Legal

Privacy

Last updated July 2026

SpyTower builds and runs websites, phone numbers and messaging for small service businesses. This policy covers our website, our web app, our mobile app, and the websites we build and host for our clients.

Two different roles, and the difference matters

Almost every question about your data has a different answer depending on which of these two you are, so this policy separates them throughout.

  • If you are a SpyTower client, a business paying us for a website, a phone number or review requests, we decide what to collect about your business and why. We are the controller of that information.
  • If you are a customer of one of our clients and you rang them, filled in their contact form, or received a text from them, your information belongs to that business. We only hold and process it on their instruction. We are a processor, and the business you contacted is who to approach about it. We will help you reach them.

What we collect from our clients

  • Business details: trading name, legal name, addresses, opening hours, services, service areas, and photographs you upload.
  • Identity required by phone carriers before any business is permitted to send text messages: legal business name, tax identification number, registered address, and the name, job title, email and phone number of an authorised representative. This is a carrier requirement, not ours.
  • Account details: the name and email of each person you give access to.
  • Billing details, handled by Stripe. Card numbers never reach our servers.
  • Usage: which screens are opened and when, so we can tell what is used.

What we hold on our clients' behalf

When somebody contacts one of our clients, we store what is needed to answer them: their name, phone number, email address, the contents of messages exchanged, whether they gave permission to be texted, and any appointment they booked. This is our client's information. We do not sell it, we do not use it to advertise, and we do not use it to train any model.

Text messages and consent

A business may only text a customer who gave them permission. We record how and when that permission was given, we never assume it, and we never tick that box on anybody's behalf. Anybody can stop the messages at any time by replying STOP, whether or not the message they are replying to spells that out, and STOP is honoured immediately and permanently unless the person starts the conversation again themselves. Consent is never bought, sold or shared, and mobile numbers are never shared with anybody for marketing.

The mobile app

  • Push notifications. The app registers a device token so we can tell a business the moment a lead arrives. It identifies a device, not a person, and it is deleted when you sign out or delete the account.
  • Camera and photo access, only if you choose to add a photograph, and only for that.
  • We do not track you across other companies' apps or websites, and we do not use your data for advertising.

Who else sees it

We use the services below to run SpyTower. Each receives only what it needs for the job named, and none of them may use it for their own purposes.

ServiceWhat it doesWhat it sees
SupabaseDatabase, authentication and file storage. The primary store for everything below.Client accounts, their customers' contact details, messages, photographs
VercelHosting for this app and for the websites we build, plus domain registration.Request logs, and the registrant details a domain purchase requires
TwilioPhone numbers, calls and text messages, and the carrier registration that permits business texting.Client business identity for carrier filings, caller numbers, message contents
ResendSending email: login links, notifications and review requests.Recipient email addresses and message contents
AnthropicGenerating website copy and reading a client's existing website to pre-fill their form.Business information supplied by the client. Not their customers' data
fal.aiGenerating header images for the websites we build.Image prompts describing the business. No personal data
GooglePlaces data for verifying a business listing, and, where a client connects it, their Google Business Profile.Business names and addresses, and reviews left on a client's listing
StripeTaking subscription payments.Billing contact and payment details. Card numbers never reach our servers
CloudflareDNS for the domains we manage.No personal data
PostHogProduct analytics, so we can see which screens are used.Usage events and a pseudonymous identifier
Sentry and Better StackError reporting and uptime monitoring.Technical diagnostics, which can incidentally include an identifier in an error

We may also disclose information where the law requires it. We do not sell personal information, and we do not share it for cross-context behavioural advertising.

How long we keep it

  • While you are a client, for as long as your account is open.
  • If you delete your account, your access stops immediately and we destroy your data 30 days later. Those 30 days exist so that a deletion made by mistake can be undone by asking us; after them it cannot be recovered by anybody.
  • If you leave any other way, we delete your account data within 90 days, except records we are required to keep for tax, accounting or carrier-compliance reasons.
  • Consent and opt-out records are kept for as long as the law requires us to prove them, because deleting an opt-out would risk somebody being texted again.
  • Diagnostic logs are kept for 30 days.

Your rights

Depending on where you live, you may have the right to see what we hold about you, correct it, delete it, get a copy, or object to how it is used. Residents of California, Colorado, Connecticut, Virginia, Utah and other states with privacy laws have these rights, and we apply them to everybody rather than checking where you live first. We will not treat you differently for exercising them.

To delete your account: you can do it yourself from inside the app, under Account, from the mobile app, or on the web at /delete-account without installing anything. If you own the business, it deletes the whole account: your logins, your website, your phone number, and every lead, conversation and customer record we hold for you. Your subscription is cancelled at the same time so you are not billed again. You do not need to email anybody to do it. If you would rather we did it, write to support@spytower.ai.

If you are a customer of one of our clients and want your information removed, the business you contacted controls it. Write to us and we will put you in touch, or pass the request on.

Security

Data is encrypted in transit and at rest. Each client's data is isolated at the database level so one client's account cannot read another's, and that isolation is enforced by the database itself rather than by application code remembering to check. Access by our own staff is limited to what is needed to run the service and is recorded.

Children

SpyTower is a tool for businesses and is not directed at children. We do not knowingly collect information from anybody under 18. If you believe a child has given us information, write to us and we will delete it.

Changes

If we change this policy we will update the date at the top, and we will tell clients by email before any change that materially affects them takes effect.

Contact

Write to support@spytower.ai, or see the support page. Our terms of service sit alongside this policy.