At a glance. Chantro is a B2B SaaS platform. When your employer creates a workspace, they are the data controller of your workspace activity; we process that data on their behalf. For the public website, marketing, and your personal account, we are the controller. We do not sell personal information for money, we do not share it for cross-context behavioral advertising, and we do not authorize our AI model providers to use Customer Data to train foundation models they or we do not own.
1. Introduction
This Privacy Policy describes how SmartTech ProServe LLC (“Chantro,” “we,” “us,” or “our”) collects, uses, discloses, retains, and protects personal information when you interact with our public marketing website at chantro.com, our product, and our other services (collectively, the “Services”). It also explains the rights you may have under applicable law and how to exercise them.
2. Scope of this policy
This policy applies to:
- Website visitors — anyone who browses chantro.com, our documentation, our blog, or related marketing assets.
- Account holders — individuals who create a Chantro account to access a workspace.
- Workspace Users — owners, administrators, estimators, project managers, field managers, workers, and other roles who use a workspace provisioned to their employer (the Customer).
- Prospects & inquirers — people who contact us, request a demo, or sign up for marketing content.
This policy does not cover third-party websites, apps, or integrations you choose to connect to Chantro — their privacy practices are governed by their own policies.
3. Our role — controller vs processor
Privacy laws distinguish between a party that decides why and how personal information is processed (a controller or business) and one that processes personal information on someone else's behalf (a processor or service provider). Chantro plays both roles depending on the context:
- We are the controller of personal information we collect through our public website, our marketing activities, our sales and support interactions, and individual account creation (for example, your name, email, and authentication data).
- We are the processor of the data that Customer uploads into, or generates within, a workspace — including project data, estimates, proposals, vendor lists, documents, internal messages, and analytics derived from those inputs. Customer is the controller of that data; our processing is governed by the Terms of Service and, where applicable, our Data Processing Addendum.
If you are a workspace User and have questions about how your employer uses data about you inside Chantro, contact the workspace Owner or your employer's privacy team first. We will refer access and deletion requests about workspace data to the Customer that controls it.
4. Information we collect
4.1 Account & identity data
- Name, work email, work phone, job title, company.
- Authentication data — hashed passwords, session tokens, and OAuth identifiers from Google, Microsoft, or other identity providers you connect. If we add multi-factor authentication, we will also process the identifiers required for that feature.
- Profile photo or avatar you upload.
4.2 Workspace & product content
- Projects, estimates, proposals, scopes of work, checklists, tasks, time entries, schedules, photos, and related documents you create or upload.
- Customer, vendor, and contact records you add to your workspace.
- Messages, comments, and audit events you generate inside the workspace, including conversational chat with the AI assistant.
- Data ingested through integrations you authorize (for example, email and calendar through Google Workspace, files from cloud storage providers, or e-signature status).
4.3 Billing data
When we begin charging for paid plans, we will rely on a PCI-DSS compliant payment processor to handle card and bank details. In that model, we expect to receive only tokenized references, the last four digits of a payment method, billing address, and invoice information — not full card numbers. When we integrate a specific payment processor, we will list it on our Subprocessor List and update this Privacy Policy.
4.4 Support & communications
- Support tickets, contact-form submissions, and their contents (which may include screenshots or attachments you send us).
- Call, meeting, or demo notes.
- Email we send you and engagement data (deliveries, opens, clicks) where permitted by law.
4.5 Device & usage data
- IP address, user-agent string, device and browser characteristics, approximate location (city-level, derived from IP).
- Page views, feature usage, error logs, performance metrics, click paths, and product events.
- Cookie and similar identifiers — see our Cookie Policy.
4.6 AI interaction data
- Prompts, instructions, and files you submit to AI features.
- AI Output returned to you.
- Thumbs-up / thumbs-down and other feedback you leave on AI Output.
4.7 Voice assistant data (if enabled)
- Audio streams captured while voice mode is active, converted to text by a speech-to-text provider.
- Transcripts of those sessions, stored within your workspace.
4.8 Sensitive categories we do not want
Chantro is not designed for, and you should not upload, (a) payment card numbers outside approved processors, (b) government-issued identifiers such as full Social Security or national ID numbers, (c) health information protected under HIPAA, or (d) precise geolocation unless required by a feature you have intentionally enabled. The Acceptable Use Policy lists the full restrictions.
5. Sources of information
We receive personal information from:
- You directly — when you create an account, use the product, or contact us.
- Your employer — when a workspace Owner invites you, imports a contact record, or configures single sign-on.
- Third-party integrations — when you authorize us to read data from services you connect, such as Google Workspace or cloud storage.
- Service providers — analytics, billing, fraud-prevention, and identity providers.
We do not buy personal information from data brokers. If we begin to use limited public-record information for account or vendor verification, we will update this policy and provide an opt-out contact.
6. How we use information
We use personal information to operate, secure, support, and improve our Services, and specifically to:
- create and administer your account and authenticate sign-ins;
- provision and isolate your workspace, enforce role-based permissions, and render the product;
- respond to support requests, contract negotiations, and customer success outreach;
- process payments, prevent fraud, and collect past-due invoices;
- monitor, debug, secure, and improve the Services — including incident response, abuse detection, rate limiting, and performance optimization;
- generate aggregated, de-identified analytics about platform usage and performance;
- send transactional and service communications (security alerts, billing notices, product change notifications) that you cannot opt out of while your account is active;
- send marketing communications where you have opted in or as otherwise permitted by law;
- comply with legal obligations, enforce our terms, and protect our rights.
7. AI & automated processing
We use AI to power features like the conversational assistant, voice mode, and summarization. Our AI Transparency Statement explains which model providers we use, what data is sent to them, their retention behavior, and the controls Workspace Owners have. In summary:
- We do not contribute Customer Data to train foundation models we do not own. Customer Data is not used to train a shared model.
- Model providers process data under commercial terms. We configure each provider's API to prohibit training on your inputs and outputs where that provider's tier supports such controls. Providers may retain content briefly for abuse monitoring where applicable — see the AI Transparency Statement for details.
- We may use workspace content to improve Chantro's own product (for example, evaluating prompts, measuring model quality, or building workspace-scoped fine-tunes) where contractually permitted.
- Automated decisions produced by AI features (for example, a risk score) are decision-support, not decision-makers. A human confirms or reviews before any material action is taken on the basis of AI Output.
8. Legal bases (EEA, UK, Swiss)
If GDPR, UK GDPR, or the Swiss FADP applies to our processing, we rely on one or more of the following legal bases:
- Contract — to provide the Service you or your employer ordered.
- Legitimate interests — to secure, debug, and improve our Services; prevent fraud and abuse; manage our customer relationships; and defend legal claims.
- Consent — for marketing communications, non-essential cookies, and optional features.
- Legal obligation — to comply with laws that apply to us.
You may withdraw consent at any time; withdrawal does not affect processing already performed.
9. How we share information
We share personal information only as described below — and we do not sell it.
- With your workspace. Your Workspace Owner, Administrators, and — based on your role — other Users can see data you create in the workspace, including audit logs of your actions.
- With integrations you authorize. We exchange data with the third-party services you connect, strictly as needed to perform the feature.
- With service providers (subprocessors). Infrastructure, storage, analytics, email, payment, AI, and support providers who act on our instructions under written contracts. See the Subprocessor List.
- With professional advisers. Lawyers, accountants, auditors, and insurers, under confidentiality.
- For corporate transactions. With advisers, counterparties, and successors in a financing, merger, acquisition, reorganization, or asset sale — subject to reasonable confidentiality protections.
- For legal reasons. To comply with law, respond to valid legal process, enforce our agreements, investigate fraud or abuse, or protect the rights, property, or safety of Chantro, our customers, or the public.
10. Subprocessors
We publish a current list of our subprocessors at chantro.com/legal/subprocessors. That list names each subprocessor, the service it performs, the categories of data it receives, and the region where processing occurs. Customers on eligible plans may subscribe to advance notice of material changes to the subprocessor list.
11. International data transfers
Chantro is headquartered in the United States, and our primary production infrastructure is located in the United States. When personal information is transferred out of the European Economic Area, United Kingdom, or Switzerland to a country that has not received an adequacy decision, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and equivalent Swiss mechanisms. Copies are available on request to privacy@chantro.com.
12. Data retention
We retain personal information for as long as needed to:
- provide the Services to you or your employer;
- comply with contractual, tax, accounting, and legal obligations;
- resolve disputes and enforce our agreements;
- maintain reasonable audit trails and backup integrity.
After a workspace is deleted, Customer Data is removed from active production systems within thirty (30) days and from routine backups in the ordinary course of our backup rotation (typically 30 days thereafter). Aggregated, de-identified data may be retained indefinitely. Marketing and prospect records are retained until you unsubscribe or request deletion, subject to suppression lists we are required to keep to honor your request under CAN-SPAM, CASL, and similar laws.
13. Security
We use administrative, technical, and physical safeguards designed to protect personal information, including TLS in transit, encryption at rest, tenant isolation enforced at the database layer via row-level security, role-based access controls, audit logging, least-privilege employee access, vendor security reviews, and a documented incident response process. Our Security Overview describes these controls in more detail. No system can guarantee absolute security.
14. Your privacy rights
Subject to applicable law, you may have the right to:
- Access the personal information we hold about you;
- Correct inaccurate or incomplete personal information;
- Delete personal information, subject to legal and operational retention needs;
- Receive a copy of your personal information in a portable format;
- Restrict or object to certain processing, including direct marketing;
- Withdraw consent where we rely on consent;
- Lodge a complaint with a supervisory authority.
To exercise these rights, email privacy@chantro.com. We verify requests by confirming control of your account email and, where needed, by asking for additional information proportionate to the sensitivity of the request. If you ask about data inside a workspace that belongs to your employer, we will refer the request to that Customer.
15. U.S. state privacy rights
If you are a resident of California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, or Virginia, you may have additional rights under your state's privacy law, including the right to know, access, correct, delete, and port your personal information, and the right to opt out of (a) the “sale” of personal information, (b) “sharing” for cross-context behavioral advertising, and (c) certain profiling. We do not sell personal information, and we do not share personal information for cross-context behavioral advertising. You may also designate an authorized agent to submit requests on your behalf; we will verify the agent's authority as permitted by law. We respond to Global Privacy Control signals where legally required. We do not discriminate against you for exercising privacy rights.
15.1 Shine-the-Light (California)
California Civil Code §1798.83 permits California residents to request certain information about our disclosures to third parties for direct-marketing purposes. Chantro does not disclose personal information to third parties for their own direct-marketing use.
15.2 Sensitive personal information
To the extent we receive “sensitive personal information” as defined by applicable state laws, we use it only to perform the Services, provide support, prevent fraud, comply with law, and as otherwise permitted without consent. We do not use sensitive personal information for purposes that require a right to limit under state law.
16. Children
The Services are not directed to, and we do not knowingly collect personal information from, children. Our Terms of Service require Users to be at least 18 years old. To the extent our processing is subject to GDPR or similar laws, we do not knowingly process personal information from children below the applicable age of digital consent (13–16 depending on jurisdiction). If you believe a child has provided us personal information, contact privacy@chantro.com and we will delete it.
17. Cookies & tracking
We and selected partners use cookies and similar technologies on chantro.com and in the product to keep you signed in, remember preferences, analyze performance, and measure marketing. Full categories, purposes, and retention periods are in our Cookie Policy. Where required by law, we ask for your consent before loading non-essential cookies, and you can change your choices at any time through our cookie preference center.
18. Marketing communications
You can unsubscribe from marketing emails using the link in every marketing email, by emailing privacy@chantro.com, or by updating communication preferences in your account. Transactional and service messages (security, billing, outages, material product changes) are not considered marketing and will continue as long as your account is active.
19. Do-Not-Track & GPC
Our Services do not respond to traditional browser “Do Not Track” signals, because there is no consistent industry standard. Where required, we honor Global Privacy Control (GPC) signals from supported browsers as a valid opt-out of sale and sharing.
20. Workspace & personnel data
When a Chantro workspace holds personal information about a User or a third party (for example, a worker, subcontractor, customer contact, or vendor), the Customer is the controller and is responsible for notices and lawful basis. We act as processor and will assist Customer in responding to data-subject requests in the manner described in our Data Processing Addendum. If you are an individual whose data appears in a workspace, please contact the Customer that owns that workspace; we will forward requests we receive directly to the appropriate Customer.
21. Changes to this policy
We may update this Privacy Policy to reflect changes to our practices, to our Services, or to applicable law. We will post the revised policy with a new “Last Updated” date. If changes are material, we will provide prominent notice (for example, in-product or by email to the Workspace Owner) at least thirty (30) days before the change takes effect, unless the law requires faster action.
22. Contact
Privacy questions, rights requests, and complaints can be sent to our Privacy Team at privacy@chantro.com.
SmartTech ProServe LLC
1405 Gallagherville Rd #1
Downingtown, PA 19335, United States
If you are located in the EEA, UK, or Switzerland and believe our processing infringes applicable law, you may also lodge a complaint with your local supervisory authority. We appreciate the chance to address concerns directly first.