Who we are and what this policy covers
PrairieStack is a managed IT and software company working from Bismarck, North Dakota. Two kinds of work are covered here. Managed IT services: we look after client computers, backups, updates, monitoring and remote support. Software: we build and operate our own products, including the BooksForge business portal and the Meta-connected publishing features that run inside it.
Where a product has its own account, the product's own policy applies to that account as well as this one. Questions about either go to hello@prairiestack.com.
Information we collect
PrairieStack collects information that businesses and their authorized users provide, including business name, contact information, service area, customer lead details, appointment details, review-notification details, billing status, and setup preferences.
When a business connects a Facebook Page or Meta product, PrairieStack may collect Page identifiers, Page names, Page access status, permissions granted to the app, lead or message metadata made available by Meta, and content the authorized user chooses to publish or manage through PrairieStack.
Client systems and machine records
For managed-IT clients, we keep an inventory of the machines and services we are responsible for: machine names and asset labels, operating system and patch level, hardware and licence counts, disk and backup job status, monitoring alerts, and the work history of service tickets. This record is what makes the service possible — a machine we cannot identify is a machine we cannot back up, patch or restore.
We do not collect the contents of your files for this purpose. We index what exists so it can be protected and restored; we open the contents of a document or mailbox only when you ask us to, or when a restore or a fault investigation requires it, and we say so when that happens.
Credentials, accounts and remote access
Administering client machines means holding administrative credentials for them. We keep those credentials in a managed password vault rather than in documents, chat or email; access is limited to the technician who needs it for a named task, and administrative actions taken on a client machine are logged.
Where a client system supports individual accounts, we use named technician accounts instead of a shared password, so an action can be attributed to a person. When a client leaves the service, our administrative access is removed and the credentials we held for the client are destroyed or rotated.
Remote sessions to client machines are established over an encrypted connection and are recorded in the service history for the account. A remote session is opened for a reason that is written down on the ticket; we do not browse client machines for anything else.
Backups and data handling
Where backup is part of the service, the protected data is transferred over an encrypted connection and stored in encrypted form. Backups are made on the schedule stated for the account, and a restore is tested rather than assumed: a backup nobody has restored is a hope, not a backup.
Backup copies are retained for the window agreed for the account. Client data is held on PrairieStack infrastructure and on the storage of the providers listed below; it is not sold, and it is not used to train anything.
How we use information
PrairieStack uses this information to provide customer-owned lead intake, forwarded missed-call follow-up, review workflows, appointment workflows, customer setup, payment-link workflows, local business page support, approved draft posting for a specifically connected Facebook Page, and the managed-IT work described above.
PrairieStack does not sell personal information. PrairieStack uses connected-provider data only to operate the services requested by the business and to troubleshoot, secure, and improve those services.
Sharing and service providers
PrairieStack may process information through service providers needed to run the product and the service, including hosting, email, SMS, payment, analytics, remote-access, backup-storage, and platform APIs such as Meta/Facebook, Google, Stripe, Twilio, and email providers. These providers process information according to their own terms and privacy commitments.
We do not disclose client information to anyone else except where the client asks us to, or where the law requires it. If a provider used for a client's account changes, we say so before the change takes effect.
Facebook Page and Meta data
PrairieStack accesses Facebook Page or Meta data only after an authorized business representative connects the Page through Meta OAuth and grants specific Page permissions. Access is limited to verifying the connected Page and preparing approved drafts within those permissions. We do not receive your Facebook password.
Users can revoke Meta access from Meta Business settings or by contacting PrairieStack. If Meta access is revoked, PrairieStack may no longer be able to provide affected Page-management features.
Retention
PrairieStack retains business records, setup records, leads, outbound activity, and connected-provider metadata for as long as needed to provide the service, meet legal or security obligations, resolve disputes, and maintain business records. Businesses may request deletion of inactive records when retention is no longer required.
Client machine records, tickets and backup copies follow the same rule, bounded by the retention window agreed for the account rather than kept indefinitely.
Data deletion
To request data deletion, email hello@prairiestack.com with the business name, the email address used for the PrairieStack account, and the connected Facebook Page or provider account involved. PrairieStack will verify authorization before deleting or disconnecting business data.
For Meta app data deletion requests, include "Meta data deletion request" in the subject line. PrairieStack will remove stored Meta access details and associated Page-management data unless retention is required for security, billing, dispute, or legal reasons.
Security
PrairieStack uses administrative access controls, account authentication, server-side storage controls, encrypted transport, credential vaulting, and operational monitoring to protect business information. No internet service can guarantee absolute security, but PrairieStack works to limit access to authorized purposes, and we tell affected clients when an incident touches their data.
Contact
Questions about this Privacy Policy can be sent to hello@prairiestack.com.