Legal

Privacy policy

What we collect, why we collect it, who we share it with, how long we keep it, and how to make it go away.

Last updated: September 3, 2026

Who we are

SMB Tiller LLC (a Delaware limited liability company), trading as SMB Tiller, operates smbtiller.com and the SMB Tiller platform. In this policy “we”, “us” and “our” mean SMB Tiller LLC.

You can reach us about anything in this policy at navendu@smbtiller.com.

The three kinds of data we handle

Keeping these separate is the clearest way to explain what happens to your information, because the rules that govern each are different.

1. Website visitor data

Information collected when you browse smbtiller.com or email us: your message and contact details, plus standard server request data such as IP address, browser type and the pages requested. We use it to respond to you, to keep the site secure and available, and to understand which pages are read.

2. Customer account data

Information about the businesses that use our platform and the people who administer those accounts: business name and address, administrator names and contact details, authentication identifiers, billing information, and records of actions taken in the product. We use it to provide the service, to bill for it, to support it, and to meet our legal and tax obligations.

3. Connected platform data

Information we retrieve from advertising, commerce, operations and payments platforms on the instruction of the business that owns those accounts — campaign and performance data, lead and order records, job and scheduling data, and payment and settlement events. We access it only after the account owner grants authorization through that platform’s own consent flow, and only within the scopes that authorization covers.

We act as a processor (or service provider) for this category: the business that owns the account is the controller, and we handle their data on their instructions. Where a platform’s own policy imposes stricter requirements on how its data is used, stored or deleted, those requirements apply in addition to this policy, and we follow whichever is more protective.

How we use data

  • To provide, operate, support and improve the service for the customer it belongs to
  • To produce the attribution and reporting the customer has asked us to produce, joining their advertising, fulfillment and payment records
  • To authenticate users, prevent fraud and abuse, and keep the service secure
  • To bill for the service and keep the records the law requires us to keep
  • To communicate about the service, and — where permitted — about relevant new features

What we do not do

  • We do not sell personal information, and we do not share it for cross-context behavioral advertising.
  • We do not use one customer’s connected platform data to benefit another customer, and we do not pool it into a shared dataset or benchmark unless a customer has separately and explicitly agreed.
  • We do not use connected platform data to train or fine-tune machine learning models, and we do not create derivative or synthetic datasets from it for that purpose.
  • We do not attempt to re-identify data that has been aggregated or de-identified.

Who we share data with

We share data only in these circumstances, and only to the extent necessary:

RecipientPurpose
Infrastructure and hosting providersRunning the service, storing data, and delivering the website
Website analytics providersCounting page views on this website in aggregate. Two are used and they are not equivalent — see Cookies and analytics below for what each one records and how each is controlled
Connected platformsCarrying out the actions you instruct — creating a campaign, retrieving a report, requesting a payment
Payment and financing providersProcessing payments and presenting financing offers. These providers are independent controllers of the data they collect and apply their own privacy policies
Professional advisersAccounting, legal and audit services, under a duty of confidentiality
AuthoritiesWhere we are legally required to, or to establish, exercise or defend legal claims. We notify the customer unless we are prohibited from doing so
An acquirerIn a merger, acquisition or sale of assets. Any acquirer remains bound by this policy for data received, and we will give notice before your data becomes subject to a different policy

Every service provider we use is bound by contract to handle data only on our instructions, to protect it, and to delete or return it when the engagement ends.

How we protect data

  • Encryption in transit (TLS) and encryption at rest
  • Access limited to personnel whose role requires it, with individual credentials and multi-factor authentication; access to production systems is logged
  • Credentials and platform tokens stored in a dedicated secrets store, never in code
  • Separation between production data and development or test environments
  • Regular patching and dependency updates, and monitoring for unauthorized access

No system is perfectly secure. If a breach affects your data we will notify you and the relevant authorities within the timeframes the law requires.

How long we keep data

CategoryRetention
Website visitor logsUp to 12 months, then deleted or aggregated
Customer account dataFor the life of the account, then up to 90 days — available for export for the first 30 — unless the law requires longer
Connected platform dataOnly as long as needed to provide the service, and no longer than the originating platform’s policy permits. Deleted within 30 days of disconnection or account closure unless a shorter period applies
Billing and tax recordsAs long as tax and accounting law requires

Your rights

Depending on where you live, you may have the right to access the personal information we hold about you, to correct it, to delete it, to obtain a portable copy, to limit how we use sensitive information, and not to be discriminated against for exercising any of these rights. California residents have these rights under the CCPA as amended by the CPRA; residents of other states and countries may have equivalent rights.

Because we sell no personal information and share none for cross-context behavioral advertising, there is nothing to opt out of in those categories — but you are welcome to confirm that with us.

To exercise any right, use the process on our data and deletion requests page. If we hold your data on behalf of a business customer, we will refer your request to that business and support them in answering it.

Cookies and analytics

This website sets no advertising cookies and no cross-site tracking identifiers. Apart from what is needed to serve and secure the pages, the only cookie it can set is the Google Analytics one described below, and only where that is permitted.

We measure website usage with Vercel Web Analytics, provided by the same company that hosts this site. It is deliberately the least invasive option we could find, and it works without a cookie: repeat page views within a day are matched using a hash derived from the incoming request, which is discarded after 24 hours and is not tied to your IP address. Nothing it collects can be used to follow you to another website, and we cannot use it to identify you.

Each page view records the time, the page address and the referring address, filtered query parameters, an approximate location (country, region, city), your device type, and your browser and operating system versions. We see this only as aggregate counts.

We also use Google Analytics, which does set a cookie, so it is handled differently. In the United Kingdom, Switzerland and the European Economic Area it is switched off before the page loads and stays off unless you tell us otherwise — you will see a request, and declining changes nothing, because nothing was on. Elsewhere it is on by default; you can turn it off at any time using the Analytics preferences link in the footer of any page on this site.

Google’s advertising features are disabled unconditionally, everywhere, for everyone. We do not use this website to build advertising audiences, and there is no setting on it that turns that on. That is why the statement above about advertising cookies holds even with Google Analytics present.

We run no advertising pixels and no conversion tags on this website. If that changes we will update this policy and, where consent is required, ask for it before anything is set.

The product itself uses cookies strictly necessary for authentication and session security.

International transfers

We are based in the United States and our infrastructure is operated in the United States. If you are outside the United States, using the service involves transferring your data there. Where required, we rely on Standard Contractual Clauses or another lawful transfer mechanism.

Children

The service is for businesses. It is not directed to children under 16 and we do not knowingly collect their personal information. If you believe we have, contact us and we will delete it.

Changes to this policy

We will update this page when our practices change and revise the date at the top. For material changes affecting existing customers we will give notice by email before the change takes effect.

Contact

Privacy questions, requests and complaints: navendu@smbtiller.com.