← Back to ISS

ISS Privacy Policy

Effective date: August 15, 2026

ISS ("we", "us") is a business-management platform. This policy explains, in plain language, what data we collect, how we use it, who else touches it, how long we keep it, and how you can get it deleted. It applies to the ISS application, the customer and vendor portals, and this marketing website, including the demo-request form.

The short version. We collect the data you and your organization put into ISS, plus the operational data needed to run it. That data is confidential: we do not sell it, do not rent it, do not use it for advertising, do not profile you for anyone else's benefit, and do not use it for any purpose beyond operating, securing, and improving the service you signed up for. Some features use AI, and some features rely on third-party service providers — both are listed below. When you delete a file, the file's contents are actually removed from our storage, not just hidden.

1. Who is responsible for your data

For the marketing site, demo requests, and your ISS account/subscription, ISS is the data controller. For the business records your organization stores inside ISS (customers, employees, documents, recordings, camera footage, and so on), your organization is the controller and ISS is a processor acting on its instructions. Questions about how your employer or a business you deal with uses ISS should go to that organization first; questions about ISS itself come to us: francisscraven@gmail.com.

2. What we collect

3. How we use it — and how we never will

We use your data to operate the service: authenticate you, run the features your organization has enabled, send the transactional emails those features generate, bill your subscription, keep the platform secure, and fix bugs. That's it.

We will not: sell or rent your data; use it for advertising or marketing to third parties; disclose it except to the service providers listed below, at your organization's direction, or where the law genuinely requires it; use it to manipulate, profile, or act against the interests of the people it describes; or train our own or anyone else's AI models on your data.

4. AI features

ISS uses AI, and we want to be direct about how. Certain features send relevant excerpts of your data to an AI model to produce a result — for example: the Company Brain assistant, document and receipt OCR, semantic search, equipment-manual Q&A for field technicians, quote/bid drafting suggestions, call-note summaries, training-quiz drafting and grading, and CCTV incident narratives.

5. Third-party service providers

We use a small set of specialized providers to run parts of the service. Each receives only what its function requires. Several are optional integrations that touch nothing unless your organization connects them.

ProviderPurposeWhat it processes
StripeSubscription billing and paymentsBilling contact, payment card (held by Stripe, never by ISS)
AnthropicAI features (Claude API)Excerpts sent per AI request
Voyage AISearch embeddingsText being indexed for search
Mapbox / OpenStreetMap (Nominatim)Geocoding, routing, map tilesAddresses; coordinates for enabled tracking features
TwilioVoice calling and SMSPhone numbers, call audio/metadata
DeepgramCall transcriptionCall recordings (where calling is enabled)
Google / MicrosoftOptional email & calendar sync your organization connectsMailbox and calendar contents of connected accounts
Intuit QuickBooksOptional accounting syncAccounting records your organization syncs
Avalara / TaxBanditsTax rate data; 1099 e-filingTax filing data where used
FedExFreight rating/trackingShipment addresses and details
Firebase Cloud MessagingPush notificationsDevice push tokens
S3-compatible object storageFile and recording storageStored files (encrypted in transit)
Collabora OnlineIn-app document editingDocuments while being edited
BigBlueButtonVideo classes/meetingsAudio/video of sessions your organization runs
AmazonAffiliate links in the optional storefront catalogNothing until you click an outbound Amazon link
DigiCert (timestamp authority)E-signature timestampsDocument hashes only, never contents
Have I Been PwnedPassword-breach check in the vaultA partial password hash (k-anonymity: the password itself never leaves your device)

Error tracking runs on our own self-hosted instance; no error data goes to a SaaS vendor.

6. Deletion — it means deletion

7. Subscriptions, auto-renewal, and cancellation

8. Security

Data is encrypted in transit (TLS). Access inside ISS is governed by role-based permissions your organization controls, with audit logging, optional two-factor authentication, and per-feature kill switches for sensitive modules. Passwords are stored as salted hashes; connected-service credentials are stored encrypted. If a breach affecting your personal data ever occurs, we will notify affected organizations without undue delay and as required by law.

9. Employee monitoring features — a note to employees

Some ISS modules (field GPS tracking, CCTV, vehicle/license-plate recognition, call recording) can process data about employees and visitors. These are operated by, and under the responsibility of, the organization that deploys them. ISS builds them with per-employee enrollment, configurable retention, and access controls — but whether and how they are used, and the legal basis for using them, is your organization's decision and obligation under local law.

10. Your privacy rights

Depending on where you live (including under U.S. state privacy laws and the GDPR where applicable), you may have rights to access, correct, export, delete, or restrict the processing of your personal data, and to not be discriminated against for exercising them. We honor these requests regardless of whether a particular statute technically applies to us. We do not sell or share personal data as those terms are defined in the California Consumer Privacy Act, so there is nothing to opt out of.

11. Children

ISS is a business tool and is not directed at children under 16. We do not knowingly collect their data.

12. Changes to this policy

If we change this policy in a way that matters, we will post the new version here with a new effective date and notify administrators of active accounts by email. We will never weaken the "how we never will" commitments in section 3 retroactively for data already collected.

13. Contact

Privacy questions, requests, or complaints: francisscraven@gmail.com.