ISS Privacy Policy
Effective date: August 15, 2026
ISS ("we", "us") is a business-management platform. This policy explains, in plain language, what data we collect, how we use it, who else touches it, how long we keep it, and how you can get it deleted. It applies to the ISS application, the customer and vendor portals, and this marketing website, including the demo-request form.
1. Who is responsible for your data
For the marketing site, demo requests, and your ISS account/subscription, ISS is the data controller. For the business records your organization stores inside ISS (customers, employees, documents, recordings, camera footage, and so on), your organization is the controller and ISS is a processor acting on its instructions. Questions about how your employer or a business you deal with uses ISS should go to that organization first; questions about ISS itself come to us: francisscraven@gmail.com.
2. What we collect
- Account data — name, email, phone, role, login credentials (passwords are stored only as salted hashes), and two-factor settings.
- Business records your organization enters — customers, quotes, invoices, work orders, payroll and HR records, and every other module's contents.
- Files — documents, photos, receipts, and attachments you upload.
- Communications — email accounts your organization connects, chat messages inside ISS, and (where your organization enables calling) call recordings and transcripts.
- Location data — only where your organization enables employee field tracking, and only for employees who are individually enrolled; and address/geocoding lookups for mapping and routing features.
- Camera and vehicle data — where your organization operates the CCTV or vehicle-access modules: video, snapshots, and license-plate reads, governed by the retention settings your organization configures.
- Demo requests — company name, contact name, email, phone, industry, company size, and anything you write in the details box. Used only to respond to your request.
- Operational data — authentication and audit logs, security logs, and error reports (sent to our self-hosted error tracker, not a third-party analytics service). We run no third-party analytics, ad pixels, or tracking cookies; the only cookies/tokens we use are the ones that keep you signed in.
3. How we use it — and how we never will
We use your data to operate the service: authenticate you, run the features your organization has enabled, send the transactional emails those features generate, bill your subscription, keep the platform secure, and fix bugs. That's it.
4. AI features
ISS uses AI, and we want to be direct about how. Certain features send relevant excerpts of your data to an AI model to produce a result — for example: the Company Brain assistant, document and receipt OCR, semantic search, equipment-manual Q&A for field technicians, quote/bid drafting suggestions, call-note summaries, training-quiz drafting and grading, and CCTV incident narratives.
- Providers. Text and vision features use Anthropic's Claude API; search embeddings use Voyage AI. Under those providers' API terms, data submitted via the API is not used to train their models.
- Control. Every AI feature is individually toggleable per company, and AI use is gated behind a dedicated permission your administrator assigns. Organizations can also supply their own API keys.
- No silent scope creep. AI features only see the data needed for the specific request; nothing is streamed wholesale to a model in the background.
5. Third-party service providers
We use a small set of specialized providers to run parts of the service. Each receives only what its function requires. Several are optional integrations that touch nothing unless your organization connects them.
| Provider | Purpose | What it processes |
|---|---|---|
| Stripe | Subscription billing and payments | Billing contact, payment card (held by Stripe, never by ISS) |
| Anthropic | AI features (Claude API) | Excerpts sent per AI request |
| Voyage AI | Search embeddings | Text being indexed for search |
| Mapbox / OpenStreetMap (Nominatim) | Geocoding, routing, map tiles | Addresses; coordinates for enabled tracking features |
| Twilio | Voice calling and SMS | Phone numbers, call audio/metadata |
| Deepgram | Call transcription | Call recordings (where calling is enabled) |
| Google / Microsoft | Optional email & calendar sync your organization connects | Mailbox and calendar contents of connected accounts |
| Intuit QuickBooks | Optional accounting sync | Accounting records your organization syncs |
| Avalara / TaxBandits | Tax rate data; 1099 e-filing | Tax filing data where used |
| FedEx | Freight rating/tracking | Shipment addresses and details |
| Firebase Cloud Messaging | Push notifications | Device push tokens |
| S3-compatible object storage | File and recording storage | Stored files (encrypted in transit) |
| Collabora Online | In-app document editing | Documents while being edited |
| BigBlueButton | Video classes/meetings | Audio/video of sessions your organization runs |
| Amazon | Affiliate links in the optional storefront catalog | Nothing until you click an outbound Amazon link |
| DigiCert (timestamp authority) | E-signature timestamps | Document hashes only, never contents |
| Have I Been Pwned | Password-breach check in the vault | A partial password hash (k-anonymity: the password itself never leaves your device) |
Error tracking runs on our own self-hosted instance; no error data goes to a SaaS vendor.
6. Deletion — it means deletion
- Files. When a document or attachment is deleted in ISS, the stored file contents — including all prior versions — are removed from storage. A nightly job additionally sweeps for and removes any residual file contents belonging to deleted records.
- Accounts. When your organization closes its ISS account, its subscription is cancelled so no further billing occurs, and its data becomes inaccessible to the service.
- Requests. You may request access to, correction of, a copy of, or deletion of your personal data at any time by emailing francisscraven@gmail.com. If your data is inside another organization's ISS tenant, we will coordinate with that organization, as the law requires of a processor. We respond within 30 days.
- Retention. We keep data only as long as needed to provide the service, meet legal obligations (e.g., tax and payroll records), or resolve disputes. Camera/vehicle data follows the retention window your organization configures.
7. Subscriptions, auto-renewal, and cancellation
- Paid ISS subscriptions renew automatically at the interval you chose (monthly or annually) until cancelled.
- You will be reminded before you are charged. We email your organization's administrators before each renewal, stating the plan, the amount, the billing frequency, and how to cancel.
- Cancelling is self-serve and immediate: Billing » "Cancel subscription" inside ISS — one confirmation, no phone call, no support ticket. Access continues to the end of the period already paid for, and nothing is charged after that.
- Trials that convert to paid plans trigger a reminder email before the first charge.
- Full subscription terms are in the Terms of Service.
8. Security
Data is encrypted in transit (TLS). Access inside ISS is governed by role-based permissions your organization controls, with audit logging, optional two-factor authentication, and per-feature kill switches for sensitive modules. Passwords are stored as salted hashes; connected-service credentials are stored encrypted. If a breach affecting your personal data ever occurs, we will notify affected organizations without undue delay and as required by law.
9. Employee monitoring features — a note to employees
Some ISS modules (field GPS tracking, CCTV, vehicle/license-plate recognition, call recording) can process data about employees and visitors. These are operated by, and under the responsibility of, the organization that deploys them. ISS builds them with per-employee enrollment, configurable retention, and access controls — but whether and how they are used, and the legal basis for using them, is your organization's decision and obligation under local law.
10. Your privacy rights
Depending on where you live (including under U.S. state privacy laws and the GDPR where applicable), you may have rights to access, correct, export, delete, or restrict the processing of your personal data, and to not be discriminated against for exercising them. We honor these requests regardless of whether a particular statute technically applies to us. We do not sell or share personal data as those terms are defined in the California Consumer Privacy Act, so there is nothing to opt out of.
11. Children
ISS is a business tool and is not directed at children under 16. We do not knowingly collect their data.
12. Changes to this policy
If we change this policy in a way that matters, we will post the new version here with a new effective date and notify administrators of active accounts by email. We will never weaken the "how we never will" commitments in section 3 retroactively for data already collected.
13. Contact
Privacy questions, requests, or complaints: francisscraven@gmail.com.