Information we collect
We collect information that is reasonably needed to provide and document our business technology services, operate the portal, communicate with customers, and protect our systems.
- Business and contact information: company names, names, email addresses, telephone numbers, service addresses, billing addresses, and authorized customer contacts.
- Account and security information: login identifiers, account status, permissions, multi-factor authentication status, session information, authentication events, IP addresses, browser or device information, and security audit records.
- Service information: requests, work orders, service locations, equipment and asset details, problem descriptions, assignments, schedules, time entries, photographs, attachments, public customer notes, private internal notes, status history, and completion records.
- Billing information: service value, billing disposition, contract-covered or courtesy value, amounts due, service statements, invoice references, payment status, returns, credits, and delivery history. Revv Tech does not store raw payment-card or bank-account information in the portal.
- QuickBooks information: when an authorized administrator connects QuickBooks, the connected company identifier, approved customer and item mappings, sanitized reference information, invoice identifiers, balances, accounting Payment links, synchronization status, webhook metadata, reconciliation results, and correction history.
- Communications: website inquiries, support requests, service-statement and invoice-delivery status, reminders, and related delivery history.
Please do not place passwords, private encryption keys, patient information, payment-card numbers, or other unnecessary sensitive information in work-order notes, attachments, or support messages.
How we use information
- Provide contracted technology, support, installation, maintenance, billing, and customer-portal services.
- Create, manage, schedule, complete, and document work orders and service history.
- Provide invoices and service statements, including statements showing contract-covered, courtesy, promotional, or no-charge work.
- Prepare and synchronize authorized accounting records with QuickBooks.
- Send operational and transactional communications.
- Authenticate users, enforce permissions and multi-factor authentication, prevent misuse, maintain audit evidence, and investigate problems.
- Maintain, test, back up, restore, and improve our systems.
- Meet contractual, accounting, tax, legal, security, and recordkeeping obligations.
We do not sell customer or portal information, and we do not use portal information for third-party targeted advertising.
QuickBooks integration
QuickBooks access is optional and must be authorized by an approved Revv Tech administrator. OAuth access and refresh tokens are stored in a protected server-side secrets vault and are not returned to portal users' browsers.
Disconnecting QuickBooks stops future authorized access and retires the portal's stored tokens. Disconnecting does not delete records already created in QuickBooks and does not automatically erase portal audit history, approved mappings, invoice references, reconciliation history, or records that Revv Tech must retain. QuickBooks remains authoritative for accounting records stored there.
When we share information
We share information only as needed to operate the services, comply with law, complete an authorized business transaction, or protect customers, Revv Tech, and our systems. Service providers currently include:
- Supabase for database, authentication, file storage, and protected secrets storage.
- Vercel for portal hosting, network delivery, and runtime logging.
- Cloudflare for the public website and network delivery.
- Intuit QuickBooks for authorized accounting integration.
- Resend for transactional email delivery.
- Source-control, monitoring, and encrypted cloud-backup providers used for secure operations, testing, disaster recovery, and maintenance.
Application processing currently uses infrastructure in the United States and managed data services in Canada. Providers process information according to their agreements and applicable privacy and security obligations.
We may also disclose information when required by law, to investigate fraud or a security incident, to protect rights or safety, or as part of a merger, financing, acquisition, or transfer of business assets subject to appropriate protections.
Retention, access, and deletion
We retain information for as long as reasonably needed to provide services and satisfy contractual, accounting, tax, legal, security, backup, dispute-resolution, and audit requirements. Some service, billing, correction, delivery, and security history is intentionally maintained as an audit record and may not be editable or immediately deletable.
Backups are retained and retired according to our backup and recovery procedures. Removing information from an active system may not remove it immediately from isolated encrypted backup copies, which expire through the normal backup lifecycle.
Requests to access, correct, export, or delete eligible information may be sent to the contact below. We may verify the requester's identity and authority. Information may be retained when required by law, a customer agreement, accounting obligations, security needs, or the rights of another person.
Security and customer responsibilities
We use administrative, technical, and organizational safeguards appropriate to the information we process. These include encrypted network connections, restricted server-side secrets storage, role-based access, database row-level security, multi-factor authentication for sensitive staff operations, audit logging, environment separation, tested backups, and controlled deployment practices.
No system can guarantee absolute security. Users are responsible for protecting their credentials, using multi-factor authentication when required, maintaining accurate authorized contacts, and promptly reporting suspected unauthorized access. Customers must ensure they are authorized to provide information about their employees, contacts, locations, equipment, and operations.
Website use and children
Our website and portal may use cookies and similar browser storage that are necessary for authentication, security, and normal site operation. The services are designed for business use and are not directed to children under 13. We do not knowingly collect personal information from children through the portal.
Changes to this policy
We may update this policy as our services, vendors, or legal obligations change. We will post the revised policy with a new effective date and provide additional notice when a material change warrants it.
Contact us
Questions and privacy requests may be directed to:
Revv Technology Services, LLC307 E Bedford Dr
Erda, UT 84074
support@revvtechservices.com
(801) 880-9008