Now self-healing — see the full UAIO loop run autonomouslyRun demo →
iTechSmart logoiTechSmart

Privacy Policy

Effective Date: January 1, 2026

Last updated: June 2026

Important Notice Regarding Text Messaging Data

iTechSmart ("we," "us," or "our") DOES NOT share customer opt-in information, including phone numbers and consent records, with any affiliates or third parties for marketing, promotional, or any other purposes unrelated to providing our direct services. All text messaging originator opt-in data is kept strictly confidential.

1. Information We Collect

Personal Information:

  • Name, email address, phone number, physical address
  • Payment information when you make a purchase or request a quote
  • Opt-in records and timestamps for all communication channels (SMS, email, etc.)
  • Authentication data via Firebase Auth

Non-Personal Information:

  • IP address, browser type, device information
  • Website usage patterns and analytics
  • Cookies and similar tracking technologies

Customer Communication Data:

  • Records of inquiries and service requests
  • Appointment details and preferences
  • Support ticket history
  • Infrastructure telemetry from connected systems (only with explicit authorization)

2. How We Use Your Information

  • Providing and improving the iTechSmart platform and services
  • Processing payments and fulfilling service agreements
  • AI-assisted diagnostics, remediation, and autonomous operations
  • Generating immutable ProofLink audit receipts
  • Compliance reporting (SOC 2, HIPAA, NIST, FedRAMP)
  • Sending transactional communications, service updates, and support responses
  • Sending SMS/text messages to which you have opted in
  • Fraud prevention and security monitoring
  • Legal obligations and regulatory compliance

3. Text Messaging (SMS)

By providing your phone number and opting in, you consent to receive text messages from iTechSmart. These messages may include service updates, appointment reminders, account notifications, and support follow-ups.

  • Opt-in: You must explicitly consent before receiving SMS messages. Consent may be provided via web form, verbal agreement, or written authorization.
  • Opt-out: Reply STOP at any time to unsubscribe. You will receive one confirmation message and no further texts.
  • Help: Reply HELP for assistance or contact us at [email protected].
  • Frequency: Message frequency varies based on your service plan and activity.
  • Rates: Message and data rates may apply depending on your carrier plan.
  • Data: SMS opt-in data and phone numbers are never shared with third parties for marketing purposes.

4. Data Sharing and Third Parties

We do not sell, rent, or share your personal information with third parties for their own marketing purposes. We share data only in the following limited circumstances:

  • Service Providers: Trusted vendors who help us operate our platform (see Section 8), bound by confidentiality agreements
  • Legal Requirements: When required by law, court order, or government regulation
  • Business Transfers: In connection with a merger, acquisition, or sale of assets, with advance notice to you
  • Your Consent: With your explicit consent for any other purpose

SMS opt-in data is never shared with any affiliate or third party for any purpose.

5. Cookies and Tracking

We use cookies and similar technologies to enhance your experience, analyze usage, and improve our services. Types of cookies we use:

  • Essential Cookies: Required for the platform to function (authentication, session management)
  • Analytics Cookies: Help us understand how visitors interact with our site (anonymized)
  • Preference Cookies: Remember your settings and display preferences

You can control cookie settings through your browser. Disabling certain cookies may limit platform functionality.

6. Data Security

We implement industry-leading security measures to protect your information:

  • TLS 1.3 encryption for all data in transit
  • AES-256 encryption for sensitive data at rest
  • Post-quantum cryptography (Kyber-1024) for future-proof protection
  • Immutable audit receipts via ProofLink (Bitcoin-anchored via OpenTimestamps)
  • Zero-trust network architecture via Cloudflare
  • SOC 2 aligned access controls and monitoring
  • HashiCorp Vault for secrets management

Despite these measures, no system is 100% secure. In the event of a data breach we will notify affected users as required by applicable law.

7. PHI Handling (Healthcare Customers)

For healthcare customers, iTechSmart supports HIPAA compliance. Protected Health Information (PHI) is:

  • Classified and tagged upon ingestion
  • Encrypted at rest and in transit
  • Access-logged via immutable ProofLink receipts
  • Processed only with appropriate authorization

Business Associate Agreements (BAAs) are available upon request. Contact [email protected] to execute a BAA before transmitting any PHI.

8. Third-Party Service Providers

We use the following trusted providers to operate our platform:

  • Firebase (Google Cloud): Authentication and database services
  • Stripe: Payment processing — we never store card numbers
  • Anthropic / NVIDIA: AI model inference (Claude, Nemotron)
  • Vercel: Website hosting and edge delivery
  • Cloudflare: DNS, CDN, Zero Trust network security
  • Mailgun: Transactional email delivery
  • GoHighLevel: CRM and SMS communication platform
  • OVH: Bare-metal server infrastructure
  • Resend: Developer email API

Each provider operates under their own privacy policies and data processing agreements.

9. Data Retention

  • Audit receipts (ProofLink): Retained for 7 years — immutable
  • Account data: Retained until account deletion request is fulfilled
  • Payment records: Retained for 7 years per financial regulations
  • Infrastructure telemetry: 90-day rolling window
  • AI conversation logs: 30 days, then anonymized
  • SMS opt-in records: Retained for the duration of your consent and 4 years thereafter
  • Support tickets: 3 years after resolution

10. Your Rights (GDPR & CCPA)

Depending on your location, you may have the following rights:

  • Access: Request a copy of the personal data we hold about you
  • Correction: Request correction of inaccurate or incomplete data
  • Deletion: Request deletion of your personal data ("right to be forgotten")
  • Portability: Receive your data in a structured, machine-readable format
  • Objection: Object to processing of your data for certain purposes
  • Opt-out of SMS: Reply STOP to any text message at any time
  • Do Not Sell: We do not sell personal information. California residents may submit requests under CCPA.

To exercise any of these rights, contact [email protected]. We will respond within 30 days.

11. Children's Privacy

Our services are not directed to individuals under the age of 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us immediately at [email protected] and we will delete it promptly.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. The latest version will always be available at itechsmart.dev/privacy with the effective date displayed. For significant changes, we will notify you by email or through a prominent notice on our website.

13. Contact Us

If you have questions about this Privacy Policy or how your information is handled, please contact us:

iTechSmart

Phone: +1 (800) ITECHSMART

Email: [email protected]

Privacy: [email protected]

Website: https://itechsmart.dev

SDVOSB · CAGE 172W2 · UEI ZCPFX4N86G36

By using our website and services, you consent to this Privacy Policy.