Privacy Policy

Last updated: October 10, 2026 · Operlio

1. Who we are

This Privacy Policy describes how Operlio (“Operlio,” “we,” “us,” or “our”) collects, uses, discloses, and protects personal information when you use our websites, progressive web applications, and related field-service software (the “Service”). The Service includes our Android app on Google Play and the mobile web / PWA experience (which is how the Service runs on iPhone; a native iOS app is not published yet).

Operlio is a software platform for field-service companies to schedule jobs, coordinate crews, capture job photos, communicate about work, and invoice customers. The controller of personal information for the Operlio product is Operlio, based in Canada. Support: support@hello.operlio.io; see Section 15.

2. Scope and roles

When a company (“Customer”) creates a workspace, that Customer typically acts as the organization responsible for deciding why personal information about its employees, contractors, and end customers is processed. Operlio processes that information to provide the Service on the Customer’s instructions (as a service provider / processor), and also processes limited account and billing data as an independent controller where needed to operate our business.

If you are an employee or crew member using Operlio through your employer, your employer’s policies also apply. Contact your company administrator for questions about workplace monitoring or job data retention.

3. Information we collect

Depending on how the Service is used, we may process:

  • Account data — name, email, phone, role, password hash, company name, industry, and authentication session identifiers.
  • Workspace / operations data — customers, job schedules, addresses, service types, notes, job chat messages, quality settings, invoices, payment status, team invites, and activity needed to run field work.
  • Job media — before/after and other job photos uploaded by crew or managers as proof of work.
  • Communications metadata — email/SMS delivery status when providers (e.g. Resend, Twilio) are configured, plus message templates and consent flags where recorded.
  • Payment-related data — invoice amounts and Stripe checkout / webhook references. Card numbers are handled by Stripe; Operlio does not store full card PAN data.
  • Technical & security logs — IP address, user agent, timestamps, and audit-log events (login, invite accept, payment actions, exports, etc.).
  • Approximate country— when you visit our website we look up the country your IP address belongs to (country only, never a precise location) so we can show prices in your currency. It’s kept in a small cookie on your device. This site or product includes IP2Location LITE data available from https://lite.ip2location.com.

Device location— every signed-in user is asked once, on first login, for their device’s location. It’s used to center maps and, for crew members, to let their own company’s managers see an approximate live position on the map while the crew member has the app open in the foreground — it never runs once the tab is closed or backgrounded, and only the most recent position is kept, never a location history. Declining or dismissing this prompt never locks anyone out of any feature; the app falls back to the business’s own address or, for crew/managers, an owner’s previously shared location. Location data is only visible inside that company’s own workspace (its own managers/owner) and is never shared outside it or with any third party. Separately, if a Customer turns on the optional geofence arrival feature, the mobile app also checks a signed-in crew member’s device location against that worker’s currently scheduled job to offer starting it automatically on arrival; it stops if location permission is denied.

If you turn on browser push notifications (an opt-in toggle under Settings → Account), we store the browser-issued subscription details needed to deliver them — not your location, and nothing your browser doesn’t already share with any site you allow to notify you. Turning this off, or denying the permission prompt, stops it entirely.

4. How we use information

We use personal information to:

  • Provide, maintain, and improve the Service (scheduling, jobs, photos, invoicing, crew access);
  • Authenticate users, manage sessions, and enforce tenant (company) isolation;
  • Send transactional messages you or your company configure (job updates, invites, invoices);
  • Process payments via Stripe and keep related accounting records;
  • Detect abuse, debug issues, write audit logs, and protect the security of the Service;
  • Comply with law and respond to lawful requests;
  • Communicate product or account notices related to your use of Operlio.

We do not sell personal information. We do not use customer job photos to train third-party advertising models.

5. Legal bases and the laws we follow

If you are in Canada, we handle personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial private-sector laws where they apply. In practice that means:

  • We identify purposes for collection and limit use to those purposes or compatible ones;
  • Consent is obtained by the Customer and/or Operlio as appropriate — for example when creating an account, inviting a teammate, or recording marketing-message consent for end customers;
  • We use safeguards appropriate to the sensitivity of the information;
  • Individuals may request access to, or correction of, their personal information (see Section 10);
  • Cross-border processing may occur when we use infrastructure or subprocessors outside Canada; we remain responsible for the information under our control and require contractual protections from providers.

If you are in the United Kingdom or the European Economic Area, the UK GDPR or GDPR applies. For account, billing, and support information Operlio is the controller, and we rely on performance of our contract with you, our legitimate interests in running, securing, and improving the Service, consent where we ask for it, and legal obligations. For the data a Customer stores about its own customers and staff, the Customer is the controller and Operlio processes it on the Customer’s instructions. Operlio is run from Canada and hosted with providers in the United States. The UK and EU recognise Canada as providing adequate protection for commercial organisations covered by PIPEDA; for transfers to the United States and to our providers we rely on the safeguards they offer, such as standard contractual clauses and the UK International Data Transfer Addendum.

If you are in Australia, we handle personal information in line with the Australian Privacy Principles under the Privacy Act 1988, and if you are in New Zealand, in line with the Privacy Act 2020. Because Operlio is run from Canada and hosted in the United States, information is disclosed to providers in those countries (see Section 6), and we take reasonable steps, including contractual commitments, so they protect it to a comparable standard.

For users in other jurisdictions, we rely on performance of a contract, legitimate interests in operating a secure SaaS product, consent where required, and legal obligations.

6. Sharing and subprocessors

We may share information with:

  • Railway — hosting and database for the Service;
  • Resend — transactional email (invites, invoices, password reset);
  • Twilio — SMS when your workspace sends text messages;
  • Stripe — card payment checkout for customer invoices. Card numbers are handled by Stripe; Operlio does not store full card PAN data;
  • OpenStreetMap / Nominatim — when a job or customer address is placed on the map, that address text is sent to Nominatim to look up coordinates. Nominatim is a free public community geocoding service and is not under a commercial data processing agreement with Operlio;
  • OpenStreetMap — map tile images shown in the job map (no customer records are sent with tile requests beyond the map viewport coordinates);
  • Open-Meteo— the latitude and longitude of the day’s first job, to show a weather forecast on the schedule (no names or addresses);
  • Apple and Google — only if you choose Sign in with Apple or Google: they confirm your identity and share your name and email address with us;
  • Sentry — when error monitoring is turned on, technical details of errors (the page, browser and device type, and the error itself) so we can fix bugs;
  • Your organization — administrators and authorized roles can see workspace data according to permissions;
  • An AI assistant you connect— Settings → Integrations lets a Customer optionally connect an MCP-compatible AI assistant (such as Claude) to their own workspace with an API key they control. That assistant’s provider will then process whatever data the enabled tools expose — job, customer, and revenue information by default, and, only if separately turned on, the ability to create or update jobs. This is off unless a Customer enables it, and can be revoked at any time by deleting the key;
  • Operlio’s own authorized personnel— a small number of platform administrators can access workspace data for support, security, fraud-prevention, or account-recovery purposes (for example, reassigning ownership of a workspace whose owner is unreachable), consistent with Section 8’s audit logging;
  • Professional advisors or authorities when required by law or to protect rights, safety, and security;
  • Successors in a merger, acquisition, or asset sale, subject to continued privacy protections.

Commercial providers such as Railway, Resend, Twilio, and Stripe operate under their standard terms and data processing terms. Nominatim is used without a bilateral contract; do not enter addresses into Operlio that you are not willing to send to a public geocoding service. An AI assistant you choose to connect operates under its own provider’s terms, not Operlio’s — review those before enabling it.

7. Retention

We retain account and workspace data for as long as the Customer’s account is active and as needed to provide the Service. After account closure or a verified deletion request, we delete or anonymize personal information within a reasonable period, except where we must retain records for legal, security, dispute, or accounting reasons (for example payment and audit logs). Job photos and messages are retained according to the Customer’s workspace lifecycle unless a shorter deletion is arranged.

8. Security

We use administrative, technical, and organizational measures designed to protect personal information, including password hashing, session-based authentication, HTTPS encrypted transport, company-scoped data access, and audit logging of sensitive actions. No method of transmission or storage is perfectly secure; see our Security overview for more detail.

9. Cookies and similar technologies

Operlio uses essential cookies or similar storage for authentication sessions and to keep you signed in. We may use limited analytics or operational metrics in the future; if we do, we will update this policy and, where required, provide choices.

10. Your rights

Subject to applicable law, you may request access to, correction of, or deletion of personal information we hold about you, and you may withdraw consent where processing is based on consent (without affecting prior lawful processing). Employees should usually start with their company administrator. You can delete your own account and data yourself, self-service, without needing to contact anyone — see Section 13 for the one exception (a sole owner with an active team still using the workspace).

If you are in Canada, you may contact the Office of the Privacy Commissioner of Canada or your provincial privacy commissioner regarding how your information is handled.

If you are in the UK or EEA you also have the right to restrict or object to processing based on legitimate interests and to receive your data in a portable format, and you may complain to the Information Commissioner’s Office (UK) or your local data protection authority. In Australia you may complain to the Office of the Australian Information Commissioner, and in New Zealand to the Office of the Privacy Commissioner. We aim to answer every request within one month.

11. Children’s privacy

The Service is intended for business use by adults. We do not knowingly collect personal information from children under 16.

12. Changes

We may update this Privacy Policy from time to time. We will post the revised version with an updated “Last updated” date. Material changes may also be communicated through the Service or by email where appropriate.

13. Account deletion

You can delete your Operlio account in the app under Settings → Account → Delete account. Sole owners delete their company workspace and associated job data; other users delete only their login. This is fully self-service — no need to contact anyone to have your data removed — with one safeguard: if you are the sole owner of a workspace where other teammates are still active, deletion is paused until you transfer ownership to one of them (one click, also in Settings). This protects a team’s live data from being erased by a single account’s deletion without anyone else’s knowledge.

To delete your account from any device, including without the phone app:

  • Sign in at app.operlio.io (or open the Operlio app).
  • Go to Settings → Account → Delete account.
  • Confirm with your password (or, if you sign in with Google or Apple, the code we email you). Deletion happens right away.

What is deleted: your login, profile and settings. For a sole owner, also the whole workspace: customers, jobs, quotes, invoices, photos, messages, team locations and history. Any active subscription is canceled.

What is kept:if you were a member of someone else’s team, the jobs you worked on stay in that team’s records with you shown as inactive. Payment records held by our payment processor (Stripe) are kept as tax and accounting law requires. Backup copies are overwritten on their normal rotation.

Can’t sign in? Email support@hello.operlio.io from the address on the account and we will delete it for you.

14. SMS and text messaging

Where a workspace enables SMS and a phone number is provided, we use that number to send job-related text messages (scheduling, reminders, invoices, and similar operational updates) via Twilio, from Operlio’s own numbers: a Canadian number, and a U.S. toll-free number for U.S. recipients. How customers agree to texts and how to stop them is explained on our text messaging page. We record SMS consent and opt-out status — a STOP reply, or a preference set in the app — and honor it going forward across the workspace(s) that number appears in. Phone numbers used for SMS are not sold and are not used for unrelated third-party marketing. See our Terms of Service for the full text-messaging program disclosures, including opt-out instructions.

15. Reaching us

Operlio
Canada

Support: support@hello.operlio.io. Account and data-deletion requests are primarily handled through the self-service tools in the app (see Sections 10 and 13), but reach out here if you need help.