Legal
Privacy Policy
Effective May 1, 2025
1. Overview
Shadow Broker LLC ("we," "us," or "our") operates Bearcat ("the Service"). This Privacy Policy explains what information we collect, how we use it, and the choices you have. We take your privacy seriously and do not sell your personal information.
2. Information We Collect
Account Information
When you create an account, we collect your email address and password (stored as a secure hash). You may optionally provide your name and business information during onboarding.
Business Data You Enter
Bearcat stores the data you actively enter into the Service, including client and contact records, job and appointment details, invoices and proposals, financial transactions, documents you upload, and notes and tasks. This data belongs to you.
Usage Information
We may collect basic usage data such as pages visited, features used, and error logs to help us improve the Service. This data is not linked to personally identifiable information beyond your account.
Payment Information
If you use Bearcat's invoicing features with Stripe integration, payment card details are collected and stored directly by Stripe, Inc. We do not receive or store full card numbers. We may receive limited transaction data (amounts, dates, last four digits) from Stripe.
3. How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain the Service.
- Send transactional emails (account confirmation, invoices, portal invites) via Resend.
- Diagnose technical issues and improve Service performance.
- Respond to your support requests.
- Comply with legal obligations.
We do not use your data for advertising, and we do not sell, rent, or trade your personal information to third parties.
4. Third-Party Services
We rely on the following third-party providers to operate the Service. Each has its own privacy practices:
- Supabase — Database and authentication infrastructure. Your data is stored on Supabase's servers. Privacy policy.
- Stripe — Payment processing for invoice payments. Privacy policy.
- Resend — Transactional email delivery. Privacy policy.
- Vercel — Hosting and deployment infrastructure. Privacy policy.
- Google — If you connect Google Calendar or Google Drive, we access those services on your behalf using OAuth. We only request the permissions necessary for the features you enable. Privacy policy.
5. Data Retention
We retain your account and business data for as long as your account is active. If you request account deletion, we will delete your data within 30 days, except where we are required to retain it by law (for example, financial records).
During the beta period, data may be reset or migrated as part of development. We will provide reasonable notice before any data-destructive operations.
6. Security
We implement industry-standard security measures including encrypted connections (HTTPS), password hashing, and row-level security on all database tables. However, no system is completely secure. We encourage you to use a strong, unique password and to notify us immediately of any suspected unauthorized access.
7. Your Rights
You have the right to:
- Access the personal information we hold about you.
- Correct inaccurate data in your account.
- Request deletion of your account and associated data.
- Export your data using the data export feature in the Service.
- Disconnect any third-party integrations (Google, Stripe) at any time in Settings.
To exercise any of these rights, contact us at steve@shadowbrokerllc.com.
8. California Residents (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act, including the right to know what personal information we collect, the right to delete it, and the right to opt out of its sale. We do not sell personal information. To submit a request, contact us at steve@shadowbrokerllc.com.
9. Children's Privacy
The Service is not directed to individuals under 18 years of age. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it promptly.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated Policy with a new effective date and, where appropriate, by email. Continued use of the Service after changes constitutes acceptance of the updated Policy.
11. Contact
Questions about this Privacy Policy? Contact us at steve@shadowbrokerllc.com.
Shadow Broker LLC
