Legal
Privacy Policy
Last updated: July 28, 2026
Rochester Concierge ("we," "us," "our"), owned and operated by Ben Murray in Rochester, New York, respects your privacy. This Privacy Policy explains what information we collect, how we use it, who we share it with, how we keep it safe, and the rights you have — including rights under the New York Stop Hacks and Improve Electronic Data Security Act (SHIELD Act, N.Y. Gen. Bus. Law § 899-aa & § 899-bb), the New York General Business Law § 899-cc (Notice of Data Breach), and, where applicable, the California Consumer Privacy Act (CCPA/CPRA) and the EU/UK GDPR.
1. Information we collect
We collect only what we need to deliver the service you request. Categories include:
- Account information: name, email, phone number, mailing address, account PIN, business affiliation, and role.
- Service request information: details you share when opening a ticket — such as service addresses, current provider names and account numbers, copies of bills, insurance policy details, vehicle/driver information for quotes, device make/model, and photos or documents you upload.
- Business profile data: business name, EIN or industry, employee count, subscribed services, secure notes for service logins (encrypted at rest), and uploaded files.
- Communications: chat messages, comments, emails, and notes you exchange with our team.
- Payment information: processed by Stripe. We receive last-four digits, brand, receipt data, and payment status — we do not store your full card number.
- Authentication data: hashed passwords, multi-factor identifiers, OAuth identifiers (Google, Apple), and session tokens managed by our authentication provider.
- Technical data: IP address, browser/device type, pages viewed, referring URL, and diagnostic logs. Collected for security and reliability.
We do not knowingly collect information from children under 13. If you believe a child has provided us information, contact us to have it deleted.
2. How we use your information
- Provide and fulfill the concierge services you request (bill negotiation, IT help, insurance quotes, setup, advocacy, etc.).
- Communicate with you — including sending ticket updates, invoices, receipts, appointment reminders, and responding to inquiries.
- Process payments and (with your explicit authorization) recurring auto-charges.
- Verify your identity before acting on your behalf with third-party vendors.
- Improve, secure, and troubleshoot the platform.
- Comply with law and enforce our Terms of Service.
We do not use your data for cross-context behavioral advertising and we do not sell your personal information.
3. Legal bases (GDPR/UK)
Where GDPR applies, we rely on: (a) performance of a contract, (b) our legitimate interests in operating and securing the service, (c) your consent (for optional communications and certain third-party outreach on your behalf), and (d) compliance with legal obligations.
4. How and with whom we share information
We share information only as needed to complete your request or run our business:
- Third-party vendors you engage us to contact — for example your internet, TV, mobile, or insurance provider. We share only what is needed to advocate on your behalf, and only after you authorize us to act as your representative.
- Service providers: our cloud hosting and database (Supabase / Cloudflare), transactional email (Resend/Lovable), payments (Stripe), and authentication (Google, Apple). These providers process data on our behalf under written data-processing terms.
- Legal: when required by subpoena, court order, or applicable law, or to protect the rights, safety, or property of Rochester Concierge, our clients, or the public.
- Business transfers: in the event of a merger, acquisition, or sale of assets, with continued protection under this policy.
We do not sell or rent your personal information.
5. Data retention
We keep information only as long as needed for the purposes described above or as required by law. See our full Data Retention Policy for category-level retention periods.
6. How we protect your information
Consistent with the reasonable-safeguards requirement of the NY SHIELD Act, we maintain administrative, technical, and physical safeguards, including:
- TLS encryption for all data in transit and encryption at rest for our database and file storage.
- Row-level security so customers can only access their own records; staff access is scoped by role and audited.
- Multi-factor authentication and per-account PINs for identity verification.
- Least-privilege access to secure notes (business login credentials are readable only by authorized business members and admins).
- Regular security scans, dependency review, and a documented incident-response process.
7. Data-breach notification (NY GBL § 899-aa)
If your private information is compromised, we will notify affected New York residents and, where required, the New York Attorney General, Department of State, and State Police, in the most expedient time possible and without unreasonable delay, consistent with law-enforcement needs and any measures necessary to determine the scope of the breach and restore system integrity.
8. Your rights
You may:
- Access, correct, or update your account information from your profile page.
- Request a copy or deletion of your personal information by emailing us.
- Withdraw consent for marketing communications at any time (transactional messages, invoices, and ticket updates will continue while your account is active).
- If you are a California resident: exercise CCPA/CPRA rights to know, delete, correct, and limit use of sensitive personal information. We do not sell or share personal information for cross-context behavioral advertising.
- If you are in the EU/UK: exercise your GDPR rights, including the right to lodge a complaint with your local supervisory authority.
To exercise any of these rights, email hello@rochesterconcierge.com. We will verify your identity (typically via your account PIN or a link sent to the email on file) before acting on the request and will respond within 30 days.
9. Cookies and analytics
We use strictly necessary cookies and local storage to keep you signed in and remember your preferences. We do not use advertising cookies or cross-site trackers.
10. International transfers
Our services are hosted in the United States. If you access the service from outside the U.S., you consent to the transfer and processing of your information in the U.S., subject to the protections in this Policy.
11. Changes to this Policy
We may update this Policy from time to time. We will post the new effective date at the top and, for material changes, notify you by email or in-app notice.
12. Contact us
Rochester Concierge · Rochester, NY
Email: hello@rochesterconcierge.com
Phone: (585) 371-8188
