Privacy Policy

Last updated: September 7, 2026

This describes what SetAllUp collects through SetAllUp, why, who it goes to, how long it is kept, and what you can ask us to do about it.

There are two kinds of people in here and it matters which one you are. Account holders are the contractors and business owners who sign up. Everyone else — the customers who receive invoices, and the workers who sign documents — did not sign up for anything. Their information is in SetAllUp because an account holder put it there. For that information, the account holder decides what is collected and why; we handle it on their behalf. If you want your details changed or removed, the fastest route is the business that sent you the document, though you can also come to us and we will help.

What we collect

Identifiers. Name, email address, phone number, business address, and the unique IDs that identify your account, invoices and signing links.

Commercial information. The estimates and invoices you create, the line items and amounts on them, what has been paid, and by what method.

Financial information. We do not collect or store card numbers or bank account numbers. Stripe collects those directly. We store the Stripe identifiers for your account and your payments, the amounts, and whether Stripe says your account can take payments and pay out.

Signature records. When someone signs a Set Up document we record their drawn signature as an image, the name they typed, the exact terms they agreed to, their consent to sign electronically, the time, their IP address and their browser's device string.

Internet activity. IP address and browser information on requests to our servers, and server logs.

A signature image is biometric-adjacent, and under California law it may be treated as sensitive personal information. We treat it that way regardless: it is encrypted at rest, and we do not use it to infer anything about anyone. It exists to be shown back as part of the record it belongs to, and for nothing else.

Photographs. Account holders can attach photos to a job — usually of the work, which means usually of somebody's property. A photo taken on a phone normally carries the GPS position where it was taken embedded inside the file. We strip that out before the photo is stored, along with every other piece of embedded metadata, so the copy we hold does not contain the coordinates. This is done on the way in, not on the way out, so no copy of the original ever reaches our storage.

How the app is used. If you agree to it on the notice, we record which screens are reached, which controls are pressed, how far a page is scrolled and how long a step takes. It carries no names, no addresses, no amounts and no recording of your screen — the technical detail is in the section on cookies below. If you do not agree, none of it is recorded at all.

We do not collect precise geolocation — see the note about photographs above, which is the one place it could otherwise have arrived. We do not knowingly collect anything from anyone under 18; if we learn that we have, we delete it.

Where it comes from

Directly from you, when you create an account, fill in your settings, or write up a job.

From an account holder, when they add you as a customer or send you a document to sign.

From you as a recipient, when you open an invoice, tell a contractor you have sent a payment, or sign a document.

From Stripe, when it tells us the status of a payment or of a payouts account.

Automatically, from your device and browser, when you use the service.

Why we use it

To run the service: creating and delivering documents, taking payments, recording signatures, and showing people their own records.

To keep signed records meaningful, which means keeping enough evidence that a signature can be relied on later.

To keep the service secure: detecting and preventing fraud and abuse, and rate-limiting our public endpoints.

To email documents and receipts to the people entitled to them.

To meet legal, tax and accounting obligations, and to resolve disputes — including payment disputes, where the record is what we and you have to work from.

We do not use any of it for advertising and we do not profile people.

Who we share it with

Stripe, for payments and payouts. Stripe collects identity and bank details directly from account holders under its own agreement and privacy policy.

Our email provider, to deliver documents, receipts and signed copies.

Our hosting and database providers, who run the servers and store the database, and the object-storage provider that holds photographs and encrypted backups.

Our translation provider (Anthropic). SetAllUp can present a document in the other language. To do that, the text of the document — its title, its notes, its terms and its line descriptions — is sent to be translated. Those are free-text fields you write, so if you type a customer's name or an address into a job title, that text is sent too. It is worth knowing, because it is the one place ordinary typing decides what leaves the server. Translations are cached so the same phrase is not sent twice.

Our address-suggestion provider (Mapbox or Google). When an account holder types a service address, what they have typed so far is sent to look up suggestions. That is a customer's address, sent while it is being typed.

The other party to a document. If you sign something, a copy goes to the business that sent it, and vice versa. That is the point of the record.

Law enforcement or a court, where we are legally required to, or to protect someone's safety or our legal rights.

We do not sell personal information, and we do not share it for cross-context behavioural advertising — as those terms are defined by the California Consumer Privacy Act. We have not done so in the preceding twelve months.

How long we keep it

Signature images, signer IP addresses and device strings: ten years from signing, then removed. Ten years matches California's outer limit for construction claims, so a contractor still has the record for as long as they could be sued over the work.

The rest of a signed record — the terms, the fingerprint, who signed, when, and the trail of events — is kept permanently. A purged record still proves that a named person agreed to specific terms on a specific date. What it loses is the picture and the address.

Account, customer and invoice records are kept while the account is open and for as long afterwards as tax and accounting rules require.

Sessions expire after 30 days. Rate-limiting counters are discarded after a day. Usage records — the how-the-app-is-used measurements below — are deleted after 90 days.

Cookies, and how the app is measured

Three cookies, and only one of them is optional.

The first keeps you signed in. The second remembers which language you are reading in. Neither is optional in any meaningful sense — without them you cannot stay logged in or read the page in your own language — so we do not pretend to ask about them. They are not used for advertising and they are not shared with anybody.

The third is the optional one, and it is only ever created after you say yes. It holds a random identifier and nothing else: it is not derived from your address, your device or anything about you, so once it is gone there is no way to reconnect it to you. It lasts 90 days.

What is measured, if you agree. Which screens are reached, which controls are pressed, how far a page is scrolled, how long each step takes, and the places where somebody presses the same thing three times because nothing happened. That last one is the most useful thing in it, and it is why this exists: it is a list of places the app is confusing.

What is not measured, and cannot be. No names, no addresses, no invoice amounts, no photographs, no recording or screenshot of your screen, and no keystrokes. The web address of the page is stored with its identifiers removed — the invoice link you followed is recorded as "an invoice page", never as the link itself, because that link is the key to the invoice. There is no field in what we collect that a name or an address would fit into. That is a limit built into the software rather than a promise about how we behave.

Where it goes. Nowhere. It is stored in the same database as everything else, on our own servers. There is no analytics company, no advertising network and no third-party tag anywhere in SetAllUp. Nothing measured is ever sold or shared, and there is nothing to opt out of with anybody else, because nobody else has it.

Saying no, and changing your mind. The notice has two buttons the same size, and refusing is remembered for a year exactly like agreeing. If you refuse, no identifier is created and nothing is recorded — not hidden from a chart, not recorded. Account holders can change the answer at any time in Settings. If your browser sends a Global Privacy Control signal, we treat that as a refusal without asking.

A contractor cannot see their customers' behaviour through this. A customer opening an invoice is not recorded against the business that sent it. That would turn a measurement tool into a way of watching somebody who never signed up for anything, and it is deliberately not built.

Your rights in California

If you are a California resident, you can ask us to:

Tell you what we hold — the categories and specific pieces of personal information we have collected about you, where it came from, why we collected it, and who we disclosed it to.

Delete it. Your name, contact details, service address, any photographs of your property, the image of your signature and the addresses your browser reported are erased. What stays is the record of what was invoiced and paid — the amount, the date, the fact it was settled — because that is the contractor's trading record and both tax law and their insurer require them to keep it. The same applies where information forms part of a signed agreement another party is entitled to rely on; the terms and the fact somebody agreed to them on a date survive, while the picture of the signature and the addresses do not.

And the honest limit. We take database backups every night and keep them for up to two years. A backup written before your request still contains you, and there is no way to reach inside one that has already been made. Those copies age out on their own schedule and are not used to restore anything except in a disaster. We would rather say this plainly than let you find it out afterwards.

Correct it, if it is inaccurate.

Opt out of sale or sharing. We do not sell or share personal information, so there is nothing to opt out of, and no "Do Not Sell or Share" mechanism is offered for that reason.

Limit the use of sensitive personal information. We only use it to provide the service, which is already the limited purpose the law describes.

We will not treat you differently for exercising any of these rights. There is no charge, and you can make up to two requests in a twelve-month period.

To make a request, email info@setallup.com or call (650) 888-7658. We will confirm who you are before we act — for a signature record, that usually means responding from the email address the record was sent to. We respond within 45 days, and will tell you if we need up to 45 more.

An authorised agent can act for you with written permission that we can verify.

If you received a document rather than sent one

Your information is in SetAllUp because a business put it there. Ask them first — they can change or remove most of it directly, and they know the context.

You can also come to us and we will act on your request or pass it to them, whichever is appropriate. What we cannot do without them is delete a signed record they may need: it is evidence of an agreement you were part of, and it exists to protect both sides of it.

How we protect it

Signature images are encrypted with AES-256-GCM before they are stored, with the key held outside the database. In a stolen database copy they are unreadable.

Passwords are hashed with scrypt and are never stored or recoverable in plain form. Sessions are held server-side so signing out actually revokes access.

Every query is scoped to the account it belongs to, so one business cannot reach another's data. Invoice and signing links use unguessable random tokens, and are marked not to be indexed by search engines.

No system is perfectly secure, and we will not claim otherwise.

Changes, and how to reach us

We will update this policy when what we do changes, and we review it at least once a year. The date below is when it last changed. If a change is significant we will tell account holders before it takes effect.

SetAllUp · P.O. Box 661216, Los Angeles, CA 90066 · info@setallup.com · (650) 888-7658

TermsPrivacySetAllUp
Privacy Policy — SetAllUp