
Privacy Policy
Effective August 20, 2026
What this policy covers
PITCH is a contractor customer relationship management, business operations, accounting, and payroll-support platform provided by Plug and Play Sales & Consulting. This policy explains how PITCH handles information about platform users, contractor businesses, employees, vendors, and the customers and projects those businesses place in their workspaces.
Information we handle
- Account and business information, including names, email addresses, phone numbers, roles, company details, authentication, and security activity.
- Contractor customer and project information, including contact details, addresses, appointments, estimates, contracts, signatures, invoices, job notes, measurements, photos, and documents.
- PITCH Books information, including ledger entries, accounts, invoices, payments, expenses, receipts, vendors, purchase orders, bank-statement evidence, reconciliations, cost allocations, reports, and professional-review records.
- PITCH Books Payroll information, including employee identity and contact information, work locations, compensation, time, deductions, tax elections and identifiers, payment and pay-statement records, job-cost allocations, approvals, corrections, workpapers, and legal or professional evidence.
- Communication records and preferences for emails, text messages, and notifications sent through PITCH.
- Integration information, including connected-account identifiers, granted permissions, and encrypted OAuth tokens or API credentials.
- Technical and security data such as browser and device information, timestamps, session data, audit activity, and keyed or hashed network identifiers.
- Demo and sales-request information a prospect chooses to provide, including business size, goals, workflow challenges, consent, referring page, campaign tags, and advertising click identifiers used to attribute a later lead outcome.
How information is used
We use information to operate and secure PITCH, provide requested CRM, job, workforce, accounting, and payroll features, respond to demos and support requests, connect services selected by authorized users, send business communications, process and reconcile authorized transactions, create audit and compliance evidence, prevent abuse, diagnose problems, recover service, and meet legal obligations. Demo-request consent does not authorize unrelated third-party marketing. We do not sell personal information or use contractor customer lists for unrelated advertising.
Roles, workspace isolation, and human access
Each contractor controls its workspace records. PITCH uses server-enforced company boundaries plus role, assignment, and purpose-based permissions. Accounting, company payroll, employee self-service payroll, approvals, and independent professional review use separate access controls. Authorized PITCH personnel may access limited information when necessary to provide requested support, investigate security or abuse, recover service, or comply with law. Such access does not authorize unrelated use.
Service providers, storage, and payments
PITCH uses hosting, managed database, email, communication, payment, mapping, storage, analytics, monitoring, malware-scanning, and security providers to operate the service. Production records are stored in a paid managed PostgreSQL database with hosting-layer encryption at rest and encrypted connections. PITCH additionally encrypts connector credentials and designated tax, payroll, receipt, banking, and vendor documents with application-controlled keys.
Payment-card and bank-account entry is handled by the connected payment processor. PITCH stores transaction references, amounts, reconciliation information, and status rather than raw card or bank-account credentials. A provider receives only the information necessary for the feature a workspace authorizes, subject to that provider's own terms and privacy practices.
Google account and Gmail data
When an authorized user connects Google Workspace or Gmail, PITCH requests basic account identity and the minimum Gmail permission needed to send messages from the selected mailbox: https://www.googleapis.com/auth/gmail.send. PITCH uses this authorization only to send messages the user initiates or enables through PITCH. PITCH does not use this connection to read, search, download, modify, or delete Gmail messages.
PITCH stores the connected email address, granted scope, token expiration information, and encrypted OAuth access and refresh tokens needed to maintain the connection. PITCH shares Google user data only with Google to provide the requested Gmail sending function, with service providers acting on PITCH's instructions when necessary to operate and secure the service, when legally required, or when the user directs the disclosure. Google user data is not sold, used for advertising, used to determine creditworthiness, or used to train generalized artificial-intelligence models.
Users and workspace administrators can disconnect Google from PITCH or revoke access from their Google Account at any time. Disconnecting deletes the stored Google OAuth access and refresh tokens from PITCH. Limited security and audit records may retain the connected account identifier and the fact that a connection or disconnection occurred, but not the deleted OAuth tokens or Gmail message contents.
PITCH's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Microsoft account and mailbox data
When an authorized user connects Microsoft 365 or Outlook, PITCH requests delegated identity permissions, offline access, User.Read, and Mail.Send to identify the selected mailbox, maintain the connection, and send messages the user initiates or enables through PITCH. PITCH does not request permission to read or search mailbox contents for this feature.
PITCH stores the selected Microsoft account identifier, granted scope, token expiration information, and encrypted OAuth access and refresh tokens. Microsoft API data is used only for the connected user-facing feature, security, legal compliance, or another use the user directs; it is not sold or used for unrelated advertising. Users can disconnect within PITCH and can revoke the application's access through Microsoft My Apps. Disconnecting deletes PITCH's stored Microsoft OAuth tokens while limited audit facts may remain.
Mobile applications and device permissions
PITCH mobile clients use the same authenticated company, role, and assignment controls as the web service. A client may request device permissions—such as camera, photo library, notifications, or location—only when needed for a visible feature. Location is collected for authorized clock-in and clock-out events, not continuous background tracking. Users may deny optional permissions or change them in device settings; the related feature may be unavailable. Privacy information and the data-deletion path are accessible from the service and mobile experience.
PITCH Books, payroll, tax, and professional records
Financial and payroll records are processed to maintain the workspace's books, reconcile evidence, calculate configured payroll, produce pay statements and job costs, support approvals and corrections, and prepare controlled professional workpapers. PITCH does not transmit payroll tax returns or tax payments to the IRS, SSA, or state and local agencies. Independently engaged professionals control final tax decisions and filings through their own systems.
Employers and workspaces select retention policies that must meet applicable law. Employment-tax records generally require at least four years of retention under IRS guidance, and records may be kept longer for state law, accounting, litigation, audit, professional, contractual, security, or legal-hold reasons. Access, deletion, and disposition are blocked while a required retention period or legal hold applies.
Mobile information and text-message consent
Mobile information will not be shared with third parties or affiliates for their own marketing or promotional purposes. Information may be shared with service providers that support message delivery, customer service, fraud prevention, or essential operations. Text-message originator opt-in data and consent will not be shared with third parties for their own marketing. Contractors remain responsible for obtaining and documenting valid customer consent before enabling text updates.
Connected accounting platforms
QuickBooks Online. If an owner or administrator connects QuickBooks, PITCH may send or retrieve customer contact details, service items, invoices, payment records, vendors, purchase orders, account names and identifiers, company information, balances, and synchronization metadata. Xero. If an owner or administrator connects Xero, PITCH sends enabled customer contacts and sales invoices, reads the selected organisation identity, chart of accounts and tax rates for mapping, and receives signed invoice-event metadata for reconciliation. PITCH stores provider tokens in encrypted form and keeps accounting links scoped to the PITCH workspace and selected provider organisation. This data is used only to provide the synchronization selected by the workspace, prevent duplicates, identify conflicts, troubleshoot the connection, and maintain security and audit records. Connected accounting data is not sold or used for advertising.
Generative AI
PITCH includes an optional AI assistant that can generate business drafts from information a user intentionally enters or selects. PITCH does not automatically send Google, Microsoft, QuickBooks, Xero, payroll, tax, bank-statement, or receipt-document data to the AI assistant merely because a provider or feature is connected. Google and Microsoft API data is not used to train generalized AI models. Users should review generated content before using it.
Retention, backups, and deletion
Information is retained while needed to provide the service, preserve financial or payroll history, protect the platform, maintain required business records, resolve disputes, or comply with law. Paid managed database backups support point-in-time recovery and age out according to the hosting plan's recovery window. Disconnecting a provider deletes locally stored OAuth tokens but does not automatically erase records already created in PITCH or retained by the provider. A verified owner can request access, export, correction, or deletion as described on the Data Access and Deletion page.
Security and incident handling
PITCH uses workspace isolation, access controls, encrypted secrets and protected documents, password hashing, signed secure sessions, security headers, signed webhook verification, malware-gated uploads, health checks, audit records, and recovery controls. No internet service can promise absolute security. Suspected security issues can be reported through the Trust Center. PITCH will investigate credible reports, contain confirmed issues, preserve relevant evidence, and provide notices when required by applicable law.
Copyright requests
When someone submits a DMCA notice or counter-notice, PITCH processes the contact information, signed certifications, affected-material details, technical request metadata, and internal handling records needed to evaluate and document the request. Information from a counter-notice may be forwarded to the original claimant as part of the statutory process. Records may be retained to document compliance, resolve disputes, prevent abuse, and satisfy legal obligations. See the DMCA Copyright Policy.
Your choices and responsibilities
Workspace owners can manage users, roles, connected providers, communication settings, exports, and verified requests. Depending on applicable law, individuals may have rights to access, correct, delete, restrict, or obtain information. A contractor customer should normally contact the contractor that collected the information; PITCH assists verified workspace owners and responds directly when required. Contractors are responsible for lawful collection, employee notices, least-privilege access, and honoring customer and worker choices.
Contact and changes
Privacy questions and verified rights requests can be sent to privacy@plugandplayco.com. We may update this policy as PITCH changes. Material revisions will be identified by a new effective date and, when appropriate, an in-product notice.