Legal

Privacy Policy

Effective August 20, 2026 · IS-Opts.ai, operated by IS Companies

IS-Opts.ai holds the operating records of the businesses that use it — jobs, purchases, invoices, schedules, and the people who do the work. This policy explains what we collect, why we collect it, who it is shared with, and how long we keep it.

1.Who this policy covers

IS-Opts.ai is business operations software operated by IS Companies. It is used by our own staff and by companies we work with to run service, construction, purchasing, finance, and workforce operations.

This policy describes what the platform does with information. It applies to the IS-Opts.ai web application, its mobile app, and the connected integrations listed below. It does not cover a third-party service's own handling of your data once you are working inside that service.

2.Information we collect

We collect only what the platform needs to do its job for the businesses that use it.

  • Account informationname, work email address, phone number, role, employer, and the permissions assigned to the account.
  • Authentication datasession tokens, sign-in timestamps, password-reset state, and access tokens issued by connected services when you authorize an integration.
  • Business operating datathe records you and your company put into the platform — jobs, estimates, purchase orders, invoices, inventory, schedules, projects, time entries, documents, photos, and notes.
  • Customer and vendor recordscontact and job details your business maintains about its own customers, vendors, and subcontractors in order to perform the work.
  • Integration datarecords synchronized from systems your company connects, such as field-service management, accounting, telephony, email, and workspace platforms, limited to the scopes granted at authorization.
  • Technical and usage dataIP address, browser and device type, pages and features used, and application error logs, used to keep the platform secure and working.

3.How we use information

We use the information above to:

  • Provide, operate, and maintain the platform and its features.
  • Authenticate users, enforce role and permission boundaries, and keep accounts secure.
  • Synchronize records with the systems your company has explicitly connected.
  • Send operational messages — notifications, approvals, reminders, digests, and service announcements.
  • Produce reporting, dashboards, and analytics for the business that owns the data.
  • Troubleshoot problems, investigate misuse, and improve reliability and performance.
  • Meet legal, tax, accounting, and recordkeeping obligations.

4.What we do not do

  • We do not sell personal information, and we do not share it for cross-context behavioral advertising.
  • We do not use your business operating data to advertise to you or to anyone else.
  • We do not use data pulled from a connected integration for any purpose beyond delivering the feature you connected it for.

5.How information is shared

Access inside the platform is controlled by role and permission: users see the records their role permits, and administrators at your company control those grants.

Outside the platform, we share information only in these situations:

  • Service providershosting, database, email delivery, telephony, error monitoring, and similar vendors that process data on our behalf under contract, limited to what their service requires.
  • Connected systems you authorizewhen your company links an external service, data moves between it and IS-Opts.ai within the scopes that authorization grants. You can revoke that authorization at any time.
  • Legal and safetywhen required by law, subpoena, or regulation, or where necessary to investigate fraud, abuse, or a threat to safety or system integrity.
  • Business transfersin connection with a merger, acquisition, financing, or sale of assets, subject to this policy continuing to apply to the transferred information.

6.Third-party integrations and OAuth

Some features read from or write to an external service on your behalf. Access is granted by an authorized administrator, and we request the narrowest set of permissions the feature needs. Where a service issues OAuth tokens, they are held as server-side secrets and used only to perform the actions that feature performs.

Revoking our access in the third-party service stops the synchronization, and any credential we hold for it becomes unusable. To have a connection removed on our side as well, write to us at the address below.

7.Data retention

Business operating data is retained for as long as the account is active, because it is the operating record of the business — job history, financial records, and project documentation have to remain available.

Sessions carry an expiry and stop granting access once they reach it. When an account is deactivated its access ends immediately, while its historical records stay attributed for audit purposes.

On written request from the business that owns the data, we will delete or return that data, except where we are required to retain it by law.

8.Security

The platform is served over HTTPS with strict transport security. Its internal areas require an authenticated session, and permissions are enforced per application and per workflow, so a user reaches only the areas their role grants.

A small number of surfaces are deliberately open, because the people who need them work in the field and cannot sign in from a job site. We keep that set as small as the work allows and review it as the platform changes.

Passwords in the account database are stored as hashes, never as the password itself, and a signed-in session is stored as a hash of its token rather than the token. Credentials for the services we connect to are stored server-side and are reachable only by the administrators and background jobs that operate those integrations.

Access to production systems is limited to the personnel who administer them. No system is perfectly secure, but we work to keep the platform's protections proportionate to the operating and financial data it holds.

9.Cookies and analytics

We use cookies that the platform needs in order to work: a session cookie that keeps you signed in, and small preference cookies that remember choices such as theme and layout.

We do not use advertising cookies and we do not run third-party ad trackers. Any usage measurement is limited to operational analytics about platform reliability and feature use.

10.Your choices and rights

You can change your password from your account page. Your name, role, and permissions are maintained by your company's administrators, who can adjust or revoke access at any time — ask them to correct a detail that is wrong, or write to us at the address below.

Depending on where you live, you may have the right to request access to, correction of, or deletion of personal information we hold about you, and to object to or restrict certain processing. Where the data belongs to a business using the platform, we will refer the request to that business and support them in responding to it.

To make a request, write to privacy@is-companies.com. We may need to verify your identity before acting.

11.Children's information

IS-Opts.ai is workplace software intended for business use by adults. It is not directed to children, and we do not knowingly collect personal information from anyone under 16.

12.Changes to this policy

We may update this policy as the platform changes. When we do, we revise the effective date at the top of this page, and material changes will be communicated to account administrators.

13.Contact us

Questions about this policy, or about how the platform handles a particular set of records, can be sent to privacy@is-companies.com.

IS Companies · 2833 E Broadway, Phoenix, AZ 85040