Protected by Relay

What happens to your information

You probably got here by tapping a privacy badge on a booking page. This is the plain-English answer: what gets collected when you book, what's stored, for how long, and why. The short version — we keep only what your booking needs, we encrypt it, and it deletes itself on a timer once your job wraps.

The disclosure

Collected, stored, deleted

Information Do we store it? For how long Why we need it
Your name & contact details name, phone number, email Yes — encrypted Auto-deleted on a timer — 30 days by default To confirm your booking, send reminders, and let the business reach you about the job.
Job address Yes — encrypted Auto-deleted on the same timer So the crew shows up at the right place.
Job details & form answers rooms, sizes, dates, options you picked Yes Kept with the job record To price the work and schedule it correctly.
Photos you attach Yes — encrypted, location data stripped Deleted on the same timer So the business can quote accurately without a site visit.
Card number No Never held by Relay Payment goes directly to the business's own payment processor (Stripe or Square). Relay never stores card numbers.
Message content the texts and emails you receive Not in our logs Delivery logs record that a message was sent — never your phone number or what it said.

How the timer works: the business you book with sets its retention window — 30 days unless they choose longer (for example, to handle disputes). While your job is still open — scheduled, or with a balance due — your details are kept so the business can reach you. Either way, contact details never outlive one year from your booking.

"Encrypted" means AES-256 encryption at rest, with the key held outside the database — a database leak alone exposes nothing readable. Your information is never sold.

Who sees it

The business you booked — that's the point

Shared with your service provider

Relay's job is to hand your booking to the business you chose — your details exist so they can do the work. In their dashboard, lists show masked details; your full information appears only when they open your specific job.

Alerts carry nothing

When the business gets a "new booking" alert on their phone, the notification contains no personal data at all — just a pointer to open the job securely.

Where responsibility sits

Inside Relay, and outside it

Inside Relay — our responsibility

Everything on this page: encryption at rest, the 30-day deletion timer, logs and alerts designed so personal details have nowhere to land, and access checks on every read and write.

Outside Relay — the business's tools

The business runs the job through accounts they own: payments in their own Stripe or Square, appointments on their own Google Calendar. Those records belong to the business and are governed by those providers' terms and the business's own practices — the business is responsible for the tools it chooses to use outside Relay. In the future, businesses will be able to connect their own CRM tools; the same rule will apply — the business chooses the connection and owns that copy of the data.

Your controls

No account, still in control

Your booking link

Every booking comes with a private link where you can reschedule, cancel, or pay — no app, no password.

Deletion by default

You don't have to ask — contact details expire on their own. Want them gone sooner? Ask the business, or email us.

Texts you control

Booking texts require your consent on the form, and you can reply STOP at any time.

This page is the plain-English summary; the Privacy Policy is the version that governs, alongside our Terms and SMS terms. Questions: hello@relayleads.io