SmithBuddy SmithBuddy
Home Terms of Service

Legal

Privacy Policy

Last updated: April 2026

1. INTRODUCTION AND PURPOSE

This Privacy Policy governs the principles for collecting, processing, storing, and protecting personal and commercial data obtained during the use of services provided by Baydar Slotenmaker ("Company", "We" or "Our") through the SmithBuddy application and web-based services ("Platform"). Our primary priority is to ensure the data privacy of professionals managing their commercial activities through our platform, as well as the end users they serve, to the highest standards. This document has been prepared based on international data protection regulations and universal privacy standards.

2. CATEGORIES OF DATA PROCESSED AND COLLECTION METHODS

In order to provide the service completely and securely, we process the following information in adherence to the principle of minimum data collection:

Identity and Account Information: Name, surname, email address, password encrypted irreversibly using cryptographic methods, and business name information for corporate users, provided during system registration.

In-Service User Data: Customer contact information, addresses, work orders, invoice records, inventory details, and financial transactions that users voluntarily enter into the system as part of the platform's core function.

Media and Hardware Data: Visual materials accessed solely based on the user's immediate permission and action, captured with the device's camera or transferred from the photo gallery. This access does not run continuously in the background.

Siri and Voice Command Data: Our application offers Siri voice assistant integration on supported Apple devices. Voice commands given through Siri are converted to text using Apple's own local audio processing infrastructure and forwarded to our application only to execute the relevant action. Your voice recordings are never transferred to our company's servers, listened to, or stored by us.

System and Device Information: Operating system version, platform type, anonymized device identification numbers, and connected IP addresses, collected for security purposes and to optimize the service.

Subscription and Financial Transaction Records: Purchase history and subscription status information processed to verify the use of paid features. Sensitive financial data such as credit card numbers, expiry dates, or security codes are absolutely not collected or stored on our servers. Payments are handled by RevenueCat Inc. and Stripe Inc., both of which process data under their own privacy policies.

Vehicle identifiers you enter on behalf of your customers, including the license plate and VIN (chassis number), are treated and protected as personal data.

3. DATA PROCESSING PURPOSES AND LEGAL BASES

Data collected by us is processed lawfully and only for the purposes stated below:

To ensure seamless data synchronization between different devices and to fulfill the core functions of the application within the scope of establishing and fulfilling the service agreement.

To detect and prevent unauthorized access, cyber attacks, or fraudulent activities that may threaten the security of the system.

To improve user experience, monitor technical infrastructure, and resolve software errors.

To deliver important reminders and notifications based on the explicit consent given by the user through device settings.

4. DATA STORAGE INFRASTRUCTURE AND INTERNATIONAL TRANSFERS

User data is hosted through cloud computing providers with global security standards and data encryption infrastructure. Our servers are located in the London region of the United Kingdom, ensuring full compliance with international data protection standards. Your data is not shared with or sold to any data broker, advertising network, or unauthorized third party for profiling, ad targeting, or behavioral analysis purposes.

The United Kingdom is covered by a European Commission adequacy decision (valid until 27 December 2031), so transfers of personal data from the EU/EEA do not require an additional transfer mechanism such as standard contractual clauses.

5. DATA CONTROLLER AND DATA PROCESSOR STATUS

When you use the Platform to manage your commercial activities, the legal authority and responsibility over the personal data of your own customers that you enter into the system belongs entirely to you. You legally hold the title of Data Controller in this context. Baydar Slotenmaker, on the other hand, acts as a Data Processor that provides secure storage services on your behalf and in accordance with your instructions only. It is your legal obligation to collect your customers' data lawfully and to provide the necessary disclosures.

If you reached this policy through a customer form sent to you by a locksmith, the controller of the data you provide is that locksmith's business; SmithBuddy acts solely as a processor that hosts the data on that business's behalf.

6. ON-DEVICE DATA SECURITY AND ENCRYPTION

Our platform stores some data locally on the user's device to provide offline operating capacity and high performance:

Data in the vault module requiring special protection is encrypted with a high-security algorithm using the device's hardware security architecture.

General business records and customer data are stored in the local database dedicated solely to the logged-in user's identification number. Ensuring the physical security of the device, keeping screen locks and operating system updates active is entirely the user's responsibility.

7. TRACKING TECHNOLOGIES AND SESSION MANAGEMENT

Third-party cookies that track visitors, analyze usage habits, or create profiles for advertising purposes are absolutely not used in our web-based services. Our system creates only mandatory security tokens in your browser's local storage to ensure your session remains securely open and to prevent unauthorized access. These tokens expire when the session ends or after a period of inactivity.

8. USER RIGHTS AND DATA DELETION PROCESSES

Our users have full control over their personal data. Through the settings menu within the application, they can permanently delete their accounts and all associated data without having to contact any customer representative. When a deletion request is submitted, data is immediately and irreversibly destroyed from our servers. Backing up commercial reports, invoices, and work history outside the platform before deleting the account is entirely the user's responsibility. You can contact us at [email protected] for data protection requests and privacy questions.

Under applicable data protection law you have the right to access, rectify, erase, restrict, port and object to the processing of your personal data. You can exercise these rights through the in-app settings or by contacting [email protected]; we handle requests without undue delay and within one month at the latest. If you are unhappy with how we handle your data, you also have the right to lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).

9. AI PROCESSING

When you use the receipt scanning feature, the receipt image is sent over a secure connection to a third-party AI service for automatic data extraction. The image is not stored — it is only processed in real time. You can opt out by not using this feature; the rest of the application is unaffected.

Questions or concerns?

If you have any questions about these terms or our practices, contact us at [email protected] or through the in-app support feature.

© 2026 Baydar Slotenmaker. All rights reserved.

Privacy Policy · Terms of Service · Account Deletion