The short version
- For our own visitors, leads and clients, Summit decides how personal information is used. For our clients’ customers, the client decides, and we only handle that information for the client.
- We do not sell personal information.
- We use AI (Anthropic’s Claude) in chat assistants, meeting notes, our own planning tools and some features of our clients’ software.
- Our servers are in the European Union. Our backups and most of our service providers are in the United States.
- Our marketing pages set no cookies and carry no analytics or advertising tags. The demo websites we build for businesses do record visits, including your IP address.
- To see, correct, export or delete your information, or to stop our messages, email info@summitintegrations.com.
1. Who we are and our two roles
Summit Integrations LLC (“Summit”, “we”, “us”) is a Texas limited liability company. We sell to businesses in Canada and the United States. We build websites, set up and run booking and follow-up systems for service businesses (inside software the business already uses, such as Jobber or Housecall Pro, or on our own CRM at summitclient.com), manage Google and Meta advertising, and build custom software.
We handle personal information in two different roles.
- As the organisation in charge (a “controller”, or a “business” under US state law) for the people we deal with directly: visitors to our websites, people who fill in our surveys or book a call, businesses we contact, our clients and their staff, and our suppliers. Most of this policy is about that role.
- As a service provider (a “processor”) for our clients. When a client uses our CRM, a chat assistant we run on its website, or custom software we host, the information about the client’s own customers belongs to the client. We handle it only on the client’s instructions. See section 13.
2. What we collect and where it comes from
From you
- Surveys and forms. Your answers (for example the service you need and where you are), your name, email address and phone number, and whether you agreed to receive texts.
- Our booking page. Your name, email address, phone number and time zone, the time you choose, anything you write in the booking form, and whether you agreed to receive texts.
- Calls, texts, emails and meetings. Your phone number or email address and what you write or say to us. For meetings we record, the recording, a transcript and notes (see section 10).
- When you become a client. Billing contact details, the access you give us to your accounts and tools, the content you send for your website, ads or software, and our contract records.
- Accounts in our software. Your email address, a scrambled (hashed) version of your password, and records of your sign-ins, including IP address and browser.
From advertising platforms and links
- Ad lead forms. If you fill in a lead form inside Meta or Google, the platform can pass us what you entered.
- Link tags. If you reach us from an ad or email, the link can carry tags that name the campaign or ad. We store them with your enquiry so we know what brought you.
From public sources
- Public business listings. Business names, phone numbers, websites, locations and categories from public map and directory listings, such as Google Maps, and from businesses’ own websites. We use these to build lists of businesses we may contact and to build demo websites for them.
From payments
Card payments are processed by Stripe. You enter card or bank details on Stripe’s pages, and we never see or store your full card number. Stripe tells us the amount, date and status of a payment, your billing name, email and country, and limited card details such as the brand and last four digits. If you pay by bank transfer, our bank shows us the sender’s name and the amount.
Automatically
- Web server logs. Our web servers record the IP address, browser type, page requested, referring page and time of each request.
- Demo websites. When we build a demo website for a business, the demo records each visit: a random visitor ID stored in your browser, the page, the referring page, how long you stayed, your IP address, your browser and device type, and your approximate location (country, region and city). We look up the approximate location from your IP address using a service called ip-api.com.
- Chat on demo websites. What you type into the chat, with your IP address and browser type.
- Survey pages. Which steps of the survey you viewed and the link tags you arrived with, recorded against a random visit ID rather than your IP address.
3. How we use it
- To answer you, book and hold calls, and send what you asked for.
- To decide whether we can help your business, and to prepare proposals.
- To deliver our services: building your website, setting up your systems, running your ads and supporting you.
- To bill you, collect payment and keep accounting and tax records.
- To send service messages, such as booking details, reminders, invoices and account notices.
- To market our services to businesses, where the law allows it (see section 9).
- To learn which ads, messages and demos work. For example, demo visit records tell us whether a business opened its demo.
- To keep our systems secure, prevent abuse and fix problems.
- To meet legal duties and enforce our agreements.
Automatic checks on our surveys
Some of our survey pages check your answers against simple rules, for example whether you are in an area we serve. If your answers do not fit, the page does not offer you a booking time. The check is automatic and does not use AI. If you think it got your answer wrong, email us and a person will look at it.
We use personal information only for these purposes or for purposes you agree to. If we want to use it for something new, we will ask first where the law requires it.
4. How we use AI
We use AI models made by Anthropic (Claude). When we do, the text needed for the task is sent to Anthropic, which returns a result. Anthropic handles it under its own commercial and privacy terms.
- Chat assistants. The chat on our demo websites, and on some of our clients’ websites, is an AI assistant, not a person. Your messages go to Claude to write the replies, and the replies are sent automatically. On our demo websites we keep the conversation with your IP address and browser type. The assistants we run on clients’ websites do not keep the conversation.
- Meeting notes. When we record a meeting, Deepgram turns the audio into a transcript and Claude writes notes from it.
- Our own planning tools. Our internal assistants summarise our sales pipeline and business numbers. They can see business names, deal details and a contact’s first name. They are not given email addresses or phone numbers.
- Text replies. Our text-messaging system includes an AI assistant that can answer replies to our texts. It is switched off today.
- In our clients’ software. Clients can use AI in our CRM to draft or send replies to their customers’ messages and to read photos and documents they upload. We do this for the client, as its service provider.
We do not use AI to make decisions about you that have legal or similarly significant effects.
6. Where your information is stored
Our servers are in a data centre in the European Union. Our off-site backups are stored with GitHub in the United States, and most of our other service providers process information in the United States.
This means your information is stored and processed outside your province, state or country, including outside Canada and outside Quebec. While it is there, the courts, law enforcement and national security authorities of those countries may be able to access it under their laws. Each provider handles the information under its own terms and the laws of the places where it operates.
7. How long we keep it
- Web server logs: 14 days.
- Backups: copies taken every 15 minutes are kept for about a day. Daily off-site copies are rotated after 30 days, but older copies stay in the history of our backup store until we purge it.
- Incoming lead forms: the raw copy of a lead sent to us is cleared once it has been filed in our CRM.
- Opt-out and do-not-contact records: kept permanently, with only what we need to keep honouring your request (your email address or phone number, and the reason).
- Financial records: for as long as tax and accounting law requires, which can be seven years or more.
- Everything else: we do not yet delete other records automatically. Leads and contact details, demo visit records, chat logs, messages, meeting recordings and notes, and sign-in records are kept until we delete them. When we set fixed deletion periods, we will list them here.
You can ask us to delete your information at any time (see section 14).
8. How we protect it
- Our websites and software use encrypted connections (HTTPS).
- In our CRM, each client’s data is kept separate from every other client’s data by the database itself, not only by the screens.
- Access is limited to the people who need it. Passwords are stored scrambled (hashed), repeated failed sign-ins are limited, and sign-ins and staff access are logged.
- We back up our databases several times a day and test restoring them every week.
No system is perfectly secure. If a breach creates a real risk of significant harm to you, we will tell you and the authorities as the law requires, including under Canada’s PIPEDA, Quebec law and Texas law.
9. Emails, texts and calls
For people in Canada, we send marketing email only with consent as Canada’s Anti-Spam Legislation (CASL) defines it. That means consent you gave us, or implied consent, for example from an existing business relationship, or where a business publishes its email address without saying it does not want marketing and our message is about its business. For people in the United States, our marketing email follows the CAN-SPAM Act.
Our marketing emails name Summit Integrations LLC, give our mailing address and tell you how to unsubscribe. Replying “unsubscribe” also works. We act on the request within 10 business days and keep a record of it so we do not email you again.
Texts
- Today we send texts only to people who asked for them, for example by ticking the box on our survey or booking page, or about something you asked us to do.
- We do not send marketing texts to US phone numbers at this time.
- Reply STOP to any text from us and we will stop texting you and record your request.
- Our automated texts are not sent overnight in your time zone.
Calls
We may call a business at the phone number it publishes, to talk about our services. Our calls are made by a person. We do not use prerecorded or artificial voices. Ask us to stop calling and we will add your number to our do-not-call list. This follows Canada’s telemarketing rules and the US Telephone Consumer Protection Act (TCPA).
10. Recorded meetings and calls
We do not record our sales calls today. We sometimes record video meetings and calls with prospects and clients so we have accurate notes. We tell everyone before a recording starts, and if you would rather not be recorded, say so and we will not record.
When we record, Deepgram turns the audio into a transcript and Anthropic’s Claude writes notes from it. The recording, transcript and notes are kept until we delete them. Ask us and we will delete them.
12. Location data
Our websites do not track your precise location. Demo websites record only an approximate location worked out from your IP address, as described in section 2.
Our CRM has a live tracking feature that a client can switch on for its customers. When a technician taps “on my way”, the technician’s phone shares its location with our system while the job page is open. The customer can follow the technician’s first name, arrival time and position through a private link that expires, 12 hours after it is created by default. We keep only the technician’s latest position for that job. Photos technicians upload have their location data removed. The client, as the technician’s employer, is responsible for telling its staff about this feature.
13. If you are a customer of one of our clients
If a business you deal with uses our CRM, a chat assistant we run, or software we host, your information is held for that business. The business decides what is collected and how it is used, and its own privacy policy applies. We handle the information only to provide our service to that business and on its instructions. We do not use it to market our own services, and we do not sell it.
To ask about, correct or delete your information, contact the business you deal with. We will help it respond. If you contact us directly, we will pass your request to that business.
14. Your rights and how to use them
Wherever you live, you can ask us to:
- tell you what personal information we hold about you and give you a copy,
- correct information that is wrong or incomplete,
- delete your information, unless we must keep it by law or to finish a contract with you,
- give you your information in a common, machine-readable format so you can take it elsewhere (clients can ask us for a full export of their data, or download it from our CRM where that option is available),
- stop sending you marketing, or withdraw a consent you gave us.
Email info@summitintegrations.com. We may need to confirm who you are before we act. We reply within 30 days and tell you if we need more time. There is no charge. Withdrawing consent does not affect what we did before, and if it stops us from providing a service, we will tell you.
15. Canada and Quebec
We handle personal information of people in Canada in line with the Personal Information Protection and Electronic Documents Act (PIPEDA) and, for people in Quebec, the Act respecting the protection of personal information in the private sector as amended by Law 25.
The person in charge of the protection of personal information at Summit is our Privacy Officer, who can be reached at info@summitintegrations.com. Section 3 explains the one automatic check we use (on our surveys) and how to ask a person to review it. Section 6 explains that your information is stored outside Quebec and Canada.
16. Texas and other US states
Summit is based in Texas and is a small business under the US Small Business Administration’s definitions. For that reason most of the Texas Data Privacy and Security Act does not apply to us. We do not sell personal data, including sensitive personal data, and we do not use it for targeted advertising. Other state privacy laws, such as California’s, apply only to businesses above size thresholds we do not meet.
We still honour the rights in section 14 for people in every state. If we turn down a request, you can appeal by replying to our decision. We will answer the appeal in writing, and if you are still not satisfied you can contact your state attorney general.
17. Children
Our services are for businesses and are not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child has given us information, contact us and we will delete it.
18. Changes to this policy
We update this policy when our services, our providers or the law change. We post the new version here with a new “Last updated” date, and we email our clients about any material change.
19. Privacy Officer and complaints
Questions, requests and complaints about privacy go to our Privacy Officer:
Privacy Officer, Summit Integrations LLC5900 Balcones Drive, STE 100
Austin, TX 78731, United States
info@summitintegrations.com
If you are not satisfied with our answer, you can complain to the Office of the Privacy Commissioner of Canada, to the Commission d’accès à l’information du Québec, to the privacy commissioner of your province (for example in Alberta or British Columbia), or in the United States to your state attorney general.