Homeowners and property managers trust contractors with a lot. They share addresses, phone numbers, alarm codes, and details about when a house sits empty. Protecting customer data is part of earning that trust, especially as more bookings start online.
What information you hold
A service company collects more than most owners realize. Field service software stores service history, equipment models, and maintenance agreement details. Technicians add notes about pets, lockbox codes, and access instructions.
Meanwhile, online booking forms capture names, addresses, and descriptions of problems. Marketing tools hold email lists and review requests. Commercial clients may also share building plans or security procedures.
Each of these deserves care. For example, a list of homeowners with gate codes is valuable to a burglar.
Start by mapping where each type of information lives. Then note which employees and vendors can reach it. That map guides every other decision in this guide.
Secure online booking and web forms
Online booking is convenient for customers, but every form is a door into your systems. Start by making sure your website uses HTTPS on every page. Then keep the website platform, themes, and plugins updated.
Next, add spam and bot protection to booking and contact forms. Otherwise, attackers can flood you with fake requests or probe for weaknesses. In addition, ask only for what you need to schedule the visit.
Avoid collecting sensitive details such as full card numbers through general web forms. Instead, use your processor’s secure payment page for deposits.
Also review where form submissions go. Some forms email every request to a shared inbox, while others feed directly into scheduling software. Either way, make sure only the right people receive them.
Control who sees customer data
Not every employee needs every record. So set roles in your field service software carefully. Technicians might see only today’s jobs and their customers, while office staff see full history.
Also limit exports. A single spreadsheet of every customer is easy to email, copy, or lose. Allow exports only for people who truly need them, and track when they happen.
Finally, remove access as soon as someone leaves. Former employees should never keep logins to scheduling or customer portals.
Personal phones deserve attention as well. When technicians text customers from personal numbers, those conversations leave with them. So use company apps or numbers for customer contact whenever possible.
A checklist for protecting customer records
Review these items with your office manager and web vendor:
- HTTPS enabled across the entire website.
- Website platform and plugins updated on a regular schedule.
- Bot protection on booking, contact, and quote request forms.
- Field service roles that limit what technicians can view.
- Gate and alarm codes stored in protected fields, not open notes.
- Customer exports limited to named staff and logged.
- Multifactor authentication on scheduling, marketing, and website admin accounts.
- Old records and unused marketing lists deleted on a set schedule.
Know your notification obligations
Every state has a data breach notification law. These laws generally require businesses to notify affected people when certain personal information is exposed. Illinois, for example, has its Personal Information Protection Act.
The details differ by state, including what counts as personal information and how fast you must act. Therefore, talk with counsel about your obligations before an incident. Also check what your cyber insurance covers for notification costs.
Commercial contracts may add their own notice requirements, so read those clauses too.
Keep customer data only as long as you need it
Old data carries risk without much value. So set a retention schedule for inactive customers, old quotes, and abandoned booking requests. Keep what you need for warranties, agreements, and tax records.
Then delete the rest on a regular basis. Similarly, clean up marketing lists so you are not holding contacts who opted out long ago.
Less stored data means less to protect and less to report if something goes wrong.
How WEBIT helps
WEBIT helps contractors lock down the accounts and devices that touch customer records. Our Security Advanced add-on includes dark web monitoring, email security, and Microsoft 365 threat detection and response. We can also add Duo MFA for systems outside Microsoft 365.
In addition, our managed compliance add-on helps you document policies and track progress. Explore our cybersecurity services or reach out to our team.
Key takeaways
- Gate codes, service notes, and booking forms all hold sensitive information.
- Keep your website and forms updated, encrypted, and protected from bots.
- Limit what technicians see and who can export customer lists.
- Understand your state breach notification duties before an incident.
- Delete data you no longer need on a set schedule.