Mandatory A2P 10DLC Carrier Mobile Privacy Disclosures
Mobile information and text messaging originator opt-in data and consent will NOT be shared, sold, rented, leased, or disclosed to any third parties or affiliates for marketing or promotional purposes under any circumstances.
All categories of service providers described in this policy exclude text messaging originator opt-in data and consent; if SMS is later activated, that data is shared only as needed to operate consent controls and route the approved message through Sent and underlying carriers.
1. Introduction & Corporate Ownership
This Privacy Policy (“Privacy Policy”) describes how Craft75, a Tennessee entity (“Company”, “Craft75”, “we”, “us”, or “our”), collects, uses, discloses, stores, and protects personal information when you visit, access, or use the Rebookt platform, website (rebookt.craft75.com), dashboard, APIs, mobile web applications, and associated services (collectively, the “Service” or “Platform”).
Rebookt is an automated client retention, aftercare, check-in, review request, and rebooking reminder SaaS platform designed for service-based businesses (e.g., salons, spas, tattoo parlors, medspas, fitness studios, auto detailing, and home service providers).
1.1 Scope & Audience
This Privacy Policy applies to three distinct categories of individuals:
- Business Owners / Subscribers: Individuals or business entities who register for an account on Rebookt to manage client follow-up sequences, staff profiles, and business settings.
- End-Clients / Consumers: Customers of Business Owners who complete an intake form (via QR code, web form at
/{slug}, or manual entry) or whose contact information is ingested via Point-of-Sale (POS) / scheduling integration (e.g., Square Appointments, Acuity Scheduling) to receive automated follow-up communications. - Website Visitors: Individuals who navigate our public marketing pages or interact with our public forms.
1.2 Data Controller vs. Data Processor Role
- For Business Owner Account Information: Craft75 acts as a Data Controller under applicable privacy laws for personal information collected directly from Business Owners during registration, billing, and account administration.
- For End-Client Information: Craft75 acts as a Data Processor (or “Service Provider” under CCPA/CPRA) on behalf of the Business Owner. The Business Owner acts as the Data Controller responsible for obtaining lawful consent and establishing appropriate legal grounds for uploading or transmitting End-Client personal information to Rebookt.
2. Information We Collect
We collect personal information directly from you, automatically through your use of the Service, and from third-party integrations as authorized by you.
2.1 Information Collected from Business Owners (Subscribers)
- Account Registration Data: Full name, business name, professional title, business email address, account credentials (managed via secure authentication provider Clerk), business phone number, and physical business address.
- Billing & Financial Metadata: Billing contact details, payment card metadata, billing address, and subscription transaction history. Note: All credit card numbers and financial credentials are collected and processed directly by our payment processor, Stripe, under Craft75's merchant account. Rebookt does not store raw credit card numbers or CVV codes on its servers.
- Business Profile & Content: Business logos, service catalog details, service pricing, aftercare instructions, custom sequence templates, staff member profiles, and business location settings.
2.2 Information Collected Regarding End-Clients (Consumers)
- Contact Identifiers: Full name, email address, and an optional mobile phone number. A saved phone number does not by itself enroll a person in text messaging.
- Service Transaction Metadata: Service type received (e.g., “Lash Full Set”, “Tattoo Session”), appointment date and time, service category, assigned staff member, and referral codes.
- Feedback & Sentiment Data: Ratings provided in response to aftercare or check-in sequences (e.g., 1-5 star sentiment selections), private feedback messages, and rebooking link interactions.
- Consent Logs: Channel, action, collection source, disclosure version, evidence fields, provider event identifier when applicable, and timestamps. Network/form evidence is recorded only when that collection surface supplies it.
2.3 Information Collected Automatically
- Device & Technical Data: IP address, operating system, browser type and version, device hardware specifications, time zone setting, language preferences, and unique device identifiers.
- Usage & Log Data: Access dates/times, pages viewed, features used, API requests, execution logs, system errors, and referring/exit URL pages.
- Message Telemetry: Provider acceptance, delivery events, link clicks, bounce notifications, spam complaints, and unsubscribe triggers. SMS receipts are processed only for a business whose carrier-approved mobile feature has been activated.
3. How We Use Your Information (Purposes of Processing)
We process personal information for the following specific operational and legal purposes:
- Service Provision & Sequence Automation: To deliver published email follow-up through Postmark. SMS through Sent may be enabled later for an individual business only after documented carrier registration, test-device evidence, and owner approval. WhatsApp and RCS are not part of the current release.
- Account Management & Authentication: To verify user identities, manage user sessions, enforce access permissions, and maintain account security through Clerk authentication.
- Billing & Subscription Processing: Stripe is connected in test mode during the controlled pilot. Live charges require a separate owner release decision.
- Template Administration: Pilot templates are selected from the Rebookt catalog and edited by authorized owners or administrators. No public generative-AI promise is part of this release.
- Customer Support & Service Operations: To respond to helpdesk inquiries sent to support@craft75.com or legal requests sent to hello@craft75.com.
- Platform Security & Fraud Prevention: To detect, investigate, and prevent fraudulent transactions, unauthorized platform access, spam dispatches, TCPA/CAN-SPAM violations, or security incidents.
- Legal & Regulatory Compliance: To satisfy statutory requirements, enforce our Terms of Service, defend against legal claims, and fulfill tax and accounting obligations.
4. A2P 10DLC & Mobile Messaging Policy
Mobile messaging is disabled by default. Rebookt will permit SMS for an individual business only after the required carrier registration, sender/campaign evidence, consented test-device delivery, and explicit owner approval are recorded. This section describes the controls that apply if SMS is activated; it is not a claim that carrier approval is currently complete.
Mobile information and text messaging originator opt-in data and consent will NOT be shared, sold, rented, leased, or disclosed to any third parties or affiliates for marketing or promotional purposes under any circumstances.
4.1 Mobile Opt-in Mechanisms
End-Clients opt into receiving text messages through clear, affirmative actions, including:
- Checking an explicit, unchecked SMS consent box that displays the current disclosure on an approved Rebookt collection surface.
- Sending an exact provider-supported re-opt-in keyword such as START, UNSTOP, or SUBSCRIBE.
4.2 Message Frequency, Rates & Carrier Liability
- Message Frequency: Message frequency varies according to the specifically disclosed and approved message purpose. No SMS is sent while mobile activation remains locked.
- Carrier Rates: Standard message and data rates may apply depending on the End-Client's wireless carrier plan.
- Carrier Disclaimers: Wireless carriers (including AT&T, T-Mobile, Verizon, Sprint, and regional operators) are not liable for delayed or undelivered messages.
4.3 Opt-Out (STOP) & Assistance (HELP) Commands
- To Stop Messages: End-Clients can opt out of SMS communications at any time by replying STOP, END, CANCEL, UNSUBSCRIBE, or QUIT. A verified keyword event immediately suppresses future Rebookt SMS for that contact.
- To Get Assistance: End-Clients can text HELP or INFO to any message received, or contact customer support directly at support@craft75.com.
5. Subprocessors & Third-Party Service Providers
We share personal information only with vetted third-party service providers (“Subprocessors”) who perform infrastructure, storage, payment, communication, and security services on our behalf. All subprocessors are bound by strict contractual data protection agreements prohibiting them from using personal data for any purpose other than providing services to Craft75.
| Subprocessor | Function / Role | Location |
|---|---|---|
| Craft75 | Platform Owner & Merchant of Record | Tennessee, USA |
| Vercel Inc. | Cloud Application Hosting & Edge Infrastructure | USA |
| Convex Inc. | Realtime Cloud Database & Storage | USA |
| Clerk Inc. | User Authentication & Identity Management | USA |
| Stripe Inc. | Payment Gateway & Billing (Craft75) | USA |
| Postmark (ActiveCampaign) | Transactional Email Dispatch Engine | USA |
| Sent | Approval-gated SMS routing; inactive until carrier and owner gates pass | USA |
| Google Cloud | Administrative catalog tooling when explicitly enabled | USA |
6. Data Security & Retention
6.1 Security Safeguards
Rebookt uses HTTPS in production, authenticated access through Clerk, server-side tenant ownership checks, provider-signature validation, and Stripe-hosted payment collection so raw card numbers are not stored by Rebookt. No security control eliminates all risk.
6.2 Data Retention Schedule
- Business Owner Account Data: Retained during the controlled pilot while the account is active and as needed to resolve support, security, legal, or deletion requests.
- End-Client Sequence Data: Retained as operational evidence during the pilot unless an authorized deletion request or legal obligation requires a different result.
- System Telemetry Logs: Retained according to the configured hosting and provider log windows. A fixed long-term deletion schedule has not yet been activated.
7. CAN-SPAM Act Compliance (Email Standards)
All emails sent through Rebookt contain accurate sender headers, non-deceptive subject lines, the physical mailing address of Craft75 (2310 Vance Avenue, Suite 202, Chattanooga, TN 37404), and an immediate one-click unsubscribe link.
8. US State Privacy Rights (Tennessee, CCPA/CPRA, etc.)
Residents of Tennessee, California, Virginia, and other US states have specific statutory privacy rights, including the Right to Know/Access, Right to Delete, Right to Correct, and Right to Non-Discrimination. Rebookt does not sell personal data or mobile opt-in information.
To exercise rights, contact us at support@craft75.com or by mail to 2310 Vance Avenue, Suite 202, Chattanooga, TN 37404.
9. Children's Privacy (COPPA)
Rebookt is a B2B platform intended for adults 18 years of age or older. We do not knowingly collect personal data from minors.
10. Contact Information
Craft75
2310 Vance Avenue, Suite 202
Chattanooga, TN 37404, United States