App Privacy Policy
This page is for locksmith business owners, dispatchers, and technicians who use the InstaCode Dispatch iOS app ("the App") to run their business — not for the customers who call a locksmith. If you are a customer who called a locksmith and want to know how your information is handled, see our Privacy Policy instead. That policy also explains the AI phone-answering service, call recording, and text-message program the App's users rely on.
1. Who We Are
InstaCode Dispatch is a service of WH Software Holdings LLC ("InstaCode Dispatch," "we," "us," or "our"). The App is a business-operations tool for locksmith companies: it lets an owner, dispatcher, or technician manage jobs, customers, invoices, payments, inventory, and their team from a phone. This page describes what the App collects from you, its user, and from the business data you enter into it.
2. What We Collect
2.1 Your account
- Name, email, and phone number — collected at signup or invite, and used to identify you, let you sign in, and let your team and customers reach you.
- Password — we store only a salted hash of your password, never the password itself.
- Multi-factor authentication (MFA) — if you enroll in MFA, we store a TOTP (authenticator-app) secret, encrypted, to verify your one-time codes at sign-in. We do not receive or store your fingerprint or Face ID data — Face ID, when you use it to unlock a saved key or access code inside the App, is handled entirely by iOS on your device and never leaves it.
- Push notification token — an Apple Push Notification service (APNs) device token, so we can deliver job alerts to your phone. This is Apple's device push token, not an advertising identifier — the App does not access and has never accessed IDFA or any advertising SDK.
2.2 Your business
If you are a business owner, the App collects the business information you enter to configure your account:
- Business name, contact details, and address;
- Service area (the region you serve — configured as a business location on a map, not your device's location; see Section 6 below);
- Business hours and after-hours settings;
- Your staff roster — the name, email, phone, and role of each technician, dispatcher, or other teammate you invite, and the invitations and access changes you make for them.
2.3 Job and customer data you enter
As you and your team use the App to do locksmith work, it collects the information you enter about each job and the customer it is for:
- Customer contact details — name, phone, and email for the person you're servicing;
- Customer address — the service location for a job, so it can be shown to whoever is dispatched;
- Vehicle and job details — make, model, year, VIN, and other job-specific notes;
- Free-text notes — capture notes, scope-change reasons, write-off reasons, and other notes you type;
- Search terms — text you type into search boxes to look up customers, invoices, inventory, or vehicles is sent to our servers to run that lookup.
2.4 Photos
The App lets you attach photos to a job — for example, a photo of the work performed. It uses Apple's PHPickerViewController, which means the App only ever receives the specific photo(s) you pick in that moment; it never requests or holds general access to your photo library, and iOS does not prompt for photo-library permission because none is needed. Photos you attach are uploaded to our servers as part of the job record.
2.5 Payment information
Payments are processed by Stripe. The App never asks for, receives, or stores a customer's card number, CVV, or other raw card data — that is entered directly with Stripe (for example, via a Stripe-hosted payment link or a Stripe-hosted onboarding page opened in-app through a sandboxed browser view). What the App does send to our servers is the form of payment selected (cash, check, or card), along with amounts, tips, refunds, and write-offs you record for a job.
2.6 Call recordings and transcripts
If your business uses our AI voice-answering service, calls with your customers may be recorded and transcribed, as described in our Privacy Policy (Section 4). Recordings are captured by our backend voice system, not by the App — the App does not record audio and cannot access your device's microphone. When you play back a call recording in the App, it streams the recording from our servers; it is not stored unencrypted on your device.
3. Local Storage on Your Device
The App keeps an encrypted, on-device cache (using SQLCipher) of the business, job, and customer data described above, so you can keep working with recently-viewed records when your connection is unreliable. This cache is encrypted with a device-held key and is scoped to the account you're signed into.
When you sign out, the App wipes this local encrypted cache and its encryption key from your device. In some short-lived cases — for example, a session timeout where the App expects you to sign back in as the same person shortly after — it may preserve the encrypted cache temporarily rather than wiping it immediately, purely so re-authenticating doesn't force a full re-download; the underlying data remains encrypted at rest either way, and a full sign-out or the account-deletion flow below always wipes it.
4. How We Use Your Information
- Run the App's core features — job management, dispatch, invoicing, payments, inventory, and team management.
- Authenticate you — sign-in, MFA, and session management.
- Deliver push notifications — job alerts and updates to your device.
- Operate the voice-answering service — if enabled for your business, to route calls, prepare quotes, and hand off booked jobs into the App.
- Prevent fraud and secure accounts — detect suspicious sign-in activity and protect your account and your customers' data.
- Improve the service — understand how the App is used so we can fix bugs and prioritize features.
The App contains no advertising or analytics SDK, and none of the data above is used for tracking or advertising, or shared with data brokers. This matches the App Store privacy manifest we publish with the App, which declares every data type above solely for "App Functionality" and declares tracking as off.
5. How We Share Your Information
We share information with the service providers that help us run the App and the business behind it, under contracts limiting their use of it to providing services to us:
- Stripe — processes payments and payouts;
- Google Cloud — hosts our backend and stores data;
- Retell and Twilio — power the AI voice assistant and SMS messaging described in our Privacy Policy, where your business uses those features;
- Apple — delivers push notifications via APNs using the device token described above.
Within a business, staff data (name, role, contact details) and job/customer data are visible to other members of that same business, according to their role — that's what makes the App a shared team tool. Data from one business is never visible to another business.
We may disclose information when required by law, to respond to legal process, or to protect the rights, safety, or property of our users or our company. We do not sell your personal information and do not share it for cross-context behavioral advertising.
6. Location
The App does not access your device's GPS or location services — it never requests location permission and cannot obtain your device's whereabouts. The one place a map appears is the business owner's Service Area setting, where the owner drags a pin or types coordinates to describe the geographic area their business serves; that is a business configuration value, not a reading of anyone's device location. Photos you attach to a job are stripped of any embedded location (EXIF) data before upload.
7. Data Retention
Placeholder — needs counsel review. We keep account, business, and job data for as long as your account and business are active, and for a period afterward as needed to meet tax, accounting, and legal recordkeeping obligations (invoices, payments, and audit records in particular — see Section 8). We have not yet finalized exact retention periods for each data category; counsel should confirm specific retention windows before this section is treated as final, and this placeholder should be replaced with those windows.
8. Account Deletion
You can request deletion of your own App account from within the App (Settings), or by emailing help@instacodedispatch.com. Because the App is used by teams working on shared business records, exactly what happens depends on your role:
- If you are a technician, dispatcher, or other staff member — deleting your account removes your access. Your membership on the business is ended, but the business's jobs, invoices, and records are left completely untouched.
- If you are the sole owner of a business — an active business needs someone who can manage billing, staff, and settings, so we can't delete your account while you're its only owner. When you request deletion, the App will ask you to confirm closing the business as part of the same step. If you confirm, the business is marked inactive, every staff member's access is ended, and your account deletion then proceeds. There is currently no in-app way to hand ownership to a teammate first — that has to happen before deletion today.
- If you belong to more than one business — each business is handled independently: businesses you own must be closed (as above) as part of deleting your account; businesses where you're staff are simply left, unaffected.
When your account is deleted, we redact it rather than erasing the row outright: your email is replaced with a random, non-identifying placeholder and your name and phone number are cleared, and the account is deactivated so it can no longer sign in or be used. We do this instead of a hard delete because other records — jobs you were assigned, invoices you created, audit log entries — need to keep resolving to a valid (now-anonymized) account rather than becoming orphaned. Financial records (invoices, payments, refunds) and compliance audit-log entries tied to a business are never deleted or altered by an account deletion — those exist to support tax, accounting, and legal recordkeeping obligations, including for a business that has since been closed, and are retained under Section 7 above. Closing a business does not delete or alter its jobs, invoices, payments, or audit trail either — it only ends staff access to it.
We do not create, modify, or delete any invoice, payment, or refund as part of an account deletion.
9. Your Choices — Access and Deletion
- Request access — email help@instacodedispatch.com with the subject line "Privacy Request" to ask what account and business information we hold about you.
- Request deletion — use the in-app deletion flow described in Section 8, or email us at the same address. As described above, financial and audit records tied to a business are retained even after your personal account is redacted.
We may take reasonable steps to confirm your identity before acting on a request.
10. Security
We use technical and organizational safeguards to protect your information, including encryption of data in transit and at rest (including the on-device cache described in Section 3), MFA for account sign-in, and access controls that limit who can see business data to members of that business. No method of transmission or storage is 100% secure, but we work to protect your information using reasonable safeguards.
11. Children's Privacy
The App is a business tool intended for adult locksmith business owners, dispatchers, and technicians, and is not directed to children. We do not knowingly collect personal information from children under 13.
12. Changes to This Policy
We may update this policy from time to time. When we do, we will revise the "Last updated" date above. Material changes will be communicated as required by law.
13. Contact Us
InstaCode Dispatch, a service of WH Software Holdings LLC
Email: help@instacodedispatch.com
To request access to or deletion of your account information, email us with the subject line "Privacy Request." If you have a disability and need this policy in an alternative format, contact us at the email above.