dailybuilt
  • Platform
  • Pricing
  • Writing
  • Get early access
Get early access
Legal

Privacy Policy

One policy covering everything dailybuilt operates: the website, the platform, the booking, signing, and payment pages we host for businesses, and the messages we deliver. Section 2 explains when we decide how information is used and when we only follow a business's instructions.

Effective July 28, 2026 · Last updated July 28, 2026

This Privacy Policy replaces the prior website-only privacy policy published at dailybuilt.co/privacy. It is one policy covering everything DailyBuilt operates.


1. Who we are, and what this policy covers

DailyBuilt, Inc., a Delaware corporation ("DailyBuilt," "we," "us," "our"), operates the DailyBuilt platform and the DailyBuilt website.

This policy applies to all of the following, with nothing carved out:

Surface What it is
The Site dailybuilt.co and its subpages, including the blog, the waitlist form, and this policy
The Service The DailyBuilt platform at app.dailybuilt.co, used by businesses that subscribe to DailyBuilt
Hosted end-user surfaces Booking pages we host for a business (for example, {business}.dailybuilt.co/book), signing pages, invoice payment pages, and inquiry forms, including when those pages are served on a business's own custom domain
Messages Email we transmit for a business or for ourselves, including replies captured at reply.dailybuilt.co, and SMS text messages we transmit through our messaging provider

Two very different groups of people appear in this policy, and the difference determines your rights and who you should contact:

  • "Customer" means a business that has a DailyBuilt subscription and a workspace in the Service, and the people at that business who log in and operate it.
  • "End User" means a person who interacts with a page or message DailyBuilt hosts or delivers on a Customer's behalf: you book an appointment, sign a document, pay an invoice, submit an inquiry, or receive an email or text. End Users do not have DailyBuilt accounts and do not have a contract with DailyBuilt for those services. The business you are dealing with does.

"Customer Data" means data a Customer submits to the Service, or causes to be submitted, including data about that Customer's own End Users.

Related documents: Terms of Service · End-User Terms · Consumer Privacy Notice · Data Processing Addendum · Cookie Policy · SMS Terms · Subprocessors · Consumer Health Data Notice · Security · Legal Process Guidelines.


2. Our role: when we decide, and when we only follow instructions

This section is the most important one in this policy. Read it before anything else.

2.1 Where DailyBuilt is the business making the decisions (controller)

DailyBuilt determines the purposes and means of processing, and is the "business" under California law and the "controller" under other US state privacy laws, for:

  • information about visitors to the Site (dailybuilt.co), including analytics and the waitlist;
  • Customer account and administrative data: the names, business email addresses and login records of the people who create and operate a workspace; workspace configuration; subscription, plan, billing and invoice-history records for the Customer's own subscription to DailyBuilt; support correspondence; and security, audit and abuse-prevention records; and
  • information we generate to keep the Service running, secure and billable.

For that information, you exercise your rights directly with us (see §10).

2.2 Where DailyBuilt only follows a business's instructions (service provider / processor)

For Customer Data, meaning everything a Customer stores in or collects through its workspace, including all End-User data, DailyBuilt is a service provider under the California Consumer Privacy Act and a processor under other US state privacy laws. The Customer is the business/controller. The Customer decides what to collect, why, who to send it to, how long to keep it (subject to the floors in §9), and when to delete it.

That means, for Customer Data, DailyBuilt:

  • processes it only to provide the Service to that Customer and for the limited purposes permitted by our DPA and applicable law, never for our own separate commercial purposes;
  • does not sell it and does not share it for cross-context behavioral advertising;
  • does not combine it with personal information we receive from other sources, except as permitted by Cal. Civ. Code § 1798.140(ag)(1)(D) (for example, to detect security incidents or prevent fraud);
  • does not use it to build advertising profiles or to train machine-learning models; and
  • does not retain, use or disclose it outside the direct business relationship with that Customer.

If you are an End User, meaning you booked, signed, paid, inquired, or received a message, the business you dealt with controls your information, not DailyBuilt. Send your access, correction or deletion request to that business. If you send it to us instead, we will not ignore it. We will identify the relevant Customer where we reasonably can, forward your request to that Customer within ten (10) business days, tell you that we have done so, and give the Customer the technical assistance it needs to respond. We do not decide an End User's request ourselves. We are a service provider for that information, so we act only on the Customer's documented instruction, and if a Customer instructs us not to act we will tell you that and identify the Customer so you can take it up directly (11 CCR § 7050(c)). We will not delete or alter a business's records on our own initiative except where the law requires us to, or where a retention floor in §9 permits deletion.

2.3 Health information

Where a Customer has enabled Healthcare Edition, DailyBuilt acts as a Business Associate and protected health information is governed by the Business Associate Agreement and HIPAA, not by this policy. See §8.

2.4 We do not sell or share personal information

DailyBuilt does not sell personal information, and does not share personal information for cross-context behavioral advertising, as those terms are defined by the CCPA and comparable state laws. We have not done so in the preceding twelve (12) months. We do not disclose personal information to data brokers. We do not knowingly sell or share the personal information of anyone under sixteen (16) years of age.


3. What we collect, surface by surface

We only describe what the software actually does today. If a feature is off, or a business has not enabled it, the collection described for it does not happen.

3.1 The Site (dailybuilt.co)

What Details
Analytics (Google Analytics 4) Pages viewed and their order; approximate location, typically city-level, derived from your IP address (GA4 does not store the IP itself); device type, browser, operating system, screen size; the site or search query that referred you; and first-party cookies (_ga, _ga_<property-id>) used to distinguish sessions. We do not collect names or email addresses through GA4 and do not link analytics data to a specific individual.
Campaign measurement (Metricool) A script that counts visits from our marketing and social campaigns and sets its own first-party cookie so repeat visits from the same browser can be recognized. Aggregate, and not linked to your identity.
Search performance (Google Search Console) Aggregated data Google already holds about how our pages perform in Google Search. It collects nothing new from you when you visit.
Waitlist The email address you submit, plus a coarse, IP-derived location: country, region/state and city as reported by our CDN's geolocation headers. We store those three fields. We do not store your IP address on the waitlist record.
Email to us Whatever you choose to send to hello@dailybuilt.co: your name, email address, business, and the contents of your message.
Edge and server logs Our CDN and servers record request metadata, including IP address, timestamp, user agent and the resource requested, for security, abuse prevention and troubleshooting.

Analytics and campaign scripts are subject to the consent mechanism described in §11.

3.2 Customer account and billing data (app.dailybuilt.co)

What Details
Authentication We use WorkOS for sign-up, sign-in and email verification. WorkOS handles credentials. DailyBuilt does not store your password. We store your user record (name, email address, verification status), your workspace memberships and your role.
Workspace configuration Business name, slug, brand assets and colors, invoicing profile (legal name, business address, email, phone, tax ID, currency, footer), service catalog, availability, booking settings, notification preferences and site settings.
Subscription and billing Plan tier, subscription status, plan-change history, usage counters, and the Stripe customer and subscription identifiers. Payment card details are collected by Stripe directly through Stripe-hosted checkout and never pass through or rest on DailyBuilt systems.
API keys and invitations API keys are stored as one-way hashes with their scopes. Invitations record the invited email address, role, and acceptance time.
Security and audit records An audit log recording, for administrative actions: the actor, the action, the affected record, before and after values, a request identifier, the originating IP address and the user agent. Rate-limiting and bot-mitigation records.
Support The correspondence you send us and our replies.

3.3 Customer Data inside the Service

The Customer decides what goes in. Typically it includes:

  • Contacts / CRM: first and last name, email address, phone number, free-text notes, the source of the record, and a marketing opt-in flag. Customers may import contacts in bulk from a CSV file, from a vCard export (for example, an iPhone contact card), or from the device contact picker on Android. The Customer is responsible for having the right to upload those contacts. DailyBuilt processes them on the Customer's instruction.
  • Bookings and intake: the appointment or request, the service, date/time and time zone, the resource or provider assigned, and the answers an End User gives to the questions that business chose to ask, including free-text answers, which may contain anything the End User types.
  • Invoices and payments: invoice and line-item records, amounts, currency, status, tax fields, payment records, payout records, and Stripe object identifiers. Payments to a Customer are processed as direct charges on that Customer's own Stripe connected account, and the Customer is the merchant of record.
  • Documents and e-signature: document content and versions, signature requests, signer records, signature field placements, and signature events, each recording the signer, the action (viewed, signed, declined), the timestamp, and the signer's IP address and user agent. Executed agreements are sealed to a PDF with a certificate of completion and stored in encrypted object storage.
  • Messages: email and SMS transmitted through the Service, including sender, destination, subject, message body, channel, direction, provider message identifier, delivery status and any error, timestamps and cost. Inbound email replies are captured. When we send email on a Customer's behalf, the reply-to address routes through reply.dailybuilt.co, and a reply is received by our email provider, stored, and threaded into the Customer's inbox, including the reply body and any attachments the sender includes. If you reply to an email you received from a business using DailyBuilt, your reply is stored in that business's workspace.
  • Files and attachments the Customer or an End User uploads.
  • Notifications and internal event records, which may carry a contact's name so a notification can be rendered.
  • Client-project records where a Customer uses the projects and client-portal features: requests, milestones, deliverables, revisions and related correspondence.
  • Clinical records where Healthcare Edition is enabled. See §8.

3.4 Hosted end-user surfaces (booking, signing, payment, inquiry pages)

What Details
Booking and inquiry forms Your name, email address, an optional mobile phone number, your answers to the business's questions, the service and time slot you select, and your time zone. Providing a mobile number is optional and is never required to book.
Bot protection (Cloudflare Turnstile) Where a business enables it, a challenge widget runs on submission. To decide whether a submission is automated, Cloudflare receives your IP address and browser/device signals. We forward your IP address to our servers for that verification and for rate limiting. Turnstile is a privacy-preserving challenge and is not used to track you across sites.
Signing pages Your typed or drawn signature, the name you enter, your affirmation that you intend to sign electronically, timestamps, and your IP address and user agent, recorded as evidence of execution.
Payment pages The invoice you are paying and the amount. Card details go directly to Stripe. DailyBuilt does not receive or store them. We receive transaction metadata: amount, status, last four digits, card brand, and Stripe identifiers.
Website analytics See §3.5.

3.5 Analytics on hosted end-user surfaces, including session replay and heatmaps

Web analytics on a business's hosted site is performed with Umami, an analytics engine DailyBuilt self-hosts at analytics.dailybuilt.co. It records page URL, referrer, browser, operating system, device type, screen size, language and coarse country. Umami does not store your raw IP address. It derives a daily-rotating salted hash so a visitor can be counted once per day without being identified or followed across days.

Session replay and heatmaps. Umami's recorder captures a reconstruction of a visit: pointer movement, scrolling, clicks and page changes, which the business can replay or view as a heatmap. This runs only where the business has enabled recording for that property. It is off by default and is toggled per site by the business. When recording is on, the recorder can capture what you type into a form field. We enable the analytics engine's input-masking setting when we turn recording on, but that masking is performed by the engine, and we do not represent that form inputs are masked. Where a business has enabled recording, the page tells you so before the recorder starts and gives you a control to decline. If you decline, the recorder does not load for that visit. If you do not want to be recorded, you can:

  • block analytics.dailybuilt.co with a content blocker or a browser privacy mode, or
  • email hello@dailybuilt.co and we will forward your objection to the business.

Do Not Track and Global Privacy Control signals are honored on hosted pages only where the privacy-hardened profile is in use; they are not honored by the standard profile today.

Healthcare surfaces run a hardened profile. On a workspace using Healthcare Edition, the recorder is never loaded: no session replay, no heatmaps. That profile additionally honors Do Not Track, excludes query strings and URL fragments, coarsens each page URL to its first path segment before it leaves your browser so a condition-specific page path is never transmitted, and routes the measurement beacon through an IP-anonymizing proxy. On a Healthcare Edition hosted surface we serve no third-party advertising, conversion or analytics tag, we do not support tenant-supplied tag injection, and our own first-party measurement runs without transmitting anything to a third party.

3.6 Error monitoring

The authenticated platform application uses Sentry for error monitoring, performance diagnostics, and session replay. Session replay records a reconstruction of a signed-in user's interaction with the application — pointer movement, clicks, navigation, and the page as rendered — for a sample of sessions and for sessions in which an error occurs. It never runs for a Healthcare Edition workspace and is never loaded on public booking, signing, or payment pages. Sentry is configured not to collect user identity, cookies, or request bodies; events carry the URL, browser and device information, the workspace identifier, and the error itself.

3.7 Text messages (SMS)

DailyBuilt transmits text messages for businesses through our messaging provider.

Transactional program. If you give a business your mobile number on a DailyBuilt-hosted page, you are opting in to receive texts about that booking or request: confirmation, schedule changes, reminders, and replies from the business. Providing your number is optional and is never required to book. Message frequency varies by booking. Message and data rates may apply. Reply STOP to opt out and HELP for help. We honor opt-out requests, and you may also opt out at any time by emailing hello@dailybuilt.co or by contacting the business directly. We record the number you provided, the booking or request it relates to, and when you provided it.

Marketing program. DailyBuilt does not currently operate a marketing or promotional text-message program on the sending number used for the messages described above. That number carries only the transactional and customer-care messages described in this section. If DailyBuilt makes a marketing tier available in the future, it will run on a separately registered number and campaign, and a business will be able to use it only where the business has obtained and retains prior express written consent from the recipient meeting 47 C.F.R. § 64.1200(f)(9): a clear and conspicuous disclosure, a signed agreement identifying the sender, and a statement that consent is not a condition of any purchase. DailyBuilt does not obtain marketing consent on a business's behalf. The business is responsible for its own per-recipient consent records and for honoring opt-outs. If you receive a marketing text you did not consent to, tell us at hello@dailybuilt.co and we will act on it.

We do not share or sell mobile phone numbers or SMS consent to third parties or affiliates for their own marketing or promotional purposes. Your number is shared only with the business you gave it to and with the messaging provider that delivers the texts on our behalf, solely to send the messages described above.

Full disclosures are in the SMS Terms.


4. How we use information

For the Site and our own business (where we are the controller):

  • to respond to inquiries, waitlist requests and support requests;
  • to operate, maintain, secure and improve the Site;
  • to understand which content is useful in aggregate;
  • to bill Customers, collect payment and maintain financial records; and
  • to comply with legal obligations and enforce our agreements.

For Customer Data (where we are a service provider or processor), only to:

  • provide, operate and support the Service the Customer has purchased, on that Customer's instructions;
  • deliver the messages, bookings, documents, invoices and integrations the Customer configures;
  • secure the Service and detect, prevent and investigate fraud, abuse and security incidents;
  • maintain the audit, financial and retention records described in §9; and
  • comply with law.

What we do not do:

  • We do not use Customer Data or End-User data for advertising. We do not disclose it to advertising networks, and we do not use it to build advertising or interest profiles. When a Customer connects its own Meta or Google advertising account, we act only on that Customer's instructions and within that Customer's own account. See §6 and §7.
  • We do not use Customer Data or End-User data to train machine-learning or artificial-intelligence models, and we do not permit our subprocessors to do so.
  • We do not make automated decisions that produce legal or similarly significant effects about you, and we do not engage in profiling for that purpose.
  • We do not sell or share personal information (§2.4).

5. Who we share information with

5.1 Subprocessors and service providers

We use the providers below. Each is bound by a written contract limiting its use of the information to providing its service to us. The current list is also published at dailybuilt.co/subprocessors, which is generated from our internal subprocessor register.

Provider What it does for us Information it processes Location
Google LLC (Google Cloud Platform) Application hosting, the primary database, secret management and system logging All categories of Customer Data and account data stored in the Service, including PHI for Healthcare Edition workspaces United States
Encrypted object storage (BAA-covered provider) Storage of sealed documents, certificates of completion, superbills, invoices and file attachments, retrieved through short-lived signed URLs Documents and files, including PHI for Healthcare Edition workspaces United States
Amazon Web Services, Inc. (SES, S3, Lambda) Outbound email delivery, and receipt, storage and threading of inbound email replies Sender and recipient names and email addresses, subject and message body, attachments United States
Stripe, Inc. DailyBuilt subscription billing, and payment processing for Customers through Stripe Connect (direct charges on the Customer's own connected account) Billing contact details, payment method data collected by Stripe directly, transaction and payout metadata United States
WorkOS, Inc. Authentication and email verification for Customer operators (AuthKit) Name, business email address, credentials, session and device metadata. End Users do not authenticate United States
Telnyx LLC SMS delivery Mobile phone number, message content, delivery status. SMS is designated a non-PHI channel and the Service blocks it for Healthcare Edition workspaces United States
Cloudflare, Inc. Authoritative DNS for DailyBuilt domains, delivery of the marketing site, and the Turnstile bot-protection challenge on public forms IP address and request metadata for the marketing site; browser and device signals submitted to the Turnstile challenge United States and global edge network
Functional Software, Inc. (Sentry) Error monitoring, performance diagnostics and session replay for the authenticated platform application Error and performance events, session-replay recordings of the authenticated application, request metadata, workspace identifier. Configured not to collect user identity, cookies or request bodies United States
Upstash, Inc. Rate limiting and abuse control IP-derived identifiers and request counters United States
Metricool S.L. Marketing-campaign attribution on the Site only Site visit events and a first-party cookie identifier Spain (EU)
Google LLC (Google Analytics 4, Google Search Console) Site analytics and search-performance reporting on the Site only Site usage events, approximate location, device and referrer data United States
Google LLC (Business Profile, Search Console, Calendar, Places APIs) Integrations a Customer chooses to connect See §6 United States
Meta Platforms, Inc. Advertising integration a Customer chooses to connect See §7 United States

Hosted booking, signing, and payment pages are served DNS-only, so Cloudflare does not terminate TLS for, or observe the contents of, requests to those pages.

We also disclose information to our professional advisors (lawyers, accountants, auditors, insurers) under duties of confidentiality, and to a Customer's own operators: a Customer's team members see the Customer Data in that Customer's workspace, as the Customer configures.

5.2 Legal disclosures

We may disclose information where we believe in good faith that disclosure is required by law, legal process or a governmental request; is necessary to enforce our agreements; or is necessary to protect the rights, property or safety of DailyBuilt, our Customers, End Users or the public. Our approach to law-enforcement and third-party requests, including the additional protections that apply to protected health information under 45 C.F.R. § 164.512, is described at dailybuilt.co/legal-process. Where we are legally permitted to do so, we will notify the affected Customer before responding to a request for that Customer's data, so the Customer can seek protective relief.

5.3 Corporate transactions

If DailyBuilt is involved in a merger, acquisition, financing, reorganization, bankruptcy or sale of all or part of its assets, information covered by this policy may be transferred as part of that transaction. We will require the recipient to honor the commitments in this policy for information transferred, or to give affected individuals notice and a choice before any materially different use.

PHI carve-out. Protected health information is not transferred on those terms. PHI may be transferred only as permitted by HIPAA and the applicable Business Associate Agreement, including where the transaction qualifies as a "health care operation" under 45 C.F.R. § 164.501, and only to a successor that assumes the Business Associate Agreement in writing. Where the BAA and this section conflict as to PHI, the BAA controls.


6. Google user data

Some features require a Customer to connect its own Google account. The Customer initiates the connection through Google's consent screen and can disconnect at any time from Settings → Integrations → Disconnect, which revokes DailyBuilt's token at Google and removes the stored connection.

We store, for each connection: the email address of the Google account that granted access, the identifiers of the accounts or properties selected, the granted scopes, and the OAuth access and refresh tokens, encrypted with AES-256-GCM before they are written to the database.

Scope requested What we access Feature it powers Retention
.../auth/userinfo.email The email address of the Google account granting access Labels the connection in Settings so the Customer knows which account is connected Held with the connection, deleted on disconnect
.../auth/business.manage Business Profile accounts and locations (title, address, phone, categories, website, place ID), reviews and review replies, posts, and performance insights Google Business Profile management: view and reply to reviews, publish posts, see performance Location and review records are cached in the Customer's workspace. On disconnect they are marked deleted and purged per §9
.../auth/webmasters Search Console property list, search-analytics metrics (queries, clicks, impressions, average position), sitemaps and URL inspection results Search Console reporting inside the Service Retrieved on demand and cached for reporting, deleted on disconnect
.../auth/siteverification Site-verification tokens for properties we host on the Customer's behalf Proving ownership of a hosted property so Search Console data is available Held with the connection, deleted on disconnect
.../auth/indexing Submission of indexing notifications for pages we host for the Customer Indexing notifications for hosted pages Not retained beyond request logs
.../auth/calendar.events, .../auth/calendar.readonly Busy intervals on the connected calendar, and creation, update and deletion of events for bookings made through the Service, including event title, description, start and end time and the attendee's email address Two-way calendar sync so bookings do not double-book Events live in the Customer's Google Calendar under the Customer's control. DailyBuilt stores the sync record and event ID until disconnect
Google Places API (Maps Platform) Business name and address search and autocomplete. Uses DailyBuilt's own API key, not a Customer's Google account. The text typed into the business-search box, and the selected place's details, are sent to and returned from Google Business lookup during onboarding and profile setup Selected place details are stored in the workspace profile. Queries are not retained beyond request logs

Healthcare Edition and Google Calendar. Google Calendar is not covered by the Google Cloud HIPAA Business Associate Addendum. For a workspace using Healthcare Edition, calendar sync writes only a generic "Appointment" event with no client name, no notes and no attendee email address.

No advertising use. We do not use Google user data for advertising, and we do not sell it or transfer it to third parties for their own purposes. Human beings at DailyBuilt do not read Google user data except where it is necessary for security purposes, to comply with applicable law, to resolve a support issue the Customer has reported to us, or with the Customer's explicit prior consent.

Limited Use. DailyBuilt's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Information Google receives in connection with the Maps and Places features is handled under the Google Privacy Policy, which is incorporated here by reference.


7. Meta platform data

A Customer may connect its own Meta (Facebook and Instagram) advertising assets to run and measure advertising from inside the Service.

What we store: the identifiers of the connected ad account, Page and business portfolio; the granted permissions; the account name; and the Meta access token, encrypted with AES-256-GCM before storage. We also store the campaign, ad set, ad and creative records the Customer creates through the Service and the performance metrics Meta returns.

We do not receive or store the personal information of the people who see or click a Customer's ads. Audience and performance data stays in the Customer's own Meta account and is returned to us only as aggregate metrics.

Deleting it. A Customer can disconnect at any time from Settings → Integrations → Disconnect. Disconnecting revokes DailyBuilt's permissions at Meta and removes the stored connection and token. Anyone may also request deletion of data associated with a Meta login through our data-deletion instructions at dailybuilt.co/meta-data-deletion, or by emailing hello@dailybuilt.co.


8. Health information and Healthcare Edition

Healthcare Edition is a per-workspace mode a Customer can enable when it is a HIPAA covered entity. When it is enabled, a click-through Business Associate Agreement self-executes between DailyBuilt (as Business Associate) and the Customer (as Covered Entity), and the workspace cannot take patient-facing intake until that BAA has been accepted.

In a Healthcare Edition workspace the Service may hold protected health information: client profiles, dates of birth, diagnoses, treatment plans, goals and measurements, clinical notes and addenda, care-team and relationship records, superbills, and the appointment, document, invoice and message records associated with a patient.

PHI is governed exclusively by HIPAA and the applicable BAA, not by this policy. Where this policy and a BAA conflict as to PHI, the BAA controls.

If you are a patient, exercise your HIPAA rights (access, amendment, restriction, accounting of disclosures, confidential communications) through your provider, who is the covered entity. DailyBuilt cannot grant or deny those rights. We support the provider in responding to them. Send your request to the practice, not to us. If you send it to us, we will forward it to the practice.

Health information outside HIPAA. Some businesses using DailyBuilt collect health-adjacent information without being HIPAA covered entities, for example wellness and fitness businesses. Consumer health data laws, including the Washington My Health My Data Act and comparable Nevada and Connecticut provisions, may still apply to that information. Our commitments regarding consumer health data are set out in the Consumer Health Data Notice. DailyBuilt does not sell consumer health data and does not use it for advertising.


9. How long we keep information

Deletion in the Service is a two-step process. When a record is deleted, it is immediately hidden from the Service for the Customer and for us in ordinary use (a "soft delete"), and it becomes eligible for permanent destruction once the longest applicable retention floor below has run from the applicable anchor date. Destruction is performed through a controlled, audited process; it is not automatic on the expiry of a floor, and a record may remain in a deleted, non-visible state after its floor expires.

We honor deletion requests, except where a legal, professional or contractual obligation requires us to keep a record. Those floors are:

Category Floor
Financial records: invoices, line items, payments, payouts, subscriptions, plan changes, and the signature records evidencing a signed financial instrument 7 years
Clinical records in a Healthcare Edition workspace: charts, notes, treatment records, and the bookings, messages, documents and events linked to a patient 7 years, or until a patient who was a minor turns 20, whichever is later
Audit-log and security records: administrative audit trail, workspace memberships, invitations, API keys 6 years
Communications: messages sent and received, campaigns, notifications 3 years
Operational records: bookings, form submissions and answers, contact notes, documents, files, integration and calendar records, event records 3 years
Platform records: waitlist entries, signup codes, hosted-site registry records 3 years
Configuration: services, resources, templates, brand, site and booking settings 1 year
Identity records: user and workspace records 90 days
Legal hold: executed Business Associate Agreements, suppression and opt-out records, and anything subject to a litigation hold or legal preservation obligation No automatic expiry. These are never purged on elapsed time alone

Notes:

  • Deletion in the Service means the record is hidden and no longer used; permanent destruction happens on a separate, deliberate schedule.
  • Suppression and opt-out records are kept indefinitely on purpose. Keeping a record that you opted out is how we keep you opted out.
  • A legal hold overrides every floor above. Nothing subject to a hold is purged while the hold is in effect.
  • A Customer may hold its own data longer than a floor. Deletion floors are minimums we enforce, not maximums a Customer must observe.
  • Site analytics: Google Analytics 4 user-level and event-level data is retained for the window configured in our GA4 property (currently the GA4 default of two months). Aggregated reports persist longer. Metricool and our CDN retain their own logs per their standard policies. Umami analytics data is retained per the configuration of the property and contains no raw IP address.
  • Backups roll off on their own schedule. A record deleted from the live system may persist in an encrypted backup until that backup expires, after which it is unrecoverable.

10. Your privacy rights

10.1 California residents (CCPA/CPRA)

DailyBuilt does not meet any threshold in Cal. Civ. Code § 1798.140(d)(1): our annual gross revenue is far below the inflation-adjusted threshold, we do not buy, sell or share the personal information of any consumer, and we derive no revenue from selling or sharing it. We are therefore not a "business" as the CCPA defines that term. We give you the rights below anyway, and we will re-test those thresholds each year. Separately, and regardless of those thresholds, we are a service provider under Cal. Civ. Code § 1798.140(ag) for all Customer Data, and those obligations are not voluntary.

Categories of personal information we have collected in the preceding twelve (12) months. Where DailyBuilt is a service provider, we collect the category on a Customer's behalf and at that Customer's direction.

CCPA category Examples we handle Sources Business purpose Disclosed to (categories)
A. Identifiers Name, email address, phone number, account and workspace identifiers, IP address, device identifiers You, the Customer, your device Provide, secure and support the Service, authenticate, deliver messages, prevent fraud Hosting, authentication, email and SMS, payment, security and monitoring providers
B. Customer records (Cal. Civ. Code § 1798.80(e)) Name, postal address, telephone number, billing information, signature You, the Customer Billing, invoicing, e-signature, service delivery Hosting, payment and storage providers
D. Commercial information Subscriptions purchased, invoices, bookings, appointments, payment and payout records You, the Customer, Stripe Deliver and bill for the Service, financial recordkeeping Hosting, payment and storage providers
E. Biometric information None. We do not collect biometric information n/a n/a n/a
F. Internet or network activity Page views, referrer, browser, operating system and device, session-replay recordings where a business enables them, error and diagnostic events Your device Site and site-analytics measurement, troubleshooting, security Analytics, CDN and error-monitoring providers
G. Geolocation data Coarse only: country, region and city derived from IP address. We do not collect precise geolocation Your device via our CDN Analytics, fraud and abuse prevention, waitlist context Analytics and CDN providers
H. Audio, electronic, visual and similar information Drawn or typed electronic signatures, uploaded documents and images You, the Customer E-signature, document delivery Hosting and storage providers
I. Professional or employment information Business name, role and title of a Customer's operators The Customer Account administration, permissions Hosting and authentication providers
J. Education information None n/a n/a n/a
K. Inferences None. We do not draw inferences to create a consumer profile n/a n/a n/a
Sensitive personal information Account log-in information (handled by our authentication provider), health information processed on behalf of Healthcare Edition Customers, payment information collected directly by Stripe You, the Customer Authentication, delivery of the Service the Customer purchased Authentication, hosting and payment providers

Sensitive personal information. We use and disclose sensitive personal information only for the purposes permitted by Cal. Civ. Code § 1798.121(a): performing the services requested, security and integrity, preventing fraud, and ensuring the physical safety of individuals. Because we do not use it to infer characteristics, the right to limit its use and disclosure does not apply, and we do not offer a "Limit the Use of My Sensitive Personal Information" link.

Your rights. Subject to verification, you may:

  • Know and access the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of third parties to whom it was disclosed;
  • Delete your personal information, subject to the exceptions in Cal. Civ. Code § 1798.105(d) and the retention floors in §9;
  • Correct inaccurate personal information;
  • Port a copy in a portable, readily usable format where technically feasible;
  • Opt out of sale or sharing. We do not sell or share personal information, so there is nothing to opt out of, and we do not publish a "Do Not Sell or Share My Personal Information" link; and
  • Not be discriminated against for exercising any of these rights. We will not deny you service, charge you a different price, or provide a different level of quality because you exercised a privacy right.

How to make a request. Email hello@dailybuilt.co with the subject line "Privacy Request." Customers may also make a request from inside the Service or by contacting their account owner. Email is our only designated method because we operate exclusively online and collect this information directly from you, which is the condition in Cal. Civ. Code § 1798.130(a)(1)(A) and 11 CCR § 7020(a) for providing an email address alone rather than a toll-free number.

Verification. We will ask you for enough information to match your request to our records, typically the email address or phone number in question and, for account-level requests, confirmation of control of the account email. We will not ask for more information than is necessary and will not use what you provide for any other purpose. An authorized agent may submit a request with written permission signed by you, and we may also ask you to verify your own identity directly.

Timing. We confirm receipt within ten (10) business days and respond within forty-five (45) days. Where reasonably necessary, we may extend once by a further forty-five (45) days and will tell you why before the first period ends.

Appeals. If we deny your request, you may appeal by replying to our decision or by emailing hello@dailybuilt.co with the subject line "Privacy Appeal." We will review and respond in writing within forty-five (45) days, with our reasons. If we deny the appeal, we will tell you how to contact the California Attorney General or the California Privacy Protection Agency.

Global Privacy Control. We treat a GPC signal on the Site as an opt-out of analytics collection. See §11 for exactly how the mechanism behaves.

10.2 Residents of other US states

If you live in a state with a comprehensive consumer privacy law, including Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah and Virginia, you may have the right to confirm whether we process your personal data and to access it, to correct it, to delete it, to obtain a portable copy, and to opt out of targeted advertising, sale, or profiling in furtherance of decisions producing legal or similarly significant effects. We do not engage in targeted advertising, sale of personal data, or that kind of profiling.

Use the same method and the same email address as in §10.1. We respond within forty-five (45) days and may extend once by forty-five (45) days where reasonably necessary. You have the right to appeal a denial. Email hello@dailybuilt.co with the subject line "Privacy Appeal." We will respond in writing within forty-five (45) days with our reasons, and if we deny the appeal we will give you a method to contact your state Attorney General.

Where your state's law requires it, we will honor a universal opt-out mechanism such as Global Privacy Control.

10.3 If you are an End User

Requests about information you gave to a business through a DailyBuilt-hosted booking, signing, payment or inquiry page, or through an email or text message, should go to that business, which decides what happens to that information. If you do not know how to reach the business, or you would rather start with us, email hello@dailybuilt.co. We will forward your request to that business within ten (10) business days, tell you that we have done so, and help the business respond. We do not decide an End User's request ourselves. We are a service provider for that information, so we act only on the Customer's documented instruction, and if a Customer instructs us not to act we will tell you that and identify the Customer so you can take it up directly (11 CCR § 7050(c)). See the Consumer Privacy Notice for a short version of your options.


11. Cookies and similar technologies

The full inventory is in our Cookie Policy. In summary:

  • The Site sets Google Analytics first-party cookies (_ga, _ga_<property-id>, roughly two-year lifetime) and a Metricool first-party cookie for campaign attribution. We run no advertising or retargeting cookies.
  • The Service uses a strictly necessary session cookie for authentication and a local preference for light or dark theme.
  • Hosted end-user surfaces use the Umami analytics beacon described in §3.5, which does not rely on third-party cookies, and, where the business enables bot protection, a strictly necessary Cloudflare challenge cookie.

How the consent mechanism actually works on the Site. We want to describe this precisely rather than generically:

  1. We show a consent banner only where opt-in consent is legally expected: the EU/EEA, the UK and Switzerland. We determine that from your browser's reported IANA time zone. There is no IP lookup, no network call and no third-party geolocation service involved. That inference is approximate: a traveler, or a person with a manually set time zone, may be prompted when they would not otherwise be, or not prompted when they might expect to be.
  2. Everywhere else, analytics is granted by default and you can opt out at any time using the controls below.
  3. A Global Privacy Control signal is treated as a denial where you have not already made a choice on this site.
  4. Your choice is stored in your browser's local storage under the key dailybuilt:consent. A stored choice governs from then on, including over a Global Privacy Control signal you enable later. If you previously allowed analytics here and have since turned on GPC, clear this site's stored data in your browser, or email hello@dailybuilt.co, and we will reset it.

Your controls, in any case:

  • Block or delete cookies in your browser settings.
  • Install Google's Analytics Opt-out Browser Add-on.
  • Send a Global Privacy Control signal.
  • Email hello@dailybuilt.co and ask us to record your opt-out.

Rejecting analytics does not change how the Site works.


12. Where we operate

DailyBuilt is a United States company. The Service is offered to businesses in the United States and to their customers in the United States. We do not target the European Economic Area, the United Kingdom or Switzerland, and this policy does not grant rights under the GDPR or UK GDPR. The consent banner described in §11 is shown to visitors who appear to be in those countries because device-storage rules there can apply regardless of where we are established; it does not change this position. Our DPA provides US state privacy terms. Standard contractual clauses may be added by mutual written agreement where a Customer genuinely requires them.

Information covered by this policy is stored and processed in the United States. If you access the Site or a hosted surface from outside the United States, understand that your information will be transferred to and processed in the United States, whose data-protection laws may differ from those of your country.


13. Children

The Site and the Service are not directed to children under 13, and we do not knowingly collect personal information from a child under 13 for our own purposes. If you believe a child has given us personal information directly, email hello@dailybuilt.co and we will delete it.

The Service may process information about minors on behalf of a Customer: a pediatric practice, a family clinic, a tutoring business, a youth program. In that case DailyBuilt acts only as a service provider under that Customer's direction, and that Customer is responsible for obtaining any parental or guardian consent the law requires and for the lawfulness of the collection. Clinical records for a patient who was a minor are held to the longer of the retention floors in §9.

We do not knowingly sell or share the personal information of consumers under sixteen (16), and we do not use information about minors for advertising.


14. Security

We maintain administrative, technical and physical safeguards designed to protect personal information. Specifically:

  • Encryption in transit (TLS) for connections to the Site, the Service and our APIs, and encryption at rest for the database and object storage.
  • OAuth tokens for connected integrations are encrypted with AES-256-GCM at the application layer before they are written to the database.
  • Tenant isolation. Every authenticated request resolves its workspace from a trusted source, either an API key bound to a workspace or a session validated against an active workspace-membership record, and every query is scoped to that workspace. Role checks gate what a member can do.
  • Database row-level security policies govern the visibility of deleted records, so a soft-deleted record cannot be read through ordinary access paths.
  • Audit logging of administrative actions, including actor, action, affected record, request identifier, IP address and user agent. Audit records are exempt from ordinary deletion.
  • Access controls and least privilege for our own personnel, with secrets held in a managed secret store.
  • Bot mitigation and rate limiting on public endpoints.
  • Payment card data never touches our systems. It is collected directly by Stripe.

We do not currently hold a SOC 2 or ISO 27001 certification, and this policy makes no such claim. More detail, kept honest, is at dailybuilt.co/security.

No method of transmission or storage is completely secure. We cannot guarantee absolute security, and you send information to us at your own risk. If a breach affecting your information occurs, we will notify affected individuals, Customers and regulators as required by applicable law, including Fla. Stat. § 501.171 and, for protected health information, the HIPAA Breach Notification Rule and the timelines in the applicable Business Associate Agreement.


15. Changes to this policy

We update this policy when our practices change. The current version always lives at dailybuilt.co/privacy with the effective date at the top.

For material changes, we will update the effective date and give notice before the change takes effect, by email to Customer account owners and/or an in-app notice, at least thirty (30) days in advance. Where this policy is incorporated into a Customer's Agreement, the change process in the Terms of Service §20 governs and Customer's termination remedy in §20.4 applies. Non-material changes (clarifications, typographical corrections, updated links) take effect when posted.

We archive prior versions of this policy. Ask us at hello@dailybuilt.co for any prior version and we will send it to you.

Continued use of the Site or the Service after a change takes effect means you accept the revised policy. Where a change materially reduces protections for Customer Data, the DPA and the Terms of Service govern the change process for Customers, and any applicable Business Associate Agreement governs PHI.


16. Contact us

Questions, requests or complaints about this policy:

DailyBuilt, Inc. Attn: Privacy c/o Corporation Service Company, 251 Little Falls Drive, Wilmington, DE 19808 Email: hello@dailybuilt.co

For a privacy rights request, use the subject line "Privacy Request." For an appeal, use "Privacy Appeal." For a request about information a business collected through a DailyBuilt-hosted page, tell us which business, so we can route it correctly.

dailybuilt

The thinking layer for your whole business. Customers, bookings, payments, messaging, and your website in one login, one bill. In early access from Miami.

Platform
FeaturesHow it worksPricing
Company
Why we’re building itWritingFAQ
Contact
Get early accesshello@dailybuilt.coLinkedIn
Legal
TermsPrivacyEnd-User TermsConsumer Privacy NoticeDPAAcceptable UseSMS TermsBilling & RefundsCopyright & DMCASecurityAccessibilityCookiesLegal ProcessMeta Data DeletionSubprocessors
Consumer Health Data Privacy
dailybuilt
© 2026 DailyBuilt, Inc. All rights reserved.