Privacy
Effective September 28, 2026. Boswell Business Systems provides this business website and operations service.
Information we store
When you sign in, the service receives your provider-specific account identifier, verified email and available display name. Firebase manages business email/password accounts, verification and password recovery. Boswell does not store your password. Administration may use ChatGPT sign-in. We store your business details, saved website versions, uploaded images, publication permissions and review history. Drafts and inboxes require authorized account access. Content you submit for publication becomes public only after approval.
Project and help requests
Request forms store your name, email, optional phone, message, answers and confirmation receipt. Business requests are available to the owning business. Boswell help requests are available to Boswell administrators. Businesses are responsible for how they use information provided to their business. We do not send automatic confirmation emails or use these forms to enroll you in marketing. Your browser tab temporarily keeps an unconfirmed submission so a refresh can recover the same request. After confirmation, only its receipt is kept. Recovery expires after 24 hours and is cleared when you start another request; closing the tab normally clears it too.
Hosting and access
The service uses ChatGPT Sites and its hosted database and file storage. OpenAI and its infrastructure providers process information needed to host and secure the service. Firebase and Google process account credentials and authentication emails. A secure session cookie connects verified Firebase identities to Boswell permissions; the Firebase SDK stores sign-in state in your browser. ChatGPT handles administrator sign-in. We use request limits and retain operational records for reliability and security. No advertising trackers are enabled. Optional business research uses OpenAI as described below.
Optional business research
When available and explicitly requested, business search sends your business name, location and optional public website to OpenAI’s web search to find relevant public pages. We retain source URLs, cited excerpts and your selections with your private draft. OpenAI response storage is disabled for these requests. Findings can be incomplete or incorrect; review them before approving content. Research does not send your password, inbox or customer records. If provider access or verified billing coverage is unavailable, enter the information manually. No research request runs just because you open the builder.
Business systems and AI setup
Your private system stores contacts, opportunities, projects, tasks, stock records, purchase orders, invoices, custom fields and activity history. When you request an AI system proposal, the business name, industry and description you enter are sent to OpenAI with response storage disabled. Other business records are not automatically sent. Review proposed settings and website copy before applying them. System exports contain private records; keep downloaded files secure. Job records can also contain estimates, changes, field notes, costs, appointments, reviewed concepts, approvals and private original files. Team access is scoped by the business owner. Backup archives include retained business records and referenced files, but exclude identity credentials and provider secrets.
Optional project-photo AI
With your explicit permission and verified provider coverage, selected job photos and your instructions can be sent to OpenAI for private analysis or a proposed concept image. Source roles and returned findings are retained in the business history and backup. Analysis response storage is disabled. A generated image is a proposal, not a measurement, engineering plan or approval. Nothing is automatically shared with customers.
Optional provider email
Provider email is currently disabled pending verified sender setup and billing coverage. When activated and explicitly requested, the approved sender, recipient, subject and plain-text message are sent to Resend. Provider acceptance and delivery events are stored separately from manual delivery evidence. A configured inbound mailbox retains signed event metadata and can retrieve private plain-text messages for owner review. Inbound email does not grant account access or trigger automated work. Attachments are not fetched and email content is not automatically sent to AI.
Customer payments
When checkout is connected, the selected payment processor handles payment details on its hosted checkout. Boswell stores the package, amount, account reference, payment status and verified receipt, plus prepaid usage records. We do not receive or store full card details. Payment records belong to the paying account and are not copied into another installation through a business backup.
Private customer portals
Business owners can explicitly share a reviewed project or invoice snapshot through an expiring private link. Anyone holding that link can read the shared snapshot and add messages, so it should be sent only to the intended customer. Portal access secrets are stored as hashes; access can be revoked by the business owner. Shared snapshots and messages remain in the business history after access expires or is revoked. Internal notes and unrelated records are not automatically shared. Portal replies stay inside Boswell and do not send email.
Retention and requests
Saved versions and requests are retained for business continuity; there is currently no automatic deletion schedule. Removing a page from publication does not erase its retained history. Use Contact Boswell to request access, correction or deletion, or report a privacy concern. We may need to verify your authority before acting. Do not submit payment-card details, health information, passwords or other sensitive data.