Privacy Policy

Effective Date: September 2, 2026 · Version 1.0

1. Introduction

This Privacy Policy explains how SERVNORA collects, uses, and protects information when you use the SERVNORA service (the “Service”).

This policy covers two categories of information: (A) information SERVNORA collects from its own users, and (B) information that business customers submit to SERVNORA about their own customers.

2. Information We Collect

A. Account Information

When you create an account, we collect:

  • Name and email address
  • Company name and business information
  • Login credentials (passwords are hashed)
  • Role and permissions within your workspace

B. Business Configuration

We store configuration data you provide, including:

  • Company name and contact information
  • Service types and business settings
  • Technician information
  • SMS identity and messaging preferences
  • Google review link configuration
  • Automation and feedback settings

C. Customer and Job Information

Business customers submit information about their own customers, including:

  • Customer names, phone numbers, and email addresses
  • Service addresses
  • Job details (service type, technician, status, amounts)
  • Feedback ratings and comments
  • Recovery case notes and outcomes

This information is submitted by the business customer and is processed by SERVNORA according to the business customer’s instructions.

D. Messaging Information

When SMS functionality is used, we store:

  • Recipient phone numbers
  • Message content (where configured)
  • Delivery status and timestamps
  • Opt-out status and timestamps
  • SMS provider metadata

E. Technical Information

We automatically collect:

  • IP address
  • Browser type and version
  • Device information
  • Usage logs and authentication events
  • Error and performance data

F. Billing Information

Payment processing is handled by our payment provider. We store:

  • Subscription plan and billing cycle
  • Transaction metadata (we do not store full card numbers)

3. How We Use Information

We use information to:

  • Provide and maintain the Service
  • Authenticate users and secure accounts
  • Send configured customer communications (SMS and email)
  • Process customer feedback and create recovery cases
  • Provide analytics and reporting
  • Provide customer support
  • Maintain security and prevent abuse
  • Process billing and subscriptions
  • Improve the Service (using aggregated, de-identified data only)
  • Comply with legal obligations

SERVNORA does not use identifiable customer data for advertising or sell personal information to third parties.

4. Customer Data vs. SERVNORA Data

Customer Data is information that a business customer submits to SERVNORA about its own customers. The business customer determines the purpose and means of processing this data. SERVNORA processes it according to the customer’s instructions and applicable agreements.

SERVNORA Data is information that SERVNORA collects directly from its own users, such as account information, usage data, and technical logs. SERVNORA is the controller of this information.

5. Data Sharing

We may share information with:

  • Service providers who perform functions on our behalf (hosting, SMS delivery, payment processing, analytics)
  • Third-party services configured by the business customer (e.g., Google review links)
  • Legal authorities when required by law or to protect rights and safety

We do not sell personal information. We do not share Customer Data with other SERVNORA customers.

6. Subprocessors

SERVNORA uses third-party subprocessors to provide the Service. For a current list of subprocessors, see our Subprocessor Disclosure.

7. Data Security

SERVNORA maintains administrative, technical, and organizational safeguards designed to protect information against unauthorized access, use, alteration, or disclosure. These include:

  • Encryption in transit (TLS)
  • Passwords and API keys hashed at rest
  • Multi-tenant data isolation
  • Role-based access controls
  • Authentication and session management
  • Activity logging and audit trails

No method of transmission or storage is completely secure. While we strive to protect information, we cannot guarantee absolute security.

8. Data Retention

We retain information for as long as necessary to:

  • Provide the Service to the business customer
  • Comply with legal obligations
  • Resolve disputes and enforce agreements
  • Maintain security and prevent fraud

Account data is retained for the duration of the subscription. After account deletion or termination, data is deleted within a reasonable period, except where retention is required by applicable law or for compliance purposes.

Opt-out records are retained indefinitely to prevent future messaging to opted-out recipients, as required by applicable telecommunications law.

Audit logs are retained for the duration of the account to support security and compliance requirements.

9. Data Deletion

When a business customer deletes a customer record:

  • The record is removed from active databases
  • Associated feedback and recovery data is deleted
  • Residual copies may remain in operational logs or other records for a limited period where required by applicable law or for compliance purposes

When a business customer cancels their account, SERVNORA will make data available for export for a reasonable period, after which data is deleted as described above.

10. Cookies and Tracking

SERVNORA uses the following types of cookies:

  • Essential cookies: Required for authentication and core functionality
  • Session cookies: Maintain your login session across page loads

SERVNORA does not currently use advertising cookies, third-party analytics tracking, or session recording tools on the public website or authenticated application.

If SERVNORA adds analytics or tracking tools in the future, this section will be updated to disclose them. Any such tools will be used only for legitimate business purposes and will be described in this Privacy Policy before they are activated.

11. California Privacy Rights (CCPA/CPRA)

If you are a California resident, you may have rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA), including:

  • Right to know what personal information is collected
  • Right to delete personal information
  • Right to correct inaccurate personal information
  • Right to opt out of sale or sharing of personal information
  • Right to limit certain uses of sensitive personal information
  • Right to non-discrimination for exercising privacy rights

SERVNORA does not sell personal information. When SERVNORA acts as a service provider for a business customer, the business customer is primarily responsible for responding to consumer privacy requests. SERVNORA assists as required by contract and applicable law.

12. International Privacy

SERVNORA is designed for use primarily in the United States and Canada. Where applicable, SERVNORA aims to support compliance with:

  • The General Data Protection Regulation (GDPR) for EU/EEA users
  • The UK GDPR for UK users
  • Canadian privacy legislation (PIPEDA and provincial equivalents)

This Privacy Policy is not intended to constitute full compliance with every applicable privacy law. SERVNORA implements technical and organizational measures appropriate to its role as a data processor/service provider.

13. International Data Transfers

SERVNORA is hosted on cloud infrastructure located in the United States. When data is transferred from the EU/EEA or UK, SERVNORA relies on appropriate safeguards as required by applicable law.

SERVNORA uses appropriate safeguards for international data transfers as required by applicable law, including contractual protections with subprocessors.

14. Children

SERVNORA is intended for business and professional users. We do not knowingly collect personal information from children under 16. If we learn that we have collected information from a child under 16, we will delete it promptly.

15. Privacy Requests

To submit a privacy request or ask questions about this Privacy Policy, contact us at:

Privacy Contact: privacy@servnora.com

If you are an individual whose data is processed by SERVNORA on behalf of a business customer, please contact the business customer directly. SERVNORA will assist the business customer as required by applicable law and contractual obligations.

16. Security Incidents

In the event of a security incident involving personal information, SERVNORA will notify affected parties as required by applicable law and contractual obligations. For B2B customers, the Data Processing Addendum establishes specific notification procedures.

17. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or through the Service with reasonable advance notice. The “Last Updated” date at the top of this page indicates when this policy was last revised.

18. Contact

Legal Contact: legal@servnora.com

Privacy Contact: privacy@servnora.com

This Privacy Policy is not a substitute for legal advice. Consult qualified legal counsel before relying on this policy for compliance decisions.

Privacy Policy | SERVNORA