Privacy Policy
Effective date: August 28, 2026 · Last updated: August 28, 2026
This Privacy Policy describes how Curbshot (“Curbshot,” “we,” “us,” or “our”) collects, uses, stores, and deletes information when you use curbshot.app, the Curbshot iOS and Android apps, homeowner share links, and related services (together, the “Service”).
Curbshot is a United States product operated from the United States. Questions: [email protected].
By creating a shop account or using the Service, you acknowledge this policy. If you do not agree, do not use Curbshot.
Who we are
Curbshot is photo proof for trades. A shop shoots before, after, and punch photos on a job, then shares an unlisted link and a one-page PDF with a homeowner. Homeowners who open a share link do not create an account and do not pay us.
We operate the website and API on Laravel Forge. We do not claim to be a limited liability company on this page. We have not published a street address or EIN here. Mail for privacy requests: [email protected].
Information we collect
Shop accounts
When you create a shop we store:
- Email address
- A hashed password — we do not store your password in plain text
- Shop name, optional logo image, and optional PDF footer text
- Sanctum device tokens so a signed-in phone can stay signed in
- Account timestamps (created, updated)
Jobs, punch items, and photos
Job names and notes, punch-item titles and status, photo metadata (kind, filename, timestamps), and the photo files themselves. Job-site photos may include house exteriors, streets, vehicles, license plates, and bystanders. That is the nature of driveway photo proof. The shop is responsible for what it shoots and who it shares those photos with.
Job, punch, and photo metadata lives on our Laravel Forge servers. Photo bytes and shop logos live in private Cloudflare R2 object storage. The shop phone also keeps an offline-first SQLite copy of jobs, punch items, and photos until it syncs, and may keep JPEG files on the device.
Homeowner share links
Each job gets an unlisted /s/{token} URL. Anyone with the link can view the job’s photos, punch status, and PDF. A homeowner who opens that link does not create an account, does not pay, and does not give us a name or email unless they write to [email protected] on their own. We do not put a login wall on share pages. The shop is responsible for who receives the link.
Billing
Subscriptions are purchased on the website through Stripe Checkout and managed in the Stripe Customer Portal. Stripe processes the card. We do not store full card numbers, CVC codes, or bank account numbers. We store Stripe customer and subscription identifiers on the shop record so we know whether the shop is entitled to shoot new jobs. Invoices, receipts, and tax-related payment records are held by Stripe as required to bill and to satisfy tax and accounting rules.
Transactional email
Password-reset and similar account email is sent through Resend. We use your email for those messages and for service notices about the account. We do not run a marketing newsletter from this stack unless we say so later and give you a way off it.
Technical logs
Our hosts (Laravel Forge and the infrastructure behind it, including Cloudflare in front of R2) may record IP address, user agent, request time, and error traces so we can keep the Service up and debug failures. We do not use those logs to build advertising profiles.
How we use this information
We use it to run Curbshot:
- Sign you in and keep a device signed in
- Store, stamp, and sync job-site photos
- Build the one-page PDF and serve the share links you create
- Bill the shop, enforce the trial, and stop the camera when a subscription lapses
- Respond to support email and security issues
- Comply with law, including tax recordkeeping
We do not sell personal information. We do not share customer photos with advertisers. We do not run third-party analytics SDKs, ad networks, or social pixels in the app or on these pages.
Processors we actually use
We use a short list of companies to operate the Service. They process information only to provide their service to us:
- Stripe — payment processing, invoices, customer portal, tax-related billing records
- Laravel Forge — application hosting for curbshot.app and the API
- Cloudflare R2 — private object storage for photos and shop logos
- Resend — transactional email such as password resets
Apple and Google distribute the iOS and Android apps. They may process device identifiers and crash information according to their own policies when you download the app from the App Store or Google Play. They are not how we bill subscriptions today.
We do not sell personal information
Curbshot does not sell personal information as that term is used under the California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA). We do not share personal information for cross-context behavioral advertising. We do not use your job-site photos to train public AI models.
If you are a California resident (or a resident of another U.S. state with similar privacy rights), you may request access to, correction of, or deletion of personal information we hold about you, and you may appeal a refusal, by emailing [email protected]. You will not be discriminated against for exercising those rights. The in-app Delete account control described below is the same deletion right, available without writing to us.
Account deletion
You can delete your shop from Settings in the Curbshot app. That control is not buried: it sits with Sign out. Confirming deletion permanently deletes the shop, its users, jobs, punch items, photos, device tokens, and share links. Billing is cancelled so Stripe stops charging the card. Share pages at /s/{token} return 404 after deletion.
You can also request deletion by emailing [email protected] from the account email. We will match that to the shop and run the same deletion.
After deletion we keep only records the law requires. That means Stripe invoices, payment history, and tax-related records Stripe already holds. We do not keep your photos, shop name, logo, job notes, or login in our application database for a “just in case” archive. Local copies on a phone are wiped by the app when deletion succeeds; a photo that was already forwarded to a homeowner is outside our control.
Access and correction
Signed-in shops can see and edit shop name, logo, and PDF footer in Settings, and can create, edit, and delete jobs, punch items, and photos in the app. For a copy of account data, or if something is wrong and the app cannot fix it, email [email protected].
Retention
We keep account, job, and photo data while the account is active. Individual jobs and photos can be deleted by the shop without deleting the account. When the account is deleted, application data is removed as described above. Server logs are kept only as long as we need them for security and operations, then rotated. Stripe retains billing records under its own retention schedule and applicable tax law.
Security
Passwords are hashed. API access from the app uses Sanctum bearer tokens stored in the device keychain / keystore. Photo objects in R2 are private; the app and share pages fetch them through our servers, not as a public bucket. No method of transmission or storage is perfectly secure. If we learn of a breach that affects your shop, we will email the account address.
Children
Curbshot is a business tool for trades, not a consumer toy. It is not directed at children under 13, and we do not knowingly collect personal information from children under 13. If you believe we have, email [email protected] and we will delete it.
Where we operate
Curbshot is v1 and United States–first. Servers and object storage are operated for a US product. We do not run a separate EU GDPR representative, DPO, or Standard Contractual Clauses program at this time. If you are in the EEA, UK, or Switzerland and still want to use Curbshot, understand that your information is processed in the United States. To access or delete your data, use the in-app Delete account control or email [email protected].
South Carolina law
This policy is governed by the laws of the State of South Carolina, United States, without regard to conflict-of-law rules, except where a privacy statute in your state gives you non-waivable rights — those rights still apply.
Changes
We may update this policy. The effective date at the top will change. Material changes will be posted on this page. Continued use of the Service after an update means you accept the revised policy. If a change is significant we will also email the shop account when we can.
Contact
Curbshot · United States
[email protected]