Effective Date: September 30, 2026 (previous version April 22, 2026)
ArborDash ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our business management platform and related services (collectively, the "Service").
1. Information We Collect
1.1 Information You Provide
- Account Information: Name, email address, phone number, company name, and password when you create an account.
- Business Data: Customer information, job details, invoices, estimates, scheduling data, and other business records you enter into the Service.
- Payment Information: Billing details and payment method information (processed securely by our payment providers).
- Communications: Messages, support requests, and feedback you send to us.
1.2 Information from Third-Party Integrations
When you connect third-party services to our platform, we may collect information from those services:
- QuickBooks Online: With your authorization, we access customer data, invoices, payments, items/services, and company information from your QuickBooks account to sync with our platform. We use this data solely to provide you with integrated accounting features.
- Payment Processors (Stripe): Transaction data necessary to process payments on your behalf.
- Google Calendar: With your authorization, we read the events on the calendar you select so they can be shown beside your scheduled work, and so you can turn an event into a job. We ask Google for only six fields per event: its identifier, title, description, location, start and end. Section 5 sets out what we do with them.
- Other Calendar Services: Calendar events and scheduling information you choose to sync.
1.3 Automatically Collected Information
- Device Information: Browser type, operating system, device identifiers.
- Usage Data: Pages visited, features used, time spent on the Service.
- Log Data: IP address, access times, referring URLs.
- Location Data: GPS coordinates when you use location-based features (with your permission).
2. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve the Service
- Process transactions and send related information
- Sync data between our platform and connected third-party services
- Send administrative messages, updates, and security alerts
- Send service-related SMS/text messages including scheduling notifications, arrival updates, and invoice reminders (with your consent)
- Respond to your comments, questions, and support requests
- Monitor and analyze usage patterns and trends
- Detect, prevent, and address technical issues and security threats
- Comply with legal obligations
3. Data Sharing and Disclosure
We do not sell your personal information. We may share your information in the following circumstances:
- Service Providers: With vendors who perform services on our behalf (hosting, analytics, payment processing).
- Third-Party Integrations: With services you choose to connect (e.g., QuickBooks, Google, Twilio) to enable functionality.
- Legal Requirements: When required by law or to protect our rights and safety.
- Business Transfers: In connection with a merger, acquisition, or sale of assets.
- With Your Consent: When you explicitly authorize sharing.
4. QuickBooks Integration
When you connect your QuickBooks Online account to our Service:
- We request access only to the data necessary to provide our services (customers, invoices, payments, items).
- Your QuickBooks data is transmitted securely using industry-standard encryption.
- We store QuickBooks access tokens securely and refresh them automatically as needed.
- You can disconnect QuickBooks at any time through our Integrations settings, which will revoke our access.
- We do not share your QuickBooks data with any third parties except as necessary to provide the Service.
5. Google Calendar Integration
When you connect a Google Calendar account to our Service:
- What we ask Google for. We request read access to your calendars and permission to create and update events, together with your Google account email address so we can show you which account is connected. When we read events we ask for only the event identifier, title, description, location, start and end. We do not ask for attendees, the organizer or creator, conferencing or meeting links, recurrence rules, reminders, attachments, colours, or private or shared extended properties.
- What we show. Events from the connected calendar are displayed beside your scheduled work. Showing them stores nothing. An owner or administrator may nominate one connection as the source of a company-wide view, in which case that calendar is shown to owners and administrators of the same company, and the Google account email address of the person who connected it is shown to them as the source. Employees see only the calendar connected to their own account.
- What we store. If you choose to turn an event into a job, we copy that event’s title, description and location into the job’s internal notes, which your staff can see and your customers cannot. Where an event is matched to services, part of the event text may also appear in the job’s service description, which is visible to the customer for that job. We also store the connection itself: the access and refresh tokens, your Google account email address, and which calendar you selected.
- What we write to your calendar. The integration also works in the other direction. When you export a job, we create or update an event on your calendar containing the customer name, the services, the property address and the estimated total. That information comes from ArborDash, not from Google.
- Disconnecting. You can disconnect at any time from the Integrations page. We send your credential to Google’s revocation endpoint, check that Google accepted it, and delete the stored tokens and the record of which events were exported. If Google does not confirm the revocation we keep the connection so you can try again, and we tell you rather than reporting success. Jobs already created from imported events keep the event text that was copied into them, and we retain that text for as long as you keep the job. You can also remove our access at any time from the Third-party apps section of your own Google Account.
- Limited Use. ArborDash’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
6. Artificial Intelligence and Machine Learning
We do not use Google Workspace data to develop, improve or train generalized artificial intelligence or machine learning models. We do not allow any third party to use it for that purpose, we do not sell it, and we do not transfer it for advertising. The use of raw or derived user data received from Google Workspace APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
One feature reads Google Calendar data with the help of a language model. When you first connect a calendar, ArborDash can compare your existing events against your existing estimates and suggest which ones describe the same work, so that setting up does not mean re-entering a season of jobs by hand. An owner or administrator starts it deliberately, and it runs over the events you are reconciling rather than continuously.
That feature sends event text to one model only: Cloudflare Workers AI, running Meta’s Llama 3.1 70B Instruct on Cloudflare’s network, which is the same infrastructure that already hosts ArborDash and already carries this data. Cloudflare is a processor for this purpose. Google Calendar data is not sent to any other model provider, and no setting in the product can redirect it to one.
Other parts of ArborDash use artificial intelligence for work unrelated to your calendar, such as answering the phone, drafting marketing copy and categorizing bank transactions. Those features may use a provider that your company configures with its own account, and none of them receives Google Workspace data.
Human access. We do not review your calendar content as a matter of course. Our staff can access a company’s data, including calendar events shown in the product, when providing support or investigating a fault. Access is limited to the people who need it for that purpose.
7. Data Security
We implement appropriate technical and organizational measures to protect your information, including:
- Encryption of data in transit (TLS/SSL) and at rest
- Secure authentication and access controls
- Regular security assessments and monitoring
- Employee training on data protection
However, no method of transmission over the Internet is 100% secure. We cannot guarantee absolute security.
8. Data Retention
We retain your information for as long as your account is active or as needed to provide the Service. We may retain certain information as required by law or for legitimate business purposes. You can request deletion of your data by contacting us.
9. Your Rights and Choices
You have the right to:
- Access: Request a copy of your personal information.
- Correction: Update or correct inaccurate information.
- Deletion: Request deletion of your personal information.
- Portability: Receive your data in a portable format.
- Withdraw Consent: Disconnect third-party integrations at any time.
- Opt-Out: Unsubscribe from marketing communications.
10. Cookies and Tracking
We use cookies and similar technologies to maintain your session, remember your preferences, and understand how you use our Service. You can control cookies through your browser settings, but disabling them may limit functionality.
11. Children's Privacy
Our Service is not intended for children under 13. We do not knowingly collect personal information from children under 13. If we learn we have collected such information, we will delete it promptly.
12. SMS/Text Messaging and Mobile Information
Our platform ("ArborDash") enables independent tree care, landscape, and arborist service companies (each a "Sender") to send service-related SMS/text messages to their customers, leads, and employees. A full description of the SMS program, including message types, frequency, and opt-out instructions, is available in our SMS Program Terms.
Types of SMS messages sent through our platform include:
- Appointment and scheduling confirmations and reminders
- Crew arrival and on-the-way notifications
- Estimate-ready and invoice / payment reminders
- Service follow-ups and review requests
- Account, onboarding, and security notifications to employees
Consent: You will only receive SMS messages from a Sender after you have provided your mobile number to that Sender and agreed to receive SMS, for example by submitting a web form that includes an SMS consent checkbox, signing a work authorization or estimate that includes SMS consent language, providing your number verbally or in person, or replying to an inbound message.
Mobile information sharing (required disclosure): No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. All other categories of personal information exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties or affiliates for any purpose.
Phone numbers and SMS consent records are used solely to deliver the messages described above and to operate and support the Service. We do not sell mobile phone numbers or SMS consent information, and we do not share them with advertisers, data brokers, lead aggregators, or any other third party for marketing or promotional purposes. We share mobile numbers only with our SMS service providers (such as Twilio) strictly as necessary to send messages on the Sender's behalf, and with the individual Sender whose customer you are.
Opt-Out: You can opt out of SMS messages at any time by replying STOP, STOPALL, UNSUBSCRIBE, CANCEL, END, or QUIT to any message. Reply HELP or INFO for assistance. Message frequency varies based on your service activity (typically 1–10 messages per month). Message and data rates may apply.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page and updating the effective date. Your continued use of the Service after changes constitutes acceptance of the updated policy.
14. Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us at:
- Email: [email protected]