← All policies

Privacy Policy

Version 3.1 · effective 8/12/2026 · acceptance required for account holders

This page is maintained by NovakOS. It describes the controls the platform actually provides — it is not a certification or independent audit.

NOVAKOS PRIVACY POLICY

**Version:** 3.0 **Effective Date:** 2026-08-11 **Last Updated:** 2026-08-11

This Privacy Policy explains how **Michael Novak O/A NovakOS, carrying on business as “NovakOS”** (“**NovakOS**,” “**we**,” “**us**,” or “**our**”) collects, uses, discloses, stores, protects, and otherwise handles personal information through NovakOS.

This Policy applies to the NovakOS website, web application, native/mobile applications, related services, customer support, payment integrations, communications systems, and other NovakOS functionality.

**Privacy Officer:** Privacy Officer **Privacy Email:** [support@novakos.org](mailto:support@novakos.org) **Mailing Address:** 2524 Hastings Road, Chemainus, BC, V0R 1K5 **Support:** [support@novakos.org](mailto:support@novakos.org) **Website:** https://novakos.org

---

1. PRIVACY ROLES

NovakOS may handle personal information in different capacities depending on the circumstances.

For information concerning:

* NovakOS account holders; * Authorized Users; * Subscription billing; * direct communications with NovakOS; * product security; * fraud prevention; * legal compliance; * NovakOS support;

NovakOS may determine the purposes for which the information is handled.

Where a subscribing business enters personal information concerning:

* its customers; * employees; * contractors; * technicians; * property owners; * tenants; * other individuals;

that subscribing business ordinarily determines why the information is collected and used, while NovakOS processes the information to provide the requested Services.

If you are an employee or customer of a business using NovakOS, that business may therefore be the appropriate first contact regarding its use of your information.

---

2. ACCOUNTABILITY

NovakOS maintains a privacy-management program appropriate to the Services.

Our Privacy Officer is responsible for overseeing NovakOS privacy practices and receiving privacy inquiries and complaints.

Where a Customer controls Customer Data, NovakOS will reasonably assist Customer in carrying out applicable privacy obligations within NovakOS’s role and capabilities.

---

3. INFORMATION WE MAY COLLECT

The categories collected depend on how NovakOS is configured and used.

---

4. ACCOUNT INFORMATION

We may process:

* name; * email address; * telephone number; * profile image; * authentication identifiers; * sign-in provider; * role; * employer or company; * account status; * preferences; * legal acceptance records.

Where Google, Apple, or another identity provider is used, the provider may authenticate the user without supplying NovakOS with that provider account’s password.

---

5. COMPANY INFORMATION

We may process:

* company name; * trade/business information; * company address; * billing address; * province; * postal code; * business telephone number; * billing email; * Subscription plan; * account configuration; * connected domains; * payment-account status; * personnel and permission information.

Business information may constitute personal information where it identifies an individual, including a sole proprietor.

---

6. END CUSTOMER INFORMATION

Businesses using NovakOS may submit information about their customers, including:

* names; * telephone numbers; * email addresses; * billing addresses; * service addresses; * properties; * communication preferences; * jobs; * appointments; * equipment; * service history; * notes; * estimates; * quotes; * invoices; * payments; * forms; * signatures; * communications; * photographs; * videos; * files.

---

7. EMPLOYEE AND CONTRACTOR INFORMATION

Depending on Customer configuration, NovakOS may process:

* names; * work contact information; * job roles; * permissions; * assignments; * schedules; * attendance information; * clock-in and clock-out information; * time entries; * paid-leave information; * pay rates; * wage-related calculations; * timesheet status; * location information; * job history.

---

8. LOCATION INFORMATION

Where Customer enables location functionality and required device permissions are granted, NovakOS may process precise or approximate location information associated with an Authorized User’s work activity.

Location information may include:

* coordinates; * timestamps; * accuracy information; * job or work context; * tracking state.

NovakOS location functionality is intended for legitimate field-service and employment-management purposes and is not intended to facilitate covert off-duty surveillance.

---

9. PHOTOGRAPHS, VIDEOS, AND MEDIA

NovakOS may process media that a user captures or selects, including:

* job photographs; * equipment photographs; * property photographs; * videos; * image attachments; * signatures; * files.

Where a feature requires audio capture, a device may request microphone access.

NovakOS does not intentionally access more of a user’s photo library than is required for the functionality the user invokes where system-level limited-selection functionality is available.

---

10. SUBSCRIPTION BILLING INFORMATION

For Customer’s NovakOS Subscription, we may process information including:

* billing email; * Stripe customer identifier; * Subscription identifier; * Subscription plan; * Subscription status; * invoice information; * charge amounts; * payment-method type; * card brand; * last four digits; * expiry information; * processor transaction identifiers.

Full payment-card numbers and CVVs are intended to be handled directly by Stripe or the applicable payment provider rather than NovakOS.

---

11. END-CUSTOMER PAYMENT INFORMATION

Where Customer uses supported payment functionality, NovakOS may process:

* Stripe Connected Account identifiers; * Checkout Session identifiers; * PaymentIntent identifiers; * payment status; * payment amount; * platform fees; * refund records; * dispute records; * payment-method identifiers; * limited card metadata; * payment consent records.

Full card credentials are handled by the applicable payment provider.

---

12. COMMUNICATION INFORMATION

Where Customer uses email or SMS functionality, NovakOS may process:

* sender; * recipient; * email address; * telephone number; * message text; * message subject; * timestamps; * delivery status; * bounce status; * complaint status; * unsubscribe requests; * SMS STOP records; * consent records.

---

13. DEVICE AND TECHNICAL INFORMATION

We may process technical information including:

* browser type; * operating system; * device type; * application version; * platform; * IP address; * session information; * authentication events; * timestamps; * connection information; * diagnostic information; * push-notification tokens; * error data; * security events; * correlation identifiers; * audit events.

---

14. SUPPORT INFORMATION

When someone contacts NovakOS, we may retain:

* correspondence; * issue descriptions; * support history; * account details relevant to support; * actions taken; * identity-verification information where required; * security or incident-related information.

---

15. SOURCES OF INFORMATION

NovakOS may receive information:

* directly from an individual; * from Customer administrators; * from Customer employees or contractors; * from End Customers; * from uploaded files; * from user devices; * from Stripe; * from Twilio; * from Resend; * from Google; * from Apple; * from Supabase; * from mapping providers; * from connected services; * from other Third-Party Services authorized by Customer.

---

16. PURPOSES OF COLLECTION AND PROCESSING

We may use personal information to:

* create accounts; * authenticate users; * create Customer companies; * administer permissions; * provide Customer relationship management; * schedule work; * dispatch workers; * manage jobs; * generate quotes; * generate invoices; * process Subscription payments; * facilitate Customer Payments; * support saved payment methods; * support recurring service plans; * record time; * record paid leave; * provide payroll-related summaries; * provide employee-location features; * provide maps and routing; * send Customer-directed communications; * provide email and text messaging; * provide notifications; * support offline operation; * respond to support requests; * prevent fraud; * secure accounts; * investigate abuse; * troubleshoot; * enforce agreements; * maintain legal records; * satisfy legal requirements; * improve reliability and functionality using appropriate aggregate or de-identified information.

---

17. CONSENT AND OTHER LEGAL AUTHORITY

Where consent is required by applicable law, NovakOS or the relevant Customer should obtain meaningful consent appropriate to the circumstances.

Depending on the jurisdiction and activity, personal information may also be processed based on another authority permitted by applicable law.

Customer is responsible for determining the lawful authority applicable to Customer’s own collection and use of Customer Data.

---

18. EMPLOYEE PERSONAL INFORMATION

Customers using NovakOS for employee-management purposes are responsible for complying with applicable employment and privacy laws.

Customer must provide legally required notices and obtain legally required consent before using NovakOS employee-information functionality.

NovakOS does not represent that an employer may lawfully monitor a worker merely because a technical feature exists.

---

19. EMPLOYEE LOCATION TRACKING

Where location functionality is enabled, Customer may use location information for legitimate work-related purposes such as:

* dispatch; * attendance; * work verification; * travel verification; * assignment management; * operational review.

Customer is responsible for ensuring its purposes are reasonable and lawful.

Customer must not use NovakOS for unlawful covert monitoring or surveillance.

---

20. LOCATION TRACKING STATE

NovakOS is designed so that background employee-location tracking is associated with an applicable active work/clock state where the functionality is enabled.

Paid vacation, sick, or statutory-holiday records are not intended to create active employee clock sessions or activate background GPS tracking.

---

21. LOCATION RETENTION

Under NovakOS’s current standard configuration, employee location history is ordinarily retained for no longer than approximately **28 days**, subject to:

* applicable Customer configuration; * legal preservation requirements; * investigations; * security incidents; * applicable law.

NovakOS may reduce this period as the product evolves.

---

22. LOCATION ACCURACY

Location information may be inaccurate or unavailable.

Factors include:

* device settings; * GPS reception; * network connectivity; * operating-system controls; * background restrictions; * battery management; * permission choices.

Location information is not intended for emergency response.

---

23. CAMERA PERMISSION

Where supported, NovakOS may request camera permission when a user chooses functionality requiring the camera.

Camera access may be used to capture job-site, equipment, form, or other work-related media.

---

24. PHOTO-LIBRARY ACCESS

NovakOS may allow a user to select photographs or videos from the device.

Where supported, NovakOS uses system selection functionality intended to limit access to media the user chooses.

---

25. MICROPHONE

Where a feature requires capture of media with audio, the operating system may request microphone permission.

NovakOS does not intend to continuously record microphone input in the background.

---

26. LOCATION PERMISSIONS

NovakOS may request:

* foreground location; * background/Always location

where required by an enabled field-service feature.

Users can deny or revoke permissions using operating-system settings, although functionality requiring that permission may no longer operate.

---

27. PUSH NOTIFICATIONS

NovakOS may request notification permission to provide:

* job updates; * schedule information; * account notices; * other operational notifications.

Push delivery depends on device and third-party infrastructure.

---

28. OFFLINE INFORMATION

NovakOS may temporarily store information locally on a device to support offline field work.

Local information may include unsynchronized changes.

Unsynchronized information may be lost if the application or browser data is cleared before synchronization.

NovakOS may clear local user-scoped application data during sign-out as part of account-security controls.

---

29. COOKIES AND LOCAL STORAGE

NovakOS may use browser or application storage for:

* authentication; * security; * interface preferences; * offline operation; * required notices; * technical functionality.

NovakOS does not currently use Customer application data for third-party behavioural advertising or cross-site advertising profiling.

If that practice materially changes, this Policy will be updated and consent obtained where required.

---

30. PAYMENT PROCESSORS

Stripe processes payment-card information for supported NovakOS payment functionality.

Stripe operates under its own terms and privacy practices.

NovakOS receives only the payment-related information reasonably required to provide and reconcile the applicable functionality.

---

31. SAVED PAYMENT METHODS

Where Customer uses stored-payment functionality, NovakOS may maintain records documenting authorization or consent.

Customer remains responsible for ensuring it has lawful authority to use an End Customer’s saved payment method.

---

32. COMMERCIAL ELECTRONIC MESSAGES

Customer may use NovakOS to send emails and text messages.

Customer is responsible for complying with applicable electronic-messaging laws.

Where legally required, Customer must have an appropriate basis for sending the communication and satisfy applicable:

* sender-identification; * contact-information; * unsubscribe; * consent requirements.

---

33. UNSUBSCRIBE AND SUPPRESSION RECORDS

NovakOS may maintain:

* email suppression lists; * SMS suppression lists; * STOP requests; * complaints; * hard-bounce information; * unsubscribe records.

These records may be retained after other information is deleted where reasonably necessary to ensure the individual is not accidentally contacted again.

---

34. SERVICE PROVIDERS

NovakOS uses service providers to operate the Services.

Depending on the functionality used, these may include:

**Supabase** — authentication, databases, application infrastructure, and file storage.

**Cloudflare and related infrastructure providers** — network, hosting, security, application delivery, or edge functionality where configured.

**Stripe** — NovakOS Subscription billing and Stripe Connect payment functionality.

**Twilio** — SMS, messaging infrastructure, telephone numbers, and related communications functionality.

**Resend** — transactional and branded email delivery.

**Google Maps Platform** — mapping, places, addresses, geocoding, routing, and related geographic functionality.

**Google identity services** — Google authentication where selected.

**Firebase Cloud Messaging** — supported push-notification delivery.

**Apple Push Notification Service** — supported Apple push-notification delivery.

**Apple** — application distribution and operating-system functionality.

**Google Play / Google** — Android application distribution and platform functionality.

**Lovable platform services** — hosting, connector, authentication, integration, or gateway infrastructure used by current NovakOS deployments where applicable.

Other providers may be added as NovakOS evolves.

---

35. SUBPROCESSOR CHANGES

NovakOS may change service providers as reasonably necessary.

Where a change materially affects processing of Customer personal information, NovakOS will update relevant disclosures and provide any notice required by applicable law or contractual commitment.

---

36. CROSS-BORDER PROCESSING

Some service providers may process personal information outside Canada.

Information stored or processed in another jurisdiction may be subject to the laws of that jurisdiction and lawful access by:

* courts; * law-enforcement agencies; * regulatory bodies; * governmental authorities.

NovakOS will use contractual, technical, or organizational safeguards appropriate to its role and legal obligations.

---

37. NO SALE OF PERSONAL INFORMATION

NovakOS does not sell Customer Data or personal information submitted to NovakOS as a data-broker product.

NovakOS does not acquire ownership of Customer Data by processing it.

---

38. GENERAL-PURPOSE AI TRAINING

NovakOS does not currently use Customer Data to train general-purpose artificial-intelligence models.

If NovakOS proposes to materially change this practice, NovakOS will update this Policy and obtain consent or authorization where required.

---

39. DE-IDENTIFIED INFORMATION

NovakOS may create and use aggregate or de-identified information for:

* security; * service reliability; * analytics; * capacity planning; * product improvement.

NovakOS will not treat information as de-identified where re-identification remains reasonably likely merely because names have been removed.

---

40. SECURITY SAFEGUARDS

NovakOS uses administrative, technical, and organizational security safeguards appropriate to the Services.

Depending on the system, safeguards may include:

* authentication; * authorization; * tenant isolation; * encrypted communications; * provider-managed encryption; * secure credentials; * webhook authentication; * role-based access; * audit logs; * access logging; * security monitoring; * backups; * payment tokenization; * rate limiting; * incident-response processes.

No information system can guarantee absolute security.

---

41. ACCOUNT SECURITY

Customers and Authorized Users share responsibility for security within their control.

Users should:

* use strong credentials; * protect devices; * avoid credential sharing; * promptly report suspicious activity; * sign out of devices they no longer control.

---

42. NOVAKOS SUPPORT ACCESS

NovakOS personnel should access Customer Data only where reasonably necessary for:

* authorized support; * security; * incident response; * troubleshooting; * legal compliance; * other legitimate operations.

Sensitive support access may be audit logged.

---

43. SECURITY AND PRIVACY INCIDENTS

NovakOS maintains procedures for investigating suspected security and privacy incidents.

Where applicable law requires notice to:

* affected individuals; * Customers; * regulators; * other authorities;

NovakOS will take steps required by law.

---

44. RETENTION PRINCIPLES

NovakOS retains personal information only for as long as reasonably necessary for:

* identified purposes; * Customer instructions; * legal requirements; * security; * fraud prevention; * accounting; * tax; * contractual obligations; * legitimate legal claims.

Different categories have different retention periods.

---

45. LOCATION DATA RETENTION

Employee location history is currently designed for an ordinary maximum retention period of approximately **28 days**, subject to a lawful hold or other exceptional requirement.

---

46. COMMUNICATION RECORD RETENTION

Operational message and delivery records may ordinarily be retained for approximately **one year**, depending on the category and applicable configuration.

Suppression, unsubscribe, and consent evidence may be retained longer where reasonably necessary to honour communication preferences and establish compliance.

---

47. AUDIT RECORDS

Security, administrative, and access-related audit records may ordinarily be retained for approximately **two years** or longer where reasonably required for:

* security; * investigation; * compliance; * legal claims.

---

48. FINANCIAL RECORDS

Financial, invoice, payment, refund, dispute, tax, and related records may be retained for approximately **seven years** or another period reasonably necessary to meet accounting, tax, audit, payment, or legal obligations.

---

49. SECURITY INCIDENT RECORDS

Security-incident records may be retained for approximately seven years or longer where reasonably necessary for legal, insurance, investigation, or regulatory purposes.

---

50. CUSTOMER BUSINESS RECORDS

Active records such as:

* customers; * jobs; * equipment; * quotes; * forms; * invoices; * photographs; * videos; * files

may remain while Customer retains them in an active account unless another specific retention rule applies.

---

51. COMPANY DELETION

When an authorized company owner initiates deletion:

1. account access may be revoked or restricted; 2. the company may remain recoverable for approximately 30 days; 3. after the recovery period, active Customer Data is scheduled for deletion subject to legal retention requirements.

Customer should export required information before requesting deletion.

---

52. BACKUP RETENTION

Deletion from active systems may not immediately erase every copy from encrypted backups.

Backup copies may remain until backup expiration or rotation.

Backup copies are not intended for ordinary processing after deletion.

---

53. LEGAL HOLDS

NovakOS may suspend ordinary deletion where information must reasonably be preserved because of:

* litigation; * threatened litigation; * tax audit; * payment dispute; * chargeback; * fraud investigation; * security incident; * regulatory inquiry; * lawful preservation obligation.

---

54. PAYMENT AND TAX RECORDS AFTER DELETION

Certain payment, invoice, refund, dispute, or tax records may remain after Customer Data is otherwise deleted.

Where reasonably possible and appropriate, personal information may be minimized or masked while preserving legally required transaction records.

---

55. CONSENT RECORDS

NovakOS may retain records demonstrating:

* recurring-payment authorization; * saved-payment authorization; * marketing consent; * SMS consent; * unsubscribe; * STOP; * privacy or location acknowledgements.

Such records may remain where reasonably necessary to establish compliance.

---

56. LEGAL ACCEPTANCE RECORDS

NovakOS may retain information showing acceptance of applicable legal documents.

This may include:

* user ID; * company ID; * document name; * document version; * exact acceptance language; * timestamp; * IP address; * user agent; * device/platform; * correlation identifier.

These records may be retained as evidence of contractual history and compliance.

---

57. ACCESS REQUESTS

Subject to applicable law and reasonable identity verification, individuals may request access to personal information for which NovakOS is responsible.

Where the information is controlled by a NovakOS Customer, we may refer the request to that Customer and reasonably assist with the response.

---

58. CORRECTION

Individuals may request correction of inaccurate personal information where applicable.

Where Customer controls the underlying information, Customer may be responsible for determining whether a correction is appropriate.

---

59. DELETION REQUESTS

Individuals may request deletion where applicable law provides that right or where deletion is otherwise available.

Deletion may be limited where retention is reasonably required for:

* legal obligations; * financial records; * fraud prevention; * security; * suppression records; * legal claims; * regulatory requirements.

---

60. WITHDRAWAL OF CONSENT

Where processing depends on consent, an individual may withdraw consent subject to:

* legal restrictions; * reasonable notice; * contractual requirements; * information that must lawfully be retained.

Withdrawal does not invalidate processing that was lawful before the withdrawal.

Certain NovakOS functionality may become unavailable if a required permission or consent is withdrawn.

---

61. LOCATION PERMISSION WITHDRAWAL

A user may change device-location permission through operating-system settings.

Where background location permission is withdrawn, applicable background-tracking functionality may stop operating.

Customer remains responsible for any employment-related consequence or alternative process.

---

62. COMMUNICATION OPT-OUT

Marketing recipients may use applicable unsubscribe or STOP mechanisms.

NovakOS may continue to send communications that are legally permitted or necessary for:

* account security; * requested transactions; * service administration; * contractual obligations;

where an unsubscribe does not legally apply to those communications.

---

63. DATA EXPORT

Authorized Customer personnel may use NovakOS export functionality to retrieve Customer Data in supported formats.

Once downloaded, exported data is controlled and secured by Customer.

---

64. IDENTITY VERIFICATION

NovakOS may verify identity and authority before responding to a sensitive privacy request.

Verification will be proportionate to the sensitivity and risk of the information involved.

---

65. AUTHORIZED REPRESENTATIVES

Where permitted, an individual may make a privacy request through an authorized representative.

NovakOS may require reasonable proof of that authorization.

---

66. PRIVACY COMPLAINTS

Privacy questions or complaints may be submitted to:

**Privacy Officer — NovakOS** [support@novakos.org](mailto:support@novakos.org) 2524 Hastings Road, Chemainus, BC, V0R 1K5

NovakOS will investigate complaints appropriate to NovakOS’s role and respond in accordance with applicable legal obligations.

---

67. REGULATORY RIGHTS

Depending on the circumstances and applicable law, an individual may have the right to complain to the appropriate Canadian or provincial privacy regulator.

Nothing in this Policy is intended to prevent an individual from exercising a legally protected regulatory right.

---

68. CHILDREN AND MINORS

NovakOS is commercial business software and is not marketed directly to children.

Customer accounts must be created by adults with legal capacity to enter into the applicable agreement.

If Customer lawfully employs or otherwise processes information concerning a minor, Customer is responsible for any additional consent, employment, or privacy requirements.

---

69. QUEBEC

Where NovakOS operates in Quebec or processes information subject to Quebec private-sector privacy requirements, NovakOS and Customer remain responsible for their respective obligations under applicable Quebec law.

This may include additional requirements concerning:

* governance; * privacy impact assessment; * incidents; * transparency; * individual rights; * cross-border processing.

---

70. AUTOMATED CALCULATIONS

NovakOS may use automated software rules for:

* billing; * permission enforcement; * payroll-related calculations; * dispatch; * fraud prevention; * payment reconciliation; * security; * notifications.

These automated functions assist users but are not intended to independently make final legal, employment, disciplinary, or professional decisions for Customer.

---

71. EMPLOYMENT DECISIONS

NovakOS does not independently hire, fire, discipline, classify, or compensate Customer’s workers.

Customer remains responsible for employment decisions and reviewing the information on which those decisions are based.

---

72. BUSINESS TRANSACTIONS

If NovakOS undergoes:

* merger; * financing; * acquisition; * restructuring; * sale of assets;

information may be disclosed to appropriate transaction participants subject to confidentiality, security, and applicable privacy requirements.

---

73. LEGAL DISCLOSURES

NovakOS may disclose information where required or permitted by applicable law, including in response to:

* court orders; * warrants; * lawful governmental demands; * regulatory requirements; * legal proceedings.

Where legally permitted and appropriate, NovakOS may notify affected Customers or seek to narrow an overbroad request.

---

74. FRAUD AND SECURITY

NovakOS may use or disclose information where reasonably necessary and legally permitted to:

* identify fraud; * investigate unauthorized access; * secure accounts; * defend legal rights; * protect persons; * prevent abuse.

---

75. CHANGES TO THIS PRIVACY POLICY

NovakOS may update this Privacy Policy as:

* the Services change; * providers change; * laws change; * privacy practices evolve.

The current Policy will display its version and effective date.

Material changes will be communicated through reasonable means.

Where applicable law requires new consent, NovakOS will seek the required consent rather than relying solely on continued use.

---

76. PRIVACY POLICY ACKNOWLEDGEMENT

Where NovakOS asks a user to acknowledge this Policy, acknowledgment means the user confirms that the Policy has been presented for review.

Acknowledgement of this Policy is not intended to create blanket consent for every possible use of personal information.

Separate consent or authorization may be requested for particular activities, including where applicable:

* location; * marketing; * recurring payments; * saved payment methods; * device permissions.

---

77. CUSTOMER PRIVACY RESPONSIBILITIES

A Customer using NovakOS is responsible for its own privacy practices.

Customer should maintain a privacy policy appropriate to Customer’s own business where required.

Customer is responsible for explaining to End Customers and employees how Customer uses information through NovakOS.

---

78. CONTACT US

Privacy questions, complaints, and requests may be directed to:

**Privacy Officer — NovakOS** **Legal Entity:** Michael Novak O/A NovakOS **Email:** [support@novakos.org](mailto:support@novakos.org) **Mail:** 2524 Hastings Road, Chemainus, BC, V0R 1K5 **Telephone:** In the works; telephone support is not yet available.

General support:

[support@novakos.org](mailto:support@novakos.org)

Security reports:

[support@novakos.org](mailto:support@novakos.org)

**END OF PRIVACY POLICY**