This Privacy Policy describes AceWatt's own data practices. When an electrical contractor or other Customer uses AceWatt to process information about its customers, workers, vendors, or other people, that Customer controls the information and its own privacy notice also applies.
1. Scope and our roles
This Privacy Policy explains how ACEWATT, a California corporation (AceWatt, we, us, or our), collects, uses, discloses, and retains personal information through acewatt.com, the AceWatt CRM platform, mobile or installable applications, customer and vendor portals, support, demos, communications, and related services (collectively, the Service).
For account, billing, website, sales, security, support, and Service-usage information that AceWatt determines how to use, AceWatt acts as a business or controller. For Customer Data submitted by an AceWatt Customer about that Customer's customers, prospects, workers, subcontractors, vendors, projects, and communications, AceWatt generally acts as the Customer's service provider, contractor, or processor. Requests about Customer Data should usually be directed first to the Customer that collected it; we will assist that Customer as required.
This Policy does not govern a third-party website or service linked to or integrated with AceWatt, or an AceWatt Customer's independent practices.
2. Personal information we collect
The categories below describe information we may collect. The actual information depends on the features used and what Customers and Users choose to submit.
2.1 Account, identity, and company information
- name, email, phone number, profile image, account identifier, login and authentication data;
- company name, legal name, address, website, tax and contractor-license information, insurance and bond information;
- role, permissions, job title, specialties, preferences, and account-administration activity; and
- subscription plan, billing status, Stripe customer or subscription identifiers, invoice metadata, and limited payment-method details such as brand, expiration, and last four digits. Full card or bank credentials are handled by the payment processor.
2.2 Customer, commercial, project, and financial records
- customer and prospect identifiers, contact details, properties, referral sources, communication preferences, service history, notes, and portal activity;
- leads, estimates, quotes, options, line items, prices, discounts, deposits, contracts, change orders, invoices, payments, payment plans, warranties, service agreements, and accounting records;
- projects, job sites, schedules, assignments, scope, permits, inspections, incidents, safety records, equipment, vehicles, materials, inventory, supplier, subcontractor, and vendor information; and
- business analytics, costs, margins, commissions, expenses, goals, reports, workflow activity, and audit events.
2.3 Workforce and professional information
- worker contact and profile information, role, schedule, time entries, availability, leave, skills, training, licenses, hire date, worker classification, pay type and rate, overtime eligibility, commissions, and expenses;
- emergency-contact name, phone number, and relationship; and
- time-clock, dispatch, route, job-site, and precise-location information when enabled by the Customer or User.
2.4 Communications and content
- email, SMS, calls, voicemails, call recordings, transcripts, sender and recipient details, delivery and opt-out events, campaigns, forms, surveys, feedback, and support messages;
- photos, video, audio, voice notes, blueprints, plans, documents, attachments, annotations, signatures, and metadata such as capture time and location; and
- AI prompts, inputs, retrieved source material, generated output, corrections, feedback, confidence and usage information.
Customers are responsible for giving legally required notice and obtaining consent before uploading, recording, transcribing, analyzing, or communicating with other people.
2.5 Device, usage, and network information
- IP address, browser and device type, operating system, app version, language, time zone, referring page, page and feature activity, clicks, session and error data, user agent, identifiers, and approximate location derived from network information;
- precise geolocation when a User enables location, geofencing, route, clock, or field features; and
- security, fraud, authentication, rate-limit, webhook, integration, and audit logs.
2.6 Sales, marketing, and demo information
- contact and company details, requested plan, referral and campaign attributes, newsletter choice, demo or lead-form content, and communications with sales or support; and
- website analytics and cookie or similar-technology data described in Section 7.
3. Sources of information
We collect information: (a) directly from Customers, Users, prospects, portal visitors, and communication recipients; (b) from Customer administrators and other Users; (c) automatically from browsers, devices, the Service, cookies, logs, and security systems; (d) from connected services such as authentication, payment, communications, accounting, AI, mapping, and supplier providers; (e) from referrals, lead forms, public or commercially available sources, where lawful; and (f) from contractors and service providers working for us.
4. How we use information
We use personal information to:
- create, authenticate, administer, secure, and support accounts and tenants;
- provide CRM, project, field, communications, AI, portal, billing, integration, reporting, and other requested features;
- process subscriptions, trials, payments, invoices, credits, renewals, cancellations, and related notices;
- route messages and calls; create transcripts; send transactional, support, product, security, or authorized marketing communications; and process opt-outs;
- personalize settings and workflows; troubleshoot; monitor performance; analyze adoption; and improve the Service;
- generate, evaluate, and improve AI-assisted results, subject to Customer instructions, provider terms, and the restrictions in our Terms;
- detect, investigate, and prevent abuse, fraud, security threats, unauthorized access, and violations of our Terms;
- comply with law, lawful process, tax and accounting duties, and enforce or defend legal rights; and
- evaluate or complete a financing, acquisition, merger, reorganization, or sale involving AceWatt, subject to appropriate protections.
Where law requires a legal basis, we rely as applicable on performance of a contract, legitimate interests in operating and securing a business Service, consent, and legal obligations. Where we process Customer Data as a processor or service provider, the Customer determines the legal basis and instructs us.
5. How we disclose information
We may disclose personal information in the following circumstances:
5.1 Customer and authorized Users
Customer administrators and authorized Users may access information within their tenant according to roles and settings. A Customer may direct us to share information through portals, links, exports, messages, webhooks, or integrations. Public or secret-link portals may be accessible to anyone who possesses the link, so Customers must distribute them carefully.
5.2 Service providers and subprocessors
We use providers for functions such as:
- hosting and data infrastructure: Convex and Vercel;
- identity and authentication: Clerk;
- payments and subscription management: Stripe;
- email, SMS, voice, and communications: Resend and Twilio;
- AI and transcription: providers that may include Google Gemini, OpenAI, Anthropic, and Deepgram depending on the selected feature and current configuration;
- security and error monitoring: Sentry;
- website and product analytics: Google Analytics, PostHog, and Vercel Analytics where configured;
- accounting, mapping, supplier, and Customer-directed integrations: providers such as QuickBooks and the services a Customer chooses to connect; and
- professional support: legal, accounting, security, and other advisers.
These providers may process information only to perform services for us or as separately directed by the Customer, subject to their contracts and applicable law. Provider availability and the exact subprocessor list may change as the Service evolves.
5.3 Legal, safety, and business events
We may disclose information when we reasonably believe it is necessary to comply with law or lawful process; protect rights, safety, property, or the Service; investigate fraud or abuse; obtain professional advice; enforce agreements; or complete a merger, financing, acquisition, reorganization, bankruptcy, or sale. We may disclose information with consent or at a Customer's direction.
6. Sale, sharing, and targeted advertising
We do not sell Customer Data for money and do not use Customer Data submitted to the CRM for cross-context behavioral advertising. We do not knowingly sell or share personal information of anyone under 18.
The public marketing website may use analytics technologies that disclose device and activity information to analytics providers. Some privacy laws may define certain analytics or advertising disclosures as a “sale,” “sharing,” or targeted advertising even when no money is exchanged. AceWatt does not currently use CRM Customer Data for those purposes. Where applicable, a person may request an opt-out by contacting support@acewatt.com. We will not discriminate for exercising a privacy right.
7. Cookies, local storage, analytics, and preference signals
The Service uses cookies, browser storage, and similar technologies for authentication, security, session continuity, preferences, attribution, analytics, and performance. Strictly necessary technologies are required for login and core functions. Analytics technologies help us understand visits and feature usage. The public site may use Google Analytics, PostHog, and Vercel Analytics where configured. The CRM also uses browser and indexed storage to support preferences, caching, drafts, and offline behavior.
Browser settings can block or delete cookies, but doing so may prevent login or break features. We do not currently respond to legacy “Do Not Track” signals because there is no uniform industry standard. Where applicable law requires recognition of a legally valid opt-out preference signal such as Global Privacy Control, we will treat it as an opt-out request for the browser or device that sends it. The CRM itself does not use cross-context behavioral advertising.
8. Retention
We retain information only for as long as reasonably necessary for the purpose collected, Customer instructions, security, dispute resolution, and legal, tax, accounting, and contractual obligations. Retention is determined by category and context:
- account, subscription, and Customer Data are generally retained while the account is active and for a limited period afterward for retrieval, continuity, backups, disputes, and legal obligations;
- Customer-controlled records remain until the Customer deletes them, the account ends, or retention is otherwise required or permitted;
- acceptance, billing, transaction, signature, audit, consent, opt-out, security, and legal records may be retained for the applicable limitation, tax, contract, or compliance period;
- support and sales communications are retained while needed to resolve the request, maintain relationship history, and protect legal rights;
- marketing contact information is retained until opt-out or until no longer needed, while suppression records may be kept to honor opt-outs; and
- de-identified information may be retained where it can no longer reasonably identify a person.
Deletion from active systems may not immediately remove copies from encrypted or disaster-recovery backups, which are isolated and expire through normal backup cycles. We may retain information longer when litigation, investigation, fraud, security, or law requires it.
9. Security
We use reasonable administrative, technical, and organizational safeguards designed for the nature of the information and Service, including authenticated tenant access, role controls, transport protections, monitoring, and provider safeguards. No internet service or storage system is completely secure, and we cannot guarantee absolute security. Customers and Users must protect devices and credentials, configure roles carefully, and promptly report suspected incidents to support@acewatt.com.
10. Privacy rights and choices
Depending on residence and applicable law, a person may have rights to request access, correction, deletion, portability, or restriction; to know categories, sources, purposes, and recipients; to opt out of certain sale, sharing, targeted advertising, profiling, or marketing; to limit certain sensitive-information uses; to withdraw consent; and to appeal a denied request. These rights may be subject to identity verification, exceptions, and the roles described in Section 1.
To submit a request, email support@acewatt.com with the subject “Privacy Request” and describe the request, relationship to AceWatt, and relevant Customer account. We may request information reasonably necessary to verify identity and authority. An authorized agent must provide proof of authority where required. We will respond within the time required by applicable law. If AceWatt processes the information only for a Customer, we may direct the request to that Customer or act on its instructions.
Users can update some profile and company information in the Service. Communication recipients can use provided unsubscribe links or reply STOP to supported SMS messages. Transactional, security, billing, and legal notices may continue where permitted despite a marketing opt-out.
California residents may also request the categories and specific pieces of information collected, correction, deletion, information about disclosures, and opt-out or limitation where applicable. California law does not require a right that does not apply to AceWatt's current practices or legal status, and exceptions may apply. We do not provide financial incentives for personal information unless separately disclosed.
11. Precise location, recordings, signatures, and other sensitive data
Some Customers enable precise geolocation for clock, dispatch, route, geofence, or field features. Device permissions can disable future collection, but doing so may prevent those features. Customers determine when workforce tracking is enabled and must provide legally required notice and choices.
The Service may store call or voice recordings, transcripts, message contents, signatures, financial or workforce details, license and insurance records, emergency contacts, and account credentials or tokens for integrations. Customer must limit collection to what is lawful and necessary, configure access, and obtain consent. AceWatt uses this information to provide the requested feature, secure the Service, and follow Customer instructions; we do not use CRM Customer Data for targeted advertising.
12. AI processing
When a User invokes an AI feature, relevant prompts, documents, images, audio, metadata, and context may be sent to the configured AI or transcription provider to produce output. We may log usage, model, latency, cost, safety, correction, and result information to operate and improve the feature. Customers should not submit sensitive information unless authorized and necessary. AI providers may have their own retention and abuse-monitoring practices governed by our provider arrangements. AI output must be reviewed by a qualified person as described in the Terms.
13. International processing
AceWatt and its providers may process information in the United States and other countries with different data-protection laws. Where applicable law requires a transfer mechanism, we will use an approved contractual or legal safeguard. The Service is currently directed primarily to U.S. businesses; Customer must contact us before using it where additional localization, residency, or regulatory commitments are required.
14. Children
The Service is a business platform and is not directed to children or anyone under 18. We do not knowingly collect personal information directly from children for AceWatt's own purposes. Customers must not create User accounts for children or submit children's information unless they have a lawful business need, authority, required parental consent, and compliance process. Contact support@acewatt.com if you believe information was collected from a child unlawfully.
15. Changes to this Policy
We may update this Policy when practices, providers, features, or laws change. We will post a fixed effective date and version rather than generating a new date on every page load. If a change materially affects how account or Customer personal information is handled, we will provide reasonable notice as required. A material Terms or DPA change will require express acceptance through the versioned policy gate before normal CRM use resumes.
16. Contact
Privacy questions and requests may be sent to support@acewatt.com or by mail to ACEWATT, 13902 Hamlin St, Valley Glen, CA 91401.