SmartOrderCapture”, “we”, “us”) collects, uses, shares and protects personal information when you visit smartordercapture.com, create an account, install and use the SmartOrderCapture Android application, or contact us.
For personal information about our own users, we act as the controller (or, under US state law, the business). Where an organisation buys the Service and you use it as a member of that organisation, we process the workspace’s content on its instructions and act as its processor (or service provider); that organisation’s own privacy notice governs its use of your information, and a data processing addendum is available at privacy@smartordercapture.com.
This policy does not cover the third-party applications your workflows interact with, the endpoints your HTTP actions call, or storage you configure yourself. Those are governed by their own privacy notices.
2.The short version
- What your phone sees stays on your phone. The Android Accessibility Service reads screen content so a workflow can find the button to tap. That content is processed on the device and is not sent to us.
- We keep the minimum needed to run an account. Email, name if you give one, plan and billing status, devices you paired, and the workflows you wrote.
- We do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not use it to build advertising profiles.
- Analytics are cookieless. We use a self-hosted analytics tool that sets no cookies and builds no cross-site profile. See the Cookie Policy.
- Run history is short-lived and yours to control. The default retention is 30 days, adjustable in Settings, and you can delete runs at any time.
The rest of this document is the precise version. Nothing in the summary overrides it.
3.Information we collect
Information you give us
- Account: email address, password (stored only as a salted hash), display name and avatar image if you set one, email-verification status, and — if you enable two-factor authentication — a TOTP secret and enrolment timestamps.
- Organisation: organisation name, member roles and invitations, and the email addresses you invite.
- Billing: plan, subscription status, renewal date, and identifiers issued by our payment processor. Card numbers go directly to Stripe and never reach our servers.
- Content: workflow names, descriptions and definitions, including any text, coordinates, URLs, phone numbers or values you put into an action; templates you publish; ratings you leave.
- Correspondence: support messages, abuse reports (including a reporter email if you give one), waitlist sign-ups, and anything else you send us.
Information collected automatically when you use the website
- Session and security data: IP address, user-agent string, session tokens and expiry, sign-in events, and administrative actions recorded in an audit log with the actor, action, IP address and user agent.
- Analytics: page views and a small number of product events (for example, publishing a workflow), collected without cookies and without cross-site identifiers.
- Error reports: when something breaks, a report containing the error, a stack trace, the page, and browser and operating-system versions. Personally identifying request data is switched off by default and sensitive headers are stripped.
- Bot mitigation: Cloudflare Turnstile runs on sign-in, sign-up and password-reset to tell humans from automated abuse.
Information from the Android application
- Device record: a label you choose, Android version, application version, how the app was installed (Play or direct), a push-notification token, and the time the device last contacted us.
- Run history: for each run — which workflow and version, which device, status, start and end time, an error message if it failed, and a step-by-step execution trace. A trace records which steps ran and their outcome. Depending on how you built the workflow, it can include values your workflow handled, such as text you configured an action to type or a value a step matched on. Treat traces as sensitive and set retention accordingly.
- Workflow sync: which workflow versions are assigned to which device and when they synced.
We do not knowingly collect government identifiers, precise location history, biometric data, health data, or the contents of your messages. Location and NFC triggers are evaluated on the device: we receive the fact that a workflow ran, not the coordinates that triggered it.
4.Accessibility Service data — what happens on your device
The Android application requests Accessibility Service permission because that is the Android API that lets software observe the screen and perform taps, swipes and text entry on your behalf. This is the most sensitive permission the application uses, so we are explicit about it.
Two things you configure can move data off the device. Both are opt-in, per workflow:
- Screenshot actions upload an image of your screen to the object storage bucket configured for your account. If that bucket is ours, we hold the image until it is deleted under our retention rules; if it is yours, we do not receive it at all. A screenshot may capture anything visible at that moment, including messages, notifications and account details.
- Actions that send data outward — HTTP calls, logging to a spreadsheet, sending an SMS, or setting the clipboard — send exactly what you configured them to send, to the destination you chose. We are not the recipient, and the destination’s own privacy practices apply.
Run traces are the one routine path by which workflow-handled values can reach us, as described above. If you do not want that, reduce your run retention to its minimum, delete runs, or avoid putting sensitive values into workflow steps.
You can revoke Accessibility Service permission at any time in Android’s Settings. Workflows will stop running. You can also uninstall the application, which removes its local data from the device.
5.How we use information
| Purpose | Information used | Legal basis (EEA/UK) |
|---|---|---|
| Providing the Service — accounts, sync, running and recording workflows | Account, content, device and run data | Performance of a contract |
| Billing, renewals, refunds and tax | Account, billing and subscription data | Performance of a contract; legal obligation |
| Security — authentication, fraud and abuse prevention, rate limiting, audit logging | Session, IP, user agent, audit log, Turnstile signals | Legitimate interests (protecting the Service and its users) |
| Support and correspondence | Account data and what you tell us | Performance of a contract; legitimate interests |
| Diagnosing errors and improving reliability | Error reports, run status and error messages | Legitimate interests (a working product) |
| Understanding aggregate product usage | Cookieless analytics events | Legitimate interests (measuring what we build) |
| Marketplace moderation and denylist enforcement | Templates, workflow definitions, targeted package names, abuse reports | Legitimate interests; legal obligation |
| Service and security announcements | Account email | Performance of a contract |
| Product email you asked for | Account email | Consent (withdrawable at any time) |
| Complying with law and enforcing our Terms | Whatever the specific matter requires | Legal obligation; legitimate interests; legal claims |
We do not use your workflow content to train machine-learning models. We do not make decisions producing legal or similarly significant effects about you by automated means alone; account suspensions of that kind are reviewed by a person.
7.How long we keep information
| Category | Retention |
|---|---|
| Account and profile | While the account is open, then deleted or de-identified within 30 days of closure |
| Workflows, versions and templates | Until you delete them, or 30 days after account closure |
| Published marketplace templates | May remain available to users who already installed them; removed from the catalogue on request |
| Run history and execution traces | Your configured retention — 30 days by default, adjustable in Settings; deletable at any time |
| Device records | Until you unpair the device or close the account |
| Session records | Until expiry or sign-out |
| Security audit log | Up to 24 months, for investigating abuse and meeting legal obligations |
| Billing and tax records | Up to 7 years, as tax and accounting law requires |
| Support correspondence and abuse reports | Up to 24 months after the matter is closed |
| Error reports | Up to 90 days |
| Analytics events | Aggregated; no identifier that would let us tie an event back to you |
| Encrypted backups | Rolling window of up to 35 days, after which deleted data ages out |
Where we are required to keep something longer — for example, because it is subject to a legal hold — we keep only that record and only for as long as the obligation lasts.
8.How we protect information
We use TLS for data in transit, encryption at rest at the storage layer, salted password hashing, optional TOTP two-factor authentication, scoped session tokens, rate limiting, least-privilege access for staff, and an audit log of administrative actions. The full description, including how we handle incidents and how to report a vulnerability, is on the security page.
No system is perfectly secure. If a breach affects your personal information, we will notify you and the relevant regulators as required by law, and without undue delay.
9.Your privacy rights
Depending on where you live, you may have some or all of the following rights. We extend the core ones — access, correction, deletion and portability — to every user, wherever you are, because drawing lines by geography is not worth it:
- Know and access the personal information we hold about you, the categories, sources, purposes and recipients, and get a copy.
- Correct inaccurate information.
- Delete your information, subject to the exceptions the law allows (for example, records we must keep for tax or security).
- Port your data in a portable, machine-readable format.
- Opt out of sale, sharing for targeted advertising, and profiling with legal or similarly significant effects. We do not do any of these, so there is nothing to opt out of.
- Limit the use of sensitive personal information. We use it only to provide the Service and for security.
- Non-discrimination — we will not deny service, charge a different price, or give you a worse experience for exercising a right.
- Appeal a decision we make on your request. Reply to our decision and ask for a review; we will respond within 45 days, and if we deny the appeal, we will explain how to complain to your state attorney general.
How to exercise them
Most of this is self-service: Settings lets you edit your profile, adjust run retention, delete runs, export workflows, manage devices, and delete your account. For anything else, email privacy@smartordercapture.com from the address on your account, or write to the postal address at the end of this policy.
We respond within 45 days, extendable once by a further 45 days where a request is complex, and we will tell you if we need the extension. We verify requests by confirming control of the account email, and may ask for more where a request concerns sensitive data. An authorised agent may act for you with written permission and we may still verify with you directly. There is no charge unless a request is manifestly unfounded or excessive.
Florida, and other US states
We are based in the State of Florida. The Florida Digital Bill of Rights imposes its principal controller obligations only on very large businesses — those with more than $1 billion in global gross annual revenue that also meet one of several platform criteria — and we are well below that threshold. We nonetheless honour the rights listed above for Florida residents, and for residents of California, Colorado, Connecticut, Virginia, Texas, Oregon, Montana, Utah and every other state with a comprehensive privacy law, on the same terms.
Global Privacy Control
We honour the Global Privacy Control (GPC) browser signal as a valid opt-out request where state law requires it. Because we do not sell or share personal information for advertising, the signal changes nothing about how we treat you — we simply have nothing to stop doing.
If you are in the EEA, the UK or Switzerland
You also have the right to object to processing based on legitimate interests, to request restriction of processing, to withdraw consent at any time without affecting prior processing, and to lodge a complaint with your supervisory authority. We would appreciate the chance to resolve it first. We transfer personal information to the United States, relying on the European Commission’s Standard Contractual Clauses and the UK Addendum, together with technical and organisational safeguards. A copy of the relevant transfer mechanism is available on request.
10.Children
The Service is not directed to children under 13, and we do not knowingly collect personal information from them. Users aged 13 to 17 may use the Service only with a parent or guardian’s involvement and consent, as the Terms of Service require.
If you believe a child under 13 has given us personal information, email privacy@smartordercapture.com and we will delete the account and its data promptly. A parent or guardian may request access to, correction of, or deletion of a minor’s information at that address.
11.Where your information is processed
We operate in the United States, and our infrastructure and most of our sub-processors are located there. Wherever you use the Service from, your information is transferred to and processed in the United States, whose data-protection laws may differ from those where you live. The sub-processors page lists the processing location for each vendor.
12.Changes to this policy
We may update this policy. If a change materially affects how we handle personal information, we will give at least 30 days’ notice by email to your account address or by a prominent notice in the Service before it takes effect, and we will update the “Last updated” date above. Where the law requires your consent to a change, we will ask for it rather than assume it.
13.Contacting us about privacy
Email privacy@smartordercapture.com with any question, request or complaint about this policy. We read every one.
SmartOrderCaptureAttn: Legal Department[street address][city], Florida [ZIP]United States