Privacy Policy
Effective Date: January 1, 2026
Last updated: June 2026
Important Notice Regarding Text Messaging Data
iTechSmart ("we," "us," or "our") DOES NOT share customer opt-in information, including phone numbers and consent records, with any affiliates or third parties for marketing, promotional, or any other purposes unrelated to providing our direct services. All text messaging originator opt-in data is kept strictly confidential.
1. Information We Collect
Personal Information:
- Name, email address, phone number, physical address
- Payment information when you make a purchase or request a quote
- Opt-in records and timestamps for all communication channels (SMS, email, etc.)
- Authentication data via Firebase Auth
Non-Personal Information:
- IP address, browser type, device information
- Website usage patterns and analytics
- Cookies and similar tracking technologies
Customer Communication Data:
- Records of inquiries and service requests
- Appointment details and preferences
- Support ticket history
- Infrastructure telemetry from connected systems (only with explicit authorization)
2. How We Use Your Information
- Providing and improving the iTechSmart platform and services
- Processing payments and fulfilling service agreements
- AI-assisted diagnostics, remediation, and autonomous operations
- Generating immutable ProofLink audit receipts
- Compliance reporting (SOC 2, HIPAA, NIST, FedRAMP)
- Sending transactional communications, service updates, and support responses
- Sending SMS/text messages to which you have opted in
- Fraud prevention and security monitoring
- Legal obligations and regulatory compliance
3. Text Messaging (SMS)
By providing your phone number and opting in, you consent to receive text messages from iTechSmart. These messages may include service updates, appointment reminders, account notifications, and support follow-ups.
- Opt-in: You must explicitly consent before receiving SMS messages. Consent may be provided via web form, verbal agreement, or written authorization.
- Opt-out: Reply STOP at any time to unsubscribe. You will receive one confirmation message and no further texts.
- Help: Reply HELP for assistance or contact us at [email protected].
- Frequency: Message frequency varies based on your service plan and activity.
- Rates: Message and data rates may apply depending on your carrier plan.
- Data: SMS opt-in data and phone numbers are never shared with third parties for marketing purposes.
4. Data Sharing and Third Parties
We do not sell, rent, or share your personal information with third parties for their own marketing purposes. We share data only in the following limited circumstances:
- Service Providers: Trusted vendors who help us operate our platform (see Section 8), bound by confidentiality agreements
- Legal Requirements: When required by law, court order, or government regulation
- Business Transfers: In connection with a merger, acquisition, or sale of assets, with advance notice to you
- Your Consent: With your explicit consent for any other purpose
SMS opt-in data is never shared with any affiliate or third party for any purpose.
5. Cookies and Tracking
We use cookies and similar technologies to enhance your experience, analyze usage, and improve our services. Types of cookies we use:
- Essential Cookies: Required for the platform to function (authentication, session management)
- Analytics Cookies: Help us understand how visitors interact with our site (anonymized)
- Preference Cookies: Remember your settings and display preferences
You can control cookie settings through your browser. Disabling certain cookies may limit platform functionality.
6. Data Security
We implement industry-leading security measures to protect your information:
- TLS 1.3 encryption for all data in transit
- AES-256 encryption for sensitive data at rest
- Post-quantum cryptography (Kyber-1024) for future-proof protection
- Immutable audit receipts via ProofLink (Bitcoin-anchored via OpenTimestamps)
- Zero-trust network architecture via Cloudflare
- SOC 2 aligned access controls and monitoring
- HashiCorp Vault for secrets management
Despite these measures, no system is 100% secure. In the event of a data breach we will notify affected users as required by applicable law.
7. PHI Handling (Healthcare Customers)
For healthcare customers, iTechSmart supports HIPAA compliance. Protected Health Information (PHI) is:
- Classified and tagged upon ingestion
- Encrypted at rest and in transit
- Access-logged via immutable ProofLink receipts
- Processed only with appropriate authorization
Business Associate Agreements (BAAs) are available upon request. Contact [email protected] to execute a BAA before transmitting any PHI.
8. Third-Party Service Providers
We use the following trusted providers to operate our platform:
- Firebase (Google Cloud): Authentication and database services
- Stripe: Payment processing — we never store card numbers
- Anthropic / NVIDIA: AI model inference (Claude, Nemotron)
- Vercel: Website hosting and edge delivery
- Cloudflare: DNS, CDN, Zero Trust network security
- Mailgun: Transactional email delivery
- GoHighLevel: CRM and SMS communication platform
- OVH: Bare-metal server infrastructure
- Resend: Developer email API
Each provider operates under their own privacy policies and data processing agreements.
9. Data Retention
- Audit receipts (ProofLink): Retained for 7 years — immutable
- Account data: Retained until account deletion request is fulfilled
- Payment records: Retained for 7 years per financial regulations
- Infrastructure telemetry: 90-day rolling window
- AI conversation logs: 30 days, then anonymized
- SMS opt-in records: Retained for the duration of your consent and 4 years thereafter
- Support tickets: 3 years after resolution
10. Your Rights (GDPR & CCPA)
Depending on your location, you may have the following rights:
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate or incomplete data
- Deletion: Request deletion of your personal data ("right to be forgotten")
- Portability: Receive your data in a structured, machine-readable format
- Objection: Object to processing of your data for certain purposes
- Opt-out of SMS: Reply STOP to any text message at any time
- Do Not Sell: We do not sell personal information. California residents may submit requests under CCPA.
To exercise any of these rights, contact [email protected]. We will respond within 30 days.
11. Children's Privacy
Our services are not directed to individuals under the age of 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us immediately at [email protected] and we will delete it promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. The latest version will always be available at itechsmart.dev/privacy with the effective date displayed. For significant changes, we will notify you by email or through a prominent notice on our website.
13. Contact Us
If you have questions about this Privacy Policy or how your information is handled, please contact us:
iTechSmart
Phone: +1 (800) ITECHSMART
Email: [email protected]
Privacy: [email protected]
Website: https://itechsmart.dev
SDVOSB · CAGE 172W2 · UEI ZCPFX4N86G36
By using our website and services, you consent to this Privacy Policy.