Privacy Policy
Last updated: September 23, 2026
This Privacy Policy explains how Amend Solutions LLC ("Amend," "we," "us," or "our") collects, uses, shares, and protects information in connection with our software platform, mobile applications, websites, and related services (collectively, the "Service"). Amend provides an AI-native operating system and CRM built for contractors and service businesses, including our AI assistant, "Mend."
Please read this Policy together with our Terms of Service, Acceptable Use Policy, and, where we process personal data on your behalf, our Data Processing Addendum. By using the Service, you acknowledge the practices described here.
1. Scope & Our Roles
Amend serves businesses and, depending on the data involved, plays two different roles under privacy law.
- Customer Data (we are a "processor" / "service provider"). When a business customer ("Customer") subscribes to the Service and uses it to manage its operations, it uploads and generates data about its business, employees, clients, jobs, invoices, documents, and communications ("Customer Data"). With respect to Customer Data, the Customer is the "controller" / "business," and Amend acts as a "processor" / "service provider" that handles that data only on the Customer's behalf and under our agreement with them. Individuals whose personal information appears in Customer Data (for example, a Customer's own clients or staff) should direct privacy requests to the relevant Customer, and we will assist that Customer as required.
- Account & Website Data (we are the "controller"). For information we collect to create and administer accounts, bill for the Service, provide support, secure the platform, and operate our public websites, Amend is the controller and this Policy governs directly.
2. Information We Collect
2.1 Account & Contact Information
- Name, business name, email address, phone number, role, and login credentials.
- Company profile details you provide (address, trade/industry, service area, team members).
- Preferences and settings you configure within the Service.
2.2 Customer Data
- Content you and your team enter or upload into the Service: contacts and clients, leads and pipeline, jobs and schedules, estimates and invoices, documents and files, notes, messages, e-signatures, and similar business records.
- Any personal information about third parties (such as your customers or staff) that you choose to store in the Service is Customer Data, and you are responsible for having a lawful basis to provide it to us.
2.3 Usage, Log & Device Data
- Log data such as IP address, browser and device type, operating system, timestamps, referring pages, feature interactions, and error/diagnostic information.
- Content-free product analytics indicating that a feature was used, not the contents of what you typed or uploaded (see Section 13).
- Approximate location derived from IP address or, if you enable it in a field/mobile context, location you explicitly permit for job or check-in features.
Crew location, on shift only. Location is recorded only while a crew member has started a
shift, and continues while the phone is pocketed or the screen is off, with a notification showing on the device
throughout. It stops when the shift ends, and cannot start without the crew member opening the app and starting a
shift. Within your company, only owners, admins and office roles can see it, used for dispatch, job assignment and
timesheet accuracy.
Your location, if you allow it. If you ask Mend a question that depends on where you are (for example "what's the weather here" or "which of my jobs is closest"), Mend will ask your permission first. If you allow it, your approximate location — rounded to about 1 kilometre on your device — is used for that question only: it is sent to Apple Weather to get a forecast, or used on our own server to measure the distance to your jobs. Your location itself isn't saved; Mend's answer is saved with the conversation like any other answer. Mend uses your location only while the app is open, and you can say no, or turn off "always allow" at any time in Settings.
2.4 Payment Information
- Billing contact details and subscription/plan information.
- Payment card and transaction data is processed by our payment provider, Stripe. Amend does not store full payment card numbers on our servers. We may retain limited billing metadata (for example, the last four digits, card brand, expiration, and a payment token) returned by Stripe to manage your subscription.
- If you connect your own Stripe account to accept payments from your clients, Stripe tells us your Stripe account ID and whether the account has finished setup and can accept payments.
- If you connect your own PayPal account, PayPal shares your PayPal account ID, email address, and whether the account can receive payments, so we can show whether the connection is ready.
2.5 Communications
- Messages you send to us (support tickets, emails, chat, feedback) and our responses.
- Records of transactional emails and notifications we send you regarding your account and the Service.
2.6 AI Receptionist & Call Data (only if you enable it)
- If your workspace turns on the AI receptionist, we process data about calls it handles on your behalf: the caller's phone number, the time and duration of the call, an AI-generated summary and outcome, and any lead or appointment created from the call.
- This is Customer Data about your callers. You are responsible for providing any call-recording notice and obtaining any consent required by the laws of your and the caller's jurisdiction.
- The receptionist's voice and its AI reasoning both run on Google Cloud (Vertex AI) under our own model configuration (see Section 7). No separate voice or transcription vendor receives your call audio.
- What the feature does today: it runs only as an in-app test call. It does not answer a telephone number, no call audio is recorded, and no transcripts are stored. We have not engaged a telephony provider; we will list one in Section 7 before the receptionist can take a real call. If we later offer call recording or transcript retention, it will be off unless you switch it on, and we will update this Policy before it takes effect (see Section 16).
2.7 Bank Account & Transaction Data (only if you connect a bank)
- If you connect a business bank account in Amend Books, we use Plaid Inc. ("Plaid") to make that connection. You sign in to your bank through Plaid; we never receive or store your bank username or password.
- With your permission, Plaid sends us information about the account you choose: the bank's name, the account's name and last digits, and its transactions (date, amount, and description). We use it only to bring those transactions into your books for you to review. We do not use it to move money.
- Plaid's handling of your information is governed by the Plaid End User Privacy Policy. By connecting a bank account, you acknowledge that Plaid will collect, use, and share your information as that policy describes.
- You can disconnect a bank at any time. Disconnecting ends our access through Plaid. Transactions already imported stay in your books until you delete them or your account data is deleted (see Section 8).
2.8 Text Messages (only if you text us)
- If you text our support number, (213) 306-5576, we receive your phone number and your messages, and use them only to reply to you and help with your account. Twilio delivers these messages for us.
- We do not share, sell, or provide your mobile phone number or messaging consent data to third parties or affiliates for marketing or promotional purposes.
- The full terms for this support line are on our Text Message Terms page.
- Message frequency varies. Message and data rates may apply. Reply STOP to stop texts from us, or HELP for help.
2.9 Questions You Ask on Our Website
- If you type a question into the Ask box on amendsolutions.app, we send it to Google Cloud (Vertex AI) so our assistant can answer it, and we store the question and the answer so we can improve the answers and learn what people want to know about Amend.
- Before storing them, we remove email addresses and phone numbers. We encrypt what we store. We do not store your IP address; we keep a one-way code made from it, used only to limit how many questions one visitor can ask.
- We delete stored questions and answers, and those codes, after 30 days.
- Please do not type personal details, such as your name or address, into the box. If you did and want it removed sooner, contact us (Section 17).
3. How We Use Information
- Provide the Service — create and maintain your account, deliver features, sync data across web and mobile, and enable collaboration within your workspace.
- Operate AI features — power Mend and other AI-assisted capabilities you invoke (see Section 4).
- Secure the Service — authenticate users, detect and prevent fraud, abuse, and security incidents, and enforce our terms.
- Billing & payments — process subscriptions, invoices, and payments through Stripe.
- Support — respond to your questions, troubleshoot issues, and communicate about the Service.
- Improve the Service — understand aggregate, content-free usage patterns, diagnose problems, and develop new features. Separately, and only within your own workspace, Mend keeps written learnings derived from your business activity in order to serve you better; these are described in Section 5 and are never used across businesses.
- Legal & compliance — comply with applicable laws, respond to lawful requests, and protect the rights, property, and safety of Amend, our Customers, and the public.
4. AI Processing
Amend is AI-native. When you use an AI feature (such as asking Mend a question, drafting content, summarizing, or extracting information), your request together with the necessary workspace context is transmitted to one or more third-party AI model providers so a response can be generated and returned to you.
- Model providers. We currently rely on Google (Gemini) models, and may use other reputable model providers over time to deliver or improve AI features. These providers process your request under their applicable API terms strictly to return a response to us.
- What is sent. Only the request and the relevant workspace context needed to fulfill it are sent. We aim to send the minimum context required for the feature to work.
- No sale of data. We do not sell your personal information or Customer Data.
- No training on your data without consent. We do not use Customer Data to train our own foundation models, and we do not authorize our AI providers to train their foundation models on Customer Data submitted through the Service, without your consent. We rely on providers' enterprise/API terms that exclude API-submitted content from training by default where such terms apply.
- Learning is not training. Mend keeps written notes about how your business works so it can help you better (Section 5). That is different from training a model: no Customer Data changes the weights of any model, ours or a provider's, and one business's notes are never used for another.
5. What Mend Learns About Your Business
Mend gets more useful the longer you use it, because it keeps a small set of written notes about how your business works. We call these learnings, and we want to be specific about them.
- What is kept. Short statements about your operations — how you price a type of job, what you call a stage, which supplier you prefer, a correction you gave Mend. They are written in plain language, and you can read every one of them.
- Where they come from. Two places: facts you tell Mend directly, and a nightly pass in which Mend reviews your recent activity in the Service and writes down what it appears to have learned.
- Personal information is removed first. Before a learning is saved, we strip client names, dollar figures, addresses, email addresses, and phone numbers. If that removal step fails for any reason, the learning Mend wrote is discarded rather than saved.
- They never leave your company. A learning is encrypted with a key derived for your business alone and is readable only inside your workspace. Nothing Mend learns from your business is used to serve, or shown to, any other business.
- They are not used to train AI models unless you say so. Learnings give Mend context when it answers you. They are not used to train our models or anyone else’s, with one exception you control — see We never benchmark you against another business below.
- You control them. Go to Settings → AI to see every learning Mend holds, edit the wording, pin one so Mend always considers it, or delete it. A deleted learning is gone from Mend's context immediately. Learnings are included in your data export and are deleted when your account is deleted.
If you would rather Mend not keep learnings at all, contact us at [email protected] and we will turn the feature off for your workspace.
We never benchmark you against another business.
What happens in your workspace stays in your workspace. We do not use one customer’s data to answer
another customer’s question, and we never pool, compare or share your prices, your margins or your win
rates — with anyone, for any purpose.
There is one thing you can switch on, and it is off unless you switch it: you can let your corrections help
train the assistant for everyone. If you turn it on, we strip out names, addresses, phone numbers, emails and
dollar amounts first, we only use ordinary day-to-day work — anything touching payroll, bank data, employee location or an uploaded document is never eligible — and your prices are never
included. You can turn it off whenever you like, and turning it off stops anything new being used from
that moment.
6. How We Share Information
We share information only in the limited circumstances below. We do not sell your personal information.
None of these circumstances includes text messaging: we do not share, sell, or provide your mobile phone number or messaging consent data to third parties or affiliates for marketing or promotional purposes (see Section 2.8).
- Service providers & subprocessors. We use trusted vendors to run the Service — including cloud hosting and object storage, payment processing (Stripe), bank account connections (Plaid), AI model providers (Google and others), transactional email delivery, and content-free analytics. These vendors may process data only to provide services to us and are bound by confidentiality and data-protection obligations. See Section 7.
- Within your workspace. Customer Data is accessible to authorized users in your organization according to the roles and permissions your administrators configure.
- Legal & safety. We may disclose information if required by law, subpoena, or legal process, or where we believe in good faith that disclosure is necessary to protect the rights, property, or safety of Amend, our Customers, or others, or to prevent fraud or security threats.
- Business transfer. If Amend is involved in a merger, acquisition, financing, reorganization, or sale of assets, information may be transferred as part of that transaction, subject to this Policy or a successor policy with comparable protections.
- With your direction or consent. We share information when you ask us to or otherwise consent.
7. Subprocessors
We engage third-party subprocessors to help operate the Service. The current list, with the service each one performs and when it receives information, is published on our Service providers page, together with the services your business can choose to connect. We update that page before a change takes effect.
Customer Data is stored and processed in the United States, in Google Cloud's us-west1 region. Where a subprocessor is used only for a feature you turn on, it receives data solely when you activate that feature.
We have not engaged a telephony provider for the AI receptionist. We will add one to the Service providers page, and update Section 2.6, before the feature is able to answer a real phone number.
8. Data Retention & Deletion
- We retain Customer Data for as long as your account is active or as needed to provide the Service, and thereafter as instructed by the Customer or as required by law.
- Account and billing records are retained as needed to operate our business, meet legal, tax, and accounting obligations, resolve disputes, and enforce our agreements.
- Upon termination of an account, we will delete or return Customer Data in accordance with our agreement with the Customer and applicable law, subject to reasonable backup retention windows and legal-hold obligations. Residual copies may persist in encrypted backups until those backups are rotated out. Our backups are append-only by design: the credential that writes them cannot delete them, which protects your data from ransomware and from a stolen key.
- Questions typed into the Ask box on our website are deleted after 30 days (Section 2.9).
- You may request deletion of your personal information as described in Section 10.
9. Security
We take the security of your data seriously and apply administrative, technical, and organizational safeguards, including:
- Per-tenant encryption at rest — sensitive Customer Data is encrypted at rest with AES-256-GCM under a key derived uniquely for each business, so tenants' data is cryptographically isolated.
- Encrypted connections — data in transit is protected with industry-standard TLS encryption.
- Signed, expiring sessions with fast revocation — authenticated sessions use signed tokens that expire, and are revoked within seconds when a password or a user's access changes.
- Server-enforced access controls — least-privilege role-based permissions enforced on the server for both the application and the Mend AI assistant, so access limits can't be bypassed through the interface or the assistant.
- Automated off-site backups — over encrypted transport, with sensitive data encrypted at rest in the backup.
If there is a breach. If we confirm a security breach that affects your personal information or Customer Data, we will notify affected Customers without undue delay, and in any event within 72 hours of confirming it, and tell them what happened and what we are doing about it.
No method of transmission or storage is 100% secure. While we work hard to protect your information, we cannot guarantee absolute security. Please safeguard your credentials and notify us promptly of any suspected unauthorized access at [email protected].
10. Your Rights & Choices
Subject to applicable law and your relationship with us, you may:
- Access the personal information we hold about you.
- Correct inaccurate or incomplete information.
- Export a copy of your data in a portable format.
- Delete your personal information, subject to legal and contractual retention needs.
- Opt out of non-essential and marketing emails via the unsubscribe link or your account settings. We may still send essential transactional and service messages related to your account.
If your personal information is contained in a Customer's workspace as Customer Data, please contact that Customer directly; we will support them in responding. To exercise rights where Amend is the controller, contact [email protected]. We may need to verify your identity before acting on a request.
11. GDPR (EEA / UK) Rights
If you are located in the European Economic Area, the United Kingdom, or Switzerland, you have rights under the GDPR / UK GDPR, including the rights to access, rectification, erasure, restriction of processing, data portability, and objection, and the right to lodge a complaint with your supervisory authority.
Legal bases. Where Amend is a controller, we process personal information on the following legal bases:
- Contract — to provide the Service you or your organization requested.
- Legitimate interests — to secure, maintain, and improve the Service, prevent fraud, and communicate about it, balanced against your rights.
- Legal obligation — to comply with applicable laws.
- Consent — where required, for example for certain communications; you may withdraw consent at any time.
Where Amend processes Customer Data on behalf of a Customer, we act as a processor and the Customer is the controller responsible for the legal basis.
International transfers. We and our subprocessors may process and store information in the United States and other countries. Where required, we rely on appropriate safeguards for cross-border transfers, such as the European Commission's Standard Contractual Clauses (and the UK Addendum) or other lawful transfer mechanisms.
12. CCPA / CPRA (California) Rights
If you are a California resident, you have the right to:
- Know the categories and specific pieces of personal information we collect, use, and disclose.
- Delete personal information we have collected, subject to exceptions.
- Correct inaccurate personal information.
- Opt out of the "sale" or "sharing" of personal information. Amend does not sell or share personal information as those terms are defined under the CCPA/CPRA, and we do not use or disclose sensitive personal information for purposes requiring a right to limit.
- Non-discrimination — we will not discriminate against you for exercising your privacy rights.
You may submit a request via [email protected]. You may use an authorized agent to make a request, and we may take steps to verify identity and authority. Where Amend acts as a service provider handling personal information on a business's behalf, requests should generally be directed to that business.
13. Cookies & Similar Technologies
- We use a strictly-necessary, signed session cookie to keep you logged in and to secure your session. This cookie is essential to operate the Service.
- We do not use third-party advertising cookies, ad networks, or cross-site behavioral tracking.
- Any analytics we perform is content-free and pseudonymized — it records that features are used, not what you typed, uploaded, or messaged.
- You can control cookies through your browser settings, but disabling the session cookie will prevent you from logging in and using the Service.
14. Children's Privacy
The Service is intended for business use by adults and is not directed to children. We do not knowingly collect personal information from children under 13 (or under 16 where a higher age applies). If you believe a child has provided us personal information, contact us and we will take appropriate steps to delete it.
15. International Users
Amend is operated from the United States. If you access the Service from outside the U.S., you understand that your information may be transferred to, stored, and processed in the United States and other countries where we or our subprocessors operate, which may have data-protection laws different from those in your jurisdiction. We take steps described in this Policy to protect your information wherever it is processed.
16. Changes to This Policy
We may update this Policy from time to time to reflect changes in our practices, technology, legal requirements, or the Service. When we make material changes, we will update the "Last updated" date above and, where appropriate, provide additional notice (such as by email or an in-product notice). Your continued use of the Service after an update takes effect constitutes acceptance of the revised Policy.
17. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, contact us at: