Who we are
TradesPilot ("we", "us", "TradesPilot") provides an AI-powered office manager for NZ tradies — plumbers, electricians, builders, painters, and other hands-on businesses. This policy explains what information we collect, how we use it, and your rights under the New Zealand Privacy Act 2020.
What this policy covers
This policy applies to:
- Tradespeople ("clients") who sign up for TradesPilot and connect their accounts
- People who contact us through our website or by email
- End customers of our clients, only to the extent their details appear in jobs, invoices, or emails handled by the agent
What data we store
To deliver the TradesPilot service, we store the following for each client:
- Google OAuth tokens — encrypted credentials allowing the agent to read and send Gmail and access Google Drive and Calendar on the client's behalf
- Xero OAuth tokens — encrypted credentials allowing the agent to raise and update invoices and quotes in the client's Xero account
- Stripe tokens — payment credentials used to process subscription billing and, where enabled, to generate customer pay-links
- Conversation logs — the history of messages between a client and their agent, retained for 90 days on a rolling basis
- Customer and job memory — names, contact details, job notes, and financial summaries stored so the agent can answer questions like "what did I last charge Dave?"
- Business configuration — business name, services, pricing templates, quiet hours, and persona settings provided during onboarding
Where data is stored
All client data is stored on a server located in New Zealand. Each client's agent runs in its own isolated, sealed container — it cannot read data belonging to any other client.
Conversation logs are retained for 90 days on a rolling basis. Financial data (invoices, quotes, job records) is retained indefinitely unless a client requests deletion.
Google user data
When a client connects their Google account, we request only the scopes needed to deliver the features they've signed up for:
| What we access | Why |
|---|---|
Gmail read (gmail.readonly) |
To search past emails and detect new incoming enquiries so the agent can draft a reply. |
Gmail send (gmail.send) |
To send quotes, invoices, reminders, and follow-ups — only after the client explicitly approves the specific message. |
Google Drive (drive) |
To store job photos in a per-job folder in the client's own Drive account. |
Google Calendar (calendar) |
To create and update job bookings in the client's calendar. |
Show → Approve → Act. TradesPilot never sends an email, posts to social media, or takes any action using a client's account without the client first seeing the exact content and explicitly approving it in their Telegram chat.
We do not use Google user data to serve advertising. We do not use it to train AI models. Email content is sent to Anthropic solely to generate the specific reply or answer the client's agent is producing in that moment.
What we don't do
- We do not sell, rent, or trade any client data to third parties
- We do not share data with advertisers
- We do not allow any person (including us) to read a client's email or financial data except where needed to resolve a specific support issue the client has raised, and only with the client's knowledge
- We do not use data from one client's agent to inform or influence another client's agent
Third parties we work with
We use the following providers to deliver TradesPilot, each with access only to what's needed for their role:
- Anthropic — AI model that powers agent responses (processes message content to generate replies; no data retained for training)
- Google — Gmail, Drive, and Calendar integrations (accessed via the client's own OAuth consent)
- Xero — invoicing and financial data (accessed via the client's own OAuth consent)
- Stripe — subscription billing and customer pay-links
- Telegram — the messaging platform clients use to talk to their agent
Your rights (Privacy Act 2020)
Under the New Zealand Privacy Act 2020, you have the right to:
- Request access to the personal information we hold about you
- Ask us to correct any information that is inaccurate or incomplete
- Request deletion of your data — send
/deleteto your agent or email us and we will wipe your data within 30 days
Revoking connected accounts
You can disconnect any connected account at any time:
- Google: revoke access at myaccount.google.com/permissions. We immediately lose access and delete stored OAuth tokens.
- Xero: disconnect via your Xero account settings. Stored tokens are deleted immediately.
- Stripe: contact us to remove billing credentials.
Changes to this policy
If we make material changes, we will update this page and the "last updated" date above. Continued use of TradesPilot after a change means you accept the updated policy.
Contact us
Questions about this policy or how your data is handled: tradespilot.cc@gmail.com.
TradesPilot's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
TradesPilot