Privacy Policy
Last updated: June 13, 2026
This Privacy Policy explains how Sidetrack Services, LLC, doing business as FlintSpan ("FlintSpan," "we," "us") handles personal information in connection with the FlintSpan platform and websites (the "Service"). FlintSpan provides software that lets rental businesses ("Clients") run a branded website and reservation system for the people who rent from them ("Renters").
Our two roles
- For our Clients' and visitors' data (account, billing, marketing-site visitors), FlintSpan is the controller.
- For Renter personal data processed through a Client's site (reservations, uploaded documents, signatures, contact details), the Client is the controller and FlintSpan is the processor / service provider, acting on the Client's instructions. If you are a Renter, direct privacy requests to the rental business you booked with; we assist them in responding.
Information we handle
- Client & account: business name, contact, login, plan, and billing details.
- Renter data (on a Client's behalf): name and contact info, reservation details, and — where a Client enables it — uploaded identity/insurance documents, e-signature data, and delivery addresses.
- Payments: handled by payment processors; we do not store full card numbers.
- Usage & device: log data, IP, and similar technical information to operate and secure the Service.
- Communications: messages you send us (e.g., support).
How we use information
To provide, secure, support, and improve the Service; to process subscriptions and billing; to send service communications; and to comply with law. We do not use Renter data for our own marketing.
We do not sell or share your personal information
FlintSpan does not sell, rent, trade, redistribute, or share personal information. We disclose it only to the service providers (sub-processors) listed below strictly to operate the Service on our or a Client's behalf, and where required by law (e.g., a valid legal request) or to protect rights and safety. We do not share personal information for cross-context behavioral advertising.
Service providers & integrations we use
We rely on the following providers to run the Service. Clients may also connect their own integrations. These are independent third parties: FlintSpan does not control how they handle data, and their practices are governed by their own privacy policies — please review them.
- Amazon Web Services (AWS) — hosting, storage, database, and email delivery.
- Stripe and/or Square — payment processing (Client-connected).
- Twilio and/or QUO (OpenPhone) — SMS messaging (Client-connected).
- Google Maps Platform — address lookup and delivery-distance calculation.
- Google Analytics — only when a Client enables it for their own site.
- Anthropic — AI used for optional document verification (OCR) and the assistant feature (see below).
- igloohome — smart-lock access codes (Client-connected).
- Google / Microsoft Calendar — calendar sync (Client-connected).
Where an integration is one a Client connects with their own account, that Client's relationship with the provider — and the provider's own terms and privacy policy — govern that data.
AI document verification (OCR)
If a Client turns on identity/insurance verification, the uploaded document image is sent to our AI provider (Anthropic) to read and validate fields (such as name, expiration, and license class). We store only the extracted fields and the verification result — not the image at the AI provider — and our AI provider does not use the data to train its models. A failed or unclear check is flagged for the rental business to review; it does not by itself reject a reservation.
Cookies & sessions
We use strictly necessary cookies for login/session security (httpOnly, secure cookies — we do not put auth tokens in local storage) and CSRF protection. We do not use third-party advertising cookies. Analytics cookies appear only on a Client site if that Client enables their own analytics.
Security
We protect data with encryption in transit and at rest, per-tenant key isolation, and envelope encryption (managed keys) for the most sensitive documents such as driver's licenses, plus access controls, tenant isolation enforced in the database, and audited access. No method is perfectly secure, but we work to protect your information.
Data retention
We keep account data while an account is active and for a limited period afterward, then delete or de-identify it. A Client may export or request deletion of data; on cancellation, data moves to archival storage and is purged on a schedule (and sooner on a valid request), subject to legal retention needs.
Your privacy rights
Depending on where you live (for example, under the California Consumer Privacy Act / CPRA), you may have the right to know, access, correct, delete, and limit certain uses of your personal information, and to not be discriminated against for exercising those rights. Because we do not sell or share personal information, there is no sale to opt out of. To exercise rights as a Client or marketing-site visitor, email privacy@flintspan.com. If you are a Renter, contact the rental business you booked with (the controller); we will help them respond.
Children
The Service is for businesses and adults; it is not directed to children, and we do not knowingly collect data from anyone under 18.
International
FlintSpan operates in the United States; if you access the Service from elsewhere, you understand your information is processed in the U.S.
Changes
We may update this policy; we will post changes here with a new date and, where appropriate, additional notice.
Contact
Questions or privacy requests: privacy@flintspan.com.