Privacy policy

Thumbtack Command Center Privacy Policy

This policy explains how BuildWithCory handles information when you use Thumbtack Command Center, its Chrome connector, background sync, Command features, billing, messaging, and support.

Connection The Thumbtack cookie jar, CSRF token, and browser user agent are encrypted on the backend.
Sync Connected workspaces can sync leads and payments in the background.
Control Customer actions need approval or an enabled rule.
No sale Workspace data is not sold or used for advertising.

Scope And Operator

BuildWithCory operates Thumbtack Command Center and Command Center Connector for Thumbtack. This policy applies to the web app at thumbtack.buildwithcory.com, the Chrome extension, and related account, sync, Command, billing, messaging, support, security, and operational alert features.

Thumbtack Command Center is an independent service. It is not made by, endorsed by, approved by, or affiliated with Thumbtack. Thumbtack and other connected services control their own products, terms, and privacy practices.

Information We Handle

Account And Workspace Data

We handle your name, email address, business and workspace name, sign in state, account role, subscription status, setup progress, settings, support messages, Command conversations, proposed actions, approvals, and audit history.

Chrome And Thumbtack Session Data

When you choose Connect, the extension reads the Thumbtack authentication and session cookies available to the signed in Thumbtack pages. It also reads the optional Thumbtack CSRF browser safety token from the page and your Chrome browser user agent. It sends those items, the account label, and the one time setup key to the BuildWithCory backend over HTTPS.

The backend encrypts the structured cookie jar, CSRF browser safety token, and browser user agent before storage. Cookie domain, host, path, security, and expiration scope are preserved so a cookie is sent only to an approved Thumbtack HTTPS address for which it is valid. The account label is stored to identify the connection. Chrome local storage keeps the account ID and label, connector token and expiration, disclosure version, optional browser safety token, and health state needed to remain paired.

The backend can use the stored session and browser user agent to sync leads, customer contact details, inbox messages, charges, payments, and refund activity in the background, including while Chrome is closed. Before any connection data is collected, the extension presents this disclosure with an unchecked consent control. A versioned acceptance receipt is required by the extension and backend for every fresh connection.

Raw cookies, connector tokens, and security tokens are treated as secrets and are not intentionally placed in ordinary activity records or Discord alerts.

Lead, Contact, Message, And Payment Data

When Thumbtack is connected, the service can handle lead and customer names, available contact details, service requests, project descriptions, locations, message threads, appointment or schedule context, charges, payment activity, refund requests and results, notes, source references, and related activity visible to the connected account. We do not intentionally collect full payment card numbers through the Command Center.

Background Sync

While an eligible workspace remains connected, the backend can use the stored encrypted Thumbtack session to check for lead, inbox, message, charge, payment, and refund activity on a schedule or after a configured inbound trigger. This background processing can occur when you are not actively viewing the web app. New records can also be evaluated against rules you have enabled.

Optional Integration Data

If you connect optional tools, we handle the settings and data needed for the selected feature. This can include Gmail authorization data, calendar availability, customer phone numbers, approved message content, SMS provider credentials, owner test results, billing identifiers, subscription state, and integration health. Connected services can include Google, Gmail, Calendar, Stripe, Twilio, OpenPhone, Quo, BlueBubbles, OpenAI, or a compatible model provider.

Usage And Security Data

We handle backend request paths, timestamps, browser and device details supplied with requests, network address or a one way network address hash, error details, server recorded feature and lifecycle events, download events, and information you submit through support or authentication forms. Browser telemetry is disabled, and the app does not run a generic click or form collector. We use this information for security, reliability, support, and product operations. It is not used for targeted advertising.

How We Use Information

  • Authenticate users and provide a private workspace.
  • Connect a signed in Thumbtack browser session and report connection health.
  • Sync and organize leads, messages, contacts, charges, payments, refunds, and activity.
  • Draft, summarize, classify, and prepare proposed actions.
  • Deliver an action after a user approves it or after a rule the workspace owner expressly enabled authorizes it.
  • Process subscriptions, provide support, investigate failures, prevent abuse, secure the service, and maintain backups.
  • Comply with law and enforce the Terms of Service.

Chrome Extension Permissions

The extension uses permissions for the single purpose of connecting an authorized Thumbtack session to the related private Command Center workspace, supporting the disclosed sync, and delivering authorized actions.

  • Cookies: reads Thumbtack authentication and session cookies during a consented connection so the backend can use the session the user chose to connect. Domain, host, path, security, and expiration scope are preserved.
  • Scripting: runs bounded logic in a Thumbtack tab for setup or an authorized browser action.
  • Storage: keeps the account label and ID, connector token and expiration, current disclosure version, optional browser safety token, fixed Command Center target, and connection health state.
  • Alarms: checks the authorized action queue and sends connection health heartbeats while Chrome is open.
  • Host access: is limited to Thumbtack domains and the Command Center web app for connection, tab lookup, polling, heartbeat, and authorized browser delivery.

Use of information received through Chrome extension permissions is limited to the disclosed user facing feature, security, and reliability, consistent with the Chrome Web Store User Data Policy, including its Limited Use requirements.

Approvals And Rule Authorized Automation

Some actions require a specific review and approval. A workspace owner can also expressly enable a messaging rule that authorizes matching actions until the rule is disabled or changed. The service checks current workspace eligibility, provider readiness, rule state, customer opt out state, and relevant lead data before delivery. A stale or changed rule, changed lead, failed provider test, missing session, provider restriction, or uncertain browser result can stop delivery or require manual review.

Enabling a rule does not guarantee delivery, customer response, refund approval, revenue, or continued access to Thumbtack or another provider.

OpenAI And Command Processing

When external AI mode is configured and you use Command features, the service can send your prompt, recent Command messages, limited Thumbtack workspace context, and needed tool results to OpenAI or the configured compatible provider. The service applies field and scope filtering before model processing, but the submitted context can still include lead, message, contact, payment, or refund information needed to answer the request.

In stateful mode, the service asks the model provider to store response state so a conversation can continue. In stateless mode, the service asks the provider not to store response state and sends the necessary conversation context with each request. Provider security logs, abuse monitoring, and other retention can still apply under the provider agreement and configured account settings. If external AI is not configured, supported Command work uses local deterministic processing.

Provider derived Command prompts, proposal edits, confirmations, replies, retries, customer messages, refund emails, and automation previews are disabled whenever the written permission gate is off. The current helper checks the live permission flag, disclosure version, and minimum helper version before reading current Thumbtack page DOM, session data, or cookies. It can inspect the active tab URL first only to detect a provider deactivation page and revoke access. Existing local records remain visible, and controls for cancellation, Disconnect, provider outcome verification, and existing subscription management remain available.

Private Discord Operational Alerts

Selected service events for a workspace owned by the configured Cory operator account can be sent to private Discord channels used and monitored only by Cory, the BuildWithCory operator. Other customer workspaces do not send customer or workspace alerts to Discord. Cory workspace alerts can include a workspace or user identity, lead label, limited money or action summary, status, error summary, browser type, request path, and a one way network address hash. Alerts are used for operations, reliability, security, and support. They are not public and are not used for advertising.

The alert system is designed to remove raw cookies, authorization values, security tokens, passwords, provider secrets, and sensitive query values. Discord still processes the alert fields that are sent under its own terms and privacy policy.

Service Providers And Disclosure

We do not sell personal information. We do not use or transfer workspace data for targeted advertising, interest based advertising, credit decisions, or lending.

Information is disclosed only as needed for these purposes:

  • Infrastructure: hosting, storage, backup, security, logging, email, and support systems used to run the service.
  • Services you connect or direct: Thumbtack, Google, Gmail, Calendar, Stripe, Twilio, OpenPhone, Quo, BlueBubbles, or similar tools.
  • AI processing: OpenAI or a configured compatible provider when you use an external Command feature.
  • Private operations: Discord for the limited Cory only alerts described above.
  • Law and safety: when reasonably necessary to comply with law, protect a person, investigate abuse, or defend legal rights.
  • Business change: as part of a sale, merger, financing, or transfer only after required notice and any explicit prior consent required by applicable Chrome Web Store policy or law.

Human Access To Workspace Data

BuildWithCory does not routinely read full customer conversations. Cory can review specific workspace data when you ask for support and consent to that review, when it is necessary to investigate a security or abuse issue, when law requires it, or when data has been aggregated and deidentified for internal operations. Cory can also see the limited private operational alerts described above.

Retention And Security

Workspace and operational records are kept while needed to provide the service and for reasonable periods needed for support, security, accounting, backup recovery, legal compliance, and dispute handling. Retention can vary by record type and connected provider. Model provider retention depends on the configured stateful or stateless mode, provider account settings, and provider rules.

We use HTTPS, access controls, restricted production access, database protections, hashed connector credentials, redaction, and AES 256 GCM authenticated encryption for stored Thumbtack cookie jars, CSRF browser safety tokens, and browser user agents. No internet service is perfectly secure. Keep your devices and connected accounts protected and notify support if you suspect unauthorized access.

Provider Restrictions And Deactivation

Thumbtack and other providers can change access, challenge a request, expire a session, restrict automation, suspend an account, or deactivate an account. Command Center does not bypass those controls. When the service detects a provider restriction, it marks the account restricted, revokes the connector token, deletes the stored provider session, stops new sync and automation work, and safely cancels unsent queued browser actions. An action that already started can have an uncertain outcome and must be checked directly with the provider. Documented written provider permission, reconnection, and manual review are required before new provider work can resume.

A provider restriction does not mean BuildWithCory caused or controls the provider decision. See the Terms of Service for account risk and responsibility terms.

Disconnecting, Deletion, And Your Rights

  • Use the in app Disconnect control to remove the encrypted provider session from the backend, revoke the connector token, stop sync and automation, and cancel unsent queued browser actions.
  • Disabling or removing the Chrome extension stops activity in that browser but does not by itself stop backend sync from a previously stored session. Use Disconnect as well.
  • Disable messaging rules and optional integrations in the workspace where controls are available.
  • Cancel a paid subscription separately through the billing controls. Removing the extension does not cancel billing.
  • Removing a lead from Inbox hides it from active views and agent context and cancels unsent work. It does not delete historical records. Request verified deletion through Support.
  • Request access, correction, export, or deletion by emailing support. We verify the request before acting.

Deletion removes active records within a reasonable period, subject to limited retention required for security, fraud prevention, accounting, legal obligations, dispute records, and backup recovery. Depending on where you live, law can provide additional rights or an appeal process.

Children

The service is for business users who are at least 18. It is not directed to children, and BuildWithCory does not knowingly collect personal information from a child through the service.

Changes To This Policy

We can update this policy when the product, providers, law, or review requirements change. The page will show the new date. We will provide reasonable additional notice before a material change applies when required.

Contact

BuildWithCory is the service operator. Send privacy questions, access requests, and deletion requests to support@buildwithcory.com.