GUIDESERVICES
Draft — Pending lawyer review

This document is a working draft prepared by GuideServices for legal counsel to review prior to use with paying customers. It is published here so charter partners and pilot participants can see the substance of how we plan to handle their data and their customers' data.

The final, executed Privacy Policy will replace this draft once counsel signs off. Until then, treat this as a statement of intent rather than as a legally binding privacy notice.

Privacy Policy

Draft v2026.07.18 · Last updated July 18, 2026
Contents
  1. Plain-English summary
  2. Who we are and what this covers
  3. Data roles — controller vs processor
  4. What we collect
  5. How we use it
  6. Who we share it with
  7. Sub-processors
  8. Data retention and deletion
  9. Your rights and how to exercise them
  10. Security
  11. Cookies and tracking
  12. International transfers
  13. Children
  14. Changes to this policy
  15. Contact

1. Plain-English summary

We're a small software company in Mobile, Alabama. We build software that helps hunting and fishing guides run their businesses. To do that, we have to handle two kinds of personal information: the guide's own contact info, and the contact info of the customers who book trips with that guide.

The rest of this document spells those points out in more detail.

2. Who we are and what this covers

GuideServices ("GuideServices," "we," "us," or "our") operates the websites at goguideservices.com, fish.goguideservices.com, and hunt.goguideservices.com, as well as the per-charter websites and booking-management portal we build and host for the charters who use our software.

This Privacy Policy covers personal information we collect, store, use, or share through any of those surfaces. It applies to charters who sign up to use our software, customers who book trips through a charter's Guide-Services-hosted site, and visitors to any of our marketing or charter sites.

3. Data roles — controller vs processor

We treat data differently depending on whose data it is and whose decisions are driving its use.

If you're an end-customer asking about the data a specific charter holds about you, the first stop is that charter; they control your record. We can help if the charter is unresponsive or has gone out of business.

4. What we collect

4.1 Charter accounts

4.2 End-customer data (held on behalf of charters)

4.3 Payment data

Payments are processed by Stripe (Connect Express, where applicable). Card numbers, bank account numbers, and other payment-instrument data go directly to Stripe and never touch our servers. We store only the booking amount, the Stripe payment-intent ID, the platform-fee amount, and the timestamps and statuses Stripe gives us via webhook.

4.4 Visitor and operational data

5. How we use it

We use personal information to:

We do not use end-customer data to send marketing on our own behalf. We do not use end-customer data to train AI models, sell ads, or build profiles for resale. We do not let one charter see another charter's customer list — multi-tenant separation is enforced by row-level security on every database table.

6. Who we share it with

We share personal information only as follows:

We do not sell personal information.

7. Sub-processors

GuideServices uses the following sub-processors. Each is selected for narrow purpose, billing transparency, and security posture; each is bound by their own privacy commitments and a data-processing agreement with us. The list below names each vendor's legal entity, primary operating jurisdiction, and the URL of their own privacy policy so you can read their commitments directly.

Provider Jurisdiction Purpose Data accessed
Supabase, Inc. Privacy policy United States
(AWS, US region)
Primary Postgres database, authentication (magic-link OTP), file storage (waiver scans, trip photos), Edge Functions, scheduled jobs. All charter and end-customer records (names, emails, phone, addresses, booking details, waiver scans, photos). Encrypted at rest; row-level security isolates each charter's tenant data.
Stripe, Inc. & Stripe Connect Privacy policy United States
(PCI-DSS Level 1)
Payment processing for trip bookings and charter platform-fee collection; charter payout routing via Stripe Connect; saved payment methods at the customer's option. Payment-instrument data (cards, bank accounts) collected directly by Stripe — we never see raw card numbers. We receive only Stripe-issued metadata: tokens, last-four, brand, billing zip, charge IDs, and connected-account payout records.
Cloudflare, Inc. Privacy policy United States Hosting (Pages), DNS, edge caching, DDoS protection, bot mitigation. Acts as data transit and TLS termination; no persistent PII storage on our behalf. Page requests, IP addresses, user-agent strings, and response bodies in transit. Bot-protection cookies (__cf_bm, cf_clearance) set per request; no behavioral profiling.
Twilio Inc. Privacy policy United States SMS notifications (booking confirmations, reminders, cancellations, weather updates) sent on the charter's behalf. End-customer phone number, booking timestamp, SMS body content. Delivery receipts and bounce metadata.
Postmark (Wildbit, LLC)
or
Resend, Inc. Postmark policy Resend policy
United States Transactional email — magic-link sign-in, booking confirmations, pre-trip reminders, post-trip thank-yous, monthly invoices, password resets. Final vendor choice pending before pilot launch. End-customer email address, charter sender identity, email subject and body content. Delivery, bounce, and open metadata.
OpenWeather Ltd. Privacy policy United Kingdom
(London)
Daily weather forecasts at charter trip locations; powers the pre-trip weather chips and the admin weather-action workflow. Charter-configured latitude/longitude coordinates only. No end-customer data is shared with OpenWeather.
Google LLC (Calendar API) Privacy policy United States Optional charter-side Google Calendar two-way sync, when the charter opts in. Disabled by default; OAuth scope limited to calendar read/write on the charter-selected calendar. Booking title, start/end time, and party size — only for charters who connect this integration. End-customer contact details are never sent to Google.

This list will be updated as we add or change vendors. Charters using the platform when a material sub-processor change occurs will be notified by email at least 30 days before the new vendor begins processing their data, so they have time to object or terminate.

8. Data retention and deletion

9. Your rights and how to exercise them

Depending on where you live, you may have rights to:

To exercise any of these rights, email [email protected]. We respond within 30 days. If you are an end-customer of a specific charter, we will route your request to the charter (the controller) and assist if needed.

You may also lodge a complaint with the consumer-protection agency in your state. We prefer to resolve concerns directly first if possible.

10. Security

We take reasonable measures to protect personal information against unauthorized access, alteration, disclosure, or destruction. Specifically:

No system is perfectly secure. If we discover a security incident affecting personal information, we will notify affected charters and end-customers as soon as practicable and as required by applicable law.

11. Cookies and tracking

We use a small number of cookies and similar technologies, all in service of running the platform:

We do not use third-party advertising trackers, retargeting pixels, or cross-site profiling cookies. We do not currently use a third-party analytics tracker; if we add one in the future, we will use one that respects user privacy and update this policy.

12. International transfers

GuideServices operates in the United States. Our primary infrastructure is hosted in the United States. End-users from outside the United States who use the platform do so understanding that their data is stored and processed in the United States, and that United States law will apply.

13. Children

GuideServices is intended for use by adults. We do not knowingly collect personal information directly from children under 13. If a parent or guardian books a trip on behalf of a child, the parent or guardian is the user of the platform, and the child's involvement on the trip itself is governed by the parent's consent and the charter's policies.

If you believe we have collected personal information directly from a child under 13, contact [email protected] and we will delete it.

14. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be posted here with the "Last updated" date at the top, and active charters will be notified by email at least 30 days before the change takes effect. Continued use after the change takes effect constitutes acceptance of the updated policy.

15. Contact

Questions about this Privacy Policy, requests to exercise a privacy right, or notices required by this policy should be sent to:

GuideServices
[email protected]
Mobile, Alabama