Privacy Policy

Last updated: August 7, 2026 · Operlio · Contact: privacy@operlio.io

1. Who we are

This Privacy Policy describes how Operlio (“Operlio,” “we,” “us,” or “our”) collects, uses, discloses, and protects personal information when you use our websites, progressive web applications, native mobile applications (iOS / Android), and related field-service software (the “Service”).

Operlio is a software platform for field-service companies to schedule jobs, coordinate crews, capture job photos, communicate about work, and invoice customers. The controller of personal information for the Operlio product is Operlio. Privacy inquiries: privacy@operlio.io. Support: support@operlio.io.

2. Scope and roles

When a company (“Customer”) creates a workspace, that Customer typically acts as the organization responsible for deciding why personal information about its employees, contractors, and end customers is processed. Operlio processes that information to provide the Service on the Customer’s instructions (as a service provider / processor), and also processes limited account and billing data as an independent controller where needed to operate our business.

If you are an employee or crew member using Operlio through your employer, your employer’s policies also apply. Contact your company administrator for questions about workplace monitoring or job data retention.

3. Information we collect

Depending on how the Service is used, we may process:

  • Account data — name, email, phone, role, password hash, company name, industry, and authentication session identifiers.
  • Workspace / operations data — customers, job schedules, addresses, service types, notes, job chat messages, quality settings, invoices, payment status, team invites, and activity needed to run field work.
  • Job media — before/after and other job photos uploaded by crew or managers as proof of work.
  • Communications metadata — email/SMS delivery status when providers (e.g. Resend, Twilio) are configured, plus message templates and consent flags where recorded.
  • Payment-related data — invoice amounts and Stripe checkout / webhook references. Card numbers are handled by Stripe; Operlio does not store full card PAN data.
  • Technical & security logs — IP address, user agent, timestamps, and audit-log events (login, invite accept, payment actions, exports, etc.).
  • Support correspondence — information you send to privacy@operlio.io or support@operlio.ioor other support channels.

We do not require live GPS tracking of workers as a core product feature. Location fields may exist for job addresses or optional operational context entered by the Customer.

4. How we use information

We use personal information to:

  • Provide, maintain, and improve the Service (scheduling, jobs, photos, invoicing, crew access);
  • Authenticate users, manage sessions, and enforce tenant (company) isolation;
  • Send transactional messages you or your company configure (job updates, invites, invoices);
  • Process payments via Stripe and keep related accounting records;
  • Detect abuse, debug issues, write audit logs, and protect the security of the Service;
  • Comply with law and respond to lawful requests;
  • Communicate product or account notices related to your use of Operlio.

We do not sell personal information. We do not use customer job photos to train third-party advertising models.

5. Legal bases and Canadian PIPEDA

If you are in Canada, we handle personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial private-sector laws where they apply. In practice that means:

  • We identify purposes for collection and limit use to those purposes or compatible ones;
  • Consent is obtained by the Customer and/or Operlio as appropriate — for example when creating an account, inviting a teammate, or recording marketing-message consent for end customers;
  • We use safeguards appropriate to the sensitivity of the information;
  • Individuals may request access to, or correction of, their personal information (see Section 10);
  • Cross-border processing may occur when we use infrastructure or subprocessors outside Canada; we remain responsible for the information under our control and require contractual protections from providers.

For users in other jurisdictions, we rely on performance of a contract, legitimate interests in operating a secure SaaS product, consent where required, and legal obligations.

6. Sharing and subprocessors

We may share information with:

  • Service providers who help us operate Operlio — for example hosting, object or file storage for photos, email (e.g. Resend), SMS (e.g. Twilio), and payments (Stripe) — under contracts that limit their use of the data;
  • Your organization — administrators and authorized roles can see workspace data according to permissions;
  • Professional advisors or authorities when required by law or to protect rights, safety, and security;
  • Successors in a merger, acquisition, or asset sale, subject to continued privacy protections.

7. Retention

We retain account and workspace data for as long as the Customer’s account is active and as needed to provide the Service. After account closure or a verified deletion request, we delete or anonymize personal information within a reasonable period, except where we must retain records for legal, security, dispute, or accounting reasons (for example payment and audit logs). Job photos and messages are retained according to the Customer’s workspace lifecycle unless a shorter deletion is arranged.

8. Security

We use administrative, technical, and organizational measures designed to protect personal information, including password hashing, session-based authentication, HTTPS encrypted transport, company-scoped data access, and audit logging of sensitive actions. No method of transmission or storage is perfectly secure; see our Security overview for more detail.

9. Cookies and similar technologies

Operlio uses essential cookies or similar storage for authentication sessions and to keep you signed in. We may use limited analytics or operational metrics in the future; if we do, we will update this policy and, where required, provide choices.

10. Your rights

Subject to applicable law, you may request access to, correction of, or deletion of personal information we hold about you, and you may withdraw consent where processing is based on consent (without affecting prior lawful processing). Employees should usually start with their company administrator. You may also email privacy@operlio.io. We may need to verify your identity before responding.

If you are in Canada and are not satisfied with our response, you may contact the Office of the Privacy Commissioner of Canada or your provincial privacy commissioner.

11. Children’s privacy

The Service is intended for business use by adults. We do not knowingly collect personal information from children under 16.

12. Changes

We may update this Privacy Policy from time to time. We will post the revised version with an updated “Last updated” date. Material changes may also be communicated through the Service or by email where appropriate.

13. Account deletion

You can delete your Operlio account in the app under Settings → Account → Delete account. Sole owners delete their company workspace and associated job data; other users delete only their login. You may also email privacy@operlio.io to request deletion.

14. Contact

Operlio
Privacy requests: privacy@operlio.io
Support: support@operlio.io