1. Overview & Data Controller
At Beedy, we believe privacy is a fundamental right. This policy explains how we collect, use, share, and protect your personal information when you use beedy.app (the "Platform"), the marketplace operated by Beedy, LLC It is written in plain language while satisfying the disclosure requirements of the California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA), the Florida Digital Bill of Rights (FDBR, Fla. Stat. § 501.701 et seq.), the Virginia Consumer Data Protection Act (VCDPA), the Colorado Privacy Act (CPA), the Connecticut Data Privacy Act (CTDPA), the Utah Consumer Privacy Act (UCPA), the Texas Data Privacy and Security Act (TDPSA), the federal Children's Online Privacy Protection Act (COPPA), and FTC Act §5.
If anything is unclear, contact our privacy team at privacy@beedy.app. You have the right at any time to receive a clear explanation of how we use your information, to exercise the rights listed in Section 7, and to file a complaint with your state Attorney General or the Federal Trade Commission.
Who's responsible for your data
Beedy, LLC is a Delaware limited liability company (Delaware file no. 10637738) operating the beedy.app platform, with registered office at 131 Continental Dr Suite 305, Newark, DE 19713, USA and headquartered in Miami, Florida. For US users, Beedy is the "Business" within the meaning of CCPA/CPRA §1798.140(d) and the "Controller" within the meaning of the Florida Digital Bill of Rights and equivalent state laws. Privacy contact: privacy@beedy.app. To exercise the rights described in Section 7, write to privacy@beedy.app or submit a request via /privacy-choices. International transfer notice: your personal information will be processed primarily in the United States (primary cloud hosting); EU/EEA users' data transferred to the U.S. is protected under the EU-U.S. Data Privacy Framework or Standard Contractual Clauses — see Section 4 for transfer safeguards.
2. Information We Collect & Sources
We only collect the information needed to operate the Platform, secure accounts, comply with legal obligations, and improve the service. The categories below capture what we process; the next section explains the legal bases.
Identity & contact: Your name, email address, phone number, and — for pros — business name, EIN or sole-proprietor tax ID, professional license references (e.g., DBPR / CILB number for Florida contractors), and identity-verification documents. Pros operating as sole proprietors are individual consumers under FIPA for the personal portion of this data.
Service usage: Bookings you make or receive, messages exchanged with the other party in a Booking, reviews, ratings, search and browsing history within the Platform, and metadata about your platform activity (timestamps, device fingerprint for fraud prevention).
Payment data: Card details tokenized by Stripe — Beedy never stores raw card numbers; billing address, transaction history, and chargeback / dispute records. For tax-invoice and anti-fraud purposes we retain transaction metadata for the period required by IRS, Florida Department of Revenue (Form DR-15 sales-tax records), and PCI DSS retention rules (see Section 6).
Technical data: Device, browser, IP address, language preference, approximate location derived from IP, analytics events, error logs. Where you grant explicit permission, precise geolocation. Technical data is used for security, fraud detection, accessibility, and product improvement (anonymised aggregate analytics).
Where the data comes from
We receive most personal information directly from you (when you register, place a Booking, message a counterparty, or submit a review). For Pros: we may also receive verification data from public state business registries (Florida Sunbiz, DBPR license lookup) and from third-party verification providers (Checkr for background checks, Sterling for identity verification). Customers and Pros each receive the other party's contact and Booking details strictly to perform the service contract between them.
3. How We Use Your Information
Each purpose below is paired with the underlying reason we process the data. We do not use your personal information for any purpose other than those disclosed here. We do not sell your personal information (Fla. Stat. § 501.715).
Run the Platform: Matching Customers with Pros, handling Bookings, processing payments, delivering customer support, sending transactional notifications related to your Bookings, and providing access to the features you signed up for.
Why: Required to perform the Beedy Terms of Service and the underlying Booking — you can't get the service you signed up for without us using this information.
Security & fraud prevention: Verifying identities, detecting suspicious activity, account-takeover prevention, chargeback fraud detection (in coordination with Stripe), abuse prevention, and protecting the rights, property, and safety of Beedy, our users, and third parties.
Why: Necessary to operate a safe marketplace under FDUTPA (Fla. Stat. § 501.204) and to meet anti-money-laundering and PCI DSS obligations tied to payment processing.
Product improvement & analytics: Anonymized or pseudonymized analytics to understand usage patterns, fix bugs, prioritize development, and measure feature performance. Where strictly necessary, we may process identifiable data to debug an issue you reported.
Why: Strictly-necessary analytics rely on our legitimate marketplace-operations interest; non-essential analytics cookies (PostHog beyond first-party usage stats, Microsoft Clarity heatmaps) fire only after you opt in via the cookies banner.
Communications & marketing: Onboarding tips, transactional notifications (always sent — required for the service), and marketing communications about new features, promotions, or related services.
Why: Marketing emails and SMS (Twilio) are sent only with your express prior opt-in consent (TCPA-compliant for SMS) and you can opt out at any time — reply STOP to any SMS, or use the unsubscribe link in every marketing email. Transactional notifications stay on as long as your account is active.
You can object to any non-essential processing at any time by writing to privacy@beedy.app or via Settings → Security & privacy. We honor opt-outs within 15 business days (Florida Digital Bill of Rights timing).
SMS messaging: your mobile number and SMS consent are used only to send account and service messages (verification codes, booking and quote-request updates). Your mobile information will not be sold or shared with third parties for promotional or marketing purposes.
5. AI Features & Automated Decisions
Beedy uses AI tools, including third-party large-language-model providers such as OpenAI (under a subprocessor agreement), for limited assistive features. These features are advisory — they help the operator or you make a decision, but they do not autonomously bind anyone or make decisions with legal effect on you.
Personal data sent to AI subprocessors is transmitted over TLS 1.2+ encrypted connections via API. Under our contractual arrangement, AI providers do not train their models on Beedy User Content, and content is not retained beyond what is necessary to process the request. We monitor regulatory developments under the EU AI Act and U.S. federal and state AI guidance and update this policy as we deploy new AI features.
AI features in use
Photo analysis — assistive review of uploaded photos for content moderation (e.g., flagging clearly unsafe or non-compliant content). Final moderation decisions are reviewed by a human before suspension or removal.
Content moderation — assistive screening of reviews, messages, and listings for community-guideline violations. Outputs are advisory; enforcement decisions involve human review.
Category & price suggestion — for Pros, AI may suggest a service category or a price range based on similar Bookings. Suggestions are non-binding; the Pro sets the final terms.
Customer-support assistance — AI may suggest draft responses to support agents. Agents review and edit every response before it is sent to you.
Automated decisions — your right to human review
Beedy does NOT make solely-automated decisions that produce legal or similarly significant effects on you. Acceptance, refusal, or pricing of a Booking is decided by you or by a human Pro, with AI providing optional assistance only. You can request human review of any decision that materially affects you by writing to privacy@beedy.app — a right also expressly recognized under the Florida Digital Bill of Rights (Fla. Stat. § 501.705(3)(d)). For fraud-prevention scoring (which may temporarily flag a transaction), no automated final decision is taken — a human reviewer evaluates flagged transactions before suspension.
6. How Long We Keep Your Data
We keep personal information only for as long as needed for the purpose for which we collected it. Where law requires longer retention (e.g., IRS recordkeeping, Florida Department of Revenue sales-tax records), the longer period prevails.
- Active account data
- Identity, contact, and service-usage data are retained for as long as your account is active and for thirty (30) days thereafter, after which personal information is deleted or de-identified — except for the items below.
- Invoices & tax records
- Tax invoices, payment receipts, sales-tax filings (Form DR-15), and accounting records are retained for seven (7) years to satisfy the IRS recordkeeping rules under 26 CFR § 1.6001-1 and Florida Department of Revenue Rule 12A-1.0915.
- Anti-fraud & dispute records
- Records relating to identified or suspected fraud, Stripe chargebacks, and disputes are retained for five (5) years after the last related event to support PCI DSS investigation requirements and Florida's four-year statute of limitations on FDUTPA claims (Fla. Stat. § 95.11(3)(f)).
- Consent & cookie preferences
- Records of consent (for marketing, SMS opt-in under TCPA, cookies, terms acceptance) are retained for five (5) years as proof of opt-in. You may withdraw consent at any time; we keep the record of withdrawal for the same period.
- Server logs & technical data
- Security logs (IP, access timestamps): retained for twelve (12) months for security and incident investigation. Analytics events: pseudonymized after ninety (90) days; aggregated thereafter.
7. Your Rights & How to Exercise Them
You stay in control of your personal information. Under the Florida Digital Bill of Rights (Fla. Stat. § 501.705) — and parallel rights under California (CCPA/CPRA), Colorado (CPA), Virginia (VCDPA), and other state privacy laws — you may exercise the following rights, free of charge unless requests are manifestly unfounded or excessive:
Right to know / access: Confirm whether we process your data and receive a copy of the data plus the information required by Fla. Stat. § 501.705(2)(a) (categories collected, purposes, recipients, retention). Up to two free copies per twelve-month period.
Right to correct: Correct inaccurate or incomplete personal information without undue delay.
Right to delete: Request deletion of your personal information. Exceptions: data we are legally required to keep (sales-tax records under FL DOR Rule 12A-1.0915, IRS recordkeeping, anti-fraud records), data needed to complete a pending transaction, and data needed to establish or defend a legal claim.
Right to data portability: Receive your data in a structured, commonly used, machine-readable format (e.g., JSON) and transmit it to another controller where technically feasible.
Right to opt out: Opt out of the sale of personal information (we don't sell, but you have the right to confirm that), targeted advertising, profiling that produces legal effects, and the processing of sensitive personal information. Opt-outs honored within 15 business days.
Right to limit sensitive data use: Limit our use of sensitive personal information (precise geolocation, government-issued ID, etc.) to what is strictly necessary to perform the service. Toggle in Settings → Security & privacy.
Right against automated profiling: Where automated processing has a legal or similarly significant effect, request human review (see Section 5 — Beedy does not make solely-automated significant decisions today).
How to exercise your rights
Most rights can be exercised directly in Settings → Security & privacy, or by writing to privacy@beedy.app. We respond within forty-five (45) days of receipt (extendable by 45 days for complex requests, with prior notice — matching FL § 501.706). We may ask for proof of identity before acting on a request involving non-public data, to protect you from impersonation. There's no fee unless the request is manifestly unfounded, excessive, or repetitive.
How to escalate
If you believe we mishandled your personal information, you can: (a) appeal our decision by writing to privacy@beedy.app — we respond within 60 days; (b) file a complaint with the Florida Attorney General (myfloridalegal.com/contact); or (c) file a complaint with the Federal Trade Commission (reportfraud.ftc.gov). For Children's data: COPPA complaints go directly to the FTC.
8. Children's Privacy
Beedy is not intended for persons under the age of eighteen (18). We do not knowingly collect personal information from children under thirteen (13) without verifiable parental consent, in compliance with the federal Children's Online Privacy Protection Act (COPPA, 15 U.S.C. § 6501 et seq. and 16 CFR Part 312). If we discover we have collected such information without proper consent, we will delete it without undue delay.
Under Florida law, minors under 18 lack capacity to enter into binding contracts without a parent or guardian; the Florida Digital Bill of Rights adds extra protections for processing the personal information of known minors under 18 (no targeted advertising or sale, no profiling for significant decisions). We will not enter into a service contract with a known minor.
If you believe a minor has shared information with us without proper authorization, please contact privacy@beedy.app so we can investigate and delete the data without delay.
9. Data Security & Breach Notification
We use industry-standard technical and organisational measures to protect your data, proportionate to the risk: encryption in transit (TLS 1.2+) and at rest (AES-256 for sensitive fields), role-based access controls with least-privilege defaults, multi-factor authentication for staff, audit logging, regular vulnerability assessments, and incident-response procedures.
Our infrastructure is hosted on cloud providers with SOC 2 Type II / ISO 27001 certification (or equivalent). We segregate production data from development environments. Access by Beedy staff is logged and limited to a documented business need.
No system is 100% impenetrable. We run a coordinated-disclosure program for security researchers — vulnerabilities should be reported to security@beedy.app with a 48-hour acknowledgement commitment, and we will not pursue good-faith research conducted within the program's scope.
Breach notification commitment
If a personal-information breach is reasonably likely to result in identity theft or other financial harm, we will notify affected Florida residents and the Florida Department of Legal Affairs within thirty (30) days of confirming the breach, as required by FIPA (Fla. Stat. § 501.171(4) and § 501.171(3)). Residents of other states are notified per their applicable state breach-notification statute. We will also notify card brands per PCI DSS when payment-card data is involved.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect new features, processing activities, regulatory developments, or operational changes. The "last updated" date at the top of this page always reflects the current version.
Where a change is material — adding a new processing purpose, expanding the scope of personal data collected, or introducing a new category of recipient — we will notify you in advance via in-app notification and email, and (where required by law) seek renewed consent before applying the change to data already collected. Non-material changes (clarifications, typo fixes) may be made without notice; previous versions remain available on request.
We recommend reviewing this page periodically. You may also subscribe to a notification list (write to privacy@beedy.app) to be alerted of every update.
12. Contact Us & Supervisory Authority
Questions, requests, or concerns about your privacy or this policy? Our privacy team is here for you. We respond within five (5) business days for general inquiries, and within forty-five (45) days for formal rights requests (extendable by 45 days for complex matters, with prior notice).
Privacy team
privacy@beedy.appIf you are not satisfied with our response, you can appeal under Section 7, file a complaint with the Florida Attorney General (myfloridalegal.com), or contact the Federal Trade Commission (reportfraud.ftc.gov). You may also bring an action in a court of competent jurisdiction where law so provides, subject to the dispute-resolution clause in our Terms of Service.
Frequently Asked Questions (FAQ)
Have more questions? Reach out via the chat or contact our privacy team.