HVAC, plumbing, electrical, pest, cleaning, and landscaping businesses now hold an unusually dangerous data combination - home addresses, gate and alarm codes, occupancy schedules, and cards-on-file - inside booking apps built with AI. 48% of trade pros already use AI tools, and Veracode found 45% of AI-generated code fails security checks.
Get a Free Security Scan See Our AI App AuditField-service apps pair exact home addresses with physical-entry information - a data combination most industries never have to think about securing.
AI-scaffolded databases (Lovable/Bolt plus Supabase) commonly ship with row-level security disabled. CVE-2025-48757 exposed 170+ Lovable apps' full tables - emails, payment details - to anyone with browser dev tools, reported March 2025.
Property notes routinely contain gate codes, alarm codes, key locations, and pet warnings. A leaked table isn't just a privacy incident - it's a burglary target list. The precedent for how badly access data gets abused: an ADT technician accessed roughly 200 customers' camera accounts 9,600+ times over 4.5 years before being sentenced by the DOJ.
51% of AI-using trade pros already use AI for estimates and quoting. If a quote form is wired to automatic texting without documented consent, each message is a – TCPA violation - home services sit among the top categories for TCPA litigation, and NexGen Air Conditioning paid to settle a ringless-voicemail case in November 2025.
Membership and maintenance-plan billing means stored payment credentials and monthly rebills. A vibe-coded billing flow that touches card data directly instead of a tokenized processor drags the whole app into PCI scope - –nth in fines plus possible loss of processing, on top of California's AB 2863 auto-renewal consent requirements (effective July 1, 2025).
Dispatch apps know exactly which houses are empty and when service windows occur. An exposed jobs-today API is a real-time "nobody's home" feed. On the employee side, GPS tracking of company vehicles without written notice is separately illegal in states like New Jersey.
52% of AI-using pros already apply AI to customer communication and follow-up. Tools that auto-draft, incentivize, or filter reviews cross the FTC's fake-review rule (effective October 21, 2024), which carries civil penalties up to per violation - a real risk given reviews are the #1 acquisition channel in local trades.
| Regulation | When it applies | Penalty |
|---|---|---|
| TCPA + FCC revocation rule | Marketing calls/texts/ringless voicemail without consent; opt-out not honored within 10 business days (eff. 2025-04-11) | – per call/text; NexGen paid .8M |
| PCI DSS | Storing/processing cards - card-on-file for memberships and recurring billing | –nth via acquiring bank; loss of processing |
| CCPA/CPRA + state privacy laws | Revenue/consumer thresholds met; lead lists count toward totals | /violation, intentional; CPPA record actions in 2025 |
| FTC Safeguards Rule (GLBA) | Offering or arranging customer financing (common for HVAC replacements) | FTC breach reporting required within 30 days for 500+ consumers |
| State contractor licensing (e.g. CA CSLB) | License number must appear on all advertising, including websites | – first advertising offense; up to + jail for unlicensed contracting |
| CA Auto-Renewal Law (AB 2863) | Auto-renewing maintenance plans sold online, effective 2025-07-01 | CA UCL enforcement/restitution; consent records must be kept 3+ years |
| FTC Fake Review Rule | AI-generated, fake, incentivized, or suppressed reviews | Up to per violation |
Not by default. AI-generated code fails security checks in roughly 45% of tasks (Veracode), and CVE-2025-48757 exposed 170+ Lovable apps' full databases because row-level security was off by default. A booking app holding customer addresses and property-access notes needs that checked before launch.
Yes, a serious one. Property notes with gate codes, alarm codes, and key locations amount to a burglary target list if exposed. An ADT technician's abuse of camera access - roughly 200 customers, 9,600+ unauthorized views over 4.5 years - shows how badly this kind of access data can be misused even by insiders.
Yes, for marketing and promotional texts. Violations carry – per text, and home services is among the most-litigated TCPA categories - NexGen Air Conditioning paid in November 2025 to settle a ringless-voicemail case with roughly 181,135 class members.
Yes, if you sell auto-renewing maintenance or service plans online to California customers. AB 2863, effective July 1, 2025, requires you to retain proof of consent for at least 3 years and let customers cancel through the same medium they used to sign up.
Not if it gates, incentivizes, or fabricates reviews. The FTC's fake-review rule, effective October 21, 2024, carries civil penalties up to per violation - a meaningful risk since reviews are the top acquisition channel for most local trades.
Rotate every API key and credential, enable row-level security if it wasn't already on, and treat any exposed gate codes or access notes as an urgent physical-security issue for affected customers, not just a data-privacy one. Notify affected customers under applicable state breach laws.
We audit AI-built home-services booking and customer-portal apps for exposed access data, missing RLS, and TCPA/PCI gaps - then fix what we find.
Get a Free Security Scan