Privacy Policy
Last updated: September 15, 2026
1. Who we are
Chaz is a trade name of Zincan LLC, a limited liability company registered in North Carolina, United States (“Chaz”, “we”, “our”, “us”). This policy explains how we collect, use, share, and safeguard personal information across the Chaz website, the Chaz mobile apps for iOS and Android, the websites Chaz publishes on behalf of businesses, and everything connected to them (together, the “Services”).
Questions, requests, or complaints go to privacy@chazcanhelp.com. We answer within 30 days.
2. The two roles we play
This matters more than it sounds, because it decides who you should ask when you want something changed.
- For your own account, we are the controller. Your name, your email, your login, your device — we decide how that is handled, and this policy governs it.
- For the records a business keeps about its customers, that business is the controller and we are its processor. When a landscaping company stores your address, your service history, and a private note about your gate code, it is doing that on its own authority. We host it and act on that company's instructions. If you want those records changed or removed, ask the business first — and tell us if they do not respond, because we will help.
3. Who appears in Chaz
Not everyone in our systems signed up for an account. It is worth being plain about that:
- Business owners and their employees, who hold accounts and run a company on Chaz.
- Customers with accounts, who request service, message businesses, and pay invoices in the app.
- Customers without accounts. A business can add a customer with nothing but a name, then message or invoice them by text or email. Those people can reply, read a thread, and pay an invoice through a private link without ever creating an account or agreeing to anything in an app.
- Visitors to websites we publish. If a business builds its site on Chaz, we process limited analytics about the people who visit it, and the full contents of any contact form they submit.
- Businesses we contact about Chaz. We keep business contact details for our own sales outreach. See section 9.
4. What we collect
4.1 Account and profile
Name, email address, phone number, postal address, profile photo, preferred language, and the company or companies you belong to. Sign-in is handled by our own authentication service using OAuth2 with PKCE. We store password hashes, never passwords. We do not offer sign-in with Google, Facebook, Apple, or any other third-party identity provider, so no such provider learns that you use Chaz.
4.2 Business and operational records
Customers and their properties, service types and pricing, availability, schedules and recurring series, estimates, invoices, payments, job history, team membership, service regions, and the private notes a business writes about its own customers.
4.3 Messages and attachments
The contents of conversations in Chaz, including photos, files, reactions, read and delivery state, and the phone number or email address used when a message is delivered by text or email. A single conversation can span the app, SMS, and email, and we hold all of it as one thread.
We also keep moderation records — flags raised on a message and the outcome — so abuse can be investigated.
4.4 Location
This is the most sensitive thing we handle, so here is exactly what happens.
- Who. Only employees using the business side of the mobile app. Customers are never location-tracked.
- When. Only while the app is open and in the foreground, and only after you grant the “while using the app” permission. We do not request background location and the app claims no background location capability. Close the app and reporting stops.
- What we keep. Your most recent reported position and a status, and nothing else. Each new report overwrites the last one. We do not build a location history, so there is no trail of where you have been to retrieve, subpoena, or leak. If no report arrives for eight hours, the record is marked offline.
- Who sees it. Only the company you are clocked in to, on its team map.
- Declining. Refusing the permission, or revoking it later in your device settings, leaves every other feature working.
Separately, and unrelated to tracking people: addresses you enter for properties and service regions are geocoded so they can be placed on a map.
4.5 Payments
We do not store full card numbers. Card details are collected and held by Stripe, Inc., which is the payment processor for everything on Chaz. We retain identifiers and non-sensitive descriptors — payment intent IDs, card brand, last four digits, expiry, amounts, tips, and status — for invoicing, accounting, and disputes. If you save a card for re-use, the card itself stays at Stripe and we hold only a reference to it.
Businesses that take payments also complete Stripe's onboarding for their own payout account, which involves giving Stripe identity and banking information directly. We do not see or store that.
4.6 The Chaz assistant, voice and text
Chaz includes an AI assistant. When you use it, we store the conversation — your prompts, the assistant's replies, which tools it used on your behalf, and any action you approved or rejected — so the assistant has continuity and so an action taken on your account is auditable.
The voice mode records audio from your microphone while you are speaking to the assistant and streams it to our voice provider for transcription and response. The microphone is used for nothing else, and only while a voice session is open.
See section 7 for who processes this and on what terms.
4.7 Published websites: visitors and leads
When a business publishes a website through Chaz, we process data about the people who visit it, even though those visitors have no relationship with us.
- Analytics. Page and block views, a rotating visitor and session identifier, browser user agent, the domain that referred the visit, a country code, and a one-way hash of the IP address. We store the hash rather than the address itself so that visits can be counted without the raw IP being retained.
- Contact forms. Everything the visitor types — name, email, phone, message, the service they are asking about — plus the submitting IP address and user agent, which we keep to fight spam and abuse. These go to the business that owns the site.
4.8 Device, app, and diagnostic data
IP address, device model, operating system version, app version, language, crash reports, and performance traces. Crash reporting uses the open-source Sentry SDK, but the reports are sent to a GlitchTip instance that we host ourselves — no third-party monitoring vendor receives them. Session replay and user-session tracing are switched off.
4.9 Notifications and links
A push token from Apple or Google (delivered via Expo) when you enable notifications, and delivery state for the texts and emails we send on a business's behalf. The private links used to read a guest conversation or pay an invoice are random tokens tied to one recipient; they expire and can be revoked.
4.10 Cookies
Session cookies and local storage keep you signed in and remember preferences such as language and theme. We do not use advertising cookies, and we do not run third-party ad or tracking pixels on our site or on the sites we publish.
5. How we use information
- Provide, operate, secure, and maintain the Services.
- Let businesses schedule work, manage customers and teams, send estimates and invoices, and get paid.
- Let customers find participating businesses, request service, communicate, and pay.
- Deliver messages and notifications across the app, push, SMS, and email, and report delivery back to the sender.
- Answer the assistant's requests and carry out actions you approve.
- Publish and serve business websites, and route their leads.
- Diagnose crashes and performance problems, and develop the product.
- Detect, investigate, and act on fraud, spam, abuse, and security incidents.
- Comply with legal obligations and enforce our terms.
We do not sell personal information, we do not share it for cross-context behavioral advertising, and we do not use your messages, your customers' records, or your assistant conversations to train general-purpose AI models — ours or anyone else's.
6. How we share information
We disclose personal information only in these circumstances:
- Between the people a job involves. A business sees the contact details, address, and history of its own customers. A customer sees the business and, where relevant, the employee assigned to the work. An employee sees the customers and jobs assigned to them.
- With a business you contacted. Submitting a contact form, requesting service, or being referred sends your details to that business, which then handles them under its own privacy practices.
- With the service providers listed in section 7, under contract and only to run the Services.
- For legal reasons — to comply with a subpoena, court order, or other legal process, or to protect the rights, property, or safety of Chaz, our users, or the public.
- In a business transfer — as part of a merger, acquisition, or sale of assets, with notice where the law requires it.
7. Service providers we use
Each of these processes personal information on our behalf, under confidentiality and data-protection obligations, for the stated purpose and nothing else.
- Stripe, Inc. — card processing, saved cards, payouts to businesses, and fraud checks.
- DigitalOcean — application hosting, databases, and file storage (photos, attachments, and website assets), in U.S. data centers.
- Twilio — sending and receiving text messages, which is how conversations reach customers who do not use the app.
- Postmark — sending and receiving email, including invoices, notifications, and email replies to a conversation.
- Expo — delivering push notifications to Apple and Google, and shipping app updates.
- Anthropic — the language model behind the Chaz assistant and AI website editing.
- xAI — speech recognition and response for the assistant's voice mode.
- Google Maps Platform — rendering maps, geocoding addresses, and place lookup.
Anthropic and xAI receive only what a request needs, and we have contractual terms with both that prohibit using our data to train their models. Error reports go to our own self-hosted GlitchTip instance rather than to a monitoring vendor.
8. How long we keep things
We keep personal information for as long as it is needed to run the Services, meet legal and accounting obligations, and resolve disputes.
- Location. Latest position only, continuously overwritten. Marked offline after eight hours without a report.
- Guest links. Access tokens for guest conversations expire after 30 days, extended each time a new message is sent.
- Financial records. Invoices, payments, and related records may be retained up to seven years to satisfy U.S. tax and accounting rules.
- Diagnostics. Crash and performance data is kept on a short rolling window.
- Business records in a company's account. Retained while that company is a customer and for a reasonable wind-down period after.
9. Our own sales outreach
Separately from running the product, we keep business contact information — company name, publicly listed contact details, notes from a conversation — about businesses we think might want to use Chaz, and we send them invitations. This is business contact data used for business-to-business marketing on the basis of our legitimate interest. To be removed from it, email privacy@chazcanhelp.com and we will delete the record.
10. Your rights and choices
Depending on where you live, you may have the right to access, correct, delete, or port your personal information, to object to or restrict processing, and to withdraw consent. You will never be treated differently for exercising them.
- Update your details in the app under Settings.
- Delete your account in the mobile app under Profile → Privacy & Security → Delete Account, or by emailing privacy@chazcanhelp.com. What deletion does is set out in section 11.
- Turn off location or notifications in your device settings at any time.
- Stop text messages by replying
STOP, and marketing email via the unsubscribe link. - Ask a business directly about records it keeps on you, per section 2 — and tell us if you get nowhere.
California residents have rights under the CCPA and CPRA, including the right to know, delete, correct, and opt out of sale or sharing. Chaz does not sell or share personal information for cross-context behavioral advertising, so there is nothing to opt out of. Residents of the EEA, the UK, and Switzerland have rights under the GDPR and UK GDPR; our lawful bases are contract performance, legitimate interests, consent (for device permissions and marketing), and legal obligation.
11. What deleting your account actually does
We want to be precise rather than reassuring, because “deleted” is doing real work in that sentence.
- Every field that identifies you — name, email, phone, address, photo — is overwritten, not merely hidden.
- Every sign-in token and pending authorization is revoked, and your push notification tokens are deleted. The account can no longer be used to sign in.
- The underlying record is kept but emptied. Invoices, payments, and job history reference it, and a business's financial records cannot be allowed to collapse because one person left. What remains points at an anonymous row.
- Deletion is refused in one case: if you are the only administrator of a company, deleting you would strand that company's customers, schedule, and payouts. Transfer ownership or delete the company first.
- Messages you sent to other people remain in their conversations, as with any correspondence.
12. Security
TLS in transit, encryption at rest for stored files and database backups, OAuth2 with PKCE, scoped and revocable API tokens, role-based authorization on every request, two-factor authentication for our own administrative access, and rate limiting against abuse. No system is perfectly secure; if a breach affects you we will notify you and any regulator as the law requires.
13. When our staff can see your data
A small number of Chaz staff can access production data to provide support, investigate abuse, and fix faults. That access requires two-factor authentication, and administrative actions — including any session where a staff member views the product as your account in order to reproduce a problem — are written to an append-only audit log.
14. Children
Chaz is not directed to children under 16 and we do not knowingly collect their information. If you believe a child has provided us with personal information, contact privacy@chazcanhelp.com and we will delete it.
15. International transfers
Chaz is operated from the United States and your information is processed there. If you use the Services from elsewhere, you are sending your information to the U.S., where privacy law differs from your own. Where required, we rely on Standard Contractual Clauses or another approved transfer mechanism with our providers.
16. Changes to this policy
We may update this policy. When we do we revise the “Last updated” date above, and for material changes we give prominent notice in the app or by email before they take effect.
17. Contact
Questions, requests, or complaints? Email privacy@chazcanhelp.com or write to:
Zincan LLCAttn: Privacy
North Carolina, United States