PurVago — Privacy Policy
Effective date: October 18, 2026 for accounts opened before September 18, 2026; on acceptance for accounts opened since · Last updated: September 23, 2026 · Previous versions
This Privacy Policy explains how PurVago LLC, a Florida limited liability company that operates the PurVago platform ("PurVago", "we"), collects, uses, discloses, and protects personal data in connection with the PurVago platform, its websites, and the PurVago app for iPhone and iPad (together, the "Service"). The iOS app shows the same PurVago web application as app.purvago.com, so everything in this Policy applies to it in the same way. The Service is offered to businesses in the United States.
1. Our two roles (important)
PurVago plays two different privacy roles:
- Controller — for personal data we handle for our own purposes: information about the cleaning businesses that subscribe ("Customers"), their Authorized Users' account and login data, billing contacts, website visitors, and support communications.
- Processor — for personal data a Customer uploads or generates about its own clients, properties, and Portal End Users ("Customer Personal Data"). There, the Customer is the controller and we process on its behalf under our Data Processing Addendum (https://app.purvago.com/legal/dpa). If you are a Portal End User or a client of a PurVago Customer and want to exercise privacy rights over that data, please contact that business (the Customer); we will assist them as processor. Portal End Users also use the portal under the Portal Terms of Use (https://app.purvago.com/legal/portal-terms).
2. Personal data we collect, and how
a) Account & business data (controller), which you give us when you sign up or edit your profile: name, business name, email, phone, title, role, address, company details, tax rate/currency settings, authentication identifiers (including your Apple or Google sign-in identifier if you use one), and the date, version, IP address and device type of your acceptance of our terms.
b) Billing & payments (controller): subscription plan, transaction and payout metadata, and platform application-fee records. Card details are entered on our payment processor's (Stripe's) own pages; PurVago never sees or stores full card numbers. We keep the card brand and last four digits so you can recognize the card. Payments from your clients run on the Customer's own connected Stripe account.
c) Customer Personal Data (processor) submitted or generated by the Customer, which may include: client and contact names, emails, phones, additional contacts and an optional birth date; property addresses, map coordinates, square footage, and access details (e.g., gate/alarm/lockbox codes, key location, parking, special instructions); job, estimate, invoice, payment, tip and scheduling records; texts exchanged with clients through the Service; photos, reference images, and photos of checks and receipts; team member records including time-clock and location stamps, pay type and pay rate, emergency contacts, documents (which may include tax forms), e-signatures, and background-screening and drug-screening status returned by Checkr when a Customer orders a screening (the full reports stay with Checkr); and property-walkthrough recordings (video frames and voice notes) plus their AI-generated transcriptions and analysis.
d) Data collected through your device, only when you use the feature (controller for Authorized Users; processor for Customer Personal Data). The app and website ask your device's permission first, and you can say no:
- Precise location — only at the moment a team member taps clock in/out or check in/out at a job, while the app is open. It is stored with that time stamp and its distance to the property. We do not track location in the background. If you decline, clock-in still works and is marked "location off".
- Camera, microphone and photos — only when you choose to take or attach a photo or record a walkthrough. If you dictate into a text box with your keyboard's microphone key, that is your device's own dictation, not PurVago's; only the resulting text is saved.
e) Usage, device & diagnostic data (controller): IP address, device and browser type, pages and features used, timestamps, audit logs of actions taken in a workspace, and offline-sync metadata. When something goes wrong, an error report is sent to our error-monitoring provider (Sentry) with your user ID, email, company ID and role, the page, and your device and browser type; a small sample (about 5%) of sessions also sends performance timings. Error reports may include the last few actions before the error.
f) Cookies & similar technologies: see the Cookie Policy (https://app.purvago.com/legal/cookies).
No tracking, no advertising. The Service contains no advertising and no advertising or product-analytics SDKs, and we do not track you across other companies' apps or websites.
We do not intentionally collect data from children (see Section 10). The only health-related data the Service holds is the drug-screening status described in 2(c), which a Customer receives through its own Checkr account and which is visible only to that Customer's authorized administrators. Voice and video inputs are transcribed to text; we do not create voiceprints, perform speaker identification, or otherwise use them for biometric identification. Sensitive operational data such as property access codes is access-restricted within the Service (field-level and role-based controls) and is your responsibility to have a lawful basis to store.
3. How we use personal data
As controller, we use data to: (a) provide, secure, maintain, and support the Service; (b) authenticate users and enforce role-based access and tenant isolation; (c) process subscriptions, billing, and platform fees; (d) communicate about the Service (service messages, security alerts, and, where permitted, product updates); (e) monitor, debug, prevent, and investigate fraud, abuse, and security incidents; (f) comply with law and enforce our Terms; (g) create de-identified analytics to operate and improve the Service (see Section 8); and (h) provide support, including, where a Customer asks for help or we are investigating a problem or security concern, having authorized PurVago personnel access that Customer's workspace with the same permissions as its administrators. Such access is limited to what the task requires, is restricted to personnel bound by confidentiality, and is recorded in an audit log available to the Customer's administrators.
As processor, we process Customer Personal Data only to provide the Service and per the Customer's documented instructions and the DPA. We do not use data collected for one purpose for an unrelated purpose without asking first.
4. AI features and your permission
Some features use artificial intelligence provided by OpenAI through its API: photo- and video-based estimating, transcription of property-walkthrough voice notes, rewriting walkthrough notes into client-ready wording, and (for PurVago staff only) drafting training-course content.
- We ask first. Before any photo, video frame, recording, transcript or note is sent to OpenAI, the Service asks the signed-in person for permission. Nothing is sent if they say no; they can do the same work by hand. The answer is saved on their login.
- Homeowners who send photos to a cleaning company through a video-estimate link choose with an unticked box whether AI may read them. Without it, no AI runs and the company looks at the photos itself.
- Withdrawing permission. Signed-in users can withdraw (or give) permission at any time under the user menu > Privacy & AI. After withdrawal nothing more is sent, and the Service asks again before any later AI use.
- What OpenAI does with it. OpenAI processes the inputs only to return the result to PurVago, does not use them to train its models, and may keep them for up to 30 days to detect abuse before deleting them.
See the AI Features Disclosure (https://app.purvago.com/legal/ai) for how AI works, its limitations, and responsible-use requirements. You must have the necessary rights and consents (including any voice/video recording consents from the people recorded) before submitting content to AI features.
5. Legal bases
We process personal data we control to perform our contract with Customers and Authorized Users; for our legitimate interests in securing, supporting and improving the Service and preventing fraud; with consent where the law requires it or where we ask for it (such as AI features and device permissions); and to comply with legal obligations such as tax and accounting. For Customer Personal Data processed on a Customer's behalf, the Customer is responsible for the legal basis.
6. How we share personal data
We share personal data only as needed:
- Subprocessors / service providers that help run the Service. Each is bound by a written agreement that requires it to give personal data the same or equal protection as this Policy and our DPA, and to use it only to provide its service to us. The current list, with each provider's purpose, the data it processes and its region, is the Subprocessors list at https://app.purvago.com/legal/subprocessors, which is the single source of truth for the vendors we use. This includes the third-party AI provider described in Section 4.
- Services a Customer chooses to connect (for example QuickBooks, Gusto or Checkr). When a Customer connects one, data moves between PurVago and that service at the Customer's direction, and the service's own terms and privacy policy apply to what it holds.
- Within the Customer's own workspace — data is visible to that Customer's Authorized Users according to the roles the Customer configures. We enforce strict tenant isolation so one Customer cannot access another Customer's data.
- Legal/protection — to comply with law, respond to lawful requests, or protect rights, safety, and security.
- Business transfers — in a merger, acquisition, or asset sale, subject to this Policy, and any successor is bound by the Terms and the DPA with respect to Customer Data.
We do not sell personal data, and we do not "share" it for cross-context behavioral advertising as those terms are defined under CCPA/CPRA.
6A. Text messages (SMS)
Cleaning companies that use PurVago can send their customers service texts through the Service: booking confirmations, appointment reminders, "on my way" notices, invoice links and a request for a review after a visit. These are transactional messages about a service the customer scheduled; they are not marketing. This section describes how the feature is designed to work.
- Consent. Texts are sent only to customers who opted in, either by ticking the (unticked by default) consent box on the company's booking page or by telling the company yes when asked by phone or in person. The opt-in, its date and its source are recorded on the customer record. Consent is not a condition of booking.
- Frequency. The Service is designed to send no more than four messages per scheduled visit. Message frequency varies with how often a customer books.
- Cost. Message and data rates may apply according to the customer's mobile plan.
- Opting out and help. Reply STOP to any message to stop receiving texts, or HELP for help. A customer who replies STOP is marked opted out and receives no further texts from that company through PurVago.
- No sharing of mobile information. No mobile information is shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent are excluded from every other category of sharing described in this Policy, and that information is not shared with any third party. Mobile phone numbers and opt-in records collected for these messages are used only to send the messages described here, and are never sold or rented. Sharing with subcontractors is limited to delivering the message itself: our messaging provider (Twilio) transmits the messages under contract as a subprocessor (https://app.purvago.com/legal/subprocessors) and may not use the numbers for any purpose of its own.
7. Where data is processed
We and our subprocessors process data in the United States, except as noted on the Subprocessors list: support email is stored with Proton in Switzerland; a geocoding fallback operated in the United Kingdom receives property addresses when Google's service is unavailable; and the job map loads its map images from OpenStreetMap's servers in the United Kingdom, which receive the viewer's IP address and the map area shown. The Service is offered to businesses in the United States; we do not offer it to individuals in the European Economic Area or the United Kingdom. Contact privacy@purvago.com with questions about data location.
8. Retention & deletion
We retain personal data for as long as needed to provide the Service and for legitimate business or legal purposes (e.g., billing, tax, audit, and dispute resolution).
- Deleting your own account. Every account holder, including customers who use a company's client portal, can delete their login from inside the app or website (user menu > Delete my account). A team member's or portal customer's deletion removes their login and profile; the employer's or cleaning company's own records about them stay with that business.
- When the only owner deletes their account, the whole company workspace is deleted immediately and permanently: every record, every uploaded file, and every other user's access to it. The subscription is cancelled at the same time. There is no export window, so export anything you need first. A single audit entry recording that the account and company were deleted, with the owner's email, is kept for our records. If you signed in with Apple, we also revoke PurVago's access to your Apple sign-in (for Apple sign-ins from September 23, 2026 onward; an earlier one can be removed under Sign in with Apple in your Apple Account settings).
- When a subscription ends any other way, Customer Data remains available for export for 30 days and is then deleted or returned as described in Section 10 of the DPA, except where longer retention is required by law.
- Other deletion. Customers control much of their data lifecycle within the Service; deleting a client through the Service removes that client's associated records from that Customer's workspace. You can also ask us to delete data we control by emailing privacy@purvago.com.
- Copies elsewhere. Routine database backups kept by our hosting provider roll off on its backup schedule. Error reports are kept by Sentry for up to 90 days. Inputs sent to OpenAI are kept by OpenAI for up to 30 days (Section 4).
- De-identified data may be retained: we will not attempt to re-identify such data, will maintain it in de-identified form, and will contractually obligate any recipient to the same.
9. Security
We use administrative, technical, and organizational measures designed to protect personal data, including role-based access control, database row-level security enforcing tenant isolation, field-level restrictions on sensitive fields (e.g., access codes and secrets), encryption of data at rest and in transit, authenticated APIs, and audit logging (including a log entry, visible to the Customer's administrators, whenever PurVago personnel access a Customer's workspace for support). Uploaded files are stored at long, random web addresses that cannot be guessed; anyone who is given a file's address can open it, so share file links only with people who should see them. No method of transmission or storage is 100% secure; we cannot guarantee absolute security. Report concerns to security@purvago.com.
10. Children
The Service is for businesses and is not directed to children under 16, and we do not knowingly collect their personal data. If you believe a child's data has been provided, contact privacy@purvago.com and we will take appropriate action.
11. Your rights and choices
Depending on your location, you may have rights to access, correct, delete, port, restrict, or object to processing of your personal data, to withdraw consent, and to lodge a complaint with a regulator.
- Withdrawing consent: AI permission under user menu > Privacy & AI; device permissions (location, camera, microphone) in your device's settings; text messages by replying STOP.
- Deleting your data: user menu > Delete my account, or email privacy@purvago.com.
- California (CCPA/CPRA): you may request to know, delete, and correct personal information, and to opt out of sale/sharing (we do not sell or share as defined). We will not discriminate for exercising rights.
- Other U.S. states: similar rights may apply under your state's privacy law.
- EEA/UK: we do not have an EU or UK establishment and do not offer the Service to data subjects in the EEA or UK, so no Article 27 representative is appointed.
To exercise rights over data we control, contact privacy@purvago.com; we will verify your request. For Customer Personal Data, contact the relevant Customer (controller); we will assist them. Authorized agents may submit requests where the law allows.
12. Third-party links & services
The Service may link to or integrate third-party services with their own privacy practices. We are not responsible for them; review their policies.
13. Changes to this Policy
We may update this Policy. The "Last updated" date reflects the latest version, and for a material change we will email Customers' admin addresses at least 30 days before the change takes effect; the updated Policy is also shown in the app. Prior versions are published at https://app.purvago.com/legal/archive.
14. Contact
Privacy: privacy@purvago.com · Security: security@purvago.com · Support: support@purvago.com · Mail: PurVago LLC, 5964 King George Parkway, Pace, FL 32571 · https://purvago.com