Barton Digital \u00b7 Barton Enterprises NH LLC
Privacy Notice
Originally effective August 24, 2026 · Last updated September 25, 20261. Scope
This Privacy Notice describes how Barton Digital, a DBA of Barton Enterprises NH LLC (“Barton,” “we,” or “us”), handles information through the Barton Digital website, hosted software platform, mobile web apps, company portals, consumer accounts, support services, and supported integrations (collectively, the “Service”). A subscribing company may separately control information it collects from its customers and employees through the Service.
2. Information we collect
We may collect account and contact details; company, role, license, subscription, and billing status; home-model preferences, saved homes, inquiries, quotes, notes, project and work-order records; employee-entered time, breaks, approvals, corrections, and payroll-integration identifiers; uploaded files and images; support and legal-request submissions; integration identifiers and synchronization records; and device, browser, IP-address, security, audit, and activity data. Payment-card and bank details are collected on Stripe-hosted pages and are not stored by Barton. OAuth credentials for supported integrations are encrypted and stored server-side.
2A. Optional showroom analytics
Only after you select Allow optional analytics, Barton and the company operating the showroom record showroom visits, full and quick model views, model identifiers, visit times, referral website host, device category, and available country and network-operator information. We use this to understand showroom engagement, returning browsers, model interest, referral sources, and browsing patterns, and to improve the showroom. A random browser identifier is transformed into a company-scoped reference for reporting. These records are pseudonymous, not guaranteed anonymous: they distinguish a browser but are not intentionally linked by this feature to your name, email, or signed-in account. The optional event records do not contain raw IP addresses, precise location, browser fingerprints, or referral query strings. A browser reference, network operator, or activity pattern is not proof of a visitor's identity, employer, competitor status, or wrongdoing. This feature does not automatically block visitors or make eligibility decisions, and Barton does not use these optional records for targeted advertising or sell them.
2B. Cookies, browser storage and your choice
Optional analytics is off unless you allow it. A first-party cookie named bd_analytics_<company> remembers your choice for up to 30 days from that choice; only an allow choice includes a random browser identifier. A denial cookie remembers that analytics is off without a tracking identifier. When allowed, tab-scoped session storage named bd_activity_session_<company> groups visits; a new session identifier is used after 30 minutes without tracked activity. Consent and browser references are specific to the company, browser, and website domain, not synchronized across devices or independently operated domains. Choose Keep analytics off or Stop optional analytics in the showroom controls at any time. This stops new optional events; it does not itself delete earlier records or downloaded reports. To request access or deletion, use the contact details in section 8. Clearing site cookies removes the local choice, and optional analytics remains off until you allow it again. Global Privacy Control (GPC) and Do Not Track signals override an allow choice for this feature. Declining does not prevent browsing, inquiries, customer sign-in, or use of essential authentication and security functions.
2C. Who can access analytics and network information
Detailed visitor reports are available to administrators of the relevant showroom company and authorized Barton platform-owner personnel, not ordinary field employees, sales users, or viewers. Administrators can download reports. Infrastructure providers, including Cloudflare, process requests to deliver and protect the Service and supply available device/network context. IP addresses and request headers necessarily reach infrastructure handling a visit even though raw IP addresses are not stored in the optional analytics event records. Company-managed websites and reverse proxies may have their own access logs, analytics, and privacy notices, which the Barton analytics toggle does not control. Through the Lakes Region showroom reverse proxy, visitor network attribution is unavailable and is omitted rather than attributing the proxy host to the visitor. Barton does not send these records to a third-party company-identification service. Contact the showroom company about its own use of reports and separately operated website services.
2D. Analytics retention, backups and exports
New optional activity collected after renewed consent under the six-month policy is kept in live storage for 186 days from the visit. The dashboard shows the selected recent reporting period, not the entire retention period. Earlier-consent events retain their original 30-day live expiry; an old opt-in does not authorize collection under the new period. A valid preservation hold can extend retention. Browser preference cookies still expire after 30 days and the visit-session entry after 30 minutes. Stopping optional analytics prevents new collection but does not itself delete earlier records; you can separately request deletion. Protected database archives are configured for at least 186 days from backup creation, so a copy can remain after the live event expires. Separate offsite recovery copies and downloaded reports have controlled recovery or company retention lifecycles and are not removed by live-event cleanup. Backups are for recovery, not live visitor reports. The receiving company is responsible for its downloaded reports. Applicable deletion rights and preservation duties are handled as described below. Historical aggregate reporting, staff activity, and essential security records remain separate.
2E. Optional Google Analytics on the Barton Digital public homepage
With your separate permission through Cookie settings on the Barton Digital homepage, Google Analytics 4 measures visits to that public marketing page. It is not installed by this integration on company workspaces, customer accounts, or hosted showrooms. Google receives a pseudonymous browser identifier, page-view and session information, referral website origin, device/browser information, and approximate geographic information. Network requests necessarily disclose an IP address to Google. We do not send names, email addresses, account identifiers, form entries, URL query strings, or URL fragments through this integration. Automatic form and enhanced-interaction measurement are disabled, as are Google Signals and advertising personalization. The bd_google_analytics cookie remembers your choice for up to 30 days; Google measurement cookies use the bdga prefix and are configured for up to 30 days without renewal on every visit. Google is a separate analytics service provider; its processing and retention settings are distinct from our first-party showroom records and recovery backups. You can decline or withdraw permission through Cookie settings on the homepage. Withdrawal stops future collection and removes this integration's measurement cookies from that host; it does not itself delete earlier reports. Global Privacy Control and Do Not Track override an allow choice. No Google tag is downloaded by this integration before permission. Google's privacy information is available at https://policies.google.com/privacy and https://policies.google.com/technologies/partner-sites. Contact support@barton-digital.com for privacy requests.
3. Location information
A signed-in user may choose to share a one-time precise device location for account security, fraud or abuse investigation, support, or a time-clock event. A subscribing company may configure location as optional, disabled, or required for its workforce time-clock workflow, subject to its own notice and consent obligations. The Service requests device permission before collecting coordinates. The choice, account, server-observed IP address, browser information, timestamp, coordinates, and reported accuracy may be logged. The Service captures location only when a user presses a disclosed action such as Clock in or Clock out; it does not continuously track a device, use location for advertising, or sell precise location data.
4. How we use information
We use information to operate and secure the Service; provide showrooms, CRM, project management, billing, support, and integrations; authenticate users and enforce roles and licenses; process inquiries and customer preferences; prevent fraud, bots, attacks, abuse, and prohibited content; troubleshoot and improve reliability; communicate service, billing, security, and support notices; maintain audit and change history; enforce agreements; and comply with applicable law and valid legal process. Optional showroom analytics is subject to the specific choices, purposes, and limits in sections 2A through 2D; these general purposes do not override an analytics opt-out.
5. How information is shared
Information may be available to the subscribing company that controls the relevant workspace and to Barton personnel authorized to operate, secure, support, audit, or administer the platform. We may share information with service providers that host or support the Service, including infrastructure, storage, authentication, payment, email, monitoring, and customer-authorized integration providers. We may also preserve or disclose information when reasonably necessary to comply with law or valid legal process, protect people or rights, investigate suspected unlawful conduct or abuse, or complete a business transaction subject to appropriate safeguards. Barton does not sell personal information or precise location data.
6. Data retention and legal holds
Business records have no scheduled automatic expiration under Barton's current retention policy. This includes CRM and lead details, customers, projects, tasks, work orders, comments, notes, business messages and email records, accepted photos, videos, documents, and related business and audit records. They are retained indefinitely for continuing service, project and warranty history, accounting, verified record requests, dispute resolution, and other lawful recordkeeping purposes, subject to applicable law and valid company instructions. Indefinite retention is not permission to keep personal information without a lawful purpose: required deletion, purpose limitations, and other privacy obligations still apply. Information subject to a preservation request, legal hold, safety investigation, suspected unlawful content review, or other legal restriction is excluded from ordinary disposal. Optional analytics and temporary security data follow their separately disclosed retention policies.
6A. Deleted records and uploaded files
Ordinary deletion removes records and files from normal workspace access but does not permanently erase their protected business archive. From deployment of this policy forward, existing retained business records and newly deleted records have no scheduled expiry, including records from deleted customer or company accounts and accepted uploaded photos, videos, and documents that are deleted or replaced. Supported business-email archives include their message content; authentication messages and unclassified email templates retain metadata only to avoid preserving login secrets. Authorized platform personnel may use protected copies for recovery, verified data requests, security investigations, and legal obligations; they are not public and are not used for optional marketing analytics. Authentication secrets, expired login codes, session credentials, incomplete uploads, and temporary operational controls retain their shorter security lifecycles. Optional visitor analytics is not converted to indefinite tracking. This policy does not recreate previously purged information, capture communications outside the Service, promise every historical edit or a complete external mailbox archive, or override a valid legal obligation to erase data sooner. Required erasure is reviewed separately from ordinary workspace deletion, including affected recovery copies. Full-database recovery snapshots rotate separately under their backup policy; rotation does not expire the protected business archives that remain in the database or the retained uploaded files. Storage limits can interrupt new backup creation and are monitored; indefinite retention does not mean unlimited storage or guaranteed recovery.
6B. Owner-managed offline archives
Indefinite retention remains the default; there is no automatic one-year purge. An authorized platform owner may export readable business records and accepted uploaded files to a private local archive. A separate, explicitly confirmed removal workflow is available for eligible deleted CRM/project records that have remained archived for more than one year, only after the saved export has been verified. Live workspace records are not removed through this workflow. Open legal holds block removal, and financial, employment, contract and legal record categories are excluded from this bulk-removal option. Age alone does not determine legal eligibility for deletion. Eligible old original files may be removed only after export and checks for remaining references and restrictions; shared files and existing recovery copies may remain. Export and removal receipts are retained. The owner is responsible for securing local archives, keeping an independent backup, applying lawful retention requirements, and responding to verified requests concerning copies in their custody. This workflow is not proof that every recovery copy has been erased. Platform-owner email review includes supported business-message content and sending metadata, but does not reveal authentication codes or reset links or capture independently sent third-party-provider messages.
7. Security
We use administrative, technical, and organizational safeguards designed to protect information, including role-based access, encryption of supported integration credentials, audit logging, bot protection, and security monitoring. No service can guarantee absolute security. Users and subscribing companies are responsible for protecting their credentials, assigning appropriate roles, and promptly reporting suspected unauthorized access.
8. Choices and requests
Depending on applicable law, you may request access, correction, deletion, or a portable copy of personal information, and object to or opt out of specified processing. Email support@barton-digital.com or use the Legal page; no new account is required. Identify the showroom or company and request, but do not send passwords or authentication codes. We may verify identity and authority when needed. Because optional visitor activity is not linked to an account or email, we may need limited browser-reference information to locate it; cleared cookies may prevent that association. Requests about company-controlled records may be referred to that company. We do not penalize users for exercising applicable privacy rights. Legal exceptions may limit a request. Marketing recipients can use the message's unsubscribe link or the Service's unsubscribe page.
8A. Responses and appeals
We follow applicable response deadlines. Where New Hampshire RSA 507-H applies, requests receive a response within 45 days, with a further 45 days when permitted and explained within the initial period. To appeal a denied request, reply to the decision or email support@barton-digital.com with Privacy appeal in the subject. Where that law applies, we respond to appeals within 60 days and, if denied, explain how to contact the New Hampshire Attorney General.
9. Age-appropriate use
The Service is designed for business use and is not intended for children under 13. Subscribing companies and users are responsible for ensuring that information submitted through the Service is appropriate and lawfully collected. Barton may take reasonable steps to restrict access, preserve relevant records, or make reports when required by applicable law or necessary to protect users and the Service.
10. Changes and contact
We may update this Privacy Notice to reflect changes to the Service, our practices, or legal requirements. The last-updated date below identifies this version; the original effective date is retained for reference. When required, we will provide additional notice or obtain consent before materially different processing. Questions or privacy requests may be sent to support@barton-digital.com or submitted through the Legal page. Requests involving a subscribing company's customer or employee records may be referred to that company.
Email a privacy request · Email a privacy appeal
Account and data deletion requests \u00b7 Legal and safety request forms \u00b7 Terms and conditions