AI for Skilled Trades & Home Services
Aware · M6 · lesson 6 of 17 · queued
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
Customer Data and AI — What You Can and Can't Send to a Model
📖
now learning

Customer Data and AI — What You Can and Can't Send to a Model

15 min

Every prompt your CSR, your Comfort Advisor, your service manager, or your owner types into ChatGPT, Claude, Gemini, Avoca, Rilla, Hatch, or any other AI tool is a data transfer. Sometimes the transfer is harmless — paste yesterday's GLSA spend, ask the model to summarize. Sometimes the transfer is a regulated event with statutory damages, partner-status loss, and front-page reputational risk attached. The difference between the two is whether the field you pasted contained an identifier the regulator cares about — a credit-card primary account number (PAN), a Social Security number, a homeowner's full street address tied to a job photo, a jobsite photo with a kid's face in it, a Wisetack soft-pull response with the approval tier, a call recording with the homeowner's voice. This lesson is the practical guardrail map: what you can paste into a consumer-tier AI (ChatGPT, Claude, Gemini free), what only goes into an enterprise-tier or BAA-eligible deployment, what never goes into a model at all, the 5-line data policy the owner posts on the wall next to the dispatch board, and the 30-second redaction habit every CSR, tech, and advisor builds in their first week.

Why This Lesson Exists — The 2026 Data Surface in a Trades Shop

A 2026 trades shop is, accidentally, a small data broker. Across an average week the shop touches: 200-600 inbound phone numbers, 60-180 home street addresses, 40-140 jobsite photos (some with kids playing in the driveway, some with house numbers, some with HVAC nameplates visible), 20-80 financing soft-pull responses with last-4 SSN and approval tier, 15-60 credit-card PANs (typed by a CSR or captured via a virtual terminal), 8-30 employee records (driver's license number, MVR data, EPA 608 cert number), and several hundred call recordings storing the customer's voice biometric. The AI surface a shop sits on for inputs is discoverable to anyone the shop hands a credential to, including the AI vendor's sub-processors.

The 2026 enforcement environment around that surface is harder than 2024. The FTC's Safeguards Rule extension to non-bank lenders has been clarified to include shops doing soft-pull intakes for Wisetack, GreenSky, and Synchrony. State privacy statutes have stacked — California CCPA / CPRA, Colorado CPA, Virginia CDPA, Connecticut CTDPA, Utah UCPA, Texas TDPSA, Oregon OCPA, Florida FDBR, plus a dozen more with active or scheduled-2026 consumer-privacy regimes. PCI-DSS 4.0 became mandatory in March 2025; HIPAA-adjacent rules touch shops doing senior-services work; the GLBA Safeguards Rule applies to consumer-finance intakes. None of these statutes care that "the CSR pasted it into ChatGPT." They care whether the consumer's data left a controlled surface for an uncontrolled one. The pasting is the breach event.

The cheap fix is also the simple fix: a known list of fields that go to which tier of model, a five-line policy that fits on a half sheet of paper, and a CSR-floor habit of redacting before pasting. Every shop — from the 1-truck plumber in Tampa to the 280-truck Wrench Group portfolio in Phoenix — can deploy the discipline by next Tuesday morning. The shops that don't will find out what statutory damages without proof of harm look like when a 13-year-old child's face from a jobsite photo ends up indexed in a model's output.

The Three Data Tiers — Public, Sensitive, Regulated

Every field that touches a 2026 trades shop falls into one of three tiers. The discipline is not memorizing every statute. The discipline is knowing which tier a field belongs to and applying the standing rule for that tier.

Tier one — public or operational. Equipment make and model, system age, refrigerant type, last service date, job complaint summary, scope of work, equipment tonnage, refrigerant SKU, dispatch-board call counts, technician initials, aggregate financial summaries, marketing channel ROAS, GLSA cost per booked call, route stops by zip, brand voice samples, the shop's own pricebook. These fields can be pasted into consumer-tier AI for drafting, summarizing, or coaching. The data does not identify a specific consumer or contain a regulated identifier. Avoca, Rilla, Hatch, CallRail, Podium AI Employee, Birdeye AI Employee, NiceJob, and ResponsiBid all routinely process tier-one data.

Tier two — sensitive but not strictly regulated. Full customer name, street address, phone, email, equipment serial tied to a customer record, jobsite photos without identifiable people, call recordings without consent issues, internal performance scorecards naming tech full names, comp-plan structures, supplier pricing, customer-facing draft copy. These fields require a controlled surface — enterprise-tier AI with a signed DPA, BAA where HIPAA-adjacent, or in-platform AI like ServiceTitan Titan Intelligence, Sera AI, Jobber Copilot, Housecall Pro AI Agents, where data never leaves the FSM. Consumer-tier ChatGPT, Claude, or Gemini Free are wrong for tier-two data: consumer terms permit training on inputs with no contractual data-handling commitment.

Tier three — regulated identifiers. Credit card PAN, CVV, full or last-4 SSN tied to a customer name, driver's license, DOB, financing soft-pull responses with credit detail, full FICO score, lender adverse-action language, jobsite photos with identifiable children or other third parties, employee MVR data, EPA 608 cert numbers tied to personal data, biometric voiceprints, ADA-protected accommodation details. Never in a general-purpose AI at any tier. They live in the systems built for them — the financing portal (Wisetack, GreenSky, Synchrony), the PCI-DSS processor (Stripe Terminal, Aurora Payments, FSM-integrated processors inside ServiceTitan / Sera / HCP), the HR system (Gusto, Rippling, ADP). When AI needs surrounding context, the regulated identifier is redacted, masked, or replaced with a placeholder ("[customer]," "[address]," "[last-4]") and AI generates around it.

Consumer-Tier vs. Enterprise-Tier AI — The Contract Is the Difference

The single most expensive mistake an owner makes is treating ChatGPT, Claude, and Gemini as if "they're all just AI." They are not. The contract behind each tier is the difference between a $40K compliance exposure and an audited, signed-off vendor relationship.

ChatGPT (OpenAI). Consumer-tier — Free, Plus, Pro — inputs may train future models unless the user disables training. Conversations stored with default retention. No DPA, no BAA, no contractual data-handling commitment. Enterprise-tier — Enterprise, Team (with admin opt-out), the API with zero-retention enabled — comes with an enterprise agreement, training opt-out by default, signed DPA, SOC 2 Type II, audit trail. The shop's policy: Plus permitted for tier-one data only; Enterprise for tier-two; never tier-three without an additional encryption/key layer.

Claude (Anthropic). Same structure. Claude.ai consumer is the toy; Claude for Work, Claude Team, Claude Enterprise, and the Anthropic API (zero-retention enabled) are the enterprise surfaces. Anthropic's commercial terms historically default to not training on enterprise API traffic. Safe operating assumption: consumer is no-DPA, enterprise is DPA-signed.

Gemini (Google). The most complex tier landscape. Gemini consumer (gemini.google.com) is consumer-tier; Gemini Advanced (Google One) is mid-tier with consumer-grade terms; Gemini for Workspace inherits Workspace data-handling (DPA-covered, no training on Workspace data); Vertex AI Gemini on Google Cloud comes with full enterprise contracts, BAA eligibility, audit trail. Workspace and Vertex are tier-two-eligible; consumer Gemini is not.

In-platform AI inside the FSM. ServiceTitan Titan Intelligence, Sera AI, Jobber Copilot, and Housecall Pro AI Agents all run inside the FSM's data perimeter. Data never leaves the tenant. The FSM vendor's DPA covers the AI feature. For tier-two data — customer name, address, equipment serial, recorded calls — this is the highest-confidence surface in 2026. It is also where 59% of contractors say they prefer AI to live (ServiceTitan 2026 State of AI in the Trades): data-handling is one contract instead of three.

The named operating rule. Tier-one: any AI, any tier. Tier-two: enterprise or in-FSM AI only, DPA on file. Tier-three: never in a general AI; only in the system built for it; redact before any AI prompt.

The Five Fields That Most Often Get Mishandled

The audit trail of trades-shop AI incidents in 2025-2026 shows the same five fields keep getting pasted into the wrong surface. Each one has a specific exposure, a specific fix, and a specific replacement workflow.

Credit-card PANs. A CSR troubleshooting a portal payment types the full PAN into ChatGPT to "check the format." The PAN now lives in OpenAI's logs with PCI-DSS implications and processor-relationship risk. Fix: PANs never leave the PCI-compliant terminal. The FSM-integrated processor (ServiceTitan Payments, HCP payment processing, Sera Pay, Stripe Terminal, Aurora Payments) handles the card. The CSR never sees more than the last-4. AI workflows reference last-4 only.

SSN for financing soft-pulls. The Comfort Advisor runs the Wisetack soft-pull. Portal returns "approved up to $18K, 84 months at 8.99%." The advisor pastes the full response — including last-4 SSN — into ChatGPT to "draft a recap text to the homeowner's spouse." Last-4 SSN tied to a name now lives in OpenAI's logs. Wisetack, GreenSky, and Synchrony all have partner-agreement data-handling provisions the shop just violated; partner-status review can follow. Fix: soft-pull response stays in the lender portal. The advisor's recap is generated by AI with a placeholder ("approved up to $X, $Y/mo over Z months") — regulated numbers come from the portal, not the model. Personalization receives first name only.

Home addresses paired with photos. A tech finishes a heat-pump replacement and snaps three install photos. The dispatcher pastes photos plus work address into a public image-recognition tool to "tag for marketing." Address paired with equipment photo and homeowner name now lives in an unknown vendor's training surface. Fix: photo tagging happens inside the FSM or inside an enterprise vision model with a signed DPA. Address stays in the customer record; photos tagged with equipment/condition labels only, not address.

Jobsite photos with people, especially kids. The most underestimated 2026 exposure. A tech in Texas photographs an attic install; the homeowner's 7-year-old is in the frame. The marketing manager auto-feeds new jobsite photos into a public AI image generator for "before/after" posts. The child's face is now in a training surface and possibly indexed in outputs. State child-protection statutes, COPPA, the FTC's Children's Privacy framework, and the homeowner's reasonable expectation of privacy all apply. Plaintiff firms are watching this category. Fix: photos with identifiable people are flagged at capture (FSM "people in frame?" checkbox), reviewed by dispatcher or marketing manager, then either cropped, used with written consent on file, or discarded. FSM photo library is the storage surface.

Call recordings. A service manager wants to "let ChatGPT find the coaching moments" in a 45-minute kitchen-table recording. The recording contains the homeowner's voice (biometric), home address, credit detail, and consent disclosure language. Pasting the audio or transcript into consumer-tier AI breaks every contract this lesson covers. Fix: recordings live inside CallRail Conversation Intelligence, Rilla, ServiceTitan call recording, or the FSM-integrated recorder — DPA-covered with per-state consent configuration. Coaching pulls happen inside the platform; audio never leaves the controlled surface.

The Five-Line Data Policy Every Shop Posts on the Wall

This is the policy. Five lines. Print it on a half sheet, laminate it, tape it next to the dispatch board, the CSR row, the Comfort Advisor's locker, the manager's desk, and inside every truck's tablet case. The owner signs the bottom; everyone in the shop reads it on day one.

One. Tier-one data (equipment, scope, aggregates, brand voice samples) can go in any AI tool. When in doubt, treat the field as tier-two.

Two. Tier-two data (customer name, address, phone, email, internal scorecards, recorded calls, photos without identifiable third parties) only goes in enterprise-tier or in-FSM AI on the shop's approved list. The approved list is on this wall.

Three. Tier-three data (credit-card PAN, full or last-4 SSN, DOB, driver's license, financing soft-pull responses with credit detail, biometric voice prints, photos with identifiable children or third parties without consent) never goes in a general AI tool. Period. It lives in the system built to handle it. The systems are on this wall.

Four. If you don't know the tier, you ask the manager. The manager has the authority to add a field to the approved list, not the individual user. The week's added fields go on the failure log on Friday.

Five. Every paste into an AI tool is a recorded event. If you pasted something wrong, you tell the manager within the hour. We fix the policy, not the person. We tell the customer if their data was exposed. We never punish a self-report.

That last clause is the load-bearing one. The shops that recover from AI data incidents in 2026 are the shops where employees report fast. The shops that get sued, fined, and dragged into state-AG inquiries are the shops where the CSR knew on Tuesday and didn't tell the owner until the customer called Friday with a screenshot. The five-line policy creates the cultural permission to self-report; the failure log creates the operating cadence; the policy survives a state contractor board audit, a state-AG inquiry, an FTC look, and the PE-portfolio QBR.

BAA, DPA, and the Contracts the Owner Actually Signs

Three contractual artifacts protect the shop's deployment of AI on customer data. The owner does not need to be a lawyer to understand them; the owner does need to know which one applies, when it applies, and what to do when it is missing.

Data Processing Agreement (DPA). The baseline contract any AI vendor signs with a business customer handling sensitive data. The DPA specifies what data the vendor processes, sub-processors, geographic storage, retention, termination handling, breach-notification timelines, and the controller-processor relationship under state privacy laws. Every enterprise-tier AI vendor — OpenAI Enterprise, Anthropic Enterprise, Google Vertex, ServiceTitan, Sera, Housecall Pro, Avoca, Rilla, Hatch, CallRail, NiceJob, Podium, Birdeye — offers a DPA. Consumer-tier products typically do not. The shop's procurement discipline: no DPA, no tier-two data, no exceptions.

Business Associate Agreement (BAA). The HIPAA-specific contract a vendor signs when the customer is a covered entity or business associate. Most trades shops are not HIPAA-regulated. The exceptions: shops doing senior-care services, in-home medical equipment installation (oxygen concentrators, lifts, accessibility), shops with healthcare-provider contracts, and shops where a homeowner mentions a medical accommodation that becomes recorded. The conservative posture: flag any AI tool that might process accommodation language as BAA-required, route those flows to BAA-covered tools (Google Workspace with BAA, Microsoft 365 with BAA), document the routing.

Sub-processor mapping. Every AI vendor uses other vendors — cloud hosting, observability, customer support, sometimes downstream model providers. The DPA lists those sub-processors and the customer's right to object to a new one. For a shop with 5+ AI tools (typical 2026 deployment: ServiceTitan, Avoca, Rilla, CallRail, NiceJob, Hatch, Wisetack), the sub-processor graph runs 40-80 vendors deep. The named workflow: at the quarterly governance review, the owner pulls the sub-processor lists, checks for changes since last quarter, confirms no new sub-processor breaks the tier policy. 30 minutes a quarter. Survives a PE-partner audit or a state-AG inquiry.

The Trades-Specific Edge Cases — Financing, Photos, Voice

The Wisetack / GreenSky / Synchrony soft-pull. Each lender's portal returns a structured response: approved amount, term, APR, monthly payment. The temptation is to paste the full response into ChatGPT to "draft the spousal recap text." Don't. Portal output stays in the portal; advisor uses an in-FSM AI prompt with first name and approved-amount aggregate only ($18K, 84 months, $X/mo); spouse text sent through the FSM. Advisor never types or pastes the SSN. Adverse-action language on declines is the lender's signed template; AI never drafts it.

Jobsite photo intake. The 2026 FSM standard is a photo-intake screen with equipment make, condition tag, before/after marker, scope tie — plus the "people in frame?" checkbox that flags for crop, consent, or discard. Marketing manager's AI workflow pulls only flagged-clean photos; Canva, Figma, Adobe Firefly receive clean photos only.

Recorded-voice biometrics. Illinois BIPA, Texas, Washington, and California CCPA / CPRA treat voiceprints as biometric data. AI tools that derive voiceprints (sentiment, speaker ID, voice cloning) touch biometric law. Discipline: features disabled by default in CallRail, Rilla, ServiceTitan call recording, Avoca; enable only with documented consent. BIPA class-action exposure: $1,000-$5,000 per consumer.

Building the Discipline Into the Shop Floor

Policy on a wall is necessary and insufficient. The cultural artifact has to land in the daily routines of the people doing the work. Four practices make the discipline survive the first 90 days.

The CSR-floor redact habit. Every CSR pasting into any AI tool reads the paste back for one breath. If they see a phone number, address, last-4, or full name, they redact it to a placeholder before sending. Takes a week to install. Enterprise-tier AI also supports input redaction as a configurable layer — ChatGPT Enterprise, Claude Enterprise, and in-FSM AI tools all auto-redact common patterns (phone, SSN, last-4) before transmission.

The Comfort Advisor's kitchen-table protocol. The advisor's tablet has two AI surfaces: in-FSM AI for proposal drafting (tier-two safe) and the lender portal for financing (tier-three handled by the portal vendor). The advisor never opens a consumer AI app at the kitchen table. The tablet is IT-provisioned to make the rule mechanically enforceable. Workflow: advisor reads system condition → in-FSM AI drafts the good/better/best presentation → advisor presents → financing pivot opens the lender portal for soft-pull → advisor reads payment math from the portal screen.

The dispatcher's photo protocol. When the tech uploads photos from a completed job, the dispatcher's first task is a 10-second photo skim. Flag any photo with identifiable people; check consent; route to marketing's clean library or hold for crop/consent. The dispatcher's existing board habit absorbs this once the FSM photo intake field is in place.

The Friday governance review. Once a week, the manager reviews the failure log: flagged tier-mismatch events, new AI tool requests, new sub-processor disclosures, photos flagged with identifiable people. Ten minutes. The documented governance cadence that survives state contractor board audits, state-AG inquiries, EPA 608 audits, and PE quarterly business reviews.

What This Lesson Fixes for the Shop

Most trades-shop AI data incidents in 2026 do not happen because the shop wanted to break the law. They happen because the CSR pasted what felt natural, the advisor wanted to be helpful, the marketing manager wanted to move fast, and nobody had told them which fields belong on which surface. Three tiers. Two contracts. Five fields that get mishandled. Five-line policy on the wall. Four daily practices. The shops that internalize this discipline in week one — before the first Avoca pilot, before the first Rilla deployment, before the first Hatch nurture sequence — deploy AI at the pace of operating leverage instead of at the pace of legal exposure. The five-line policy is the comprehensive policy that ships. Tape it up; sign the bottom; move.

Key Takeaways

  • Three data tiers govern every paste. Tier one (equipment, scope, aggregates) goes anywhere. Tier two (customer name, address, photos, recordings) goes only in enterprise-tier or in-FSM AI with a DPA. Tier three (PAN, SSN, DOB, soft-pull responses, biometric voice, photos with identifiable kids) never goes in a general AI — only in the system built for it.
  • Consumer-tier AI is the wrong surface for customer data. ChatGPT Free/Plus, Claude.ai consumer, Gemini consumer all have no DPA and may train on inputs. Enterprise tiers — ChatGPT Enterprise, Claude Team/Enterprise, Vertex AI Gemini, Workspace Gemini — sign DPAs with training opt-out by default. In-platform AI (Titan Intelligence, Jobber Copilot, HCP AI Agents, Sera AI) is the highest-confidence surface for tier-two data because the data never leaves the FSM tenant.
  • The five most-mishandled fields: credit-card PANs (stay in the PCI processor), SSNs for financing soft-pulls (stay in Wisetack/GreenSky/Synchrony portal), home address paired with photos (stay in the FSM), jobsite photos with kids or identifiable third parties (FSM intake, "people in frame?" checkbox, crop or consent), call recordings (stay in CallRail / Rilla / ServiceTitan with per-state consent configuration).
  • The five-line data policy posts on the wall. Tier-one anywhere; tier-two enterprise/FSM with DPA; tier-three never in a general AI; ask the manager if unsure; self-report fast — we fix policy not people.
  • DPA is the baseline contract. No DPA, no tier-two data, no exceptions. BAA applies to senior-services, accessibility, in-home medical contexts. Sub-processor mapping at the quarterly governance review prevents new vendor flows from breaking the policy.
  • The 30-second redact habit lives at the CSR row and the Comfort Advisor's tablet. Phone numbers, addresses, last-4s, full names redacted to placeholders before any AI prompt. Enterprise-tier tools auto-redact common patterns; the human habit is the second layer.
  • Voice biometrics are the under-watched 2026 exposure. Illinois BIPA, Texas and Washington analogs, California CCPA / CPRA all touch voiceprints. Disable voice biometric features by default in CallRail, Rilla, ServiceTitan, Avoca; enable only with documented consent.
  • The Friday governance review takes 10 minutes. Failure-log scan, new-tool requests, new sub-processor disclosures, photo flags. The documented cadence that survives state contractor board audits, state-AG inquiries, and PE quarterly reviews.
  • Self-report culture beats blame culture. The shop that recovers from a data incident is the shop where the CSR tells the manager within the hour. Punish the policy gap, not the person.