October 3, 2026
Privacy notice
This notice describes the Dirty Bristles business app. Patcher is the technical operator contact for questions and data-handling requests: jake@patcher.me.
Information handled
The workspace stores customer contact and service-address details, appliance information, appointments, office and field notes, work orders and signatures. Messaging records include recipient addresses, message content, contact preferences, consent and opt-out records, sending attempts and available delivery status. Sign-in records include account details, password hashes and login attempts with IP addresses. A session cookie supports sign-in and request protection.
Google Calendar and Gmail
An authorized Calendar connection reads events and can create, change or cancel events in the configured calendar to reconcile appointments. Event details can include names, service locations, times and appointment notes. Google account identity and offline access allow the connection to refresh authorization and synchronize while the browser is closed.
Gmail authorization is separate and send-only. The app verifies the connected account identity and sends approved recipient addresses and message content to Google. It records the returned message ID and sending outcome. It does not read inbox messages.
Dirty Bristles' use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Square and optional messaging
Square access is read-only: customer and business-location details, payment and refund metadata, and available order details support import review and reconciliation. The app does not collect or store card numbers or security codes, charge cards or issue refunds. Customer import does not establish marketing consent.
If separately enabled, Gmail or SMTP handles outbound email and Telnyx handles SMS. These services receive the recipient details and message content needed for delivery. The app also processes configured delivery callbacks and opt-outs. Hosting and database services hold the workspace records; connected services handle requests under their own policies.
Storage and access
Saved OAuth provider tokens are encrypted using Fernet with an operator-provisioned key. Passwords are stored as hashes. Business records are stored in the application database; the app does not encrypt every business-data field. Authorized office users can review workspace records, including imported calendar events and conflicts; field users are limited to assigned work. Technical administration of hosting and storage is separate from these app roles.
Disconnecting and requests
Disconnecting stops that connection locally and attempts to revoke provider access. Confirmed revocation removes the saved credentials. If revocation cannot be confirmed, disabled encrypted tokens can remain for a retry; access can also be removed in the provider account. Disconnecting retains business and message history.
You can request deletion of Google-derived data held by this app by contacting jake@patcher.me. Patcher will verify your identity and authority, identify the Google-derived records and credentials, stop the connection and attempt revocation, arrange scoped deletion, and report the result. Independently created business and message records are handled separately. Any proposed retained records or backup handling will be explained as part of the request.
The app has no self-service whole-account deletion or automatic retention deadline for business records. Contact Patcher for access, correction or deletion requests; no fixed completion time is stated here.
Build 0987506