Legal

Privacy Policy

How we handle your data — plainly, what we collect, who we share it with, and the rights you have.

Effective date: July 5, 2026

1. Introduction

This Privacy Policy explains how Mortar ("Mortar," "we," "us," or "our") collects, uses, shares, and protects information when you use our website at https://www.withmortar.com and the Mortar software service (together, the "Service"). Mortar is an all-in-one CRM for small service businesses: it brings estimating, quoting, invoicing, e-signature, payments, lead and job tracking, scheduling, bookkeeping, and marketing into a single record.

By creating an account or using the Service, you agree to the practices described here and in our Terms of Service. If you do not agree, please do not use the Service.

2. Who we are

Mortar is operated by a United States sole proprietor based in Knoxville, Tennessee, USA. For any privacy question, request, or concern, contact us at build@withmortar.com. We are the point of contact for all matters described in this policy.

3. Controller and processor — how roles work

Mortar is a multi-tenant service. Each business that signs up (a "tenant" or "account") has its own isolated workspace. It is important to understand two different roles:

  • For your own account information (the email and password you use to sign in, your billing details, and how you personally use the Service), Mortar is the controller — we decide how that information is handled, as described in this policy.
  • For the business and customer data a tenant enters into Mortar (the tenant's own contacts, leads, jobs, quotes, invoices, financial transactions, and similar records), the tenant is the controller and Mortar is the processor. We store and process that data on the tenant's behalf and under the tenant's instructions. We do not use tenant CRM data for our own purposes, and we do not sell it. If you are an end customer of a business that uses Mortar and you have questions about your data, please contact that business directly; they control it. We will assist the business in responding to your request.

4. Information we collect

4.1 Account information

When you sign up, we collect your email address and a password. Passwords are stored only as a securely hashed value — we never store your plaintext password. We may also collect a display name and basic profile or organization details you provide.

4.2 Tenant CRM data (you are the controller)

When you use the Service, you enter business data into your workspace. Depending on the modules in your plan (Solo, Core, or Suite), this may include:

  • Contacts and companies (names, phone numbers, email addresses, physical addresses);
  • Leads, jobs, and pipeline records;
  • Estimates, quotes, invoices, e-signatures, and payment records;
  • Financial transactions, categories, and bookkeeping records;
  • Scheduling, dispatch, and recurring-service data;
  • Marketing records and campaign data;
  • Files, photos, and documents you upload.

You are responsible for having the appropriate basis and permissions to enter data about your own customers and contacts. Mortar processes this data on your behalf to provide the Service.

4.3 Billing information

When you subscribe to a paid plan, payment is handled by Stripe. Your card and bank details are collected and processed directly by Stripe under its own security controls and are not stored on Mortar's servers. We receive limited billing metadata from Stripe (for example, a customer identifier, plan, subscription status, and the last four digits or brand of a card) to manage your subscription.

4.4 Bank-transaction data (only if you connect a bank)

If you use the Bookkeeping module and choose to connect a bank account for automatic transaction feeds, that connection is handled by Plaid. With your authorization, Plaid provides Mortar with read-only financial data — such as transactions, balances, and liabilities — for the accounts you connect. Mortar cannot move money or initiate payments through this connection; it is read-only. See Section 7 (Financial data) for details, including how to revoke a connection. Connecting a bank is entirely optional; the Service works fully without it (you can also import statements manually).

4.5 Usage, log, and device data

Like most web services, we automatically collect basic technical information when you use the Service — such as IP address, browser type, device and operating-system information, pages or features accessed, timestamps, and error/diagnostic logs. We use this to operate, secure, and improve the Service.

4.6 Cookies

We use only essential/session cookies needed to keep you signed in and to keep the Service functioning securely. See Section 9 (Cookies).

We do not knowingly collect special categories of sensitive personal data beyond what a tenant chooses to enter into their own CRM records, and we do not use third-party advertising trackers.

5. How we use information

We use the information described above to:

  • Provide, operate, maintain, and secure the Service;
  • Create and manage your account and authenticate sign-in;
  • Process subscription billing and payments (via Stripe);
  • Provide the specific modules and features in your plan, including — where you enable them — bank feeds, e-signature, and payments;
  • Send transactional and service communications (account, authentication, security, billing, and notification emails) via Resend from build@withmortar.com;
  • Respond to your requests and provide support;
  • Monitor, debug, and improve the Service, including reliability, performance, and security;
  • Detect, prevent, and address fraud, abuse, and violations of our Terms; and
  • Comply with legal obligations and enforce our agreements.

We do not sell your personal data, and we do not share it with third parties for their own advertising.

6. Sub-processors and third parties we share data with

To run the Service, we rely on a small set of trusted third-party providers ("sub-processors"). Each receives only the data needed for its function, and each is bound by its own privacy and security obligations. This list is provided in the interest of transparency and to satisfy customer due-diligence requests.

ProviderPurposeLocationPrivacy policy
VercelWebsite and application hosting, delivery, and CDNUSAvercel.com/legal/privacy-policy
SupabasePrimary database, authentication, and file storage — stores account credentials (email + securely hashed password) and all tenant CRM dataUSA (us-east-1)supabase.com/privacy
StripePayment processing — (a) Mortar's own subscription billing and (b) Stripe Connect, so tenants can collect payments from their customers; may also provide bank verification via Stripe Financial Connections. Card and bank details are handled by Stripe under PCI standards and are not stored on Mortar's serversUSAstripe.com/privacy
PlaidRead-only bank-account data aggregation for the Bookkeeping bank feed (transactions, balances, liabilities), only when a tenant connects a bankUSAplaid.com/legal/#end-user-privacy-policy
ResendTransactional email delivery (account, authentication, and notification emails) sent from build@withmortar.comUSAresend.com/legal/privacy-policy
CalendlyDemo scheduling on the marketing website only (the /demo page); not part of the application itselfUSAcalendly.com/privacy

Optional, tenant-connected integrations

The following integrations are only active if a tenant chooses to connect them, and they receive data only for the feature the tenant enables:

We may update this list as our providers change. Material changes will be reflected here, and we will update the effective date. We will provide account owners with advance notice of new sub-processors on request.

7. Financial data (Stripe and Plaid)

Because Mortar handles money-related features, we want to be especially clear about financial data.

7.1 Payments (Stripe)

Payment card and bank-account details for both Mortar's own subscription billing and tenant payment collection (Stripe Connect) are processed directly by Stripe, which is a PCI-compliant payment processor. Mortar does not store full card numbers or bank credentials on its servers. Where bank-account verification is used, it may be performed through Stripe Financial Connections under Stripe's terms.

7.2 Bank feeds (Plaid)

If you connect a bank account through Plaid:

  • The connection is read-only — Plaid provides Mortar with transaction, balance, and liability data for the accounts you select. Mortar cannot move funds or initiate transactions through it.
  • Your bank login credentials are entered with Plaid, not with Mortar. Mortar does not see or store your online-banking username or password.
  • Plaid's handling of your data is governed by Plaid's End User Privacy Policy (plaid.com/legal/#end-user-privacy-policy) and Plaid's data-use terms.
  • The connection is revocable at any time. You can disconnect a bank from within the Service (Settings → Integrations), or by emailing build@withmortar.com, or through Plaid's own portal at my.plaid.com. When you disconnect, we stop syncing and purge the associated bank-connection tokens and synced bank-transaction data from that connection.

Connecting a bank is always optional. You can use the Bookkeeping module with manual statement import (CSV/OFX/QFX) instead and never share a bank login.

8. Data retention and deletion

Retention. We retain account information and tenant CRM data for as long as your account is active and as needed to provide the Service. After an account is closed, we retain data only as long as reasonably necessary to comply with legal, tax, accounting, and audit obligations, to resolve disputes, and to enforce our agreements — after which it is deleted or anonymized. Backups containing residual data are cycled out on a rolling basis in the ordinary course.

Deletion on request. You may request deletion of your account and associated personal data at any time by emailing build@withmortar.com. Upon a verified request, we will delete or anonymize the relevant personal data from our production systems within 30 days, except where we are required to retain certain records by law (for example, records of transactions for tax purposes). Residual copies in routine backups are removed as those backups age out.

Bank connections. Bank connections made through Plaid are revocable at any time (see Section 7.2). When a connection is revoked or your account is deleted, we stop syncing and purge the associated bank-connection tokens and synced bank data.

Tenant end-customer data. If you are an end customer of a business that uses Mortar and you want your data deleted, please contact that business — they control it. We will assist the business in fulfilling deletion requests as their processor.

9. Cookies

Mortar uses only essential/session cookies — the cookies required to authenticate your session, keep you signed in, and operate the Service securely. We do not use advertising cookies or third-party cross-site tracking. Because these cookies are strictly necessary to provide the Service, disabling them may prevent the Service from working.

10. Your rights and choices

Depending on where you live, you may have rights over your personal data. We honor these rights for our users regardless of location, subject to reasonable verification and legal limits.

Everyone may request to:

  • Access a copy of the personal data we hold about you;
  • Correct inaccurate or incomplete personal data;
  • Delete your personal data (see Section 8);
  • Export / portability — receive your data in a portable format.

To exercise any of these, email build@withmortar.com. We will respond within the time required by applicable law.

California residents (CCPA/CPRA). You have the right to know what personal information we collect and how we use and disclose it, to request access and deletion, to correct inaccurate information, and to not be discriminated against for exercising your rights. We do not sell or "share" (as those terms are defined under California law) your personal information, and we do not process it for cross-context behavioral advertising.

EU / UK / EEA residents (GDPR / UK GDPR). Where these laws apply, you have rights to access, rectification, erasure, restriction of processing, data portability, and to object to certain processing, as well as the right to lodge a complaint with your local supervisory authority. Where Mortar acts as a processor for a tenant, we will refer your request to that tenant (the controller) and support their response. This policy describes our practices honestly; it does not claim a formal certification or a specific compliance certification program.

11. Consent at signup

When you create an account, you are asked to affirmatively agree to our Terms of Service and this Privacy Policy before your account is created. That acceptance is your consent to the collection and use of information as described here. Continued use of the Service after changes to this policy constitutes acceptance of the updated policy.

12. Security

We take reasonable and appropriate measures to protect information, including:

  • Encryption of data in transit (HTTPS/TLS);
  • Passwords stored only as securely hashed values;
  • Authentication and row-level access controls that keep each tenant's data isolated from other tenants;
  • Capability-based permission checks on sensitive actions and data;
  • Delegating payment-card and bank-credential handling to specialized providers (Stripe, Plaid) so those secrets never touch our servers.

No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. You are responsible for keeping your account credentials confidential. If we become aware of a breach affecting your personal data, we will notify affected users and authorities as required by applicable law.

13. Children's privacy

The Service is intended for use by businesses and adults. It is not directed to children. We do not knowingly collect personal data from anyone under 18, and in no case from a child under 13. If you believe a minor has provided us personal data, contact build@withmortar.com and we will delete it.

14. International data transfers

Mortar and its sub-processors are based in the United States, and information is stored and processed in the United States. If you access the Service from outside the United States, you understand that your information will be transferred to and processed in the United States, where data-protection laws may differ from those in your country. Where required, we rely on appropriate safeguards for such transfers.

15. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the effective date at the top and, where appropriate, provide additional notice. Please review this page periodically. Your continued use of the Service after an update means you accept the revised policy.

16. Contact us

Questions, requests, or concerns about this Privacy Policy or your data:

Email: build@withmortar.com

Operator: Mortar (a US sole proprietor), Knoxville, Tennessee, USA

Book a live demo