1. Scope
DetailSlate L.L.C. ("Company," "we," "us," or "our") operates the DetailSlate service and is the data controller/business responsible for the personal information described in this Privacy Policy, except where a service business controls its own client records under applicable law. This Privacy Policy explains how DetailSlate collects, uses, shares, and retains personal information when a person creates a business or client account, books as a guest, searches for a business, pays through the Service, or otherwise uses DetailSlate. It works alongside the DetailSlate Terms of Service.
DetailSlate currently supports businesses and users across the United States. The Service is not intended for use where these privacy practices do not satisfy applicable requirements.
2. Information we collect
We collect account and profile information such as name, email address, phone number, business name, service categories, business or service locations, account preferences, and authentication identifiers.
We collect booking and client-record information such as appointment details, service history, notes, addresses, and category-specific records that may include vehicle, pet, grooming, wellness, or other information relevant to the selected service.
When enabled, businesses may upload before-and-after or other job photos associated with bookings and client records. Users should upload only content they have the right and permission to use.
Stripe collects payment-card, bank-account, identity-verification, and connected-account information under its own privacy practices. Payments are processed securely by Stripe. DetailSlate does not store full payment-card information. DetailSlate stores transaction, fee-absorption choice, state-rule, refund, dispute, payout, and subscription metadata needed to operate the Service.
We collect communications information, including phone numbers, message content, delivery attempts and status, and consent or opt-out choices for transactional and promotional email or text messages.
If you enable browser push notifications, we store an encrypted device subscription and send the browser's push service a generic appointment-message alert and an inbox link. Push payloads do not include message text, customer names, or business names.
When a business uses the referral program, we collect referral codes and attribution, signup and vesting status, reward and payout records, and signals used to review eligibility or prevent abuse.
If a business connects Google Calendar, we receive the connected Google account email and selected calendar identifier, and store encrypted OAuth tokens to access that business's chosen calendar. We also process availability or busy-time ranges and appointment events synced to that calendar. A synced event may include the business name, service label, appointment date and time, associated address when available, and internal booking and business identifiers; it does not include the customer's name or contact information.
We collect first-party product analytics and resource-use information, such as feature and booking-funnel events and counts or amounts for storage, uploads, imports, exports, API requests, and message or booking requests. For published booking pages, this includes page views, short-lived anonymous session counts, booking-funnel outcomes, and the sizes of business-scoped API request and response payloads. These public-traffic analytics do not include visitor names, contact information, or IP addresses; random page-view and session identifiers are hashed when received and deleted after a short period. Authenticated business workspace usage may be attributed to the owner's or team member's account ID so authorized administrators can distinguish users; the report shows display names rather than raw account IDs. API payload sizes do not represent static assets or total browser bandwidth.
We and our service providers may also collect technical information needed to operate and secure the Service, such as IP address, device and browser information, timestamps, request logs, cookie or session identifiers, and product-usage events.
3. Digital Waivers & Intake Forms
When a business enables digital waivers or intake forms, including forms it customizes per individual service, DetailSlate may collect and store customer electronic signatures, including a typed name, drawn signature image, or equivalent; signature timestamps and IP address where captured; responses and answers entered into intake forms; photos attached to forms, such as pre-existing damage photos; and documents a business uploads as a custom waiver or intake form.
This information is collected at the business's direction to facilitate the business's waiver and intake process and to maintain a record of a customer's acknowledgment before service.
Signed forms and attached materials are visible to the business with which the customer booked through that booking's record. They are not shared with other businesses on the platform. Customers may access their own signed forms through their client account.
Signed forms are retained as part of the booking record under DetailSlate's standard data-retention practices and are included in Business Data Export and Restore functionality. Deletion requests should be made through the existing data-deletion process described in this Policy.
Signed forms and attached documents are stored using the same infrastructure described in Section 11 below; no separate e-signature or document-storage vendor is used for this feature as of this Policy's last-updated date. If a separate provider is added, this Policy will be updated to identify it.
4. How we use information
We use information to authenticate users; provide business discovery, booking, scheduling, records, photos, payments, payouts, subscriptions, exports, calendar integrations, and support; deliver transactional messages through enabled channels, including browser push notifications when you opt in; calculate referral eligibility and rewards; report and manage resource usage; analyze and improve the Service; send marketing announcements only where separately authorized; maintain security; prevent fraud and abuse; and comply with legal obligations.
We do not sell personal information or use it for targeted advertising.
4A. Information About Gift Recipients
When a customer purchases a gift card or package deal as a gift, they may provide us with the name and contact information (email address and/or phone number) of the intended recipient. We use this information solely to deliver the gift card or package deal notification and redemption code to the recipient, and to assist the issuing business with locating the record for redemption support.
We do not use recipient information for marketing purposes unless the recipient separately creates their own DetailSlate account and provides consent. The purchaser is responsible for ensuring they have appropriate permission to share the recipient's contact information with us for this limited purpose.
5. How information is shared
Information a customer provides for discovery, booking, payment, or a client record is shared with the service business the customer selects as needed to provide and manage the service. Published business profile information is visible to people searching for or booking with that business.
We share information with third-party service providers that operate the Service, including the providers listed in the Subprocessors section below. Each provider processes information under its own terms and privacy practices.
Business owners control which team members can access business information through role-based permissions. DetailSlate uses tiered permissions for its own administrative tools; authorized personnel may access information as needed to provide support, operate and secure the Service, investigate abuse, or meet legal obligations. Certain administrative and security actions may be logged.
We may disclose information when reasonably necessary to comply with law or legal process, enforce our agreements, investigate fraud or security issues, or protect DetailSlate, users, or the public. Information may also transfer as part of a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets, subject to this Policy or a materially similar policy.
We do not sell personal information, and we do not share personal information with third parties for their own cross-context behavioral advertising or targeted advertising purposes.
6. Marketing and communications choices
Booking confirmations, reminders, cancellation or rescheduling notices, receipts, security notices, and payout notices may be sent as transactional messages related to use of the Service. Transactional email may be sent through Resend from no-reply@detailslate.com. Transactional SMS is sent through Twilio only when a customer has expressly enabled text notifications for the relevant business in the customer notification preferences available in the Service; providing a phone number or selecting a contact method by itself is not SMS consent. Consent to SMS is not a condition of purchasing a service. Message frequency varies with appointment activity, and message and data rates may apply. No mobile information, including SMS/text messaging opt-in status or consent, will be shared with third parties or affiliates for marketing or promotional purposes. This mobile opt-in data is used solely to deliver transactional messages as described in this section.
Browser push is optional and separate from email and SMS preferences. You can enable or disable it in account Settings and revoke browser permission in your device or browser settings. DetailSlate's push alerts are generic and do not contain appointment-message text.
For help, Reply HELP or contact support@detailslate.com. Reply STOP to opt out of texts from the sending number. Text and email preferences are independent: opting out of SMS does not stop email notifications, and opting out of email does not stop text messages you separately enabled. Marketing email or text announcements, when available, require separate channel-specific consent; transactional notices are not marketing. Users should keep their contact information current and should not rely on any single delivery channel for time-sensitive notices.
7. Data retention and deletion
We retain different categories of information for different periods, as follows:
Bookings and customer records: retained while a business account is active, and for 30 days after account closure to allow data export, after which they are deleted or de-identified except as noted below.
Deleted appointments remain recoverable for 30 days without payment activity, or 120 days with payment activity, including intake evidence for disputes. At expiry, customer links and personal details are erased; cancellation/status audit and financial records remain. Confirmed manual purge is irreversible: unpaid appointments and their audit are deleted; those with payment activity are de-identified without deleting financial records. The separate client profile is unaffected.
Other deleted customer and form/waiver records keep a 30-day window. Cleanup is deferred when needed to protect a linked appointment's 120-day dispute window.
Signed waivers and intake forms: retained as part of the associated booking record, following the same schedule as bookings and customer records above; businesses remain responsible for their own longer retention obligations under laws applicable to their industry or state.
Photos (before/after, vehicle profiles): retained on the same schedule as the booking or vehicle record they're attached to.
Payment and transaction records: retained for at least 7 years to satisfy tax, accounting, and payment-processor recordkeeping requirements, regardless of account closure.
Backups: system backups may retain deleted or de-identified information for up to 90 days after deletion from primary systems, after which backups are rotated out.
Logs and audit trails (security, access, and system logs): retained for up to 12 months for security, fraud-prevention, and troubleshooting purposes.
Usage analytics: daily authenticated-business user and resource records are retained for approximately 90 days. Hashed public page-view and anonymous session identifiers are retained for approximately 27 hours before deletion. Daily business-level public-traffic aggregates are retained for approximately 395 days.
Message content, delivery metadata, and consent or opt-out choices are retained with the related customer or booking records and operational logs for the periods applicable to those records, and as needed to honor communication choices, resolve delivery issues or disputes, and meet legal requirements.
Encrypted browser push subscriptions are retained until you disable push notifications, delete your account, or the browser push service reports that the device subscription has expired.
Data retained after a business deletes its account: account and profile information is deleted or de-identified 30 days after closure and export; certain records (payment/tax records, records needed for an open legal dispute, and information already shared with a service business as part of that business's own records) may be retained longer as described above or as required by law.
Account deletion or a privacy request may remove or de-identify eligible information, but some transaction, consent, security, audit, dispute, and backup records may be retained where reasonably necessary or required by law. Information shared with a service business may also remain in that business’s records, subject to its own legal obligations.
8. Your privacy choices and rights
You may review or update available account information in the Service and may request access, correction, export, or deletion by emailing legal@detailslate.com. We may need to verify your identity and authority before completing a request. We aim to respond within 30 days of receiving a verifiable request (or sooner where required by law); if we need more time, we will tell you why.
Depending on where you live and whether applicable legal thresholds are met, you may have additional rights concerning access, correction, deletion, portability, or appeal, as described in the State-Specific Disclosures section below. DetailSlate does not sell personal information or use it for targeted advertising.
8A. State-Specific Disclosures
This section supplements the rest of this Privacy Policy for residents of California, Colorado, Virginia, Connecticut, and Utah, and other states with comparable consumer privacy laws.
Categories of personal information we collect (mapped to the categories above): identifiers (name, email, phone, account IDs); commercial/transaction information (bookings, payments, subscription history); customer records information (booking and client-record details, which may include category-specific information such as vehicle or pet information); visual information (photos uploaded to the Service); internet/network activity (device, browser, usage, and log data); and, where digital waivers are enabled, signature and form-response data.
Sources: directly from you, from the business you interact with, and automatically through your use of the Service.
Sale or sharing: We do not sell personal information, and we do not "share" personal information as that term is defined under the California Consumer Privacy Act (i.e., for cross-context behavioral advertising).
Retention: see Section 7 above.
Your rights. Subject to certain exceptions, you may have the right to: know/access the personal information we hold about you; correct inaccurate personal information; delete personal information; obtain a portable copy of your personal information; and not be discriminated against for exercising these rights. To exercise a right, email legal@detailslate.com. We will verify your request before acting on it.
Appeals (Colorado, Virginia, Connecticut residents). If we decline to act on your request, you may appeal by replying to our decision email or contacting legal@detailslate.com with "Privacy Appeal" in the subject line. We will respond to an appeal within 45 days, and the appeal will be reviewed by someone who was not involved in the original decision. If we deny your appeal, we will provide information on any further complaint process available in your state (such as a submission to your state Attorney General's office).
California "Shine the Light." California residents may request information about any disclosure of personal information to third parties for their own direct marketing purposes during the prior calendar year. DetailSlate does not currently make such disclosures.
9. Cookies and similar technologies
DetailSlate and its providers use cookies, local storage, and similar technologies for authentication, security, preferences, reliable operation, and understanding product usage. Blocking required storage may prevent account or booking features from working.
10. Security
We use reasonable administrative and technical safeguards designed to protect personal information and rely on payment infrastructure designed for payment-card compliance. Business team access is controlled through role-based permissions, and DetailSlate administrative access is tiered. No transmission, storage, or security system is completely secure, so we cannot guarantee absolute security.
10A. Where we process data
Personal information is primarily processed and stored within the United States. We do not guarantee that data is processed exclusively within the United States at all times — some of our third-party service providers (see Section 11) may process or store information using infrastructure located outside the United States as part of their own global operations, subject to their own data-processing and security terms. If this changes in a way that affects you, we will update this Policy.
11. Third-Party Service Providers and Subprocessors
DetailSlate uses the following third-party service providers and subprocessors to operate the Service:
• Clerk — authentication.
• Stripe — payment processing, subscription billing, connected-account services, and payouts.
• Resend — transactional email, sent from no-reply@detailslate.com.
• Twilio — transactional SMS delivery. For each text, Twilio receives the sender and recipient phone numbers, message content, and transmission and delivery metadata (such as message identifiers, timestamps, and delivery status), as well as SMS opt-out or help replies, to transmit the notification and report its status.
• Browser push services — when you opt in, the push service selected by your browser or device (such as Google Firebase Cloud Messaging, Apple Push Notification service, or Mozilla Autopush) receives the device subscription and encrypted notification payload needed to deliver the alert. The payload contains only generic alert text and an inbox link, not the message itself.
• Google Calendar — optional per-business OAuth, appointment synchronization, and availability checks. Google provides the connected account email; DetailSlate stores the OAuth tokens encrypted and uses them to access the calendar selected by that business. Calendar data may include event details described in Section 2 and busy-time ranges.
• Replit — application hosting, database, and related infrastructure services, including storage of uploaded photos and documents. (DetailSlate may change its hosting/database provider in the future; this Policy will be updated to reflect that if it happens.)
DetailSlate uses first-party product analytics and resource-use counters as described in Section 2. We do not currently use a third-party analytics or advertising-tracking provider, and we do not use personal information for targeted advertising.
Providers may process personal information only as needed to provide their services, subject to their own terms and privacy practices.
12. Children
DetailSlate is not directed to children, and a person must be at least 18 to create an account or book independently. A parent or guardian may arrange a service for a minor using the adult’s own account or booking information.
13. Changes
We may update this Privacy Policy as the Service, our providers, or legal requirements change. We will provide reasonable notice of material changes through the Service or another appropriate channel and will identify the current version by its last-updated date.
14. Privacy, legal, and general contact
DetailSlate L.L.C. is responsible for this Privacy Policy and the DetailSlate service. Formal legal and privacy requests, including access, correction, deletion, and appeal requests, should be sent to legal@detailslate.com. We aim to respond within 30 days (see Sections 8 and 8A for details). General support questions can still go to support@detailslate.com.