← VAREVO

Privacy Policy

Draft — last updated [date]. This is a first draft, not yet reviewed by a lawyer; do not treat it as final or legally binding until it has been.

1. Who this policy covers

VAREVO is business software: an organization that signs up (“you”) enters data about its own contacts, employees, and customers into the Service. This policy describes how [Company legal name] processes that data as the Service operator. If your organization uses VAREVO to manage its own customers' data, your organization is responsible for its own obligations to those customers under applicable law (e.g. having a lawful basis to store their contact details) — this policy covers our role as the platform, not your organization's.

2. What we collect

Account and organization data: your name, email, and role, and your organization's name.

Data you enter to use the Service: contacts, companies, jobs, quotes, invoices, payments, products, tasks, activities, and any automation rules you configure.

Usage data: standard web server/application logs (timestamps, routes accessed, error events).

3. Where it's hosted

The database (Supabase, PostgreSQL) is hosted in Zurich, Switzerland. The application itself (Vercel) runs in the United States. This means data is processed in both Switzerland and the US in the course of operating the Service — relevant if your organization needs to represent this to its own customers under Swiss FADP or EU GDPR.

4. Sub-processors

The following third parties may process data on our behalf:

5. How long we keep data

Deleting a record (a contact, company, job, quote, invoice, or an entire organization) moves it to Trash for 30 days, during which an OWNER or ADMIN can restore it; after 30 days it is permanently deleted and cannot be recovered. We do not currently offer a separate retention or export policy for data that hasn't been deleted — if your organization needs a defined retention schedule for active data, this is not yet built; contact us to discuss.

6. Security

Every organization's data is isolated at the database level (row-level security keyed to organization membership) so one organization cannot query another's data even in the event of an application bug. Traffic to the Service is encrypted in transit. Passwords are handled entirely by Supabase Auth; we never see or store your password in plain text.

7. Cookies

We use a session cookie (Supabase Auth) to keep you signed in, and a cookie to remember your preferred language. Neither is used for advertising or cross-site tracking.

8. Your rights

Depending on your jurisdiction, you may have the right to access, correct, export, or delete your personal data. Account and organization data can be exported or deleted directly from the Service (Settings); for anything else, contact [contact email].

9. Changes to this policy

We may update this policy from time to time; material changes will be reflected by an updated “last updated” date above.

10. Contact

Questions about this policy, or a data access/deletion request: [contact email].