Legal

Privacy Policy

Summons, Inc. — Effective April 6, 2026

1. Introduction

Summons ("we," "us," or "our") operates the Summons on-demand marketing marketplace platform (the "Service"). This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use our Service, whether as a Client, Genie (service provider), or Agency.

By using Summons, you agree to the collection and use of information in accordance with this policy.

2. Information We Collect

2.1 Account Information

  • Name and email address — provided during registration
  • Phone number — for account verification and communication
  • Profile photo — uploaded during onboarding
  • Professional bio, skills, and hourly rate — provided by Genies and Agency members

2.2 Identity Verification (Genies & Agencies)

  • Government-issued ID documents — submitted during the application process
  • Business registration documents — for Agency applicants
  • Identity documents are used solely for verification purposes and are stored securely

2.3 Payment Information

  • Credit/debit card details — collected by Stripe (our payment processor) for Client payments; we do not store card numbers on our servers
  • Bank account information — collected by Stripe Connect for Genie and Agency payouts
  • Transaction records — amounts, dates, and status of payments processed through the platform

2.4 Usage Data

  • Pages visited, features used, and actions taken within the platform
  • Device type, browser, operating system, and IP address
  • Session logs and timestamps

2.5 Communication Data

  • Messages exchanged between Clients and Genies through the in-app chat
  • Files and deliverables shared during sessions

3. How We Use Your Information

  • Provide the Service — matching Clients with Genies, processing payments, facilitating sessions
  • Identity verification — reviewing Genie and Agency applications
  • Payment processing — charging Clients, disbursing Genie earnings via Stripe Connect
  • Communication — sending account notifications, session updates, and marketing emails (with opt-out)
  • Safety & trust — detecting fraud, enforcing our Terms of Service, resolving disputes
  • Improvement — analyzing usage patterns to improve the platform experience

4. Data Sharing

We do not sell your personal information. We share data only in these circumstances:

  • Stripe — our payment processor receives payment and identity information necessary to process transactions and comply with financial regulations
  • Supabase — our infrastructure provider hosts and processes data on our behalf as a data processor
  • Resend — our email provider sends transactional emails on our behalf
  • Between users — Clients see a Genie's name, photo, bio, skills, and rating; Genies see the Client's name and project details
  • Legal requirements — when required by law, regulation, legal process, or government request
  • Business transfers — in connection with a merger, acquisition, or sale of assets

5. Data Retention

  • Account data is retained as long as your account is active
  • Transaction records are retained for 7 years for financial compliance
  • Identity verification documents are deleted within 90 days of verification completion
  • Chat messages and session files are retained for 1 year after session completion
  • When you delete your account, personal data is removed within 30 days (except where retention is legally required)

6. Data Security

We implement industry-standard security measures:

  • All data is encrypted in transit (TLS 1.2+) and at rest
  • Payment card data is handled entirely by Stripe (PCI DSS Level 1 certified) and never touches our servers
  • Access to production databases is restricted and logged
  • Row-level security policies enforce data isolation between users

7. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access — request a copy of the personal data we hold about you
  • Correction — update inaccurate or incomplete data
  • Deletion — request deletion of your personal data ("right to be forgotten")
  • Portability — receive your data in a machine-readable format
  • Restriction — limit how we process your data
  • Objection — opt out of certain processing activities including marketing

To exercise any of these rights, contact us at privacy@getsummons.com.

8. California Residents (CCPA)

If you are a California resident, you have the additional right to know what categories of personal information we collect and for what purpose. You may also request that we do not sell your personal information. We do not sell personal information.

9. Cookies

Summons uses essential cookies for authentication and session management. We do not use third-party advertising cookies. Analytics cookies may be used with your consent to understand how the platform is used.

10. Children's Privacy

Summons is not intended for users under 18 years of age. We do not knowingly collect personal information from children. If we become aware that a child has provided us with personal data, we will delete it promptly.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and, where appropriate, via email. Your continued use of the Service after changes constitutes acceptance.

12. Contact Us

If you have questions about this Privacy Policy or our data practices:

Last updated: April 6, 2026