Last updated: July 2026
This policy covers both the public website at smartreach.dev (sections 1–6) and the SmartReach application used by our team and our clients (sections 7–9). Sections 10–13 apply to both.
The controller responsible for data processing on this website is:
SmartReach LLC
2880 W Oakland Park Blvd, Suite 225C
Oakland Park, FL 33311, USA
Email: support@smartreach.dev
We process personal data of our users only insofar as this is necessary to provide a functional website as well as our content and services. Processing is carried out on the basis of the General Data Protection Regulation (GDPR).
The legal bases are in particular Art. 6(1)(a) GDPR (consent), (b) GDPR (contract or pre-contractual measures) and (f) GDPR (legitimate interest).
This website is hosted by an external service provider. When the website is accessed, the server automatically collects information that your browser transmits, in so-called server log files:
This data is used for the technical provision, security and stability of the website. The legal basis is our legitimate interest (Art. 6(1)(f) GDPR).
Our website uses cookies and comparable technologies. Technically necessary cookies are set on the basis of our legitimate interest (Art. 6(1)(f) GDPR). Cookies used for analysis or marketing are only set with your consent (Art. 6(1)(a) GDPR). You can set your browser to inform you about the setting of cookies and to allow or reject cookies individually.
If you contact us by email or via WhatsApp, your information will be stored to process the request and in case of follow-up questions. The legal basis is Art. 6(1)(b) GDPR (pre-contractual measures) or (f) GDPR (legitimate interest in responding).
For contact, we offer the option of writing to us via WhatsApp (provider: WhatsApp Ireland Limited). If you use this channel, your phone number and message content are transmitted to WhatsApp. We have no influence over the data processing carried out by WhatsApp; WhatsApp's privacy policy applies: whatsapp.com/legal/privacy-policy-eea. Use is voluntary and based on your consent (Art. 6(1)(a) GDPR).
This website loads fonts ("Google Fonts") via servers operated by Google (Google Ireland Ltd.). When a page is accessed, the required font is loaded from a Google server; your IP address is transmitted to Google in the process. The legal basis is our legitimate interest in a consistent, appealing presentation (Art. 6(1)(f) GDPR). Further information: policies.google.com/privacy.
Access to the SmartReach application is by invitation only and is used by our team and by our clients to organize scheduling, appointments, and client work. It is not open to public sign-up. In this context we process:
The legal basis is Art. 6(1)(b) GDPR (performance of the contract with the user or the client) and Art. 6(1)(f) GDPR (our legitimate interest in operating and securing the application). Where we process contact data that a client enters on their own behalf, we act as a processor under a separate data processing agreement pursuant to Art. 28 GDPR.
The following processors support the operation of the application: our hosting provider (Laravel Cloud, application and database hosting), Resend (delivery of transactional emails such as booking confirmations and reminders), and Stripe (payment processing, where appointments are charged). Each is bound by a data processing agreement.
Connecting a Google account is optional and is always started by the user. If a user connects one, we request the following Google OAuth scopes:
.../auth/calendar.readonly — to read existing calendar entries so that busy times are excluded when free slots are calculated;.../auth/calendar.events — to create, update, and cancel the appointment events booked through the application;.../auth/userinfo.email — to show which Google account is connected and to match it to the SmartReach account.From your calendar we read only the information needed to determine availability (start and end times, busy status, and — for events created by us — their identifiers). We write only events that originate from a booking made in the application, and we never delete or modify unrelated calendar entries. Calendar content is not stored beyond what is required to keep a booking in sync with the corresponding event.
The OAuth access and refresh tokens issued by Google are stored encrypted in our database and are used solely to call the Google Calendar API on your behalf. The legal basis is your consent given in the Google authorization dialog (Art. 6(1)(a) GDPR) together with Art. 6(1)(b) GDPR for the performance of the calendar function.
SmartReach's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Google user data is used only to provide and improve the user-facing calendar features described above. It is never sold, never used for advertising or ad targeting, never used to train generalized artificial-intelligence or machine-learning models, and never made available to humans to read unless you explicitly ask us to (for example for support), it is necessary for security purposes or to comply with applicable law, or the data has been aggregated and anonymized.
You can disconnect your Google account at any time in the calendar settings of the application, or revoke our access at myaccount.google.com/permissions. On disconnection we delete the stored tokens immediately and stop all further calendar access; events already created in your calendar remain with you and can be deleted by you.
We retain personal data only for as long as it is needed for the purposes described above. Google OAuth tokens are deleted as soon as the connection is disconnected or revoked. Account and appointment data is deleted or anonymized when the account is closed or the client engagement ends, unless statutory retention periods (in particular under commercial and tax law) require longer storage. You can request deletion at any time at support@smartreach.dev.
Some of the services used (in particular Google, WhatsApp) may transfer data to the USA. Insofar as a transfer to third countries takes place, this is done on the basis of appropriate safeguards (e.g. EU standard contractual clauses) or your explicit consent pursuant to Art. 49(1)(a) GDPR.
You have the following rights regarding your personal data vis-à-vis the controller:
To exercise your rights, a message to support@smartreach.dev is sufficient. You also have the right to lodge a complaint with a data protection supervisory authority.
We hereby object to the use of contact data published within the scope of the imprint obligation for sending unsolicited advertising and information materials.
This privacy policy is currently valid. As our website develops or due to changed legal or regulatory requirements, it may become necessary to amend this privacy policy.