Working draft — not live legal until effective date is set.
Effective date: [EFFECTIVE DATE]
Controller: TradesKnow (“TradesKnow,” “we,” “us,” or “our”)
Product: TradesKnow (tradesknow.com)
Contact: [CONTACT EMAIL]
Address: [COMPANY ADDRESS]
This Privacy Policy explains how TradesKnow collects, uses, and shares personal information in connection with TradesKnow. It applies to the marketing site, invite-only accounts, Ask, and Field if enabled for you.
It is a Phase 1 notice for an invite-only, free service. It is not a certification of CCPA, GDPR, or SOC 2 compliance.
By using the Service, you acknowledge this Policy. Our Terms of Service and Acceptable Use Policy also apply.
1. Who is responsible
TradesKnow is the controller of personal information processed for TradesKnow unless we say otherwise (for example, if we later process data as a processor for a shop under a separate agreement — we do not claim that structure for Phase 1 invitees without a signed BAA/DPA).
Contact: [CONTACT EMAIL] / [COMPANY ADDRESS].
2. What we collect
We collect information in these categories. We do not collect more than we need for Phase 1 operation.
2.1 Account and invite
- Name, email address, invite token / source
- Shop or employer name if you provide it
- Password or authentication secrets (stored hashed / via our auth provider; we do not store plaintext passwords)
- Role or trade you self-describe (e.g., electrician, HVAC), if collected
2.2 License metadata (if collected) — no images
If we collect license information at all, it is only:
- license number
- issuing state
- trade
- expiry date
We do not collect license images, ID photos, or scans in Phase 1. License-image intake is on hold. Do not email pictures of licenses to [CONTACT EMAIL] as a workaround unless we later open a counsel-cleared channel.
License metadata is not state-board verification. We do not operate a “Verified {trade}” government-status badge.
2.3 Ask queries and Outputs
- Prompts you submit to Ask
- Outputs shown to you
- Provenance labels associated with an answer (Verified = drawn from verified corpus; Draft = model draft). These labels are not license or state-board verification
- Safety-refuse events (e.g., we refused a gas / live-panel / structural / confined-space how-to)
2.4 Field job data (if Field is enabled for you)
If Field is available — including if it is loopback-only or otherwise restricted — job captures may include:
- photos, measurements, equipment / part identifiers, voice notes, job notes, site or equipment context you capture
- device and app diagnostics needed to run Field
Field job captures are member job data. They are used to operate the Service for you, not to train models. See Section 4.
If Field is not enabled, we do not collect Field job captures.
2.5 Usage, device, and log data
- Approximate timestamps of access, feature used (Ask / Field / site)
- IP address, user-agent, device type, coarse location derived from IP if our host logs it
- Security and abuse logs (failed logins, rate limits, AUP flags)
2.6 Cookies and similar technologies
See Section 10. We will not claim “we don’t use cookies” if the site in fact uses session or analytics cookies. Actual tags should be listed in [ANALYTICS / COOKIE NOTICE] before publish.
2.7 Communications
- Emails you send us (support, invite replies, Feedback)
- If we survey invitees, responses you choose to give
2.8 What we do not intentionally collect in Phase 1
- Payment card data (no monetization)
- License images or government ID images
- Precise GPS tracking of your person as a product feature (unless Field later requires job-site geotag you choose to capture — treat that as job data under the two-door rule)
- Children’s data (see Section 11)
- Special-category data we do not ask for. Do not submit health information, someone else’s Social Security number, or unnecessary bystander faces.
3. Purposes of use
We use personal information to:
| Purpose | Examples |
|---|---|
| Provide the Service | Account, authentication, Ask answers, Field capture storage if enabled |
| Safety and acceptable use | Refuse hazardous how-to; enforce AUP; prevent bulk-approve on hazards; abuse detection |
| Security and operations | Logs, debugging, uptime, fraud/account takeover |
| Communicate | Invites, service notices, material legal-term changes |
| Legal | Comply with law, enforce Terms, protect rights and safety |
| Improve the Service without training on member job data | Aggregate product analytics; bug fixes; UI; retrieval quality that does not train model weights on your job data |
We do not sell personal information. We do not use TradesKnow as a lead-gen broker for third-party advertisers.
4. Two-door training rule (core privacy promise)
4.1 Door 1 — member job data: no training
Member job data and Field job captures are never used to train, fine-tune, or otherwise improve foundation models or TradesKnow’s task models.
That includes Ask prompts that are your job-site questions to the extent they are your member work product, and all Field captures. We may process that data through subprocessors to generate an answer or to store a job for you. That is operation of the Service, not training.
We contract with model and hosting providers to prohibit their use of that data to train their models, to the extent we send it to them. If a provider cannot accept that restriction, we will not send member job data to that provider.
4.2 Door 2 — expert / Teach content only, and only when cleared
The only intended path for using content to train or evaluate models is consented expert / Teach content under separate contributor terms.
Those contributor terms are not in production as of this Policy. They remain a working draft pending outside counsel. Until a cleared Teach agreement is in force:
- we do not treat your ordinary Ask/Field use as training consent;
- we do not present a production Teach clickwrap;
- we do not train on member job data “because an expert might have typed it.”
If Teach launches later, consent will be separate, specific, and withdrawable as that agreement provides.
4.3 Feedback vs. job data
Product Feedback (e.g., “this button is broken”) may be used to improve the product. We will not re-label Field job captures as Feedback to evade Section 4.1.
5. Sharing
We share personal information only as follows:
Processors / service providers. Hosting, authentication, email delivery, error monitoring, and (if used) model-inference providers who process data on our instructions. They may not use member job data to train their models for their own purposes.
Legal / safety. If we believe disclosure is required by law, valid legal process, or to protect a person from serious harm, prevent crime, or enforce our Terms (including safety no-gos).
Corporate transaction. If TradesKnow is involved in a merger, acquisition, or asset sale, information may transfer under continuing restrictions consistent with this Policy (including the two-door rule).
With your direction. If you ask us to send something to a shop admin or co-worker we have jointly provisioned.
We do not sell personal information. We do not share personal information for cross-context behavioral advertising as a Phase 1 practice. If that ever changes, we will update this Policy and provide required opt-out.
Processors to name before publish (placeholder): [LIST OF PROCESSORS: e.g., hosting provider, auth provider, email, model inference — names and roles to be filled by engineering before go-live].
6. Retention
| Data | Retention (Phase 1 working rule) |
|---|---|
| Account identifiers | For the life of the account, then deleted or de-identified within a reasonable period after deletion request or invite withdrawal, unless a legal hold applies |
| Ask queries / Outputs / safety-refuse logs | Access and safety logs may be kept longer than license metadata, as needed for security, AUP, and safety-refuse integrity — [RETENTION PERIOD FOR LOGS, e.g., 18 months] unless a hold applies |
| Field job data | For the life of the account or until you delete the job / account; not retained as training data; loopback-only Field should not sync job payloads to shared training stores |
| License metadata (number / state / trade / expiry) | Shorter than access logs. If we reject an invite or you withdraw, we delete license metadata rather than keep it “in case.” Working rule: delete on reject/withdraw promptly (target: within 30 days), and do not keep license metadata longer than [LICENSE METADATA RETENTION, e.g., 12 months after last active use] even for active accounts if it is no longer needed for the purpose collected |
| License images | Not collected. If received in error (e.g., emailed), delete and do not store |
| Backup media | Rolling backups may persist deleted data for a limited backup cycle [BACKUP CYCLE] |
We may retain records as required by law or to resolve disputes.
7. Security
We use administrative, technical, and organizational measures appropriate to a small invite-only service (access control, hashing of passwords, TLS in transit, least-privilege for staff). No method of transmission or storage is 100% secure. Field job photos can be sensitive; treat devices accordingly.
You are responsible for your account credentials and for job-site photos you choose to capture (bystanders, homeowner interiors, etc.).
Report suspected security issues to [CONTACT EMAIL]. This Policy is not a bug-bounty charter.
8. Your rights — access, delete, export
Subject to law and to verifying your request:
- Access. You may request a copy of personal information we hold about you.
- Correction. You may request correction of inaccurate account or license metadata.
- Deletion. You may request deletion of your account and personal information, subject to legal holds, safety/security logs we must keep, and backup cycles.
- Export. You may request an export of account data and User Content you submitted (Ask history and Field jobs if stored), in a reasonable machine-readable format we support.
Email [CONTACT EMAIL] from the address on your account. We may decline requests that are unlawful, abusive, or would compromise others’ privacy or our security controls.
If you are a resident of a state with additional consumer privacy rights (e.g., California), we will not discriminate against you for exercising them. Phase 1: we do not sell personal information; “Do Not Sell or Share” is therefore not a monetization toggle, but you may still email us to record a preference.
We do not currently operate an automated “appeal an AI decision that produces legal or similarly significant effects” because TradesKnow does not decide licenses, credit, employment, or housing. Outputs are informational. Safety refuses are product rules, not credit scores.
9. Automated processing and Ask labels
Ask uses automated systems to draft answers and to refuse certain hazardous how-to. That is not a consumer-credit decision.
“Verified” / “Draft” on Ask answers refer only to provenance (verified corpus vs. model draft). They are not a verification of your license, a state board result, or an AHJ approval.
10. Cookies and analytics
[COOKIE / ANALYTICS DISCLOSURE — FILL BEFORE PUBLISH]
Until filled, assume at least:
- Strictly necessary cookies or local storage for session / authentication / load balancing;
- Optional analytics only if actually deployed.
If we use analytics, we will identify the provider here and, where required, honor opt-out or consent. Do not enable advertising pixels for Phase 1 without updating this Policy.
The marketing site should not silently identify invitees to third-party ad networks.
11. Children
The Service is not for anyone under 18. We do not knowingly collect personal information from children. If you believe a minor has created an account, contact [CONTACT EMAIL]; we will delete it.
12. International
We are a U.S. company (TradesKnow). The Service is operated from the United States. If you access it from outside the U.S., you understand information will be processed in the United States, where laws may differ from those in your country.
Phase 1 is not offered as a GDPR-established EU service. We do not appoint an EU representative in this draft. If we later onboard EU/UK users in a systematic way, this Policy must be revised with counsel (SCCs, representative, lawful basis).
13. Changes
We may update this Policy. Material changes will be noticed in-product or by email a reasonable time before they take effect, unless the change is required by law or needed for safety or security. The “Effective date” above will change.
The two-door rule (no training on member job data / Field captures) will not be weakened by a quiet Policy edit. If that promise ever changed, it would be a material change requiring clear notice — and it is not contemplated for this launch.
14. Contact
TradesKnow
Attn: TradesKnow Privacy
Email: [CONTACT EMAIL]
Address: [COMPANY ADDRESS]
For license, permit, or code questions, contact your licensing board or AHJ — not TradesKnow as a licensing authority.