Legal
Privacy Policy
This page describes what information 1Stop Service Pro collects from Client and Provider organizations, why it is collected, and how long it is kept.
Draft pending legal review
No lawyer has reviewed this document. It was drafted in-house so counsel has something concrete to mark up, and it is published here for that purpose. It is not legal advice, and 1Stop does not represent that it is enforceable as written. Nothing on this page should be relied on until a licensed attorney has signed off on it.
- Version
- 0.1
- Drafted
- 5 September 2026
- Status
- Draft, not in force
1Who this policy covers
This policy covers business users of 1Stop Service Pro: staff at property management companies who request and oversee work ("Clients") and staff at independent trade businesses who perform that work ("Providers"). It does not cover residents or tenants of the properties serviced through the platform. Residents and tenants are not 1Stop users and do not have accounts, but information about their unit, including its address and interior photographs taken during a work order, is stored by the system. That is addressed directly in this policy.
1Stop Service Pro is pre-launch. As of the date on this page it has no paying customers. This policy describes the system as it is built and as it is intended to operate, not a program that is currently serving anyone.
2What we collect
The table below lists the categories of information the platform stores, in plain terms, drawn directly from its database structure.
| Category | What is stored | Where it comes from |
|---|---|---|
| Identity | Full name, work email, phone number and job title of the individual user, plus the organization's name, legal name, email, phone and address. | Entered by the user or the organization at signup. |
| Account and access | A hashed password, session tokens, a hashed phone verification code, the time of last login, and email and phone verification timestamps. | Generated by the system when the account is created and used. |
| Property and unit detail | Property street address, city, state, postal code, county, latitude and longitude, plus unit label, floor, bedroom and bathroom counts, occupancy status, and free-text access notes and access instructions. | Entered by the Client when the property and unit are set up. |
| Worker location | Job start and end coordinates, and a Provider's home base coordinates. | Captured by the Provider's device. See the dedicated section below. |
| Photographs | Before, after and damage photographs of work areas, plus the filename, file type, size and dimensions of each image. | Uploaded by the Provider during a work order. |
| Device and network | IP address and browser user agent, recorded only on an electronic signature and on an audit log entry. | Captured automatically at the moment of signing or the audited action. |
| Timing | Job start and end times, scheduled windows, assignment, acceptance and completion times, signature times, audit timestamps, notification read times and login times. | Generated by the system as work moves through the platform. |
| Money | Invoice amounts, invoice line items, payouts and rate-card amounts, a payout method label, and a free-text payment reference. | Generated from work performed and entered by Clients and Providers. |
| Compliance documents | Certificates of insurance with issuer, policy number and expiry date, W-9 forms, and trade license numbers. | Uploaded by the Provider. |
| Free text | Job notes, request descriptions, access instructions, invoice notes, turnover notes, job rating comments, time entry notes and adjustment reasons, blocked stage reasons, and work order scope descriptions. | Entered by Clients and Providers as part of ordinary use. |
Photograph files are stored as uploaded. 1Stop does not currently strip the EXIF metadata embedded in image files, so a photograph may carry the camera or phone's own location and device information in addition to what is visible in the image itself.
IP address and user agent are not collected as a general practice across the platform. They are recorded in exactly two places: on an electronic signature record and on an audit log entry.
A list of what is not collected follows in the next section.
3What we do not collect
The platform does not process payments and does not store any of the following.
- No bank account number or routing number.
- No ACH transfer detail.
- No payment card data of any kind.
- No Social Security number.
- No Employer Identification Number.
- No background check results.
4Where the information comes from
Information reaches the platform in four ways: entered directly by a Client or Provider user through the application, captured automatically by the Provider's mobile app at the moment a job is started or ended, generated by the system itself as a byproduct of using the platform, such as timestamps and audit rows, and uploaded as a compliance document by a Provider.
5Why we use it
1Stop uses the information described above for the following purposes.
[counsel to confirm how to frame the legal basis for each purpose, and whether consent, contract or legitimate interest is the right frame in each state]
To dispatch work orders and allow a Provider to perform the work.
To prove that work was performed, through photographs, timestamps and signatures.
To invoice Clients and pay Providers.
To check a Provider's insurance, license and tax documentation before assigning work.
To secure user accounts, including password hashing and phone verification.
To keep an audit record of actions taken in the platform.
To resolve disputes between a Client and a Provider about a job.
6Photographs of occupied homes
Providers take before and after photographs, and sometimes damage photographs, of the work area. These photographs are often taken inside private residential units, and a unit may be occupied by a resident or tenant at the time.
The resident or tenant whose home is photographed is not a 1Stop customer and has not agreed to anything with 1Stop. The Client that manages the property authorizes the Provider's entry and the taking of photographs, and is responsible for giving the resident or tenant any notice the law or the lease requires. Under Fla. Stat. 83.53, a landlord must give a tenant at least 24 hours notice before entry for the purpose of repair, with repair entry between 7:30 a.m. and 8:00 p.m.
[counsel to confirm the allocation of notice-of-entry duties, and the Georgia equivalent]
1Stop asks Providers to photograph the work area itself rather than personal belongings, and not to photograph people.
[a written photo-capture standard for Providers is still to be written]
7Worker location
The Provider's device records its coordinates at two moments only: when a job is started and when it is ended. Each pair of coordinates is tied to a specific work order. This is not continuous tracking. The platform does not track a Provider's location in the background, between jobs, or off shift.
Coordinates are stored at full precision as reported by the device. Because Fla. Stat. 501.702(31) lists precise geolocation data as sensitive data, 1Stop treats job start and end coordinates as sensitive information, even though the threshold that would bring 1Stop within that statute's controller definition is not met today.
[counsel to confirm worker notice and consent requirements for location capture in Florida and Georgia]
9How long we keep it
1Stop does not currently have an automated process to delete, purge or archive data. With the exception of one soft-delete column on the notes table, records persist in the database until someone removes them by hand. Session tokens and phone verification codes carry expiry timestamps that make them unusable after a period of time, but the rows themselves are not deleted. Property records, unit records, photographs, location coordinates, signatures and audit rows are all kept indefinitely today. This is a known gap that 1Stop intends to close.
Fla. Stat. 501.171(8) requires reasonable measures to dispose of customer records containing personal information once they are no longer to be retained.
[retention schedule to be set with counsel, balancing tax and construction record needs against Fla. Stat. 501.171's disposal requirement]
10How it is protected
Passwords are stored as hashes, never in the clear. Phone verification codes are stored as hashes. Sessions expire. Access to data is scoped by the signed-in user's organization and role in the application's own code, using a role matrix: a Client sees its own organization's data, a Provider sees only the work assigned to it, and 1Stop staff can see across organizations. This scoping is enforced in application code, not by database row-level security.
The platform is self-hosted on a single server. No system is secure against every possible attack, and 1Stop does not represent that its systems are impenetrable. 1Stop does not hold a SOC 2 report, an ISO 27001 certification, or any similar third-party audit or certification.
11If there is a breach
Fla. Stat. 501.171 requires reasonable measures to secure personal information, notice to affected individuals following a breach, and notice to the Florida Department of Legal Affairs where a breach affects 500 or more individuals in Florida, no later than 30 days after determining a breach occurred, with up to 15 additional days available for good cause shown in writing. 1Stop will follow the notice requirements that apply to it if a breach occurs.
12Access, correction and deletion
A user or an organization can ask what information 1Stop holds about them, or ask for it to be corrected or deleted, through the contact page. Some records cannot be deleted on request because they document work performed or paid for. This includes signature records, audit rows, invoices, and photographic proof of completed work, which may need to be kept for contractual, tax or dispute reasons. 1Stop will respond to a request within [response time to be set].
13State law notes
Florida. Fla. Stat. 501.171 applies broadly to businesses that handle the personal information of Florida residents, and its security and breach notice requirements are addressed above. The Florida Digital Bill of Rights, Fla. Stat. 501.702, defines a "controller" subject to most of its obligations as an entity that, among other conditions, makes in excess of $1 billion in global gross annual revenue. 1Stop is far below that threshold today.
[counsel to confirm which provisions of the Florida Digital Bill of Rights apply regardless of the revenue threshold]
California. The California Consumer Privacy Act, Cal. Civ. Code 1798.140(d), applies to a "business" that meets at least one of three thresholds: annual gross revenue over $25,000,000, buying, selling or sharing the personal information of 100,000 or more consumers or households, or deriving 50 percent or more of annual revenue from selling or sharing personal information. 1Stop meets none of these thresholds today. If it ever does, California residents who use the platform as staff or contractors of a Client or Provider would fall within the law's scope, because the law's earlier business-to-business and employee exemptions have expired.
Georgia. [Georgia's consumer privacy and breach notification position is being verified and this section is a placeholder]
14Children
1Stop Service Pro is a business tool for staff at Client and Provider organizations. It is not directed at children, and 1Stop does not knowingly collect information from children. A photograph taken inside an occupied home could incidentally include a child who is present at the time. Providers are told not to photograph people.
15Changes and contact
If this policy changes, an updated version will be published on this page with a new draft date. Questions about this policy can be sent through the contact page.
This document is a working draft pending review by a licensed attorney. See the notice at the top of this page.