Privacy Policy

Last updated: August 4, 2026

1. Who we are

PowerOps (“we,” “us,” or “our”) operates the generator service operating system available at powerops.io. This privacy policy explains how we collect, use, share, and protect information when you use our website, hosted web application, Home Screen PWA, or, where your company has provisioned it, the PowerOps technician app for iPhone and iPad. The iOS app displays the hosted PowerOps service in a secure web view and adds only the native capabilities described below.

2. Information we collect

Account information: name, email, phone number, company name, billing address, and payment information (processed and stored by Stripe — we never see your full card number).

Operational data: customers, sites, equipment records, work orders, invoices, quotes, photos, signatures, and service history that you enter or upload.

Device and app data: device/browser type, app version, IP address, authentication and session identifiers, notification permission and registration status, and diagnostics that are actually enabled for security, reliability, and support.

Native permissions: the iOS app may ask for camera access when you capture job evidence, use the system photo picker when you choose evidence, and ask for notification permission when dispatch alerts are enabled. Permission is requested at the point of use, not at launch.

Location and directions: PowerOps does not currently request or collect the device's live location merely to open directions. When you tap Directions, the job-site address is sent to Google Maps in an external browser or maps application so it can show that destination. Google processes that request under its own privacy terms. If a future feature collects live device location, this policy and the in-app disclosure must be updated before that feature is enabled.

3. How we use information

  • Provide and operate the PowerOps platform
  • Process payments via Stripe
  • Send transactional emails and SMS (appointment reminders, invoices, dispatch updates)
  • Respond to support requests
  • Detect and prevent fraud or abuse
  • Register devices for dispatch notifications and, when notification delivery is configured and you opt in, deliver those alerts
  • Improve our services through aggregated analytics
  • Comply with legal obligations (compliance records, tax law, court orders)

4. Outbound calls and SMS (TCPA & A2P 10DLC)

PowerOps may place outbound phone calls and send SMS messages on behalf of a generator service company to contacts that company supplies. The company using those tools is responsible for obtaining any required consent, honoring suppression requests, and configuring its campaigns for the laws and carrier rules that apply to it. PowerOps provides consent, opt-out, and registration controls intended to support that process; those controls do not establish legal compliance by themselves.

Recipients can use supported methods such as replying STOP to an SMS or using an email unsubscribe link. Senders must classify transactional and marketing messages correctly and honor every opt-out required by applicable law and carrier policy.

AI voice agents used in outreach will identify themselves as an AI assistant on request and will end the call and record a suppression request if the recipient says "do not call."

5. How we share information

We disclose information to the following categories of recipients for the purposes described:

  • Subprocessors strictly necessary to operate the service: Supabase (database/auth), Vercel (hosting), Stripe (payments), Anthropic (AI), Resend (email), Twilio (SMS), GoHighLevel (voice AI), Intuit (QuickBooks sync if enabled), and Apple (App Store distribution and APNs notification delivery when enabled).
  • Directions provider: Google Maps receives the job-site address when a user chooses Directions. PowerOps does not send the device's live location in that request.
  • Public-website advertising measurement: Google Ads and OpenAI advertising measurement may receive public-page interaction, browser/device, network, referrer, cookie, or similar attribution data when their website tags are enabled. Those advertising tags are excluded from the authenticated iOS container.
  • Public-website analytics: Google Analytics may receive public marketing page views and manually submitted conversion events when a dedicated PowerOps web stream is configured. Google Analytics is not loaded on authenticated product routes or in the authenticated iOS container.
  • Product analytics: PostHog receives limited page-view and manually submitted event data when it is configured for the web service. Automatic interaction capture and session recording are disabled, and PostHog is excluded from the authenticated iOS container.
  • Your own customers through the Customer Portal (if you enable it) — limited to equipment they own, invoices addressed to them, and compliance reports for their facilities.
  • Law enforcement when legally compelled, after meaningful review.

We never sell customer data or contact lists.

6. Data retention

We retain account and profile data only while needed to provide and secure PowerOps, resolve a request, or satisfy an approved legal obligation. When an account-deletion request completes, the Auth identity and direct profile details are removed or pseudonymized and eligible preferences, registrations, and personal data are deleted.

A limited set of operational records may need to remain with the customer's workspace: service history, safety/compliance evidence, immutable gate and permission audit events, contractual records, financial and tax records, and records subject to a valid legal hold. A retained record keeps only the minimum actor reference needed for accountability; the deleted person's profile is replaced by an opaque, pseudonymous identifier.

Backups expire through the normal rotation after primary deletion unless a documented legal hold requires otherwise.

7. Security

Our service providers encrypt traffic in transit and protect stored data using their platform controls. Database access is scoped per tenant through Supabase Row Level Security, and inactive profiles resolve to no tenant at that boundary. We follow least-privilege access practices and preserve immutable audit evidence for accountable operational actions.

8. Account deletion

A signed-in user can initiate deletion in the technician app from Me → Delete my account. The app requires recent reauthentication and an exact destructive confirmation, then shows the request status in-app. You may cancel before processing begins. Email or phone support may assist but is not the only way to start deletion.

A workspace Owner must first complete PowerOps' existing ownership-transfer process, including both parties' confirmations and the 24-hour cool-down. Deleting one person's login does not automatically delete the company's workspace or records belonging to that company. Workspace closure and sole-owner requests require a separate authorized business process.

9. Your rights

Depending on where you live, you may have rights to:

  • Access the personal information we hold about you
  • Correct inaccurate information
  • Delete information (subject to legal holds)
  • Port your data to another service
  • Opt out of marketing communications

Use the in-app account-deletion control where applicable, or contact privacy@powerops.io to exercise other rights.

10. Children

PowerOps is a business-to-business product and is not directed at children under 13. We do not knowingly collect personal information from children.

11. Changes to this policy

We will post changes to this policy here and update the “Last updated” date at the top. Material changes will be announced via email to account administrators at least 30 days before taking effect.

12. Contact

PowerOps.io
#1144

78 Folly Road Ste B9

Charleston, SC 29407

United States

Phone: 843-212-0829
Email: privacy@powerops.io
Web: powerops.io