Privacy Policy
Last updated September 7, 2026
This site is operated by Bloombilt LLC, a Minnesota limited liability company. We've kept this short and in plain language. If anything's unclear, email hello@bloombilt.com.
Who we are
Bloombilt LLC. Minnesota LLC, file #1647899600022. Registered agent: Northwest Registered Agent, Owatonna, MN. For all privacy questions: hello@bloombilt.com.
What we collect from site visitors
This section covers visitors to bloombilt.com. If your business uses one of our products, we also process data on your behalf. That's covered separately under Customer product data below.
Information you send us. When you fill in the contact form or email hello@bloombilt.com, we receive the name, email address, and message you submit. We use this to reply to you and to manage the engagement if you become a client.
Aggregate analytics. We use Cloudflare Web Analytics to count page views and referrers in aggregate. It does not set cookies, does not fingerprint browsers, and does not collect IP addresses we can tie back to you.
Server logs. Cloudflare keeps standard request logs (IP, user agent, timestamp) for a short window for security and abuse prevention. We don't combine these with any other data.
What we don't collect. No advertising cookies, no third-party tracking, no pixel tags, no session recording, no behavioral profiling.
How we use it
- To reply to your enquiries and run the engagement if you hire us
- To improve the site (aggregate analytics only)
- To meet legal and tax obligations
We don't sell your data. We don't share it for advertising.
Who processes site-visitor data for us
We use a small number of vendors for the site itself. Each one is contractually bound to handle data per our instructions. (For the vendors involved in delivering our products to customers, see Customer product data below.)
- Cloudflare: hosting, CDN, DNS, analytics, edge security
- Resend: sending and receiving transactional email on bloombilt.com
- GitHub: code repository (not visitor data)
Customer product data
If your business uses one of our products, we process data on your behalf as part of running it. This is separate from the site-visitor data above and is governed by our service agreement with you.
What we process. Lead data captured by the AI intake (caller name, callback number, address, and the nature of the request), call recordings and transcripts where applicable, content you provide for your website (logos, photos, copy, team information), and the operational records you keep in our apps (clients, properties, jobs, schedules, crew assignments, and job photos).
Accounting integrations. If your business connects QuickBooks Online, we access your QuickBooks data only with your authorization, through Intuit's official interfaces. We read your customer list and service items to link them to records in our apps, and we create and send invoices you ask us to create. We store the connection tokens encrypted, and we don't pull anything we don't need for those features. We use this data solely to provide the product to you; we act as an independent business and don't process it on Intuit's behalf. We never sell it or share it with anyone other than the subprocessors that run the product. If you disconnect QuickBooks (from our app or from Intuit's side), we stop accessing it immediately, delete the connection tokens, and delete the QuickBooks-sourced records on request.
Protection. Encrypted in transit (TLS 1.2 or better) and at rest, isolated from every other customer, and protected with reasonable administrative, technical, and physical safeguards.
No AI training. We don't use your lead data, call recordings, transcripts, or content to train AI or machine-learning models. The third-party AI services we use to deliver our products have confirmed they don't either.
Subprocessors. In addition to the site-visitor vendors above, we use third-party services for telephony, AI inference, hosting, error monitoring, email delivery, and accounting integrations (Intuit, for QuickBooks Online) to run our products. A current list of those subprocessors and the data each one processes is available on request, and we give customers reasonable notice before adding or replacing a material subprocessor.
Sensitive data. Our products aren't designed for health, biometric, financial-account, or government-identification data, and customers agree not to submit it through the AI services.
After an engagement ends. Customers can export their lead data as a CSV on request. We then delete it after a short retention window so there's time to migrate, except for routine backups that we don't access for any other purpose.
The Bloombilt Dispatch mobile app
Bloombilt Dispatch is the phone app crews use when their employer runs their schedule on our Dispatch product. The employer is the one who decides what goes into the system; we process it on their behalf, same as the rest of the customer data above. This section spells out what the app itself touches on a worker's phone.
Location. The app records precise location while a worker's day is running: from the tap on Start day until the tap on End day. Between those two taps it keeps recording when the app is in the background or the phone is in a pocket, which is why it asks for "Always" location access. It records nothing before Start day or after End day, and our server discards any fix that arrives outside a running work day. A reading is taken about every 40 meters of movement, so a parked phone records nothing. What it's for: working out how long each job took without the crew pressing anything on each stop, and tying proof photos to the right property. The office sees the time per job that comes out of it. No screen in the product shows a live map of where a worker is, and none shows the raw trail. The raw readings are permanently deleted after 30 days; the per-job times worked out from them stay with the job record. A worker can say no to location, or allow it only while using the app, and the app still works; only the automatic time on each job is lost.
Photos and videos. Proof photos, and site-walk videos with sound, that a worker takes (or attaches from their photo library) are uploaded to the employer's account and shown to the office. The microphone is used only while recording a walkthrough video. The app only accesses photos the worker picks or takes; it doesn't scan the library.
Who the worker is. The app knows a worker's name, email address, and work phone number because their employer put them in the system and invited them. Sign-in runs on Clerk, our authentication provider.
Face ID and Touch ID. Unlocking the app with Face ID or Touch ID happens entirely on the phone through Apple's own mechanism. Biometric data never reaches us, and we couldn't read it if we wanted to.
Notifications. If a worker allows notifications, we store the device's push token so the office's schedule updates can reach them. That's its only use.
Crash reports. If the app crashes, a report goes to Sentry, our crash-reporting provider, with the device model, OS version, and what the app was doing at the time. It doesn't include the worker's name, email, or any location readings.
What's not in the app. No ads, no analytics or tracking SDKs, and nothing is sold or shared for advertising. Besides our own servers, the only third parties the app itself talks to are Clerk for sign-in, Expo for app updates and push notifications, and Sentry for crash reports.
Retention and deletion. Work records (stops, photos, videos, and the per-job times worked out from location) belong to the employer's account and follow the retention terms above; the raw location readings themselves are deleted after 30 days as described under Location. Workers who want their data corrected or deleted can ask their employer, or email us directly at hello@bloombilt.com and we'll help within 30 days.
Legal basis (for visitors in the EU/UK)
- Contact form submissions: processing is necessary to respond to your request and, if you become a client, to perform the contract.
- Aggregate analytics: our legitimate interest in understanding how the site is used. The provider is cookieless, so no consent banner is required.
- Server logs: legitimate interest in operating the site securely.
How long we keep it
- Contact form submissions: as long as needed to reply, then up to 24 months for follow-up
- Active client correspondence: for the duration of the engagement plus 7 years for tax records
- Server logs: 30 days at Cloudflare's default
- Aggregate analytics: retained at Cloudflare's defaults, not tied to individuals
Your rights
If you're in the EU, UK, or California, you have the right to access, correct, delete, or export the data we hold about you, and to object to how we process it. Email hello@bloombilt.com and we'll respond within 30 days. You can also complain to your local data protection authority.
Children
The site isn't directed at children under 16, and we don't knowingly collect data from them. If you think we have, email us and we'll delete it.
International transfers
Cloudflare and Resend operate globally. Data may be processed in the United States or other jurisdictions. Where applicable, transfers from the EU/UK are covered by Standard Contractual Clauses.
Changes
We'll update the "Last updated" date at the top when we change this policy. Material changes get a notice on the site.