Privacy Policy
Last updated · August 8, 2026
This explains what OpsMove collects, why, who else can see it, and what you can ask us to do about it. It covers both the people who use OpsMove and the people whose details you record in it — your employees and your customers.
1. What we collect
Account information: the name, email, username and role of everyone who can sign in, your company name, and the password hash if you use a password (never the password itself). If you sign in with Google or Microsoft we receive your name, email and a verified identifier from them — never your password.
Business data you enter: clients and their addresses and phone numbers, jobs, employees and their pay rates, trucks, expenses, documents and photos. This is your operational record; you decide what goes in it.
Billing information: your subscription status, plan, seat count and invoice history. Card details go directly to Stripe and are never stored by us or transmitted through our servers.
Activity: every change made in your workspace is recorded with who made it and when, so an owner can audit their own company. This log is visible to your owners and managers, not to other companies.
Technical: server logs with IP address and request information, kept for security and debugging.
2. Why we collect it
To run the service you are paying for, to bill you correctly, to keep your account secure, to answer you when you ask for help, and to comply with tax and accounting law. That is the complete list.
We do not sell your data. We do not rent it. We do not share it with advertisers, and we do not use your business data to train machine-learning models.
3. Your employees and your customers
When you record an employee's pay rate or a customer's address, you are the controller of that information and we process it on your behalf. You are responsible for having the right to hold it and for telling those people what you hold, as Quebec's Law 25 requires.
Crew members and customers who open a link we send them are identified by a single-use token, not an account. Those links expire. Signatures a customer draws on their confirmation page are stored on the work order as part of your record.
4. Who else touches it
We use a small number of service providers, each for one job, none of whom may use your data for their own purposes: Vercel (application hosting, data in transit), Neon (the PostgreSQL database, hosted in Canada or the United States depending on region), Stripe (payments and tax calculation), Resend (transactional email — invitations, reminders, password resets), Vercel Blob (document and photo storage), and Google or Microsoft if you choose to sign in with them.
Some of these providers process data in the United States. Where that happens it is covered by the provider's own contractual safeguards, and we assess it before adding a provider.
We disclose data to authorities only when legally compelled, and we will tell you if that happens unless we are prohibited from doing so.
5. How it is protected
Every company's data is separated at the database level, not by application logic — the database itself refuses a query that reaches across companies. Traffic is encrypted in transit. Passwords are hashed, never recoverable. Access to production data by us is limited to what is needed to operate and support the service, and support access is logged.
When you remove a user, their access ends immediately. Sessions are re-checked against your user list continuously rather than trusting a token until it expires.
6. How long we keep it
Your business data is kept while your account is active, and for 60 days after cancellation so you can retrieve it. The activity log keeps its full detail for 30 days and the audit line indefinitely. Billing records are kept as long as tax law requires, currently six years in Canada.
You can ask us to delete your workspace sooner than the 60 days and we will.
7. Your rights
Under Quebec's Law 25 and Canada's PIPEDA you can ask for a copy of the personal information we hold about you, ask us to correct it, ask us to delete it, and withdraw consent where consent is what we rely on. Write to info@opsmove.com; we answer within 30 days.
Much of this you can do yourself without asking: you can export every table from inside the app, and correct or remove records directly.
If you are unhappy with how we have handled a request, you can complain to the Commission d'accès à l'information du Québec or the Office of the Privacy Commissioner of Canada.
8. Cookies
app.opsmove.com sets a session cookie so you stay signed in and remembers your language and theme choice. That is all — there is no advertising or cross-site tracking anywhere in OpsMove, and this marketing site sets no tracking cookies either.
9. Children
OpsMove is business software and is not intended for anyone under 16. We do not knowingly collect information from children.
10. Changes
If we change this policy in a way that materially affects you, we will email the address on your account at least 30 days before it takes effect. The date at the top always reflects the current version.
Privacy questions, or a request about your own information: info@opsmove.com. A person reads it.
info@opsmove.com