Smart Order Capture

Legal

Privacy Policy

Effective
Last updated

SmartOrderCapture is built so that the sensitive part — what is on your screen — never leaves your phone. This policy explains what we do hold, why, for how long, and what you can do about it.

If you only read one section, read Accessibility Service data: it covers the permission that makes automation possible and the two ways data can deliberately leave your device.

1.Scope and who we are

This Privacy Policy explains how SmartOrderCapture, the business operating the smartordercapture.com website and the SmartOrderCapture Android application (SmartOrderCapture, “we”, “us”) collects, uses, shares and protects personal information when you visit smartordercapture.com, create an account, install and use the SmartOrderCapture Android application, or contact us.

For personal information about our own users, we act as the controller (or, under US state law, the business). Where an organisation buys the Service and you use it as a member of that organisation, we process the workspace’s content on its instructions and act as its processor (or service provider); that organisation’s own privacy notice governs its use of your information, and a data processing addendum is available at privacy@smartordercapture.com.

This policy does not cover the third-party applications your workflows interact with, the endpoints your HTTP actions call, or storage you configure yourself. Those are governed by their own privacy notices.

2.The short version

  • What your phone sees stays on your phone. The Android Accessibility Service reads screen content so a workflow can find the button to tap. That content is processed on the device and is not sent to us.
  • We keep the minimum needed to run an account. Email, name if you give one, plan and billing status, devices you paired, and the workflows you wrote.
  • We do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not use it to build advertising profiles.
  • Analytics are cookieless. We use a self-hosted analytics tool that sets no cookies and builds no cross-site profile. See the Cookie Policy.
  • Run history is short-lived and yours to control. The default retention is 30 days, adjustable in Settings, and you can delete runs at any time.

The rest of this document is the precise version. Nothing in the summary overrides it.

3.Information we collect

Information you give us

  • Account: email address, password (stored only as a salted hash), display name and avatar image if you set one, email-verification status, and — if you enable two-factor authentication — a TOTP secret and enrolment timestamps.
  • Organisation: organisation name, member roles and invitations, and the email addresses you invite.
  • Billing: plan, subscription status, renewal date, and identifiers issued by our payment processor. Card numbers go directly to Stripe and never reach our servers.
  • Content: workflow names, descriptions and definitions, including any text, coordinates, URLs, phone numbers or values you put into an action; templates you publish; ratings you leave.
  • Correspondence: support messages, abuse reports (including a reporter email if you give one), waitlist sign-ups, and anything else you send us.

Information collected automatically when you use the website

  • Session and security data: IP address, user-agent string, session tokens and expiry, sign-in events, and administrative actions recorded in an audit log with the actor, action, IP address and user agent.
  • Analytics: page views and a small number of product events (for example, publishing a workflow), collected without cookies and without cross-site identifiers.
  • Error reports: when something breaks, a report containing the error, a stack trace, the page, and browser and operating-system versions. Personally identifying request data is switched off by default and sensitive headers are stripped.
  • Bot mitigation: Cloudflare Turnstile runs on sign-in, sign-up and password-reset to tell humans from automated abuse.

Information from the Android application

  • Device record: a label you choose, Android version, application version, how the app was installed (Play or direct), a push-notification token, and the time the device last contacted us.
  • Run history: for each run — which workflow and version, which device, status, start and end time, an error message if it failed, and a step-by-step execution trace. A trace records which steps ran and their outcome. Depending on how you built the workflow, it can include values your workflow handled, such as text you configured an action to type or a value a step matched on. Treat traces as sensitive and set retention accordingly.
  • Workflow sync: which workflow versions are assigned to which device and when they synced.

We do not knowingly collect government identifiers, precise location history, biometric data, health data, or the contents of your messages. Location and NFC triggers are evaluated on the device: we receive the fact that a workflow ran, not the coordinates that triggered it.

4.Accessibility Service data — what happens on your device

The Android application requests Accessibility Service permission because that is the Android API that lets software observe the screen and perform taps, swipes and text entry on your behalf. This is the most sensitive permission the application uses, so we are explicit about it.

Screen content read through the Accessibility Service — window contents, on-screen text, view identifiers and layout — is used only on your device, only to match the conditions and perform the actions in workflows you built, and is not transmitted to us, sold, or used for advertising or any secondary purpose.

Two things you configure can move data off the device. Both are opt-in, per workflow:

  • Screenshot actions upload an image of your screen to the object storage bucket configured for your account. If that bucket is ours, we hold the image until it is deleted under our retention rules; if it is yours, we do not receive it at all. A screenshot may capture anything visible at that moment, including messages, notifications and account details.
  • Actions that send data outward — HTTP calls, logging to a spreadsheet, sending an SMS, or setting the clipboard — send exactly what you configured them to send, to the destination you chose. We are not the recipient, and the destination’s own privacy practices apply.

Run traces are the one routine path by which workflow-handled values can reach us, as described above. If you do not want that, reduce your run retention to its minimum, delete runs, or avoid putting sensitive values into workflow steps.

You can revoke Accessibility Service permission at any time in Android’s Settings. Workflows will stop running. You can also uninstall the application, which removes its local data from the device.

5.How we use information

Purposes for which we use personal information and the legal basis for each
PurposeInformation usedLegal basis (EEA/UK)
Providing the Service — accounts, sync, running and recording workflowsAccount, content, device and run dataPerformance of a contract
Billing, renewals, refunds and taxAccount, billing and subscription dataPerformance of a contract; legal obligation
Security — authentication, fraud and abuse prevention, rate limiting, audit loggingSession, IP, user agent, audit log, Turnstile signalsLegitimate interests (protecting the Service and its users)
Support and correspondenceAccount data and what you tell usPerformance of a contract; legitimate interests
Diagnosing errors and improving reliabilityError reports, run status and error messagesLegitimate interests (a working product)
Understanding aggregate product usageCookieless analytics eventsLegitimate interests (measuring what we build)
Marketplace moderation and denylist enforcementTemplates, workflow definitions, targeted package names, abuse reportsLegitimate interests; legal obligation
Service and security announcementsAccount emailPerformance of a contract
Product email you asked forAccount emailConsent (withdrawable at any time)
Complying with law and enforcing our TermsWhatever the specific matter requiresLegal obligation; legitimate interests; legal claims

We do not use your workflow content to train machine-learning models. We do not make decisions producing legal or similarly significant effects about you by automated means alone; account suspensions of that kind are reviewed by a person.

6.When we share information

We share personal information only in these circumstances:

  • Sub-processors. Vendors that process data on our behalf, under contract, for the purposes we specify. Each one, what it processes and where it is located is listed on the sub-processors page.
  • Within your organisation. If you belong to an organisation workspace, its administrators can see the workspace’s workflows, members, roles and related activity.
  • At your direction. Anything a workflow you built sends to a destination you configured, and anything you publish to the marketplace — a published template and its author name are public.
  • Legal and safety. Where we reasonably believe disclosure is required by law, subpoena or court order, or is necessary to investigate suspected fraud or abuse, to protect the rights, property or safety of any person, or to establish or defend legal claims. Where we are permitted to do so, we will notify you first and will challenge requests we consider overbroad.
  • Business transfer. In a merger, acquisition, financing or sale of assets, subject to this policy continuing to apply until the acquirer gives you notice of any change.
  • Professional advisers, such as auditors and lawyers, under duties of confidentiality.
We do not sell personal information, and we do not share it for cross-context behavioural advertising or targeted advertising, as those terms are defined under US state privacy laws. We have not done so in the preceding twelve months, including for anyone we know to be under 16.

7.How long we keep information

Retention periods by category
CategoryRetention
Account and profileWhile the account is open, then deleted or de-identified within 30 days of closure
Workflows, versions and templatesUntil you delete them, or 30 days after account closure
Published marketplace templatesMay remain available to users who already installed them; removed from the catalogue on request
Run history and execution tracesYour configured retention — 30 days by default, adjustable in Settings; deletable at any time
Device recordsUntil you unpair the device or close the account
Session recordsUntil expiry or sign-out
Security audit logUp to 24 months, for investigating abuse and meeting legal obligations
Billing and tax recordsUp to 7 years, as tax and accounting law requires
Support correspondence and abuse reportsUp to 24 months after the matter is closed
Error reportsUp to 90 days
Analytics eventsAggregated; no identifier that would let us tie an event back to you
Encrypted backupsRolling window of up to 35 days, after which deleted data ages out

Where we are required to keep something longer — for example, because it is subject to a legal hold — we keep only that record and only for as long as the obligation lasts.

8.How we protect information

We use TLS for data in transit, encryption at rest at the storage layer, salted password hashing, optional TOTP two-factor authentication, scoped session tokens, rate limiting, least-privilege access for staff, and an audit log of administrative actions. The full description, including how we handle incidents and how to report a vulnerability, is on the security page.

No system is perfectly secure. If a breach affects your personal information, we will notify you and the relevant regulators as required by law, and without undue delay.

9.Your privacy rights

Depending on where you live, you may have some or all of the following rights. We extend the core ones — access, correction, deletion and portability — to every user, wherever you are, because drawing lines by geography is not worth it:

  • Know and access the personal information we hold about you, the categories, sources, purposes and recipients, and get a copy.
  • Correct inaccurate information.
  • Delete your information, subject to the exceptions the law allows (for example, records we must keep for tax or security).
  • Port your data in a portable, machine-readable format.
  • Opt out of sale, sharing for targeted advertising, and profiling with legal or similarly significant effects. We do not do any of these, so there is nothing to opt out of.
  • Limit the use of sensitive personal information. We use it only to provide the Service and for security.
  • Non-discrimination — we will not deny service, charge a different price, or give you a worse experience for exercising a right.
  • Appeal a decision we make on your request. Reply to our decision and ask for a review; we will respond within 45 days, and if we deny the appeal, we will explain how to complain to your state attorney general.

How to exercise them

Most of this is self-service: Settings lets you edit your profile, adjust run retention, delete runs, export workflows, manage devices, and delete your account. For anything else, email privacy@smartordercapture.com from the address on your account, or write to the postal address at the end of this policy.

We respond within 45 days, extendable once by a further 45 days where a request is complex, and we will tell you if we need the extension. We verify requests by confirming control of the account email, and may ask for more where a request concerns sensitive data. An authorised agent may act for you with written permission and we may still verify with you directly. There is no charge unless a request is manifestly unfounded or excessive.

Florida, and other US states

We are based in the State of Florida. The Florida Digital Bill of Rights imposes its principal controller obligations only on very large businesses — those with more than $1 billion in global gross annual revenue that also meet one of several platform criteria — and we are well below that threshold. We nonetheless honour the rights listed above for Florida residents, and for residents of California, Colorado, Connecticut, Virginia, Texas, Oregon, Montana, Utah and every other state with a comprehensive privacy law, on the same terms.

Global Privacy Control

We honour the Global Privacy Control (GPC) browser signal as a valid opt-out request where state law requires it. Because we do not sell or share personal information for advertising, the signal changes nothing about how we treat you — we simply have nothing to stop doing.

If you are in the EEA, the UK or Switzerland

You also have the right to object to processing based on legitimate interests, to request restriction of processing, to withdraw consent at any time without affecting prior processing, and to lodge a complaint with your supervisory authority. We would appreciate the chance to resolve it first. We transfer personal information to the United States, relying on the European Commission’s Standard Contractual Clauses and the UK Addendum, together with technical and organisational safeguards. A copy of the relevant transfer mechanism is available on request.

10.Children

The Service is not directed to children under 13, and we do not knowingly collect personal information from them. Users aged 13 to 17 may use the Service only with a parent or guardian’s involvement and consent, as the Terms of Service require.

If you believe a child under 13 has given us personal information, email privacy@smartordercapture.com and we will delete the account and its data promptly. A parent or guardian may request access to, correction of, or deletion of a minor’s information at that address.

11.Where your information is processed

We operate in the United States, and our infrastructure and most of our sub-processors are located there. Wherever you use the Service from, your information is transferred to and processed in the United States, whose data-protection laws may differ from those where you live. The sub-processors page lists the processing location for each vendor.

12.Changes to this policy

We may update this policy. If a change materially affects how we handle personal information, we will give at least 30 days’ notice by email to your account address or by a prominent notice in the Service before it takes effect, and we will update the “Last updated” date above. Where the law requires your consent to a change, we will ask for it rather than assume it.

13.Contacting us about privacy

Email privacy@smartordercapture.com with any question, request or complaint about this policy. We read every one.

SmartOrderCaptureAttn: Legal Department[street address][city], Florida [ZIP]United States