Legal
ServiceM8 Integration Privacy
Last updated: 26 August 2026
This page covers the BuildScope add-on for ServiceM8. It sets out exactly what BuildScope reads from your ServiceM8 account, what it writes back, where that information is held and what happens when you disconnect.
It sits alongside our Privacy Policy, which covers BuildScope as a whole. Where this page is more specific about ServiceM8 data, this page applies.
These documents are general draft website policies and should be reviewed by an Australian lawyer before publication.
1. Connecting the add-on
The add-on is connected by someone with owner or admin access to the BuildScope company account, and installed by someone with the rights to install add-ons on the ServiceM8 account. Nobody else can connect it on your behalf.
The connection uses OAuth 2.0. You sign in to ServiceM8 on ServiceM8's own site and approve the access there. BuildScope never asks for, sees or stores your ServiceM8 username, password or two-factor codes.
Access can be withdrawn at any time, from either side: Disconnect on the BuildScope Integrations page, or disable the add-on inside ServiceM8.
2. What BuildScope reads from ServiceM8
BuildScope reads a job only when you send it across, by opening that job in ServiceM8 and clicking the BuildScope action. It does not copy your job list, sync in the background, or read jobs you have not sent.
When you send a job, BuildScope reads:
- The job description, job number, site address and job status
- The client name attached to that job
- The site and billing contacts on that job: name, contact type, phone, mobile and email
- The name and identifier of your ServiceM8 account, so the connection knows which business it belongs to
- The staff member who clicked the action, so the job can be attributed correctly
- Your tax rates, so line items sent back carry the right GST
That is the lot. BuildScope does not read your invoices, payments, card or bank details, timesheets, photos, other jobs, or anything else in your ServiceM8 account.
3. What BuildScope writes back
Nothing is written back until you press Send to ServiceM8 on a finished scope. When you do, BuildScope writes:
- The Scope of Works PDF, attached to the job diary
- A short diary note listing the exclusions and clarifications
- The scope line items into Items & Services on that job
- The job and quote description, so it matches the scope
Line items added by BuildScope are tagged. If you send the same scope again, BuildScope replaces its own rows and leaves any rows you added yourself alone.
4. The permissions we ask for
ServiceM8 shows you a list of permissions when you connect. In plain terms:
- Account details: identify which ServiceM8 business the connection belongs to
- Staff: know who clicked the action on the job
- Read jobs: bring the job description, number, address and status across
- Manage jobs: update the job and quote description when you send the scope back
- Read clients and job contacts: bring the client and site contact details across
- Attachments: put the finished PDF in the job diary
- Job notes: add the exclusions and clarifications note
- Job materials: write the scope line items into Items & Services
- Read tax rates: apply the correct GST to those line items
BuildScope asks for the minimum the add-on needs to do its job, and every permission on that list is used by a feature described on this page.
5. Where the information is held
Imported job details become a BuildScope job inside your own company account, stored the same way as any job you type in yourself, in Firebase / Firestore with Vercel hosting. Company data separation applies: see Data & Security.
The connection itself is stored as a single record holding your ServiceM8 account identifier, the connection status, the dates it was connected or disconnected, which permissions were granted, and when it last spoke to ServiceM8.
The access keys that let BuildScope talk to ServiceM8 on your behalf are encrypted at rest with AES-256-GCM before they are written down. They are never sent to your browser, never shown in the app and never written into logs.
The Scope of Works PDF is built in your browser and passed straight through to ServiceM8. BuildScope does not keep a copy of it.
6. AI processing of imported jobs
A job you import is worked on by the BuildScope estimator the same way a job you typed in is. The description, address, client name and contact details you bring across form part of what the AI reads while it builds the scope.
Our AI provider (Anthropic) processes this through its commercial API under terms that do not allow it to use that data to train its AI models. The full detail is in our AI Use Policy.
7. Who else sees it
Information brought across from ServiceM8 is handled by the same providers that run the rest of BuildScope: cloud hosting, our database, and our AI provider. Nobody else receives it.
BuildScope does not sell it, and never passes ServiceM8 data to advertising networks, data brokers or any other third party for their own purposes. Job details, client details, site addresses and scopes are not sent to our email or analytics tools.
8. Disconnecting, and what happens to your data
Disconnect from the BuildScope Integrations page, or disable the add-on inside ServiceM8. Either way:
- The stored access keys are deleted immediately, and BuildScope can no longer reach your ServiceM8 account
- Scopes you already built stay in your BuildScope account, because they are your work
- PDFs, notes and line items already sent to ServiceM8 stay in ServiceM8, under your control
- A record of which ServiceM8 job matched which BuildScope job is kept, identifiers only and no personal details, so reconnecting relinks the same jobs instead of duplicating them
You can delete an imported job in BuildScope at any time. To have everything removed, including the connection record, email admin@buildscope.app or delete your BuildScope account, which removes your company data with it.
9. Who is responsible for what
BuildScope is responsible for handling ServiceM8 data as described on this page, keeping the access keys secure, and asking for no more access than the add-on needs.
You decide whether to connect the add-on, who in your business may use it, and which jobs get sent across. You are also responsible for reviewing every scope before it goes to a client, as set out in our Disclaimer.
ServiceM8 is responsible for the data held in your ServiceM8 account, under ServiceM8's own terms and privacy policy. Once BuildScope has written a PDF, note or line item into your job, that information sits in ServiceM8 and is governed by their policy.
BuildScope is a separate product with its own account and its own subscription. It is not built, owned or operated by ServiceM8.
10. Contact
For any question about this integration, or to request access to or deletion of data brought across from ServiceM8, contact admin@buildscope.app.
