Privacy Policy
Effective date: [EFFECTIVE DATE] · Last updated: [EFFECTIVE DATE]
This Privacy Policy explains how [COMPANY LLC NAME] ("Company," "we," "us") collects, uses, and shares information in connection with Tenet ERP (the "Service"). It applies to account holders and their team members ("you"). It does not directly govern how our customers use the Service to process information about their own clients or employees — customers are responsible for their own compliance obligations toward the people they enter into the Service.
1. Information We Collect
Account & team information: name, email, phone number, role, and organization details you or your admin provide when creating or managing accounts.
Business data you submit: client and lead records, estimates, jobs, schedules, cost entries, invoices, vendor and purchasing records, and similar business records entered into the Service, which may include personal information about your own clients, employees, or subcontractors (e.g., addresses, phone numbers, pay rates, emergency contacts).
Payment information: subscription payments are processed by Stripe; we receive limited billing metadata (such as plan and payment status) but do not store full card numbers.
Communications data: messages sent through the Service's SMS, email, or AI chat features, and the content of support requests you send us.
Usage & device data: log data, IP address, browser type, and pages/features used, collected automatically for security and to improve the Service.
Location data: approximate job-site addresses you enter for scheduling and route optimization; we do not track device GPS location in the background.
2. How We Use Information
- To provide, maintain, and secure the Service, including authentication and access control;
- To process subscription billing and communicate about your account;
- To send operational notifications you or your organization configure (e.g., schedule reminders, invoice follow-ups) by email or SMS;
- To power the AI assistant feature, which uses a snapshot of your organization's business data as context to answer questions or perform actions you request;
- To sync data with accounting/payroll systems you connect (e.g., QuickBooks, Xero, Gusto) via Merge.dev;
- To monitor, debug, and improve the Service, including error monitoring;
- To comply with legal obligations and enforce our Terms of Service.
We do not sell personal information, and we do not use Customer Data to train third-party AI models beyond what is required to generate a response to your request.
3. Sub-Processors & Third-Party Services
We share information with the following categories of service providers as needed to operate the Service:
- Supabase — database hosting, authentication
- Vercel — application hosting
- Stripe — subscription billing and payment processing
- Twilio — SMS delivery for schedule and business notifications
- Resend — transactional email delivery
- Merge.dev — accounting/payroll integrations (QuickBooks, Xero, Gusto), when you choose to connect them
- Anthropic — powers the in-app AI assistant
- Inngest — background job processing (notifications, nightly syncs)
- Infrastructure providers for rate limiting and error monitoring, where configured
Each provider only receives the information necessary to perform its function and is contractually or contractually-equivalent restricted from using it for unrelated purposes.
4. Data Retention & Deletion
We retain Customer Data for as long as your account is active. You can export your data at any time from within the Service. If you close your account, we retain data for a limited period to allow reactivation or export, after which it is deleted or anonymized, except where we are required to retain it (e.g., billing records for tax purposes).
5. Your Privacy Rights
If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we hold about you, request its deletion or correction, and opt out of the sale or sharing of personal information — which we do not engage in. Residents of other states with similar privacy laws have comparable rights. To exercise these rights, contact us at [CONTACT EMAIL]. We may need to verify your identity before completing certain requests.
If you are a member of a customer's organization and want to exercise rights over data your employer has entered about you, please also contact your organization's administrator, since they control that data within the Service.
6. Security
We use industry-standard safeguards including encryption in transit, database-level row security scoping data to your organization, and role-based access controls. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
7. Children's Privacy
The Service is intended for business use by adults and is not directed at children under 18. We do not knowingly collect personal information from children.
8. International Users
The Service is hosted and operated in the United States. If you access the Service from outside the United States, your information will be transferred to and processed in the United States.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated by email or in-app notice before they take effect.
10. Contact Us
Questions or requests regarding this Privacy Policy can be sent to [CONTACT EMAIL].