SNAPBOARD

Privacy Policy

Last updated 2026-08-19 (draft)

Draft, not yet reviewed

This page is a working draft prepared for the HighLevel Marketplace submission. It has not been reviewed by the owner's legal counsel and must not be relied on, published externally, or cited in a live submission until that review is complete.

Who this covers

This policy describes how Snapboard Toolkit ("Snapboard," "we," "us") handles data for agencies and sub-accounts that install or use the product, including through the HighLevel Marketplace. Snapboard Toolkit is operated by [LEGAL ENTITY NAME], [BUSINESS ADDRESS], governed by the laws of [GOVERNING JURISDICTION].

What we store

We store the minimum data needed to run Theme Builder and the rest of Snapboard Toolkit for your account:

  • Tenant and account records. Your agency ("client") record, the HighLevel sub-accounts you connect, and which of your users have access, held in our Supabase database and isolated per tenant by row-level security policies keyed to your account.
  • An encrypted HighLevel access credential. Today this is a Private Integration Token (PIT) you provide during setup; as the app completes its HighLevel Marketplace OAuth integration this becomes an OAuth access and refresh token pair instead. Either way, the credential is encrypted at rest with AES-256-GCM before it is ever written to the database, and the browser is never shown the plaintext value, only the last four characters for identification. See "Security" below.
  • Theme configuration. The brand colors, navigation and menu customizations, presentation/behavior rules, and other Theme Builder settings you create, plus their draft and published history so you can review or restore prior versions.
  • Install heartbeat metadata. A timestamp and originating surface each time your installed theme successfully loads in a HighLevel sub-account, so the install screen can show you an honest "installed, last seen …" status. We do not log the page content your sub-account users viewed, only that the artifact loaded.
  • Support and account activity. If your agency also uses Snapboard's build-request queue, we store the requests you submit and any comments on them, tied to your account the same way.

Why we store it

Every category above exists to operate the product you installed: authenticating your team, applying your theme to your HighLevel sub-accounts, letting you undo or audit a change, and confirming an install is actually working. We do not sell data, and we do not use your HighLevel data to train models or to build profiles for advertising.

What we do not access

Snapboard Toolkit only calls HighLevel's official, documented public API (services.leadconnectorhq.com). It does not use HighLevel's internal or private endpoints. The Marketplace install requests exactly two read-only OAuth scopes: locations.readonly (confirms a connected sub-account still resolves, and applies your theme to the right location) and companies.readonly (confirms your agency and shows its name during setup). No write scope is requested, so nothing in this OAuth grant lets Snapboard Toolkit itself create, edit, or delete records in your HighLevel account through the API. It does not read your contacts, conversations, or opportunity data.

Retention

We keep your tenant records, theme configuration, and history for as long as your account is active, plus a limited retention window after cancellation so you can reactivate without losing your configuration. Encrypted credentials are deleted promptly when you disconnect a sub-account or close your account. Exact retention windows: [RETENTION PERIOD, e.g. 30/60/90 days post-cancellation], to be confirmed by the owner before publishing this policy.

Sub-processors

  • Supabase: hosts our application database (tenant records, theme configuration, encrypted credentials) and handles user authentication.
  • Cloudflare: hosts and serves the application (Cloudflare Workers) and the public theme artifact endpoints your HighLevel sub-accounts load.
  • HighLevel (GoHighLevel LLC): the platform this app integrates with. HighLevel is a separate company; see our Terms of Service for the affiliation disclaimer.

Requesting deletion

To request deletion of your account data, disconnect a sub-account, or ask what we hold about you, contact us at the address on our Support page. We will confirm your identity as the account owner before acting on a deletion request, and we will confirm back to you once it is complete.

Security

Access and refresh credentials are encrypted at rest (AES-256-GCM); the plaintext value is never returned to the browser. Preview links used inside HighLevel are short-lived, cryptographically signed tokens (HMAC-SHA256, capped at 15 minutes), not standing credentials. Public artifact endpoints are served with Cache-Control: no-store so nothing sensitive is cached at an intermediate layer. Full detail is in our security questionnaire answers, available to HighLevel on request. See also Terms of Service.

Contact

Questions about this policy: [SECURITY CONTACT EMAIL]. General support: see Support.