Privacy Policy
How we handle your data.
How WrapAlly collects, uses, shares, and protects data about wrap businesses and the customers they serve.
Effective date: September 14, 2026Who This Policy Covers
- WrapAlly is a platform for vehicle, commercial, residential, and other wrap installers and businesses ("Users"). This policy explains how we handle personal information for two groups.
- Users: the installers, business owners, and team members who create WrapAlly accounts and use the CRM, scheduling, invoicing, and Get Leads features.
- Prospective customers ("Customers"): the individuals whose contact details, project information, and photos reach WrapAlly through lead-generation forms, the sample picker, the kitchen visualizer, or information a User enters. Customers may submit an inquiry without a WrapAlly account, and much of their data is handled on behalf of the User or lead-generation partner who collected it.
Information We Collect From Users
- Account information: name, email address, phone number, profile photo, authentication status, organization membership, and organization role (provided via our authentication provider, Clerk).
- Organization data you enter into WrapAlly, including leads, customer contact details, tasks, schedules, templates, invoice content, activity history, uploaded files and photos, and related notes.
- Billing information for paid features: when you save a card for the Get Leads marketplace or enable customer payment collection, your card details are collected and stored by Stripe. WrapAlly stores only limited card metadata (brand, last four digits) and Stripe identifiers, never full card numbers.
- Integration data needed to connect services such as Gmail, Google Calendar, DocuSign, and QuickBooks, including connection status, account identifiers, and encrypted access or refresh tokens.
- Technical and usage data needed to operate and improve the service, such as request logs, device and browser information, error logs, security events, and cookies or similar technologies used for authentication, analytics, and session replay.
Information We Collect About Prospective Customers
- When a Customer submits a quote request, uses the sample picker, or uses the kitchen visualizer, we may collect their name, email address, phone number, address or ZIP code, project details (such as cabinet style, door count, and estimate range), photos of their kitchen or space, and the finishes or samples they select.
- We may also collect advertising and attribution identifiers when a Customer arrives from an online ad, including advertising click identifiers, campaign parameters (UTM values), and cookie-based identifiers set by advertising platforms (for example, Meta/Facebook Pixel identifiers). See "Advertising and Conversion Measurement" below.
- This information is used to create and route the lead to an installer, to let the Customer preview finishes, and to measure the performance of the advertising that generated the inquiry. Some lead information is collected through funnels operated by us or by our lead-generation partners and is shared with the installer who receives the lead.
AI Image Generation (Kitchen Visualizer)
- The kitchen visualizer and sample picker let a User or a homeowner upload a photo and generate an AI preview of how a finish would look. To create the preview, the uploaded photo and the selected finish are sent to a third-party AI provider for processing.
- The provider processes these images to return the generated preview under its applicable terms. Do not upload photos containing sensitive personal information you do not want processed by a third-party AI service.
WrapAlly AI Assistant
- WrapAlly AI is an optional chat assistant for Users. When you use it, the messages you type, any photos you attach, and the account data the assistant looks up to answer you (for example lead names, stages, tasks, and schedule entries) are sent to a third-party AI model provider (Anthropic) to generate the reply. The provider processes this data under its terms and does not use it to train its models.
- Conversations are stored in your account so you can return to them, and you can delete any conversation from the assistant. If you turn on memory, the assistant keeps short notes about your preferences; you can turn memory off or clear it at any time in the assistant settings.
- Do not share information in the assistant that you do not want processed by a third-party AI service. The assistant can make mistakes, so check important details before acting on them.
Voice Dictation and Spoken Responses
- When you choose voice dictation, WrapAlly uses the operating system's speech-recognition service in the mobile app or the browser's speech-recognition service on supported web browsers. Microphone access and, where applicable, speech-recognition permissions are requested. Depending on your device, browser and settings, recognition may be processed by the operating-system or browser provider rather than entirely on the device.
- When you send the resulting text to Ally, it is processed and stored as conversation content under the AI assistant provisions above. Spoken responses use your device or browser's speech functionality. You can manage microphone and speech-recognition permissions in your device or browser settings.
Organization Content, Community and Messages
- Content you add to an organization may be available to other members with access. Community posts are visible to the audience of the community area where you post them. Direct messages and attachments are provided to their intended recipients. Only share information appropriate for that audience.
How We Use Information
- To provide the WrapAlly CRM, task, template, invoice, scheduling, sample, visualizer, and lead-routing features.
- To create, route, and deliver leads to installers, and to bill installers for leads they receive through the Get Leads marketplace.
- To send emails, invoices, signature requests, and notifications when an authorized User takes that action or has opted in. In the mobile app, push notifications (new leads, tasks, messages) are optional and controlled by the device's notification permission and the app's notification settings.
- To measure and improve advertising performance and to report conversions to advertising platforms.
- To maintain security, troubleshoot issues, prevent abuse, and improve product reliability.
Gmail, Google Calendar and Google API Use
- WrapAlly requests Gmail send permission so you can send customer follow-up emails from your own connected Gmail account.
- The Google connection also requests Calendar event access. WrapAlly uses it to read, create, update and delete events for connected scheduling features, processing event details such as titles, descriptions, times and related scheduling information.
- You can disconnect Google in WrapAlly Settings or revoke access through your Google account.
- WrapAlly does not read your Gmail inbox, search your mailbox, import contacts, delete messages, or manage labels.
- Email content is created from templates you control, previewed before sending, and sent only after you click the send action.
- Google access and refresh tokens are stored encrypted and used to provide connected Gmail sending and Google Calendar scheduling features.
- WrapAlly's use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements. (Note: the separate AI image-generation feature described above is a distinct third-party service used only to produce visual previews.)
QuickBooks (Intuit)
- If you connect QuickBooks Online, the connection is made through Intuit and applies to the single QuickBooks company you select. It is shared by your whole WrapAlly organization, and anyone on your team can disconnect it.
- WrapAlly uses this connection only to create and update customer, invoice, and payment records in that QuickBooks company, reflecting work you complete in WrapAlly. It is not used to read your books for any other purpose.
- WrapAlly never receives or stores your Intuit sign in credentials. Authorization happens on Intuit's own screens, and WrapAlly stores only encrypted access and refresh tokens, the QuickBooks company identifier and display name, and the identifiers of the customer, invoice, and payment records it creates in your QuickBooks (used so a re-sent invoice updates the existing record instead of creating a duplicate).
- QuickBooks data is not sold, not shared with advertising platforms, and not used to train AI models or to build profiles.
- You can disconnect QuickBooks at any time from Settings, which revokes WrapAlly's access at Intuit. Records already written to your QuickBooks company remain in your books and are yours to keep or remove in QuickBooks.
DocuSign and Other Integrations
- If you connect DocuSign, WrapAlly uses the connection to create and send signature envelopes from invoice or document workflows you approve.
- Integration tokens are used only for the connected workflow and are not sold or used for advertising.
- You can disconnect supported integrations from your WrapAlly settings.
SMS / Text Message Notifications
- If you provide a mobile phone number and opt in, WrapAlly sends SMS text notifications alerting you when a new lead is delivered to your pipeline.
- We do not sell or share your mobile phone number or SMS opt-in consent with third parties or affiliates for their own marketing purposes. Information needed to operate and deliver these notifications may be processed by service providers acting on our behalf.
- Message frequency varies based on your lead volume. Message and data rates may apply.
- You can opt out at any time by disabling lead text alerts in your Settings, or by replying STOP to any message. Reply HELP for assistance.
Advertising and Conversion Measurement
- We and our lead-generation partners use advertising cookies and identifiers to measure the performance of online ads and to report conversions back to advertising platforms such as Meta (Facebook) and Google.
- This may include storing advertising click identifiers, UTM campaign parameters, and cookie-based identifiers (such as Meta Pixel _fbc/_fbp values) alongside a lead, and later sending conversion signals to those platforms to measure which ads generated inquiries or completed jobs.
- Where enabled, conversion signals may also include hashed customer name, email address, phone number and postal code to help match an inquiry to an advertising interaction. Hashing changes the format of these identifiers but does not make them anonymous.
- Depending on your location, you may be able to control advertising cookies through your browser settings or the advertising platforms' own opt-out tools. Some of this activity may be considered "sharing" for cross-context behavioral advertising under certain state privacy laws. See "Your Privacy Rights" below.
Analytics and Session Recording
- WrapAlly uses Microsoft Clarity for product analytics and session replay (behavioral metrics, heatmaps, and recordings of page interactions) so we can understand usage and improve the service. Clarity is disabled in the mobile app's embedded web views and website sessions opened through the app's sign-in handoff. Ordinary website browsing may still use Clarity. For signed-in sessions, we provide your account ID, name and email address to associate analytics with your account and help diagnose issues.
- Clarity supports masking of page text and form inputs. Masking does not anonymize account identifiers, names or email addresses provided separately to the analytics service. Session replay records page layout and interaction patterns.
- Usage data collected through Clarity is processed under Microsoft's privacy terms. For more information, see the Microsoft Privacy Statement at privacy.microsoft.com.
Cookies and Similar Technologies
- We use cookies and similar technologies for three purposes: strictly necessary cookies for authentication and security; analytics and session-replay technologies (Microsoft Clarity); and advertising/attribution identifiers set by us or advertising platforms.
- Strictly necessary cookies are required for the service to function. Analytics and advertising technologies are used to understand usage and measure advertising, as described above.
- You can control cookies through your browser settings. Where required by law, we will provide additional consent controls.
Service Providers and Data Sharing
- We share data with service providers ("processors") only as needed to operate WrapAlly. These include: Clerk (authentication); our application hosting and database provider; a cloud storage provider (file and photo storage); Resend (transactional email delivery); Stripe (payment processing and card storage); Google (Gmail sending and Google Calendar scheduling for connected accounts); third-party AI model providers (image previews and the WrapAlly AI assistant); Microsoft Clarity (analytics and session replay); a lead-routing/CRM provider (for certain funnels); Meta and Google (advertising and conversion measurement); a sample catalog and checkout provider; DocuSign (signature workflows); Intuit (QuickBooks accounting sync for connected accounts); Expo (push notification delivery for the mobile app, which receives device push tokens and notification text); the NHTSA vPIC service (decoding vehicle identification numbers you enter); and our SMS delivery provider.
- Customers seeking an installer voluntarily submit their contact and project details and agree to have those details shared to help find an installer. Participating installers may pay to receive these customer-requested leads. For certain funnels, the information also passes through a connected CRM or lead-routing provider used by us or our partner.
- We do not sell User account information or private CRM content to third parties for their own marketing. Customer-requested lead matching is described above. Separately, some sharing of advertising and analytics identifiers with the platforms above may be considered "sharing" or a "sale" for cross-context behavioral advertising under certain U.S. state privacy laws. See "Your Privacy Rights."
- We may disclose information if required by law, to protect rights and safety, or to investigate abuse of the service.
Security and Retention
- WrapAlly uses access controls, encrypted integration tokens, and hosted infrastructure safeguards to help protect data.
- No internet service can guarantee perfect security, but we work to keep access limited to authorized users and operational service providers.
- We retain data while your account or organization uses WrapAlly and as needed for the purposes described here, unless deleted or removed according to product functionality, support requests, or legal requirements. Lead and billing records may be retained as needed for accounting, dispute, and legal purposes.
Your Privacy Rights and Choices
- Users can update or remove many lead, template, task, and organization records inside WrapAlly, and can export their data using the "Download my data" option in Settings.
- Ally, VIN photo scanning and the AI Visualizer ask permission before sharing personal data with Anthropic or Google Gemini. You can decline and keep using other tools, or withdraw permission through AI privacy in the app or the corresponding tool on the website. Withdrawal stops future requests; information already sent cannot be recalled.
- You can disconnect Google (Gmail and Calendar), DocuSign, or QuickBooks from the Settings page, and opt out of SMS as described above.
- You can delete your account yourself at any time: in the WrapAlly app under Settings, then Delete account, or on the website under Settings. Deleting your account removes your login and your personal data from WrapAlly; lead and billing records may be kept only as described under Security and Retention.
- You can request access to, correction of, or deletion of your personal information by contacting us at contact@wrapally.com. Customers may also contact us to request access to or deletion of information we hold about them; where a lead was collected on behalf of an installer or partner, we may direct the request to them.
- Depending on your state or country, you may have additional rights (such as to access, delete, correct, or opt out of certain sharing of your personal information). To exercise these rights, submit a request at wrapally.com/privacy-request, opt out of sale or sharing at wrapally.com/do-not-sell, or contact us at contact@wrapally.com. We will respond as required by applicable law.
Children's Privacy
- WrapAlly is intended for users aged 13 and older and is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us personal information, contact us so we can investigate and delete that information. Users who are under 18 or the age of legal majority where they live must have a parent or legal guardian’s permission and supervision as described in our Terms of Service.
Changes to This Policy
- We may update this Privacy Policy from time to time. We will update the effective date above and, for material changes, provide notice by email or in-app notice.
Contact
For privacy questions or data requests, contact WrapAlly at contact@wrapally.com.
