Skip to content
S Protocol
S ProtocolJobs, dispatch, team, money S InvoiceEstimates, invoices, payments Open S Protocol Open S Invoice
Compare Pricing How it works Integrations
S Protocolapp.s-protocol.com S Invoiceinvoice.s-protocol.com
Choose a product

Choose a product

S Protocol Jobs, dispatch, team, money. Web · iPhone · Free · $24.99/mo S Invoice Estimates, invoices, payments. Web · iPhone · Free · $4.99/mo
Compare Pricing How it works Integrations Contact Sign in to S Protocol Sign in to S Invoice Terms of Service Privacy Policy

S Protocol / Privacy Policy

Privacy Policy

Last updated: July 19, 2026 · Version 2026-07-19

This Privacy Policy explains how Elevate Repair LLC (“S Protocol,” “we,” “us,” or “our”) collects, uses, shares, and protects information when you use S Protocol and S Invoice — including s-protocol.com, app.s-protocol.com, invoice.s-protocol.com, our iOS application, and related services (together, the “Services”).

Contents

  1. Our role & your business’s role
  2. Information we collect
  3. Sign-in & authentication
  4. How we use information
  5. How information is shared
  6. Payments & Stripe
  7. Cookies & local storage
  8. Push notifications
  9. Analytics & diagnostics
  10. Logs, security & fraud prevention
  11. Data retention
  12. Deletion requests
  13. Business transfers
  14. Legal disclosures
  15. International processing
  16. Children’s privacy
  17. U.S. state privacy rights
  18. Changes to this policy
  19. Contact us

1. Our role & your business’s role

S Protocol is business software. It helps service businesses manage their own customers, jobs, estimates, invoices, and payments. That creates two distinct roles:

  • S Protocol as the service provider. We operate the platform and are responsible for the account information of the people who sign up and for how the platform itself processes data.
  • Each business as the owner of its customer records. When a business using S Protocol or S Invoice enters information about its customers (names, phone numbers, addresses, job details, and similar), that business decides what to collect and how to use it. We process those records on the business’s behalf to provide the Services. If you are a customer of a business that uses S Protocol, contact that business directly about its records; we will refer requests we receive to the relevant business where appropriate.
  • Payment processing by Stripe. Online card payments are processed by Stripe, which handles cardholder data under its own privacy policy (see Section 6).

2. Information we collect

Account & profile information

When you create an account we collect your name, email address, and credentials (passwords are handled by our authentication provider and are never stored in plain text). If you sign in with Google or Apple, we receive basic profile information from that provider (see Section 3).

Company & workspace information

Business details you provide for your organization — such as business name, business type, phone, city/market, state, timezone, website, logo, branding preferences, tax settings, and invoice document settings.

Customer information entered by businesses

Records a business keeps about its own customers: contact details, service addresses, notes, communication history, and related information. These records belong to the business that entered them (Section 1).

Jobs, estimates, invoices, payments & attachments

Operational and financial records your business creates in the Services: jobs and appointments, estimates and their line items, invoices, recorded payments and refunds, tips, price-book items, photos and document attachments, and customer signatures captured in the product.

Communications

Messages sent and received through the Services — for example customer text-message threads, emails sent from the platform, internal team chat, and messages exchanged through connected integrations (such as Thumbtack leads).

Device & browser information

Standard technical information such as IP address, browser and device type, operating system, timezone, and app version — collected when you use the Services, and used for security, delivery, and troubleshooting. For some security features (Section 10) we store only keyed one-way hashes of identifiers like IP addresses or phone numbers, not the raw values.

Website contact form

If you use the contact form on s-protocol.com, we collect the name, email, business name, phone, and message you submit, along with the page you sent it from, so we can respond. This form is processed for us by a Google service.

3. Sign-in & authentication

Authentication for the Services is provided through Supabase. You can sign up with an email address and password (with email verification), and single sign-on with Google or Apple is supported where offered in the product. When you use a single sign-on provider we receive basic profile details from it — typically your name and verified email address — and the provider’s own terms and privacy policy apply to your use of that provider. One-time SMS verification codes are used for certain customer-facing lookup features; for those flows we store hashed identifiers and never the raw code.

4. How we use information

  • Provide, operate, and maintain the Services, including syncing your data across web and mobile;
  • process subscriptions and payments, and maintain billing records;
  • send service communications — such as email verification, appointment reminders, notifications, and messages your business asks us to deliver to its customers;
  • provide customer support and respond to inquiries;
  • secure the Services — including authentication, rate limiting, abuse and fraud prevention, and audit logging;
  • understand product usage and improve the Services (Section 9); and
  • comply with legal obligations and enforce our Terms of Service.

We do not sell personal information, and we do not use your business’s customer records for third-party advertising.

5. How information is shared

We share information only as described here. Because the Services depend on infrastructure and specialized providers, some processing by service providers is inherent in operating the platform — so we cannot promise that data is “never shared”; instead, we limit sharing to what is needed to run the Services:

  • Supabase — our core backend platform (database, authentication, file storage, and server functions). Your data is stored in Supabase-managed infrastructure hosted in the United States.
  • Stripe — payment and subscription processing, including Stripe Connect accounts for businesses that accept online payments (Section 6).
  • Apple — for the iOS app: App Store distribution, push notification delivery, and — where offered — Sign in with Apple and in-app subscriptions billed by Apple.
  • Google — Sign in with Google; Google services a business connects (such as Calendar, Maps, or Business Profile); fonts served on our marketing site; and the Google service that processes our website contact form.
  • Email delivery providers (currently Resend) — to send verification and service emails on our behalf.
  • SMS delivery providers — to send and receive text messages, such as appointment reminders, customer messages, and verification codes.
  • Cloudflare — human-verification (Turnstile) during signup and related security or delivery infrastructure.
  • Microsoft — website analytics for our public marketing site through Microsoft Clarity, which may include session-replay and heatmap data (see Section 9).
  • Integrations you connect — such as Stripe, Thumbtack, Quo, Google services, or custom webhooks. When your organization enables an integration, we exchange the data needed for it with that provider, under its own terms.
  • Professional advisers and authorities — as described in Sections 13 and 14.

Service providers are permitted to process information only to provide their services to us. We do not share your information with unrelated third parties for their own marketing.

6. Payments & Stripe

Card payments, online invoice payments, payouts, and S Protocol Pro subscriptions purchased on the web are processed by Stripe — as are tips and in-person card payments, where those options are offered in the product. When your business enables online payments it creates a Stripe connected account, and information required for onboarding, compliance, and payouts is collected and processed by Stripe under its own privacy policy. Full card numbers are collected and held by Stripe — not by us; we store payment records (amounts, status, references) needed to show your business its invoicing and payment history. Where subscription purchase is offered through the iOS app, those subscriptions are billed by Apple, and Apple processes that payment information.

7. Cookies & local storage

We use cookies and browser local storage for things the Services need to work: keeping you signed in, remembering preferences, and security (including the Cloudflare Turnstile check during signup). Our public marketing website (s-protocol.com) also uses cookies and similar technologies set by Microsoft Clarity for usage analytics, including identifiers that recognize repeat visits (see Section 9). These analytics cookies are set when you visit the site — the site does not currently display a cookie-consent banner. We do not use third-party advertising cookies. Most browsers let you limit or block cookies in settings; blocking storage that the app needs may prevent sign-in from working.

8. Push notifications

If you enable push notifications in the iOS app, we store your device’s push token and use it to deliver notifications such as job updates and team messages through Apple’s push notification service. You can turn notifications off at any time in your device settings, and tokens for signed-out or removed devices are deactivated.

9. Analytics & diagnostics

First-party product diagnostics

Within the S Protocol and S Invoice products, we collect limited usage and diagnostic events to understand how features are used and to find errors — for example, screen-flow events and error reports from our apps. These events are designed to be privacy-safe: they are scoped to the relevant organization and use hashed session identifiers rather than raw personal identifiers, with restricted metadata.

Microsoft Clarity (website analytics)

Our public marketing website (s-protocol.com — including the S Invoice, Terms, and Privacy pages) uses Microsoft Clarity, a third-party website analytics service from Microsoft, to understand how visitors use the site and to improve its usability. Clarity may capture page interactions such as clicks, scrolling, mouse movement, and navigation behavior, together with device and browser information and approximate location derived from your IP address, and may produce heatmaps and session-replay recordings of website visits, subject to Clarity’s masking and privacy controls. Clarity uses cookies and similar identifiers to recognize repeat visits (see Section 7). The marketing website contains no password or payment fields; the only form on it is the contact form described in Section 2. Microsoft processes this data to provide the Clarity service and may also process it under Microsoft’s own privacy terms — see the Microsoft Privacy Statement — and retains it for limited periods under Microsoft’s policies. Clarity runs on these public marketing pages only; it does not run inside the signed-in S Protocol or S Invoice applications.

We use analytics for usability and product improvement — not for advertising. We do not use cross-site behavioral-advertising trackers on the Services.

10. Logs, security & fraud prevention

We keep logs and security records to protect the Services and their users, including signup and authentication event logs, rate-limit counters, notification and webhook delivery logs, and audit trails of significant account and billing changes. Several of these systems deliberately store keyed one-way hashes of identifiers (such as email addresses, IP addresses, and phone numbers) instead of raw values, so the logs can detect abuse without accumulating readable personal data. We use industry-standard safeguards such as encrypted connections (HTTPS), authenticated APIs, row-level access controls that scope every record to its organization, and human-verification challenges on public signup. No system is perfectly secure, and we cannot guarantee absolute security.

11. Data retention

We retain information for as long as needed to provide the Services and for legitimate business purposes: account and workspace data for the life of the account; business records (such as invoices and payment records) while your organization keeps them and as needed for legal, accounting, and audit purposes; and security logs and diagnostic events for limited periods appropriate to their purpose. Retention periods vary by record type, and some records may persist in encrypted backups for a period after deletion.

12. Deletion requests

Businesses can delete many records directly in the product. To request deletion of your account, your organization, or specific personal information, contact us at support@s-protocol.com from the email associated with your account. We will verify the request and respond within a reasonable time. Some information may be retained where the law requires it or where we have a legitimate need — for example, billing and tax records, fraud-prevention logs, or records of legal acceptance. If you are a customer of a business that uses S Protocol, please direct requests about that business’s records to the business itself (Section 1).

13. Business transfers

If we are involved in a merger, acquisition, financing, reorganization, or sale of assets, information may be transferred as part of that transaction. We will require the receiving party to honor commitments materially consistent with this policy, and we will notify affected users of material changes as described in Section 18.

14. Legal disclosures

We may disclose information where we believe in good faith that it is required by law or legal process, or reasonably necessary to protect the rights, safety, or property of our users, the public, or S Protocol — for example, responding to lawful requests from authorities, enforcing our Terms, or investigating fraud or abuse.

15. International processing

The Services are operated from the United States, and our primary database and file storage run on Supabase-managed infrastructure located in the United States (US West). Some services around that core operate more broadly: security and delivery services (such as Cloudflare’s verification service and Apple’s and Google’s delivery networks) run on globally distributed infrastructure, and third-party providers such as Stripe, Apple, Google, and email and SMS delivery providers may process data in other countries under their own policies. If you use the Services from outside the United States, you understand that your information will be transferred to and processed in the United States — and by these providers where they operate — where privacy laws may differ from those in your jurisdiction.

16. Children’s privacy

The Services are business tools intended for adults and are not directed to children. We do not knowingly collect personal information from children under 13. If you believe a child has provided us personal information, contact us at support@s-protocol.com and we will delete it.

17. U.S. state privacy rights

Depending on where you live, state privacy laws may give you rights over personal information — such as the right to know what we collect, to access or correct it, to request deletion, and to not be discriminated against for exercising those rights. You can exercise applicable rights by emailing support@s-protocol.com; we will verify your request and respond as required by applicable law. We do not sell personal information, and we do not use personal information for cross-context behavioral advertising; our website analytics provider (Section 9) processes data to provide its service to us. Note that for customer records held on behalf of a business (Section 1), your request may need to be directed to — or will be referred to — that business.

18. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will update the “Last updated” date and version above, and for material changes we will provide additional notice — such as email, in-product notice, or renewed acceptance at sign-in. Please review this page periodically.

19. Contact us

Questions or requests about privacy can be sent to:

Elevate Repair LLC (operating S Protocol and S Invoice)
Email: support@s-protocol.com

↑ Back to top
S Protocol

Two products for service businesses: S Invoice for the estimates and the invoicing, S Protocol for running the whole operation. Same foundation, same company.

Open S Protocol Open S Invoice

S Protocol

Overview Dispatch & scheduling Pricing iPhone app

S Invoice

Overview Estimates & invoices Pricing Open on iPhone or web

Compare

Which product Growth path Integrations FAQ

Company

Contact support@s-protocol.com

Legal

Terms of Service Privacy Policy One set of documents covers both products. Subscriptions bought through the App Store are billed by Apple and managed in your Apple account.
© 2026 Elevate Repair LLC. S Protocol and S Invoice are Elevate Repair LLC products.