00Who is the controller
AirInk LLC, an Arizona limited liability company, is the controller of the personal information you provide to AirInk. Contact: privacy@airink.ai.
01What we collect
- Account data: name, email, phone, password hash, MFA status, role (vendor, client, planner, admin), and the persona/theme choices you save.
- Identity verification (vendors): the outcome and required fields from Stripe Identity. AirInk stores the verdict, timestamps, and issue codes only. Biometric identifiers (selfies, facial-geometry templates) are collected, used, and retained by Stripe under Stripe's privacy policy; AirInk does not receive or store them.
- Business data: contracts, milestones, messages, uploaded evidence (including photos), and audit events you create.
- Precise geolocation (evidence photos): when you upload milestone evidence, we read the EXIF metadata attached to the photo, which may include precise GPS coordinates, capture timestamp, and device details. We use this only to attach evidence to the milestone and share it with the client party on that contract. You may strip EXIF before upload; we show a notice at the point of collection.
- Payment metadata: Stripe customer and Connect account identifiers, payout status, fee breakdowns. Card and bank credentials are held by Stripe. AirInk never sees them.
- Bank account data (Stripe Financial Connections): when you link a bank account to pay by bank transfer or to receive payouts, Stripe Financial Connections accesses tokenized account and routing numbers, account ownership details, and balance information. Stripe uses this to verify the account is real and yours and to reduce failed or returned payments before a bank payment is initiated. Your bank login credentials go to Stripe or your bank, never to AirInk; AirInk stores only the bank name, the last four digits of the account, and the verification status.
- Consent records: which legal disclosures you saw (by hash) and when, plus the IP address and user agent used to accept them.
- Product telemetry: pages viewed, features used, device and browser type. First-party only; no cross-site advertising trackers or ad-network pixels.
02Why we collect it
- Operate the service and process the payments you initiate.
- Verify identities and prevent fraud (KYC/AML obligations).
- Verify linked bank accounts (account ownership and, where applicable, balance) before initiating a bank payment, to prevent fraud and reduce failed or returned payments. We do not use bank data for credit, insurance, housing, or any other FCRA-covered eligibility decision, and we do not access bank transaction history.
- Send transactional notifications (contract signed, payment released, dispute opened).
- Screen messages for fraud, spam, and abuse.
- Provide support and enforce our Terms.
03Subprocessors we share with
We share only what is needed to run the service. Current subprocessors:
- Stripe, Inc. - payments, Connect payouts, Identity verification (including biometrics), and Financial Connections bank account verification.
- Supabase (via Lovable Cloud) - application database, authentication, and file storage.
- Cloudflare, Inc. - edge hosting, DNS, and DDoS protection for AirInk requests.
- Lovable Email - transactional email delivery from notify.airink.ai.
- Twilio - outbound SMS notifications (when you opt in).
- Lovable AI Gateway - routes AI requests (drafting, extraction, review, moderation, assistants) to underlying model providers (including Anthropic and OpenAI) under commercial terms. Prompts and content are not used to train foundation models.
- Documenso - long-form e-signature delivery when used for a specific contract.
- Google Maps / Places - vendor business-address verification.
We do not sell personal information and we do not share personal information for cross-context behavioral advertising.
04How long we keep it
- Signed contracts and financial records: 7 years from creation, to satisfy tax, audit, and Arizona statute-of-limitations requirements.
- Consent event records: 7 years, to prove which disclosures you saw and accepted.
- Identity-verification outcomes: 5 years after account closure.
- Bank account link metadata (bank name, last four digits, verification status): retained with the related payment records; balance and ownership details are read at verification time by Stripe and are not stored by AirInk.
- Message content and moderation flags: 3 years, then deleted.
- Milestone evidence (photos): retained with the contract for 7 years.
- Support conversations: 24 months.
- Product telemetry: 13 months in raw form, then aggregated.
05Your controls
- Access, export, or correct your data from the settings page.
- Close your account at any time; we retain what we are legally required to keep and delete the rest.
- US residents (including CA, CO, VA, CT, UT) may exercise state-specific rights (access, deletion, correction, portability, and where applicable opt-out of "sharing" for behavioral advertising: which AirInk does not do) via our Privacy Rights Request form or by emailing privacy@airink.ai. We do not discriminate for exercising these rights.
- You may withdraw electronic-communications consent under E-SIGN by emailing support@airink.ai. Withdrawal does not affect prior electronic records.
06Security
Transport-layer encryption in transit, encryption at rest for the application database, row-level security on all business data, secrets in a managed vault, and least-privilege access for the AirInk team. Admin reveal of raw PII requires MFA re-authentication. Details on the Trust & security page.
07Automated decisions and AI
AirInk uses AI to draft, extract, review, moderate, and assist. AI is not used to make solely automated decisions that produce legal or similarly significant effects about you, a human at AirInk or the vendor reviews outcomes that materially affect eligibility, payment, or dispute resolution. When you interact with an AirInk-provided chatbot, you will see a clear notice that it is AI.