Effective date: July 26, 2026
This Privacy Policy explains how Flying Flamingo Junk Removal (“Flying Flamingo,” “we,” “us,” or “our”) collects, uses, discloses, and protects personal information through flyingflamingojunkremoval.com, our booking and contact forms, Flappy AI chat, phone calls, text messages, emails, payments, and junk-removal services.
Flying Flamingo Junk Removal is currently an unincorporated business operating under that trade name in Washington State. This Policy does not represent that Flying Flamingo is a limited liability company or corporation.
1. Information we collect
The information we collect depends on how you interact with us.
A. Information you provide
We may collect:
- name;
- email address;
- telephone number;
- service address, city, state, ZIP code, and apartment or unit number;
- residential or commercial service type;
- property, building, parking, gate, elevator, and access information;
- requested date, preferred time, and availability;
- item lists, material descriptions, quantities, condition, and job details;
- photographs, videos, files, and before-and-after media;
- messages sent through forms, email, text, or Flappy AI;
- quote approvals, appointment information, invoices, payment status, and customer-service history;
- marketing preferences and consent records;
- reviews, feedback, survey responses, and dispute information;
- call recordings and transcripts after required notice and consent; and
- any other information you choose to provide.
B. Payment information
Payments may be processed by Stripe.
Stripe may collect payment-card numbers, bank details, billing information, authentication data, device information, and fraud-prevention information. We generally receive payment status, amount, payment method type, transaction identifiers, and limited billing information rather than complete payment-card data.
C. Information collected automatically
When you use the website, we and our service providers may automatically collect:
- IP address;
- approximate location derived from IP address;
- browser, device, operating system, and language;
- pages viewed, links clicked, referring URLs, and timestamps;
- session, navigation, scroll, click, and interaction information;
- advertising identifiers and campaign information;
- cookie, pixel, local-storage, and similar identifiers;
- map interactions and service-area tool activity;
- form, chat, and website error information; and
- security, fraud, and diagnostic logs.
If Microsoft Clarity is configured and you grant Analytics consent, it may provide session-replay and interaction analytics such as clicks, scrolling, navigation, and device information. Booking and contact fields are marked for masking or exclusion from replay. We do not intentionally use analytics tools to collect names, contact details, service addresses, job descriptions, uploaded media, full payment-card numbers, or account passwords.
D. Visitor journeys and incomplete booking drafts
The website uses separate identifiers for separate purposes:
- a short-lived first-party session identifier for the current visit;
- after Analytics consent, a cryptographically random, persistent first-party visitor identifier for return-visit and journey measurement; and
- after you actively begin entering the booking form, a necessary draft identifier and random access token that allow the website to save and resume the incomplete form.
A visitor identifier identifies a browser installation, not a person. We do not treat it as proof of identity, place it in public URLs, or provide the internal visitor, session, draft, identity-link, or merge identifiers to advertising or analytics providers.
Before Analytics consent, first-touch and last-touch information may remain in short-lived session storage so it can accompany a request you choose to submit during that visit. Cross-session first-touch, last-touch, return-visit, and journey-event storage begins only after Analytics consent. If Analytics consent is rejected or withdrawn, the persistent visitor identifier and cross-session attribution storage are removed from the browser and no new analytics journey events are sent.
An incomplete server-side booking draft is created only after you type in or actively choose a booking-form value. Draft saves are debounced and may also occur on blur, step changes, and supported page-exit events. The draft may contain the booking fields you entered, including a provisional name, contact details, service address, project details, access information, scheduling choices, and attribution context. Uploaded-media contents are not included in draft autosave. An incomplete draft:
- is not a submitted request, lead, quote, booking, or appointment;
- does not authorize marketing;
- is not used for sales follow-up without a completed submission or separate permission; and
- is kept outside general analytics and session-replay event metadata.
Names in drafts are provisional display names and are unverified. We do not merge records automatically by name. Phone numbers, email addresses, and WhatsApp sender identifiers may be normalized on the server and converted into keyed HMAC-SHA-256 match tokens using a server-held secret. Automatic linking is limited to strong evidence such as an exact signed WhatsApp reference or an exact verified phone, email, or WhatsApp identity. An exact but unverified phone or email may produce a reviewable, reversible suggestion with an audit record. We do not automatically link people using IP addresses, device information, approximate location, addresses alone, similar behavior, close timestamps, or names.
The website may add a short Flying Flamingo reference code to a prewritten WhatsApp message. The reference connects the outbound click to the permitted website session, attribution, and draft context. A click alone is not treated as a conversation, lead, quote request, or booking. No WhatsApp Cloud API webhook is currently configured in this website repository. If an inquiry is later linked manually or through a verified integration, the operational record may include the WhatsApp sender identifier, unverified profile name, message identifier, timestamp, message, and valid reference. A WhatsApp profile name is never treated as verified identity.
We do not use browser fingerprinting, canvas, font, audio, or WebGL fingerprinting; attempt to detect a Google, Chrome, Apple, or other browser account; or use IP address as a persistent identity key. Cross-device linking occurs only after the devices provide a shared strong identifier under the rules above.
D. Information from other sources
We may receive information from:
- advertising platforms when you click or respond to an advertisement;
- payment and fraud-prevention providers;
- maps, address, and location providers;
- property owners, managers, tenants, estate representatives, businesses, or other people coordinating a job;
- referral partners or public business directories; and
- service providers that help us operate the website and CRM.
2. How we use information
We may use personal information to:
- respond to inquiries and provide customer support;
- evaluate, quote, schedule, confirm, perform, and document services;
- check whether an address appears within our service area;
- communicate about appointments, access, quotes, invoices, and changes;
- process payments and maintain transaction records;
- operate Flappy AI and generate automated responses;
- maintain lead, customer, property, job, invoice, and communication records;
- prevent fraud, misuse, unauthorized removal, and security incidents;
- troubleshoot, maintain, test, and improve the website and services;
- understand website use through analytics and session-replay tools;
- measure advertising and marketing performance;
- personalize or target advertising where permitted;
- send promotional texts or emails with appropriate consent;
- comply with legal, tax, accounting, safety, and dispute-resolution obligations;
- protect our rights, customers, workers, property, and the public; and
- establish, exercise, or defend legal claims.
3. Flappy AI and OpenAI
Flappy is an automated AI assistant. Messages and related context submitted to Flappy may be sent to OpenAI so that a response can be generated.
AI chat may collect:
- the message you submit;
- conversation history;
- page or service context;
- technical and security information; and
- any contact or project details you voluntarily include.
Do not submit payment-card numbers, passwords, Social Security numbers, medical information, private access codes, confidential documents, or other highly sensitive information.
Flappy responses may be inaccurate and do not confirm appointments, quotes, item acceptance, or service availability. A human team member may review chat information when needed to assist with your request, troubleshoot the service, address safety issues, or investigate misuse.
4. Calls and Quo
We use Quo for business calling and related communications.
Calls may be recorded or transcribed for documentation, quality, training, safety, and dispute-resolution purposes. When a private call will be recorded, we will provide the notice and obtain the consent required by applicable law. The recording will include the announcement where required.
Quo may process telephone numbers, call metadata, messages, contacts, recordings, transcripts, device information, and approximate location data as a service provider.
If you do not want a call recorded, tell us before continuing. We may disable recording when practical or communicate through text, email, or the website.
5. Cookies, pixels, analytics, and advertising
We use or plan to use:
- Google Analytics and Google Ads tags;
- Meta Pixel;
- Microsoft Advertising Universal Event Tracking (UET);
- Microsoft Clarity;
- Google Maps;
- consent and preference storage; and
- other necessary website technologies.
These technologies may collect or receive page URLs, IP addresses, browser and device information, cookie identifiers, ad-click identifiers, events, form or booking milestones, and interaction data.
We use a cookie-consent system to manage nonessential technologies. See our Cookie Policy for categories, examples, and controls.
6. How we disclose information
We may disclose personal information to the following categories of recipients.
A. Website, infrastructure, and CRM providers
- Netlify for hosting, delivery, serverless functions, logs, and website operations.
- Supabase for database, authentication, storage, CRM, lead, customer, job, and operational records.
B. AI and communications providers
- OpenAI for Flappy AI response generation and related safety processing.
- Quo for business calls, text messages, call records, recordings, and transcriptions.
- Email and communication providers used to deliver customer and marketing messages.
C. Payment providers
- Stripe for payment processing, invoicing, fraud prevention, and transaction records.
D. Maps, analytics, and advertising providers
- Google for Maps, Analytics, Google Ads, measurement, and advertising.
- Meta for Meta Pixel, advertising measurement, audience creation, and advertising.
- Meta/WhatsApp for communications you choose to initiate through WhatsApp.
- Microsoft for Microsoft Advertising/UET, Clarity, analytics, session replay, measurement, and advertising.
E. Operational and professional recipients
We may disclose information to:
- team members and service workers who need it to perform the job;
- disposal, reuse, recycling, donation, transfer, or specialty-handling locations when reasonably necessary;
- accountants, tax professionals, legal advisers, insurers, and consultants;
- government agencies, courts, law enforcement, or regulators when required or lawfully requested;
- parties involved in a business transfer, financing, reorganization, or sale; and
- other parties with your direction or consent.
We do not authorize service providers to use customer information for unrelated purposes except as permitted by their contracts, policies, and applicable law.
7. Sale, sharing, and targeted advertising
We do not sell personal information for money.
Our use of Meta Pixel, Google Ads, Microsoft Advertising/UET, and similar technologies may be considered “sharing,” targeted advertising, or a sale under some state privacy laws even when no money is exchanged.
You may reject Advertising cookies or change your choice through the Privacy Choices link. Where applicable law gives you a right to opt out of targeted advertising, sale, or sharing, we will process a verified request as required.
8. Marketing communications
We may send promotional email or text messages when we have the consent or other lawful basis required for that communication.
Marketing consent is optional and is not a condition of receiving a quote or purchasing service.
You may opt out by:
- replying STOP to a promotional text;
- using the unsubscribe link in a promotional email;
- changing available communication preferences; or
- contacting us.
We may still send non-marketing messages about an active request, appointment, quote, payment, safety issue, or customer-service matter.
9. Photographs, videos, and files
Photographs and uploads may reveal:
- home or business interiors;
- addresses and location details;
- people or personal belongings;
- license plates;
- documents;
- property condition; and
- access or security information.
Only upload material you are authorized to share. Remove or cover confidential documents, financial information, medical information, faces, access codes, and other unnecessary sensitive details when practical.
We use uploaded media to evaluate, quote, schedule, perform, document, or support the requested work.
We do not treat a job upload as automatic permission for public advertising. Identifiable marketing use requires separate permission or another lawful basis.
10. Data retention
We retain information only for as long as reasonably necessary for the purposes described in this Policy.
Retention depends on:
- whether you become a customer;
- the status of the request or job;
- legal, tax, accounting, payment, and recordkeeping requirements;
- fraud, safety, complaint, and dispute needs;
- whether information is stored in backups;
- your privacy request; and
- our legitimate operational needs.
Lead information may be retained to follow up on a request and understand service history. Customer, invoice, payment, and job records may be retained for longer periods when needed for tax, accounting, legal, or dispute purposes.
Unsubmitted booking drafts are configured to expire after 30 days. Raw pseudonymous visitor events are configured for 180-day retention. Deidentified aggregate metrics may be retained longer. The first-party persistent visitor identifier is kept in the browser for up to 12 months unless consent is withdrawn, the identifier is rotated or deleted, browser storage is cleared, or a material policy change requires renewal. Submitted lead and customer records follow the existing business, tax, legal, payment, safety, and dispute-retention rules.
The database migration includes an owner-run cleanup function for draft, event, contact-attempt, and session retention. That function must be scheduled or run through the owner-controlled Supabase process; this Policy does not claim that cleanup is scheduled before that operational step is completed.
Call recordings, AI chats, photos, and uploads may be deleted, de-identified, or retained when reasonably needed for service, training, safety, support, or claims. We will not keep information longer than necessary solely because storage is available.
11. Security
We use administrative, technical, and physical safeguards designed to protect information, including access controls, private storage where appropriate, authentication, encrypted transmission where supported, and service-provider security tools.
No website, database, transmission, or storage system is completely secure. You should not send information through the website that is not reasonably necessary for your request.
If we learn of a security incident, we will investigate and provide legally required notice.
12. Your privacy choices and rights
Depending on your location and applicable law, you may have the right to:
- know or access personal information;
- correct inaccurate information;
- delete certain information;
- request review, correction, unlinking, or deletion of linked identity records where applicable;
- receive a portable copy;
- opt out of sale, sharing, or targeted advertising;
- withdraw consent;
- limit certain uses of sensitive information;
- appeal the denial of a request; and
- receive equal service without unlawful discrimination for exercising a privacy right.
You may submit a request by:
- emailing privacy@flyingflamingojunkremoval.com;
- using the website contact form and writing Privacy Request;
- calling (206) 474-7420; or
- mailing the address below.
We may need to verify your identity and authority before completing a request. We may deny or limit a request when permitted by law, including when records must be retained for legal, security, tax, payment, or dispute purposes.
An authorized agent may submit a request where allowed, but we may require proof of authority and identity.
Even when a particular comprehensive privacy law does not apply to us, we may voluntarily consider reasonable privacy requests.
13. Cookie and advertising choices
You can use the cookie banner or the permanent Privacy Choices link to:
- accept all categories;
- reject nonessential categories; or
- choose Functional, Analytics, and Advertising settings.
Changing consent does not automatically delete cookies already stored by your browser. You may also clear cookies through browser settings.
Browser settings may block cookies, but some website features may not function correctly.
14. Children’s privacy
The website and services are not directed to children under 13, and we do not knowingly collect personal information online from children under 13.
A parent or guardian who believes a child submitted personal information should contact us so we can review and delete it where required.
People requesting or authorizing paid services must be at least 18 years old or act through a legally authorized adult.
15. Interstate and international processing
Our business operates in Washington State, but service providers may process information in other states or countries.
By using the website, you understand that information may be transferred to and processed in the United States and other locations where our providers operate, subject to applicable safeguards and law.
16. Third-party websites and services
The website may contain embedded maps, payment pages, social-media features, or links to third-party websites.
Their privacy practices are governed by their own notices. We do not control independent third-party websites or how they use information collected directly from you.
17. Changes to this Policy
We may update this Policy as our services, providers, technology, or legal obligations change.
The revised version will be posted with an updated effective date. We will provide additional notice when required by law.
18. Contact
Flying Flamingo Junk Removal
300 Lenora St
Seattle, WA 98121
Phone: (206) 474-7420
Privacy email: privacy@flyingflamingojunkremoval.com
Website: flyingflamingojunkremoval.com
