Ash.Labs
T2Legal

Privacy Policy

Effective August 10, 2026 · Last updated August 10, 2026

Template notice

This document is a business-drafted starting point, not legal advice. Have it reviewed by a licensed attorney in your state before publishing - particularly the SMS/messaging consent sections, given TCPA requirements for automated text communications.

01

Who We Are

Ash Labs ("Ash Labs," "we," "us," or "our") is an AI automation agency exclusively serving HVAC (heating, ventilation, and air conditioning) businesses. This Privacy Policy explains how we collect, use, disclose, and protect information when you visit our website at ashlabs.io ("Site"), engage us as a client, or interact with automated communications we operate on behalf of an HVAC business that has retained our services (a "Client").

Our registered business address is Austin, TX. You can reach us at contact@ashlabs.io or (555) 014-2280.

02

Two Kinds of Data We Handle

Because of what we do, this policy covers two distinct relationships. It's worth reading both sections even if you think only one applies to you:

  • Client data - information you give us directly as an HVAC business owner considering or using our services (your business details, contact info, billing info, and access credentials to your own tools).
  • End-customer data - information belonging to your customers (homeowners and businesses who call, text, or book with your HVAC company), which we process on your behalf as part of delivering automations like missed-call text-back, follow-up sequences, appointment booking, and review requests.

When we process end-customer data, we do so as a service provider / data processor acting under your instructions as the Client - you remain the party responsible for the underlying customer relationship and for having a lawful basis to communicate with your own customers.

03

Information We Collect

From website visitors:

  • Contact form submissions (name, email, phone, company name, message)
  • Basic analytics data (pages visited, browser/device type, approximate location, referral source)
  • Cookies and similar tracking technologies (see Section 9)

From clients (HVAC business owners):

  • Business name, contact details, service area, and billing information
  • Access credentials or authorized access to your phone system, website, Google Business Profile, calendar, and CRM, as needed to build and operate your Autopilot System
  • Brand voice, service offerings, pricing, and operational details you share with us during onboarding

From your customers (processed on your behalf):

  • Name, phone number, and/or email address
  • Call and message history relevant to lead follow-up, scheduling, and review requests
  • Appointment details, job status, and communications generated through the automation system

We do not knowingly collect financial account numbers, government ID numbers, or other sensitive personal data through these systems, and we ask Clients not to input such data into the CRM or automations we manage.

04

How We Use Information

  • To build, configure, test, and operate the automations included in your Autopilot System (missed-call text-back, lead follow-up, booking, reminders, review requests, CRM organization)
  • To communicate with you about your account, service delivery, billing, and support
  • To generate your monthly performance report
  • To respond to inquiries submitted through our website
  • To maintain, secure, and improve the systems we operate
  • To comply with legal obligations and enforce our agreements

We do not sell personal information, and we do not use Client or end-customer data to market unrelated third-party products or services.

05

SMS and Automated Text Messaging

A core part of our service involves sending automated text messages on a Client's behalf - including missed-call text-backs, lead follow-up, appointment confirmations and reminders, and review requests. The following applies to anyone who receives these messages:

  • Messages are sent using the Client's business phone number or a number designated for the Client's business, not a generic Ash Labs number.
  • Message and data rates may apply.
  • Recipients may opt out at any time by replying STOP, and may request help by replying HELP.
  • It is the Client's responsibility to ensure it has a lawful basis (such as an existing business relationship, prior express consent, or another applicable exemption) to text its own customers, consistent with the Telephone Consumer Protection Act (TCPA) and applicable state law. Ash Labs configures and operates the technology; the Client controls who is contacted and on what basis.
06

Third-Party Service Providers

We rely on third-party platforms to deliver the Autopilot System, which may include a CRM platform, an automation/workflow engine (e.g., n8n or Make), SMS and communication providers, and online booking/scheduling software. These providers process data as sub-processors under our direction, and each maintains its own security and privacy practices. A current list of providers used for your account is available on request.

We may also use standard website tools such as analytics and hosting providers to operate this Site.

07

How We Share Information

We do not sell personal information. We may share information:

  • With the third-party service providers described in Section 6, solely to deliver the services
  • With a Client, regarding that Client's own customers, since the data belongs to the Client's business relationship
  • If required by law, subpoena, or legal process
  • To protect the rights, safety, or property of Ash Labs, our clients, or others
  • In connection with a business transfer, such as a merger or acquisition, subject to the transferee's agreement to honor this policy's commitments
08

Data Retention

We retain Client and end-customer data for as long as reasonably necessary to deliver the services, comply with legal obligations, resolve disputes, and enforce our agreements. When a Client relationship ends, we will delete or return CRM and automation data within 90 days of the termination date, except where we are required to retain certain records for legal, accounting, or compliance purposes.

09

Cookies and Analytics

Our Site may use cookies and similar technologies to understand site usage and improve performance. You can control cookies through your browser settings. Disabling cookies may affect some Site functionality.

10

Data Security

We use reasonable administrative, technical, and organizational safeguards designed to protect information from unauthorized access, disclosure, alteration, or destruction. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

11

Your Rights and Choices

Depending on your location, you may have rights to access, correct, delete, or restrict use of your personal information, and to opt out of certain communications. To exercise these rights:

  • End customers receiving texts from a Client's Autopilot System may reply STOP to opt out of messaging at any time, or contact the Client business directly.
  • Clients and website visitors may contact us at contact@ashlabs.io to request access to, correction of, or deletion of their information.

We will respond to verified requests within the timeframe required by applicable law.

12

Children's Privacy

Our services are directed at businesses and adults, not children. We do not knowingly collect personal information from individuals under 18. If you believe a child has provided us information, contact us and we will delete it.

13

Changes to This Policy

We may update this Privacy Policy from time to time. We will post the revised version on this page with an updated "Last Updated" date. Material changes affecting how we handle previously collected data will be communicated to active Clients directly.

14

Contact Us

Questions about this Privacy Policy or how we handle data can be directed to:

Ash Labs
Austin, TX
contact@ashlabs.io · (555) 014-2280