Privacy Policy
How Service Opus handles information across our website, applications, customer portals, mobile workflows, support, and marketing experiences.
Last updated: August 27, 2026
This Privacy Policy ("Policy") describes how Cordelio LLC, doing business as Service Opus ("Service Opus," "we," "us," or "our"), handles personal information when you visit serviceopus.com, contact us, create or administer an account, use our field service management platform or mobile applications, access a customer portal, connect an integration, or otherwise interact with our services (collectively, the "Services").
Customer Data: A business customer decides which records its authorized users enter, which product features it enables, who may access those records, and how it uses resulting information. For that Customer Data, Service Opus generally acts as a processor or service provider on the business customer's instructions. This Policy does not replace the business customer's notices to its employees, contractors, vendors, or customers.
1. Roles and Scope
Service Opus determines the purposes and means of processing for our public website, demo and contact requests, subscription administration, direct support relationship, marketing preferences, fraud prevention, and security records. We also process limited account and system activity information for authentication, service security, abuse prevention, and compliance.
When a business customer uses the Services to manage its employees, technicians, subcontractors, vendors, leads, or end customers, that business customer controls the Customer Data and Service Opus processes it to provide the requested functions. An individual may therefore be an account holder while still being a Customer End User whose business controls most account content.
This Policy covers Service Opus-operated websites, applications, mobile workflows, customer portals, signup and billing flows, support channels, and marketing communications. A website created and controlled by a business customer through Site Builder must provide that business's own privacy notice. Independently operated third-party services and integrations have their own privacy practices.
2. Information We Collect and Process
The information involved depends on how you interact with us and which features a business customer enables.
A. Website, Contact, Subscription, and Account Information
- Identity and contact information: Name, business email, phone number, company, address, job title, landing page and campaign parameters, and information included in contact, demo, signup, support, or forum submissions.
- Account and authentication information: User identifier, username or email, password hash, multi-factor authentication settings, recovery information, roles, permissions, account status, consent versions, and security events.
- Service Opus subscription information: Plan, billing status, transaction history, Stripe customer and payment-method identifiers, card brand, last four digits, and expiration metadata. Card numbers and card security codes entered through Stripe's payment interface are processed by Stripe rather than stored by Service Opus.
- Communications: Messages, support requests, forum content, feedback, notification preferences, and email or SMS delivery and engagement events.
B. Customer Data Processed for Business Customers
- Customer and job records: Customer, lead, vendor, and contact information; addresses and service locations; quotes; jobs; schedules; work orders; invoices; service agreements; equipment; notes; documents; photos; and customer portal activity.
- Workforce and HR records: Employee and contractor profiles, tax identifiers, pay rates, overtime settings, employment dates, time entries, schedules, skills, documents, emergency contacts, leave and benefits information, workplace-safety and OSHA records, and related review evidence.
- Location and field evidence: Customer and job-site coordinates, route information, technician or device location when an enabled workflow collects it, location precision and purpose, clock-in or job photos, timestamps, and acknowledgements.
- Financial and payment records: Invoices, payments, refunds, disputes, accounting records, tax records, bank-reconciliation records, customer payment profiles, ACH authorization evidence, account-holder information, bank and account metadata, and vendor routing or account information used in customer-directed payment workflows.
- Communications and media: Email, SMS, direct messages, notes, uploaded files, images, notification data, and call or audio records when a business customer enables and lawfully uses a recording feature.
- Integration information: External account identifiers, encrypted access or refresh tokens, sync history, and information exchanged with customer-enabled providers such as QuickBooks Online, Xero, Stripe, mapping providers, and communications providers.
C. Device, Usage, Security, and Analytics Information
- Device and network data: IP address, browser and operating-system information, device or installation identifiers, screen and application information, user agent, and approximate location inferred from an IP address.
- Usage and diagnostics: Pages or features used, referring page, timestamps, application events, performance measurements, errors, security signals, and administrative or audit activity.
- Website analytics: Page location, page title, page path, campaign parameters, and interaction events may be sent to the configured analytics provider unless a saved opt-out or supported Global Privacy Control signal is present.
D. Sensitive Personal Information
Depending on customer configuration, Customer Data may include account credentials, financial account information, precise location, tax identifiers, medical or protected-leave documents, workplace injury information, and other information treated as sensitive under applicable law. Service Opus does not use sensitive personal information for advertising or to infer characteristics for Service Opus marketing.
E. Sources
We obtain information directly from you; from the business customer and its authorized users; automatically from browsers, devices, and use of the Services; from customer-enabled integrations and payment, communications, identity, mapping, security, and hosting providers; and from records generated through use of the Services. If you communicate with a Service Opus social-media account, the platform may provide your public profile and message information.
3. How We Use Information
- Provide the Services: Create and administer accounts; operate jobs, schedules, dispatch, communications, documents, HR, accounting, invoicing, payments, reporting, portals, and integrations; and carry out customer instructions.
- Support and communicate: Respond to requests, send administrative and security notices, provide customer-selected email, SMS, or push communications, and manage marketing preferences.
- Process transactions: Administer subscriptions and support customer-directed payment, ACH, accounting, reconciliation, and financial workflows.
- Secure and maintain the Services: Authenticate users, prevent abuse and fraud, investigate incidents, debug errors, monitor availability, preserve audit evidence, and enforce agreements.
- Analyze and improve: Measure product and website performance, understand website activity, improve workflows, and plan capacity.
- Automation and document extraction: Provide customer-selected scoring, scheduling, routing, reconciliation, and recommendation tools. When payable-document extraction is requested, invoice content is sent to Microsoft Azure Document Intelligence to return structured fields for review. Customers remain responsible for reviewing automated output and making business, employment, financial, or legal decisions.
- Legal purposes: Comply with law, respond to lawful requests, establish or defend claims, maintain required business records, and protect people, rights, and property.
SMS disclosures: Service Opus supports customer-directed SMS for operational and marketing workflows. Mobile information and SMS consent records are not sold or disclosed to third parties or affiliates for their own marketing or promotional purposes. Message frequency varies. Message and data rates may apply. Recipients may reply STOP to opt out and HELP for assistance. A business customer remains responsible for the notices, consent, calling times, and message content required for its use.
4. How We Disclose Information
We disclose information only as needed for the purposes described in this Policy:
- Cloud, security, and operations providers: Microsoft Azure for hosting, storage, communications, notifications, document extraction, and Azure Monitor or Application Insights telemetry; Cloudflare for content delivery and security; and an additional configured telemetry provider, such as Grafana Cloud, when enabled.
- Payments and accounting providers: Stripe and customer-enabled accounting or payment integrations, including QuickBooks Online and Xero.
- Google services: Google Fonts on interfaces that request hosted fonts; reCAPTCHA for signup abuse prevention; mapping services for address, location, and route functions; and Google Analytics for restricted public-site measurement unless the browser's saved choice or Global Privacy Control signal disables it.
- Device notification providers: Apple, Google or Firebase, and Azure Notification Hubs when push notifications are enabled.
- Business customers and authorized users: Customer administrators and other users may access Customer Data according to assigned permissions, enabled features, and customer configuration. Sensitive workforce records have additional permission boundaries.
- Customer-selected recipients and integrations: We send records to recipients, portals, providers, or integrations when directed by the business customer or user.
- Professional advisers and transaction participants: Auditors, insurers, advisers, lenders, or prospective transaction parties where reasonably necessary and subject to appropriate confidentiality obligations.
- Legal and safety disclosures: Government authorities or other parties when required by law or reasonably necessary to protect rights, safety, security, and the integrity of the Services.
Providers process information under their applicable agreements or service terms. They may independently control information when you open their site, create an account with them, or use a service outside Service Opus.
Sale, Sharing, and Targeted Advertising
Service Opus does not sell personal information for money or other valuable consideration. We do not use Customer Data for cross-context behavioral advertising. Basic public-site analytics may load by default, but advertising storage, advertising user data, advertising personalization, Google Signals, and advertising-personalization signals are disabled in our site configuration. Because some privacy laws may classify an analytics disclosure of identifiers or internet activity as “sharing” or targeted advertising, visitors can disable analytics at any time using “Your Privacy Choices” in the footer or a supported Global Privacy Control signal.
5. Cookies, Local Storage, and Analytics Choices
6. Security
We use administrative, technical, and organizational safeguards designed to reduce the risk of unauthorized access, loss, misuse, or alteration. Depending on the system and information involved, these safeguards include transport encryption, access controls, password hashing, protected credential storage, tenant and role boundaries, audit logging, monitoring, backups, and incident-response procedures. No service can guarantee absolute security. Please report suspected account or data security issues promptly through our contact information below.
7. Retention
We retain information only for the period reasonably necessary for the purpose collected, customer instructions and configuration, legal and accounting obligations, security, dispute resolution, and enforcement. Current criteria include:
- Account and Customer Data: Generally for the subscription term. The Terms provide a 60-day post-termination export period, after which Customer Data may be deleted or de-identified unless a longer period is required by law, legal hold, customer configuration, or an Agreement.
- Workforce location and clock-photo evidence: The business customer selects a retention period between 1 and 3,650 days for enabled collection, subject to legal holds and applicable recordkeeping rules.
- Audit history: Customer-configurable from 30 to 36,500 days; the default is 365 days, subject to archival, legal-hold, and compliance settings.
- Completed communications webhook processing records: Deleted after 90 days under the current operational rule.
- HR, safety, leave, payroll, tax, accounting, payment, consent, and transaction evidence: Retained under the applicable customer policy, Agreement, statutory recordkeeping period, legal hold, or limitation period.
- Website, contact, support, and security records: Retained while the relationship or request remains active and afterward only as needed for follow-up, consent evidence, security, legal obligations, or claims.
- Backups: Deleted information may remain temporarily in restricted backups until overwritten under the applicable backup lifecycle.
8. International Processing
Service Opus is operated from the United States. We and our providers may process information in the United States and other locations where they operate. Privacy laws may differ in those locations. Customer-specific data-location or transfer requirements must be documented in the applicable Agreement or data-processing addendum. We use transfer measures required by an applicable Agreement and law.
9. Privacy Rights and Requests
Depending on your location, our role, and applicable law, you may have rights to:
- Know or access the personal information we process about you.
- Correct inaccurate personal information.
- Delete personal information, subject to legal and operational exceptions.
- Receive a portable copy of certain information.
- Opt out of sale, sharing, targeted advertising, or qualifying profiling.
- Limit or withdraw consent for certain sensitive-information processing where applicable.
- Appeal a denied request and receive equal service without unlawful discrimination or retaliation for exercising a privacy right.
Submit a request through our privacy request form or email [email protected] with the subject “Privacy request.” We may ask for information reasonably necessary to verify identity, authority, account, and jurisdiction. An authorized agent may submit a request if it provides proof of authority and we can verify the consumer as permitted by law.
We generally respond to verified requests within 45 days when that period applies. If permitted, we may extend the response period and will explain the reason. To appeal a decision, reply to the decision or submit a new request labeled “Privacy appeal.” Marketing email recipients may also use the unsubscribe link, and SMS recipients may reply STOP.
If your request concerns Customer Data controlled by a Service Opus business customer, contact that business first. We will assist the business customer with a verified request as required by our Agreement and applicable law.
Global Privacy Control and Analytics Opt-Out
The public website treats a supported browser Global Privacy Control signal as a request to disable analytics for that browser. You may also use the “Your Privacy Choices” link in the footer. These controls do not disable cookies or storage strictly necessary for security, authentication, saving the privacy choice, or a service you request.
10. Supplemental Notice for California Residents
This section applies to the extent Service Opus is subject to the California Consumer Privacy Act, as amended (CCPA). It describes categories the Services collect when the corresponding features are used, sources, purposes, and disclosure recipients. Customer Data handled solely as a service provider is also governed by the business customer's instructions and notices.
Sale and sharing: We have not sold personal information. We do not sell or use Customer Data for cross-context behavioral advertising. Unless a saved opt-out or supported Global Privacy Control signal is present, identifiers and internet activity may be disclosed to Google Analytics for restricted public-site measurement; because some laws may treat that disclosure as sharing, the visitor may opt out through Your Privacy Choices or Global Privacy Control.
Sensitive personal information: We use sensitive information only to provide requested services, secure accounts and systems, prevent fraud, process transactions, comply with law, and carry out customer instructions. We do not use it to infer characteristics for advertising.
California rights: Subject to the CCPA's scope and exceptions, California residents may request access, categories and specific pieces, sources, purposes and recipients; correction; deletion; portability; and opt-out of sale or sharing. They may use an authorized agent and may not be unlawfully discriminated against for exercising these rights. Use the methods in Section 9.
11. Customer End Users and Workforce Information
If you are an employee, technician, subcontractor, vendor, or end customer of a business using Service Opus, that business determines the Customer Data it collects and who can access it. Authorized users may access records according to permissions and configuration; they do not automatically receive unrestricted access to every action, communication, location record, or sensitive HR record. Contact the business for questions about its practices or to exercise rights concerning Customer Data. Service Opus will support verified requests from the business as required.
12. Children's Information
Service Opus accounts and direct commercial Services are intended for adults acting for a business and are not directed to children under 16. We do not knowingly solicit personal information directly from children. A business customer may process Customer Data involving a minor when legally permitted and remains responsible for required notices, consent, and safeguards. If we learn that a child submitted information directly to Service Opus without appropriate authorization, we will take appropriate steps to delete or otherwise handle it subject to legal, security, backup, and processor obligations.
13. Changes to This Policy
We may update this Policy to reflect changes in the Services, vendors, or law. We will post the revised Policy and update the date above. If a change materially affects how active customers' information is used, we will provide an additional notice through the Service or email when appropriate.
14. Contact Us
For privacy questions, requests, or security reports, contact Cordelio LLC, doing business as Service Opus:
- Email: [email protected]
- Phone: +1 (415) 935-3770
- Privacy request form: serviceopus.com/contact?topic=privacy