Indigo Labs
Privacy Policy
Last updated 5 September 2026
Who we are
Indigo Labs builds and runs marketing systems for small businesses — the website, the pages the adverts point at, the follow-up behind them, and the CRM it all runs through. This policy covers our own site and software at command.indigolabsai.com and indigolabsai.com.
When we run a system on behalf of a client, that client decides what is collected on their pages and we act on their instructions. Their own notice governs those pages, not this one.
What we collect, and when
When you ask us to build something. The answers you give in the build questionnaire — your trade, where you work, how enquiries reach you today, what you want a customer to do — plus your email address and, if you give it, your phone number. We use these to actually build the thing, which is the entire product.
When you enquire. Your name, email, phone and whatever you tell us about your business, so that a person can call you back.
When you visit. Standard request data, and a Meta pixel on the pages our adverts point at — dataset 37509080538737527for Indigo Labs’ own pages. It records that a page was viewed and, if you complete a build, that a build was completed. It does not receive the contents of your answers.
Pages we run for our clients. A landing page we host for one of our clients carries that client’s Meta pixel and their dataset, not ours, so the enquiry reaches the business you are actually contacting. If they have not set one up, ours is used instead.
What we do not do
We do not sell your personal information, and we do not share it with anyone who wants to market to you. The only third parties who receive it are the ones needed to run the service — the hosting, email, text-message and payment providers listed below — and they may only act on our instructions.
We do not use the contents of a client’s customer records to market to those customers ourselves.
Texts and email
If you give us a phone number we may text you about the build you asked for. Consent to be contacted is never a condition of purchase. Reply STOP to any text and the number is suppressed across every message we send — calls, texts and email — not paused. Use the unsubscribe link in any email for the same effect.
Messages are not sent during quiet hours in your own timezone rather than ours.
If you connect your Google Calendar
Connecting a Google Calendar is optional, and you do it inside your own Google account. We never ask for your Google password and never see it.
We request one permission, https://www.googleapis.com/auth/calendar.freebusy, which is the narrowest one Google offers for this. It returns the times you are busy and nothing else. We cannot read the title of a meeting, who is attending, where it is, or any note attached to it, and we have no permission to create, change or delete anything in your calendar. We ask only about your primary calendar.
Those busy times are used for one thing: checking whether you are already occupied before the system offers that time to somebody booking with you. They are read at the moment the question is asked and are not written to our database, not used for advertising, not sold or shared with anyone, and not used to train any AI model.
What we do store is the token Google gives us so we can ask again without making you sign in every time. It is held in our database in the United States, is never sent to a browser, and never appears in any export, list or report.
You can disconnect at any time under Integrations in your settings. Disconnecting revokes the token with Google first and then deletes our copy, so the access actually ends at Google rather than only in our records. You can also remove it yourself at myaccount.google.com/permissions.
Our use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.
Who processes it for us
Supabase (database and files), a DigitalOcean server in the United States (the application), Brevo (email), TextBee (text messages), Stripe (payments — card details go to Stripe and never reach us), Meta and Google (advertising measurement), and the AI providers we use to draft copy and images. Drafts are reviewed by a person before anything is published under your name.
How long we keep it
For as long as you are a client, and afterwards for as long as we need it to meet tax and legal obligations. A build you abandoned and never paid for is deleted on request, and otherwise cleared out once it is plainly dead.
Your choices
Ask us for a copy of what we hold about you, ask us to correct it, or ask us to delete it, and we will — subject only to records we are required to keep. Depending on where you live you may have additional rights, including under the CCPA and the GDPR, and we apply the same process to everyone rather than asking you to prove which applies.
Email tariqhaskins@indigolabsai.com and say what you want done. A person answers it.
One honest caveat
This page is written to be accurate about what our software does rather than to be exhaustive legal cover, and it will be reviewed by counsel as the company completes its incorporation. If anything here turns out to be wrong, the fix is to change the behaviour or change the page — not to widen the wording until it is technically true.