Privacy Policy
Effective October 2, 2026
LFS Software Engineering ("LFS", "we", "us") is a software business based in South Florida, United States, operated by Luis F. Salazar. We provide a web platform (the "Service") that local service businesses use to run their website, collect job photos and videos from their crews, generate social media posts with the help of artificial intelligence, and publish approved posts to the business's own Facebook, Instagram and TikTok accounts.
This policy explains what information we collect, how we use it, who we share it with, and how you can have it deleted.
1. Who this policy covers
- Business customers and the owners, managers and crew members they invite to the Service.
- People who connect a social media account to the Service so a business can publish to it.
- Visitors to websites we host for our business customers, including people who send an estimate request.
When we host a website or process content for a business, that business decides what is collected from its own customers and is responsible for its own privacy practices. We process that information on the business's behalf.
2. Information we collect
Account information
Name, email address, the business you belong to and your role. We sign you in with one-time email links and keep a session cookie so you stay signed in.
Content businesses upload
Job photos and videos, job labels, notes, the service performed, tags such as "before" or "after", and records of customer consent to use the media. A business may add a private address note for its own reference. That note is never sent to AI providers and is never published.
Estimate requests on business websites
The details a visitor enters, such as name, phone number, email, location and a description of the job. These are delivered to the business. To prevent abuse we use a bot check and store a one-way hash of the visitor's IP address rather than the address itself.
Connected social accounts
When a business connects a social account we receive the account's identifier, display name, username, profile picture, the permissions that were granted, and access tokens. Details for each platform are in the sections below.
Publishing records
What was scheduled, when it was published, the platform's post identifier and a link to the post, so the business can see its posting history.
Technical information
Basic server logs needed to run and secure the Service. We do not write access tokens, contact details or addresses into our logs.
3. TikTok data
Businesses can connect a TikTok account using TikTok Login Kit. We request only these permissions:
- user.info.basic: the account's open ID, display name, username and avatar. We use these to show the business which TikTok account its posts will go to.
- video.publish: lets us publish videos to the account through TikTok's Content Posting API. We publish only content the business has approved in our portal, at the time the business scheduled.
We also read the posting options TikTok provides for the account, such as the allowed visibility levels, whether comments, duets and stitches are turned off, and the maximum video length. We use these only to show the owner valid choices and to send each post with the settings the owner picked.
We store the TikTok access token and refresh token encrypted, and use them only to publish the business's approved posts and keep the connection active. We do not read the account's followers, messages, other videos or analytics, and we do not use TikTok data for advertising, profiling or any purpose unrelated to publishing the business's own posts.
4. Facebook and Instagram data
Businesses can connect a Facebook Page and its linked Instagram professional account using Facebook Login. We receive the signed-in person's Facebook user ID and name, the Pages and Instagram accounts they choose to share with their names, usernames and pictures, the permissions granted, and access tokens. We use this access only to publish the business's approved posts to those accounts and to confirm that a post was published. We store the tokens encrypted.
5. How we use information
- To provide the Service: host websites, deliver estimate requests, process uploads, create post drafts, and publish approved posts.
- To keep the Service secure and working, prevent abuse and fix problems.
- To communicate with you about your account and the Service.
We do not sell personal information, we do not share it for advertising, and we do not show ads.
6. AI processing
To create post drafts, we send a business's job photos, still frames from its videos, the job label and notes, and basic business details such as its name and services to an AI provider, currently Anthropic. The AI suggests which media to use and writes captions. The business reviews every draft before anything is published. We do not send address notes, estimate request contact details, or social account tokens to AI providers. Anthropic processes this content under its commercial terms, which do not allow it to train its models on our inputs by default.
7. Who we share it with
- The social platforms the business connects, when we publish the business's approved posts.
- Service providers that host and run the Service for us, such as cloud hosting, database, file storage, email delivery, bot protection and the AI provider described above. They may use the information only to provide their services to us.
- The business whose website or account the information belongs to.
- Legal reasons: when required by law, or to protect the rights, safety and security of our users and the Service.
If LFS is involved in a merger or sale of its business, information may be transferred as part of that transaction under the same protections described here.
8. How long we keep it
- Social account tokens are kept only while the account is connected and are deleted as soon as it is disconnected.
- Uploaded media, drafts and publishing records are kept while the business uses the Service, and deleted within 30 days after the business closes its account or asks us to delete them.
- Server logs are kept for a short period for security and troubleshooting.
9. Disconnecting and deleting data
You can remove our access and your data at any time:
- Disconnect inside our portal. Go to Posting and choose Disconnect next to the account. We immediately delete the stored tokens and the connected account details.
- Remove access from the platform. In the TikTok app, remove LFS Software Engineering from the apps that have access to your account in your security settings. On Facebook, remove the app under Settings & privacy, then Business integrations. Once access is removed we can no longer publish to the account.
- Ask us to delete everything. Contact us as described below and tell us which business or account the request is about. We will delete the account information, uploads, drafts and publishing records we hold within 30 days and confirm when it is done.
Posts that were already published live on the social platform. Removing our access does not delete them. You can delete them in the platform's app at any time.
10. Security
We use HTTPS for all traffic, encrypt social account tokens at rest with AES-256-GCM, keep each business's data separated at the database level, and limit access to the people who operate the Service. No system is perfectly secure, but we work to protect your information and will notify affected businesses of a breach as required by law.
11. Your choices and rights
You can ask to access, correct or delete your personal information, or to stop a connection, by contacting us. Depending on where you live, you may have additional rights under local law, and we will honor them. If you are a customer of one of our business customers, you can also contact that business directly.
12. Children
The Service is meant for businesses and is not directed to children under 13. We do not knowingly collect personal information from children.
13. Changes to this policy
We may update this policy as the Service changes. We will post the new version here with a new effective date, and tell business customers about significant changes.
14. Contact
LFS Software Engineering, South Florida, United States. For privacy questions, data requests or deletion requests, contact us through luisfsalazar.com.