Skip to main content
Angel Tree Services
Menu

Privacy at Angel Tree Services.

One clear policy for our website, customer service records, secure portals, staff platform, and field app.

Certified Arborist-led · Insured · 30+ years of tree-industry experience

Who we are

Angel Tree Services LLC is a family-operated tree-service and property-care company serving the Fredericksburg region. Questions may be sent to info@angeltreeservice.org or discussed at (540) 388-8715.

Scope

This policy covers angeltreeservices.org, admin.angeltreeservices.org, proposal and invoice portal links, payment flows, and the Angel Tree employee iOS app. It covers customer, property, organization-contact, and employee/app-user information used to operate the business.

Information customers and contacts provide

We may receive names, phone numbers, email addresses, communication preferences, property or service-location addresses, requested services, project descriptions, gate or access instructions, photos, documents, and other details needed to prepare, schedule, perform, document, or follow up on work.

Estimate requests may also include whether the request is residential or commercial, marketing-consent choices, the page and referring page used to submit the request, campaign parameters present in the URL, and a submission identifier used to prevent accidental duplicates.

Business and service records

As work progresses, we may maintain customer and organization records, contacts, service locations, estimates, appointments, proposals, work orders, invoices, payment status and transaction references, communications, notes, job photos, documents, materials, equipment records, and activity history. Payment-card or bank details entered in a Stripe payment experience are processed by Stripe; Angel Tree systems retain business records such as amount, status, method category, and provider transaction reference rather than full card or bank credentials.

Employee and app-user information

Staff systems may process work-account identity, contact details, roles and permissions, employee-profile and work-assignment information, schedules, time and payroll-related operational records, credentials, training and safety records, documents, emergency contacts, job notes, photos, and actions taken in company systems. Access is limited according to assigned responsibilities.

Authentication, devices, and local storage

Our web platform and iOS app use Supabase authentication. Necessary session credentials are stored using supported browser or device session mechanisms. The web platform also uses limited browser storage for interface preferences, temporary work drafts, and portal-view session identifiers.

The iOS app may cache assigned schedules, customer or organization summaries, service locations, jobs, estimates, proposals, invoices, notes, and related field information on the device. A limited schedule snapshot may be stored in the shared App Group container for the Angel Tree widget. Signing out clears app-managed user caches and the widget snapshot.

Website forms and address suggestions

When address suggestions are enabled and a visitor types at least three characters in the property-address field, the browser requests suggestions from Google Maps Platform. Google may receive the typed address fragment, browser/network information, and a general Fredericksburg-area location bias. This assists typing only; it does not verify property ownership, service eligibility, or address accuracy. Manual entry remains available.

Automatically collected information

Our hosting, application, authentication, payment, and security providers may process IP address, request time, browser or device type, requested URL, response status, and similar operational logs. We use this to deliver and secure systems, diagnose failures, apply rate limits, prevent abuse, and maintain audit history.

The public website currently uses Google Analytics to understand aggregate website visits and interactions. This may use browser identifiers or cookies supplied by Google. We do not use the Angel Tree iOS app for advertising, and our application code contains no advertising SDK, IDFA integration, or data-broker integration.

How we use information

  • Respond to requests and communicate about estimates, scheduling, work, proposals, invoices, and payments.
  • Deliver, document, and improve tree-care and property services.
  • Operate staff accounts, permissions, schedules, field workflows, and business records.
  • Generate customer documents and maintain accounting, safety, audit, and legal records.
  • Protect systems, prevent duplicate or abusive submissions, investigate errors, and support recovery.
  • Send optional seasonal tips, service reminders, or scheduling updates where consent or an existing service relationship supports them.

Service providers

We use Supabase for authentication, database, and file storage; Netlify for hosting; Google for Maps/Places suggestions, staff-selected Calendar synchronization, and public-site analytics; Stripe for customer payment processing; Resend for transactional email; and Apple system services for the iOS app and widget.

Google Calendar receives only information needed for connected events, such as title, timing, location, status, and relevant work context. The iOS app contacts Supabase for authentication and the Angel Tree backend for operational data; it does not send customer records directly to Stripe, Resend, Google Calendar, or Google Analytics.

Customer portals and payments

Proposal, change-order, and invoice links use high-entropy tokens with expiration and revocation controls. A valid link may display a customer or organization name, service address, scope, pricing, approval or invoice status, and related documents. Portal-view security records may include a pseudonymous session identifier, document type, time, and technical request information. Recipients should protect portal links and avoid unnecessary forwarding.

Security

We use reasonable administrative, technical, and organizational safeguards, including authenticated access, role-based permissions, row-level database controls, protected storage, tokenized portal links, rate limits, security headers, and activity logging where appropriate. No internet or storage system can be guaranteed completely secure.

Retention and deletion

We retain information for as long as reasonably needed to provide service, maintain business continuity, support safety and security, meet accounting or legal obligations, resolve disputes, and preserve accurate operational history. Retention varies by record type and circumstances.

Login identity, employee records, customer records, service locations, operational history, financial records, and audit/security history are separate. Disabling or deleting a login does not automatically erase completed jobs, assignments, proposals, invoices, payment records, work history, or audit evidence reasonably needed by the business. We assess verified requests record by record and may remove, correct, restrict, de-identify, or retain information as appropriate.

Your choices and requests

You may ask for access, correction, deletion, account/access removal, or another privacy review through our Privacy & Data Request page. We verify identity and authority before disclosing or changing records. Submitting a request does not itself delete or alter data.

You can decline optional marketing messages, type an address without choosing a Google suggestion, and use browser controls to limit cookies or analytics. Blocking necessary authentication storage may prevent protected systems from working.

Children

Our services and company operations systems are intended for property owners, business contacts, customers, and authorized staff—not for children. We do not knowingly design these systems to collect information from children.

Policy changes

We may update this policy when our services, systems, or providers change. The effective date identifies the current version.