Privacy Policy
This policy explains what information Mojo Systems LLC collects when you use our software, why we collect it, and the choices you have. We've tried to write it in plain language. If anything is unclear, email build@mojosystems.io.
1. Who we are
Mojo Systems LLC ("Mojo Systems," "we," "us," or "our") is a Pennsylvania limited liability company that provides software for lead capture, customer relationship management (CRM), field operations check-in, and related business workflows ("Services").
Our customers ("Account Holders") use the Services to run their own businesses. When an Account Holder's customer or employee interacts with the Services — for example, by submitting a lead form or checking in to a job site — that data belongs to the Account Holder and is processed by us on their behalf. This policy describes both our practices as a service provider to our Account Holders and our direct relationship with anyone who visits our website or uses the Services.
2. Information we collect
Information you give us
- Account information. When you sign up, we collect your name, email address, and a hashed password. If you upload contact details (your "vCard"), we collect job title, phone number, company name, website, and address.
- Payment information. If you subscribe to a paid plan, our payment processor collects your billing information directly. We do not store full credit card numbers.
- Communications. If you contact us by email, we keep that correspondence so we can respond and improve our service.
Information collected through the Services
- Lead and contact data. When end users submit a lead form created by an Account Holder, the form fields (typically name, email, phone, company, message) are stored under that Account Holder's data.
- Third-party sign-in (optional fast-fill). An Account Holder's capture page may offer the option to fill the form using a third-party identity provider (Apple, Google, or LinkedIn). If an end user chooses one of these buttons, the provider sends us a limited set of profile information — typically name, email address, profile picture URL, and (for LinkedIn) a public profile URL — based on the consent the end user gives in the provider's authorization screen. We use this information solely to pre-fill the capture form and pass the resulting submission to the Account Holder. We do not store the provider's access token after the form is submitted, and we do not write any information back to the provider.
- Field check-in data. If the Account Holder uses our check-in product, we collect the check-in time, approximate geolocation (when the device permits), the user's identity, and any photo or note they attach. SMS messages sent through the dispatch flow are stored.
- Inbox sync. If an Account Holder connects an email inbox, we periodically read messages relevant to leads (subject, sender, body, timestamps) so the conversation history can be displayed in the CRM.
Information collected automatically
- Log and device data. IP address, browser type, operating system, request paths, timestamps, referring URL.
- Cookies. A session cookie keeps you logged in. See cookies below.
3. How we use information
- To provide, maintain, and improve the Services.
- To authenticate users and protect against fraud and abuse.
- To communicate with you about your account, including transactional notifications, security alerts, and product updates.
- To respond to support requests.
- To comply with legal obligations.
We do not sell your personal information. We do not use your account data, lead data, or message content to train artificial intelligence models.
4. SMS & phone numbers
Our field check-in product uses SMS to coordinate dispatch and check-in workflows on behalf of Account Holders.
Consent and opt-in
An Account Holder collects opt-in consent from each individual before sending them SMS through the platform. We rely on the Account Holder's representation that they have obtained appropriate consent. Recipients can stop receiving messages at any time by replying STOP. Replying HELP returns contact information for support.
Frequency and cost
Message frequency varies based on operational activity. Standard message and data rates may apply per the recipient's wireless carrier. Mojo Systems is not responsible for carrier charges.
Carriers and delivery
Wireless carriers (including AT&T, T-Mobile, Verizon, and US Cellular) are not liable for delayed or undelivered messages. SMS service availability depends on carrier coverage and recipient device capability.
5. How we share information
We share information only as follows:
- With service providers ("subprocessors") who help us operate the Services. Current subprocessors include:
- DigitalOcean — cloud hosting and infrastructure.
- Twilio — SMS and voice messaging.
- SendGrid (Twilio) — transactional email delivery.
- Stripe — payment processing for paid plans and Deployment Kit orders.
- Printful — print and fulfillment for physical Deployment Kits (receives shipping address only).
- Apple, Google, and LinkedIn — third-party identity providers used only when an end user chooses to fast-fill a capture form via one of those providers. We receive identity information from the provider; we do not send Customer Data to them.
- With your Account Holder if you interacted with the Services as an Account Holder's customer, employee, or contact.
- To comply with law — for example, in response to a valid subpoena, court order, or legal process, or to protect the rights, property, or safety of Mojo Systems, our users, or others.
- In a business transfer. If we are involved in a merger, acquisition, financing, or sale of assets, your information may be transferred as part of that transaction. We will notify you before your information becomes subject to a different privacy policy.
We do not sell or rent your personal information to third parties.
Note on third-party sign-in. When an end user chooses to fast-fill a capture form using Apple, Google, or LinkedIn, the data shared from that provider flows to the Account Holder whose capture page was scanned. Mojo Systems handles that data on the Account Holder's behalf for the purpose of completing the submission. Mojo Systems does not use third-party-sign-in data for its own marketing, advertising, or model-training purposes. End users can decline a fast-fill option at any time and complete the form manually instead.
Note on AI connectors ("talk to your data"). On eligible paid plans, an Account Holder may choose to connect their Mojo account to a third-party AI application (for example, Claude or ChatGPT) so they can ask questions about their own data. The connection is read-only — the AI can read the Account Holder's own leads, capture points, and follow-ups, but cannot create, change, or delete anything — and it is scoped to that one account: it can never reach another customer's data. The Account Holder authorizes the connection by signing in through a secure authorization flow (OAuth), and can revoke access at any time. When an Account Holder uses a connected AI application, the data they request is transmitted to that AI provider at the Account Holder's direction, and their use of that provider is governed by the provider's own terms and privacy policy. Mojo Systems does not use data accessed through the connector for its own marketing, advertising, or model-training purposes.
6. Cookies and analytics
We use a small number of first-party cookies that are necessary for the Services to function, primarily a session cookie that keeps you signed in. We do not use advertising cookies or third-party advertising trackers. Basic server-side request logs are retained for a limited period for security and debugging purposes.
7. Data retention
We retain account information for as long as the account is active. Lead, contact, and check-in data is retained for the life of the Account Holder's account, plus a short grace period after cancellation during which the Account Holder can export their data. After that, data is deleted from our active systems and from routine backups within ninety (90) days. Server logs are retained for up to thirty (30) days. We may retain certain information longer if required by law.
8. Security
We use industry-standard security measures: data is transmitted over TLS, passwords are hashed with bcrypt, and per-tenant data is isolated at the database level. No system is perfectly secure. If we become aware of a breach affecting your information, we will notify you in accordance with applicable law.
9. Your rights and choices
Depending on where you live, you may have rights over your personal information. To exercise any of them, email us at build@mojosystems.io with the subject "Privacy Request." We will verify and respond within the timeframe required by applicable law, and you may use an authorized agent. We will not discriminate against you for exercising your rights.
We do not sell your personal information, and we do not "share" it for cross-context behavioral advertising as those terms are defined under California and other state privacy laws. Because we do not sell or share, there is no separate "Do Not Sell or Share My Personal Information" process — but you may still exercise the rights below.
U.S. state privacy rights (California, Virginia, Colorado, Connecticut, Texas, Oregon, and others)
If you are a resident of a state with a comprehensive privacy law, you may have the right to: (a) know and access the personal information we hold about you, including categories of sources, purposes, and recipients; (b) correct inaccurate information; (c) delete your information; (d) obtain a portable copy; (e) opt out of the sale of personal information, sharing for targeted advertising, and certain profiling (we do not engage in any of these); and (f) not be discriminated against for exercising your rights. If we deny your request you may appeal by replying to our decision, and where your state provides (for example, Virginia and Colorado), you may contact your state Attorney General.
Europe, the UK, and other regions (GDPR)
Where the EU or UK GDPR (or a similar law) applies, our legal bases for processing are: performance of a contract (to provide the Services), our legitimate interests (to secure, maintain, and improve the Services), your consent (where we request it, such as certain SMS or marketing), and compliance with legal obligations. You may have the right to access, correct, delete, restrict, or object to processing, to data portability, to withdraw consent at any time, and to lodge a complaint with your supervisory authority. Where we transfer personal information internationally, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.
Leads and other end users
If you interacted with us as an end user of an Account Holder's workflow (for example, you submitted a lead form to, or were scanned at a booth by, one of our customers), that Account Holder is the controller of your information and we act as their service provider/processor. Please direct access, correction, or deletion requests to that Account Holder. You may also contact us and we will route your request to the appropriate Account Holder or act on their documented instructions.
10. Children's privacy
The Services are not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, contact us and we will delete it.
11. Changes to this policy
We may update this policy from time to time. When we make material changes, we will update the "Last updated" date at the top and, if the changes are significant, notify Account Holders by email. Continued use of the Services after the effective date of an updated policy constitutes acceptance of the changes.
12. Contact us
Questions, requests, or complaints about this policy can be sent to: