Privacy Policy
Effective Date: September 8, 2026 Last Updated: September 8, 2026
This Privacy Policy explains how Chicago Renovation Studio ("CRS," "we," "us," or "our") collects, uses, discloses, and protects information — including through the AI-powered automation tools we use to run our business — when you interact with us or use our website. This policy is published at chicagorenovationstudio.com/privacy.
By using our website or engaging with CRS, you agree to the collection and use of information as described here. If you do not agree, please do not use our website or services.
A note on scope: CRS uses Google Workspace and Intuit QuickBooks Online integrations internally, through our own operations tools, to run day-to-day business functions like client communication and bookkeeping. We are not a software company distributing an app to the public — but because our internal tools connect to Google's and Intuit's APIs, both companies require us to publish a policy meeting their disclosure standards. Sections 3 and 4 below satisfy those requirements.
1. Who We Are and What We Do
Chicago Renovation Studio is a Chicago-based general contracting and residential remodeling company. We use a set of internal, staff-operated AI automation tools — connected to our business Google account and our QuickBooks Online account — to help manage client communications, scheduling, and bookkeeping. These tools are operated by CRS staff for CRS's own business purposes; they are not made available for the public or clients to install or connect their own accounts to.
2. Information We Collect
2.1 Client and Contact Data
When you contact us — by phone, text, email, web form, or social media — we collect information such as your name, phone number, email address, project address, and details about the work you're inquiring about.
2.2 Data From Connected Business Platforms (Google and Intuit QuickBooks)
Our internal automation tools access data from our own Google Workspace account and our own QuickBooks Online account, as described in Sections 3 and 4, solely to run CRS's business operations (drafting client replies, reconciling bookkeeping records, etc.). No client or third party connects their own Google or QuickBooks account to our systems.
2.3 Usage and Log Data
Our website automatically collects standard technical information such as IP address, browser type, device identifiers, pages viewed, and timestamps.
2.4 Cookies
We use cookies and similar technologies as described in Section 12.
3. Google User Data
3.1 The App Accesses Google User Data
CRS's internal business automation ("the App") accesses data in our own Google Workspace account (Gmail and, where connected, Google Drive) through Google APIs, using the OAuth scopes below. This account belongs to CRS — it is used to manage the business's own inbound client email and shared files, not to access any other person's Google account.
3.2 Google OAuth Scopes We Request
ScopePlain-Language PurposeGmail — read (gmail.readonly or gmail.metadata)Lets our system read incoming messages sent to our business inbox so client inquiries can be triaged and routed to the right pipeline.Gmail — send (gmail.send)Lets our system draft and send email replies to client inquiries on our behalf, subject to staff review for anything non-routine.Google Drive — read (drive.readonly or drive.file)[Confirm with your automation provider whether this is enabled.] Lets our system read job-site photo/video files placed in a shared folder, for use in our content and marketing workflow.
The exact scopes above should be checked against what's actually configured on the Google Cloud OAuth consent screen for this project — see the setup checklist delivered alongside this document. Remove any row above that isn't actually enabled, and add any that are (e.g., Google Calendar, if scheduling is later connected directly rather than through GoHighLevel).
3.3 Limited Use Disclosure
CRS's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically:
We do not use Google user data for serving advertisements of any kind.
We do not sell Google user data.
We do not allow humans to read Google user data except in the following limited circumstances:
With the relevant person's explicit consent;
Where necessary for security purposes, such as investigating suspicious activity;
Where necessary to comply with applicable law; or
Where the data has been aggregated and anonymized.
We do not transfer Google user data to third parties, except:
As necessary to provide or improve the features of our internal business tools (only under confidentiality and data-protection obligations — see Section 6);
For security purposes;
To comply with applicable law, regulation, legal process, or enforceable governmental request; or
As part of a merger, acquisition, or sale of assets, with prior notice.
3.4 Storage, Encryption, and Retention of Google User Data
Google account data accessed by our tools is processed through our automation platform provider(s) [name the specific vendor(s) here once confirmed — see checklist] and is encrypted in transit via TLS 1.2 or higher. We retain synced Gmail/Drive data only as long as needed to service the related client inquiry, and in no case longer than 12 months, after which it is deleted from our systems.
3.5 How to Revoke Access and Request Deletion
Because this is our own business Google account (not a third party's), day-to-day revocation is handled by CRS directly:
CRS staff: Access can be revoked at any time from the Google Cloud Console for this project, or by removing the app's access at myaccount.google.com/permissions on the connected account.
If you are a client or contact and want data about you deleted from our systems (including anything captured through email or our automation tools), email info@chicagorenovationstudio.com with the subject line "Data Deletion Request." We will confirm and complete deletion within 30 days, except where we're required to retain certain records by law (for example, contract or tax records).
4. Intuit QuickBooks Data
4.1 The App Connects to Intuit QuickBooks
Our internal bookkeeping automation connects to CRS's own QuickBooks Online account so that transactions can be automatically reconciled against job costs, flagged for missing receipts or uncategorized expenses, and summarized into a weekly financial snapshot for the business owner. This connection is to CRS's own company file — no client or outside party connects their own QuickBooks account.
4.2 QuickBooks Data We Access and Why
Data CategoryAccessed?PurposeCompany information (name, address, industry)YesIdentifies which QuickBooks company file is connected.Transactions / General ledgerYesWeekly reconciliation against job costs; flags missing receipts and uncategorized expenses.Vendors / BillsYesExpense tracking and categorization.Customers[Confirm — likely No unless invoicing is added later]—Invoices[Confirm — likely No]—Payments[Confirm — likely No; only needed if QuickBooks Payments scope is enabled]—PayrollNoNot accessed.
4.3 Intuit Scopes We Request
ScopePurposecom.intuit.quickbooks.accountingRead transaction, vendor, and company data for weekly bookkeeping reconciliation.openid / profile / emailIdentify and authenticate the connected QuickBooks company.
If QuickBooks Payments (com.intuit.quickbooks.payment) is enabled, add it here with its specific purpose and complete Section 4.5 below in full.
4.4 Security Controls
Encryption in transit: All data transmitted between our systems and Intuit's servers uses TLS 1.2 or higher.
Encryption at rest: QuickBooks data stored by our automation tools is encrypted at rest.
Access controls: Access to the connected QuickBooks account is restricted to CRS ownership and authorized bookkeeping staff only.
Token handling: OAuth tokens issued by Intuit are stored encrypted, are never shared with third parties, and are used only to make authorized API calls for CRS's own reconciliation workflow.
4.5 Payment Data and PCI Posture
CRS does not currently request Intuit's payment scopes and does not process, transmit, or store payment card data through this integration. We do not store full payment card numbers or sensitive authentication data. [Update this section if QuickBooks Payments is added later.]
4.6 Disconnecting QuickBooks
If the QuickBooks connection is disconnected (from within our tools or from the Intuit App Center):
The associated OAuth token is immediately revoked and stops working.
All further access to QuickBooks data stops immediately.
Previously synced QuickBooks data is deleted from our systems within 30 days, except where retention is required for tax or accounting recordkeeping purposes.
4.7 No Affiliation With Intuit
Intuit Inc. is an independent company and is not affiliated with, and does not endorse or sponsor, Chicago Renovation Studio beyond our use of QuickBooks as a customer and, where applicable, participation in Intuit's developer program. "QuickBooks" and "Intuit" are trademarks of Intuit Inc.
4.8 Data Breach Notification
In the event of a data breach affecting Google or QuickBooks data connected to our systems, we will notify affected parties and, where required, the relevant regulator without undue delay.
5. How We Use Information
We use the information described above to:
Respond to client inquiries and manage the sales/scheduling pipeline;
Operate our internal bookkeeping and reconciliation process;
Communicate with clients about active or prospective projects;
Maintain and improve our website and internal tools;
Comply with legal and tax obligations.
We do not use Google or QuickBooks data for advertising, and we do not sell it, as stated above.
6. Sub-Processors and Third Parties
We use the following categories of service providers, each bound by confidentiality and data-protection terms appropriate to the data they handle:
Sub-ProcessorCategoryWhat They ReceivePurposeGoHighLevel (GHL)CRM / communications platformClient contact info, messages, call dataUnified inbox for SMS, email, web-form, and Instagram leads; scheduling; pipeline trackingGoogle WorkspaceEmail / file storageBusiness email content, shared job-site filesClient email and internal file sharingIntuit QuickBooks OnlineAccountingFinancial transactions, vendor/bill dataBookkeeping and reconciliationJobTreadProject managementJob, schedule, and material dataProject and crew scheduling, job costingAutomation/AI platform provider(s) [name your integration/agency platform — e.g., Composio, and the AI model provider — e.g., Anthropic/Claude]Workflow automation & AI processingData routed through the automated workflows described abovePowers the drafting, triage, and reconciliation logic behind the tools described in this policy
Fill in the exact platform name(s) your automation agency is using once confirmed — this table should list every system that actually touches client or business data, per the setup checklist.
We do not sell personal information to any third party.
7. International Data Transfers
Our business, staff, and the platforms listed above operate primarily within the United States. If any service provider processes data outside the U.S., we require that an appropriate transfer safeguard (such as Standard Contractual Clauses) is in place.
8. Data Retention and Deletion
Client inquiry data: retained for the life of the client relationship, plus up to 3 years for warranty and recordkeeping purposes.
Google-sourced data (Sections 3): deleted within 12 months, or sooner upon request.
QuickBooks-sourced data (Section 4): deleted within 30 days of disconnection, except records we're required to retain for tax/accounting purposes (generally up to 7 years, per standard accounting practice).
To request deletion at any time, email info@chicagorenovationstudio.com.
9. Your Privacy Rights
9.1 General Rights
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of the personal data we hold about you, and to object to or restrict certain uses. To exercise any of these rights, email info@chicagorenovationstudio.com. We will respond within 30 days.
9.2 California Privacy Rights (CCPA/CPRA)
California residents have the right to know, delete, and correct their personal information, and to opt out of any sale or sharing of it. We do not sell or share personal information as defined under the CCPA/CPRA. We will not discriminate against you for exercising these rights. Contact info@chicagorenovationstudio.com to make a request.
10. Children's Privacy
Our website and services are not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, contact info@chicagorenovationstudio.com.
11. Data Security
We use reasonable technical and organizational safeguards, including encryption in transit and restricted access to connected accounts, to protect information. No system is 100% secure, and we cannot guarantee absolute security.
12. Cookies and Tracking
Our website may use cookies to support basic functionality and understand site usage. You can control cookies through your browser settings; disabling them may affect site functionality.
13. Changes to This Policy
We may update this Privacy Policy from time to time. The "Last Updated" date above will reflect the most recent revision. Material changes will be posted on this page.
14. Contact Us
Chicago Renovation Studio 2155 West Belmont Avenue, Suite 1035 Chicago, IL 60618 info@chicagorenovationstudio.com
This Privacy Policy was prepared as a working draft to meet Google API Services User Data Policy and Intuit Developer Program disclosure requirements for Chicago Renovation Studio's internal automation tools. It has not been reviewed by an attorney. A few technical details (exact Google/Intuit scopes enabled, and the specific automation/AI platform name) should be confirmed against your automation agency's actual configuration — see the accompanying setup checklist — and the document should be reviewed by legal counsel before publishing.