Privacy Policy
Effective date: August 23, 2026
1. Introduction
Biptach is an HVAC field-service management application. This Privacy Policy explains what information we collect, why we collect it, how long we keep it, and how you can delete it. It describes only the features that are currently available in the service.
2. Information We Collect
2.1 Account & authentication data
Account and authentication information — name, email address, account identifier, role, and authentication/session information necessary to operate and secure your account. Authentication credentials are handled by our authentication provider, and Biptach does not have access to your plaintext password.
2.2 Company, member & role data
We collect your company name, country and state, default tax group, and the roles (owner, manager, dispatcher, technician) of the members you add to your company.
2.3 Customer data
We collect customer names, email addresses, phone numbers, addresses, and notes. This is used for customer management, scheduling, job execution, and billing/business records.
2.4 Work orders
We collect work-order data including title, description, status, priority, job type, schedule, line items, notes, photos, and signature.
2.5 Service-location data
We collect the job address and its coordinates. This is used for service-location address autocomplete/geocoding, map display, and technician distance/geofence/location functionality.
2.6 Technician GPS
We collect start and force-start coordinates used to verify that a technician is at the job site. This GPS data is retained for 90 days after the job reaches a terminal state, after which it is automatically deleted.
2.7 Equipment, photos & signatures
We collect equipment details and photos, job photos, and customer signatures to document the work performed, service history, evidence, and sign-off.
2.8 Tax & invoice data
Tax is determined by the owner or manager selecting a Saved Tax Group or creating a one-off Custom Tax. Tax is calculated offline. Mapbox does not determine, suggest, or populate tax.
We record the finalized work order’s financial and invoice snapshot, including line items, subtotals, trip charge, tax rate, tax snapshot, tip, grand total, and credit memo. This snapshot is frozen (locked) once the job is completed. Each completed work order is assigned a standalone invoice number, and Biptach generates a PDF invoice and tracks payment status for that invoice.
2.9 Square payment data
When a customer pays an invoice online, payment is processed through Square, our payment processor. Biptach does not collect or store full card numbers, CVV codes, or other sensitive payment credentials. Card details are entered directly into Square’s secure payment form and handled by Square under its own privacy and security practices.
Biptach receives and stores the payment status and, where applicable, the payment amount and the date and time the payment was received, so that the invoice reflects the correct paid or unpaid status. Payment processing is subject to Square’s terms and privacy policy.
2.10 Public invoice link
When a work order is completed, Biptach generates a public, unauthenticated invoice link that is shared with the customer so they can view and pay their invoice. This link is accessible to anyone who has it and does not require a login.
Because the link is unauthenticated, anyone in possession of it can view the customer’s name, contact details, address, job details, and the invoice’s financial information (line items, amounts, and payment status). The link is intended to be shared only with the customer. Please treat it as sensitive and do not forward it to others. If you believe a link has been shared inappropriately, contact us so we can assist.
2.11 QuickBooks / Intuit data
Biptach may provide an optional integration with QuickBooks Online. If you choose to connect a QuickBooks Online account, Biptach will request access to the data necessary to provide the integration. Depending on the functionality enabled, this may include information such as customers, items, and invoices for synchronization. The integration is optional and is activated by the account owner. You may disconnect the integration as supported by the integration.
Biptach may also store technical integration information such as the connected QuickBooks company identifier and encrypted authorization credentials needed to maintain the connection.
2.12 Local storage / offline data
We cache data in your browser using localStorage and IndexedDB so the app works offline. This locally cached data is cleared when you log out.
3. How We Use Information
We use the information we collect to provide the service, run jobs, generate the work-order invoice snapshot, issue invoices and process payments, enforce roles and permissions, send notifications, verify job location, and sync to QuickBooks when you connect it.
4. Service Operator and Data Responsibilities
Biptach is operated by its developer and service operator. Biptach provides a software platform through which business customers may collect, organize, manage, and otherwise process information relating to their operations, customers, personnel, work orders, service locations, equipment, and related business activities.
Depending on the nature of the information involved, the purposes for which it is processed, and the requirements of applicable law, Biptach may process certain information on behalf of the business customer that uses the service. In such circumstances, the business customer may remain responsible for determining the purposes for which certain customer and business information is collected, used, disclosed, retained, or otherwise processed.
Biptach may also independently process certain information as necessary to establish and maintain accounts, authenticate users, administer access and permissions, maintain the security and integrity of the service, prevent misuse or unauthorized activity, provide customer support, maintain service functionality, comply with applicable legal obligations, and protect the rights and security of Biptach and its users.
The respective responsibilities of Biptach and the business customer may therefore vary depending on the nature of the information and the processing activity involved. Nothing in this section is intended to establish a legal classification or allocation of responsibilities beyond what is required under applicable law.
For privacy questions, data-related requests, or questions regarding the handling of personal information, contact privacy@biptach.com.
5. Third-Party Services
- Supabase — hosting, authentication, database, file storage, and server functions.
- Square — payment processing for online invoice payments. Card details are entered into Square’s secure payment form and handled by Square under its own privacy and security practices. Biptach does not store full card numbers or CVV codes.
- Mapbox — used for service-location address autocomplete/geocoding, coordinates, map display, and technician distance/geofence/location functionality only. Mapbox does not determine, suggest, populate, or calculate taxes.
- Resend — transactional email, such as invitations and verification codes.
- QuickBooks / Intuit — an optional integration that Biptach may offer. If you choose to connect a QuickBooks Online account, Biptach will request access to the data necessary to provide the integration, which may include customers, items, and invoices for synchronization. The integration is optional and user-initiated. You can disconnect it from Biptach as supported by the integration.
6. How We Store & Protect Data
Data is stored in Supabase with row-level security scoped to your company. Roles control what each member can see and change. QuickBooks tokens are encrypted.
7. Data Retention
- Technician GPS data: 90 days after a job reaches a terminal state.
- Work orders, customers, photos, signatures, and tax/invoice snapshots: until the company is deleted. Tax/invoice financial snapshots are immutable after finalization.
- Invoice payment status and payment records: until the company is deleted. Payment card details are not stored by Biptach and are handled by Square.
- Account data: until the account is deleted.
- QuickBooks connection and synchronization data: handled according to the disconnect and company-deletion behavior described on the Data Deletion page.
- Local/offline data: until you log out or clear your local cache.
- Certain deletion and security audit records, including account-deletion and work-order-deletion records, may be retained after account or company deletion for accountability, security, fraud prevention, legal compliance, or dispute resolution.
- Some operational records, such as notifications and invitations, may be subject to separate lifecycle or expiration rules.
8. Your Rights & Choices
Depending on your location and applicable law, you may have additional privacy rights. Biptach currently provides the following account and data controls:
- Access & correction — you can view and edit your data in the app where supported.
- Logout clearing — logging out clears locally cached data.
- Account deletion — you can delete your account from Settings.
- Company deletion — an owner can delete the company, with a 15-day grace period.
- Member removal — an owner can remove a member from the company where applicable.
Biptach currently does not provide a self-service data export/portability tool, a formal automated data-subject-request workflow, or a dedicated consent-management interface. For any privacy request not supported by in-app functionality, please contact us (see Section 12).
9. Data Deletion
See our Data Deletion page for the exact steps to delete your account, company, or local data, and for what is retained after deletion.
10. Children’s Privacy
The service is not directed at children under 13, and we do not knowingly collect personal information from children.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will post the revised version on this page.
12. Contact / Privacy Requests
For privacy questions or requests, contact us at privacy@biptach.com.