Privacy Policy

Effective September 19, 2026

Boomtown (“Boomtown”, “we”, “us”) is a business platform at app.boomtown.so. A business signs up, gets a workspace, and runs its website, bookings, contacts, documents, contracts, invoices and the follow-up between them — with the same customer record carrying through all of it. This policy explains what personal information we collect, how we use it, who we share it with, how long we keep it, and the choices you have. It covers our own website and the Boomtown application, including the workspace consoles, the portals and the mobile app.

The two roles we play

Almost every privacy question about Boomtown has two answers, because we hold two different kinds of data:

  • Your Boomtown account — we decide. When you sign up for a workspace, we are the controller of your account and billing information and of the data you give us to run the service. This policy governs it.
  • The data inside a workspace — its owner decides. Contacts, bookings, messages, documents, files and portal members belong to the business that runs that workspace. We process them on that business’s instructions, to deliver the service. If you are a customer, contact or portal member of a business that uses Boomtown, that business is the controller of your information — ask them about their own privacy practices, and about access or deletion of your record. We will help them respond.

Information we collect

  • Account information. Your email address, used to sign you in and to send service notifications, and the name and workspace details you enter. We do not set or store a password — sign-in is by one-time email code or through Google.
  • Workspace content. Everything you and your team create in Boomtown: contacts and their notes, bookings and calendar entries, website and funnel pages, documents, spreadsheets, drawings and presentations, contracts and signatures, quotes and invoices, tasks, messages and email threads, files you upload, and recordings you make.
  • Connected-account data. If you connect Google, or another service, the data that connection is scoped to. The Google case is set out in full below.
  • Activity data. Sign-ins, page and feature usage, and an append-only history of changes made in your workspace — who changed what and when — so that edits can be reviewed and undone.
  • Technical data. Browser and device type, request trace identifiers, and, if you enable push notifications, a push token from your browser or phone. Our hosting and infrastructure providers process standard connection data, including IP addresses, to deliver and secure the service.
  • Payment data. If you pay us, or take payments through Boomtown, our payment processor handles the card details. We receive the result of the transaction and the last four digits — we never see or store a full card number.

How we use your information

  • to provide and operate Boomtown — sign you in, run the features you use, and deliver what you send;
  • to send notifications you have asked for, in-app, by email and by push, which you control in Settings;
  • to bill you, and to take payments you configure;
  • to keep the platform safe — abuse prevention, tenancy isolation between workspaces, and enforcing our Terms;
  • to maintain, secure, debug and improve the service; and
  • to comply with legal obligations.

We do not sell your personal information. We do not show advertising in Boomtown, and we do not use third-party advertising or analytics trackers on it.

AI features. Some features send content you choose — a document you ask to be drafted, a transcript you ask to be summarised, a task you ask an agent to do — to a model provider on our behalf, to return the result to you. Those providers act as our processors and are contractually barred from training their models on it. We do not feed your workspace content into any model for training, and Google user data is never sent to any AI model, ours or anyone else’s.

Google user data

This section is the complete account of how Boomtown accesses, uses, stores and shares data from your Google Account. It applies whenever you sign in with Google or connect a Google service to your workspace.

Signing in with Google

“Continue with Google” requests only the openid and email scopes. We read your verified email address, use it to find or create your Boomtown account, and set a session cookie. We do not ask for a refresh token for sign-in and we store nothing from Google beyond the email address on your account.

Connecting a Google service

Connecting a Google service is always something you start, from the integration screen for that feature, and each connection asks only for the scopes that feature needs. Today those are:

  • Gmailgmail.send, gmail.readonly, gmail.modify. We send the emails you and your automations compose from your own address so they arrive as you rather than as a robot; we read the messages in that mailbox so replies from a contact appear on that contact’s record in Boomtown instead of being lost in an inbox; we read the Sent folder so mail you sent by hand appears there too; we confirm that a message we sent was actually delivered; and we mark messages we have processed so the same reply is not filed twice. Message content we file against a contact is stored in your workspace so you can read the thread in Boomtown.
  • Google Calendarcalendar.readonly, calendar.events. We read your busy times so the booking page never offers a slot you are not free for, and we write the meeting to your calendar when someone books it, so the invitation and reminders come from your own calendar.
  • Google Contactscontacts. If you turn on contact sync, we read your contacts to bring them into your workspace, and write back changes you make in Boomtown, so one address book stays correct in both places.
  • Google Sheetsspreadsheets. Only for the specific spreadsheet a workflow step you built names: to read rows as input, or append rows as output.
  • Google Business Profilebusiness.manage. To publish the posts you schedule to your own business listing.
  • YouTubeyoutube.upload, youtube.readonly, and youtube.force-ssl only if you enable playlists. To upload the videos you publish to your own channel, read back their status, and add them to a playlist you choose.

We request each scope only for the feature described beside it, and we use the data for nothing else. A connection you never make is a scope we never ask for.

How we store it

Google access and refresh tokens are encrypted at rest with keys held outside the database, stored on a row belonging to the single workspace that authorised the connection, and never shared between workspaces. Data we fetch from a Google API — a filed email, a synced contact, a calendar busy time — is stored in that same workspace, subject to the same isolation, and is visible only to that workspace’s members. Our staff do not read it, except with your explicit permission to resolve a support issue you have raised, or where we are required by law or must act to protect someone’s safety.

Limited Use

Boomtown’s use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we do not transfer Google user data to third parties except as necessary to provide or improve the features described above, to comply with applicable law, or as part of a merger or acquisition with notice to you; we do not use or transfer it for serving advertising, including retargeting or personalised advertising; we do not sell it; and we do not use it to develop, improve or train generalised or non-personalised artificial-intelligence or machine-learning models. Human access is limited to the cases listed directly above.

Taking it back

You can disconnect a Google service from the same screen you connected it on, at any time, and you can revoke Boomtown’s access from your Google Account permissions page. Disconnecting deletes the stored tokens immediately and stops all further access. Records already filed in your workspace — an email thread on a contact, a synced contact, a booked meeting — stay there, because they are your workspace’s records; you can delete them individually, or delete the workspace, and email us at privacy@app.boomtown.so if you want everything fetched from a connection removed at once.

Who we share information with

We share data only with the providers that make Boomtown work. Each acts as our processor under contract, may use the data only to provide its service to us, and is not permitted to sell it.

  • Supabase — the database and account records.
  • Vercel — application hosting and delivery.
  • Cloudflare — storage of the files and recordings you upload.
  • Resend — delivery of email we send on the platform’s behalf.
  • Twilio — text messages and calls, where a workspace uses them.
  • LiveKit — live audio and video, where a workspace uses it.
  • Stripe — payments and card handling.
  • Modal — video rendering and transcription compute.
  • OpenRouter, and the model providers it routes to — AI features you invoke. Google user data is never sent here.
  • Google — sign-in, and any Google service you connect.
  • Apple, Google and Mozilla push services — only if you enable push notifications, to reach your device.

We may also disclose information if required by law, to enforce our Terms, or to protect the rights, safety and security of Boomtown, our customers or the public. If Boomtown is ever involved in a merger, acquisition or sale of assets, we will give notice before your information becomes subject to a different policy.

Cookies and local storage

We use the essential cookies needed to keep you signed in and to know which workspace you are looking at, and your browser’s local storage to remember preferences such as a chosen theme or an open tab. We do not use advertising cookies or third-party tracking on Boomtown. A website you publish with Boomtown is yours, and what it sets is governed by your own policy.

How long we keep it

We keep your information while your account is active. Delete a record and it goes to your workspace’s trash, where it is recoverable for a limited period and then removed. Delete your account and we permanently remove your profile, your workspaces and their content, and your sign-in; tokens for connected services are deleted at once. Files you uploaded are removed from our file storage on a purge cycle after deletion. Residual copies may persist briefly in encrypted backups before they are overwritten on a rolling basis. We keep the minimum required for legal, tax and fraud-prevention purposes — invoices, for instance — for as long as the law requires.

Your rights and choices

You can, at any time:

  • Access and correct your information by editing it in Settings;
  • Control notifications — in-app, email and push — in Settings;
  • Disconnect any connected service, including Google;
  • Export your workspace content; and
  • Delete individual records, a workspace, or your whole account.

Depending on where you live — the EEA, the UK, California and others — you may also have rights to a copy of your data, to portability, to restrict or object to processing, to withdraw consent, and not to be discriminated against for exercising them. To exercise any of these, email privacy@app.boomtown.so. We do not sell or share personal information for cross-context behavioural advertising, so there is nothing to opt out of. If you are a customer, contact or portal member of a business that uses Boomtown, send the request to that business — it is the controller of your record — and write to us if you cannot reach them.

Security

We encrypt data in transit with HTTPS, authenticate without passwords, encrypt connected credentials at rest with keys held outside the database, and isolate every workspace at the database row level so one workspace cannot read another’s data. That isolation is verified by an automated sweep of the live database every night rather than assumed. No online service can be completely secure, but we work hard to protect your information and to respond promptly to any incident.

Children

Boomtown is a business tool, is not directed at children, and is not intended for anyone under 16. We do not knowingly collect personal information from children. If you believe a child has given us information, contact us and we will delete it.

International data transfers

Boomtown and its providers process and store data in the United States. If you use Boomtown from elsewhere, your information will be transferred there and protected by appropriate safeguards and by this policy.

Changes to this policy

We may update this policy. When we do, we will move the effective date at the top of this page, and for material changes we will give additional notice in the application before the change takes effect.

Contact us

Questions about this policy, your data, or a request under it? Email privacy@app.boomtown.so. Our Terms of Service are at app.boomtown.so/terms.