Skip to content
PROMPT

Legal

Privacy Policy

Last updated September 4, 2026. This policy covers PROMPT Technologies’ website, mobile app, and booking marketplace (“PROMPT”, “we”, “us”).

1. Information we collect

  • Account & profile: name, email, phone number, password (handled by our authentication provider, GoTrue — we never see or store raw passwords), and, for providers, certification and verification-badge details.
  • Booking data: service requested, location, scheduling window, and messages exchanged between client and provider to coordinate a booking.
  • Location: approximate or precise location you share, used only to match you with nearby providers or clients.
  • Payment data: processed directly by Stripe. PROMPT stores booking amounts and transaction references, never full card numbers.
  • Device & usage: basic technical data (IP address, browser/app version) needed to keep the service secure and working. PROMPT does not use third-party advertising trackers or sell browsing data.

2. How we use it

We use your information to operate the marketplace: matching clients with providers who have a genuine opening, processing payments, sending booking and account notifications (by email via Mailjet, SMS via Twilio, and push notifications via Expo), preventing fraud and abuse, and complying with legal and tax obligations.

3. Who we share it with

We share the minimum data necessary with the service providers that run PROMPT: Stripe (payments), Mailjet (email), Twilio (SMS), Expo (push notifications), and our infrastructure/hosting providers. The other party to a booking sees the profile and booking details needed to complete that job — nothing more. We do not sell personal information.

4. How long we keep it

You can request account deletion at any time, which starts a 30-day cancellation window during which you can change your mind. After that window, we pseudonymize your login credentials, metadata, and profile name so the data can no longer identify you. Booking and payment records are kept for seven years to meet financial record-keeping obligations, then permanently purged.

5. Security

Access to your data is enforced at the database layer with Postgres row-level security, not just application code, so a request can only ever touch the rows it’s authorized for. Backups are encrypted (AES-256) and stored separately from production data. All traffic to PROMPT is encrypted in transit (TLS).

6. Your rights

You can access, correct, or export your profile information from within the app, and request deletion at any time. Depending on where you live, you may have additional rights under applicable privacy law (for Canadian users, PIPEDA). To exercise any of these rights, contact us using the details below.

7. Children

PROMPT is not directed at, and is not knowingly used by, anyone under 16. If you believe a child has provided us personal information, contact us and we will delete it.

8. Changes to this policy

If we make material changes, we’ll update the date at the top of this page and, where required, notify you directly.

9. Contact us

Questions about this policy or a data request: privacy@prompttechnologies.ca.

← Back to PROMPT