Privacy Policy

What we do with your information, and the choices you have

Effective
28 July 2026
Last updated
26 August 2026

1. About this policy

Operant360 is a job management platform for restoration, remediation and construction contractors. Contractors use it to run projects, build scopes and estimates, manage inventory and contents, issue work orders and purchase orders, track time, invoice their clients and take payment.

This policy explains what personal information we handle, why we handle it, who we share it with and what choices you have. It applies to the Operant360 website at operant360.com, the Operant360 web application, and the emails and documents the platform sends on a contractor’s behalf.

In this policy, “we” and “us” mean Purenvironmental Restoration Services Ltd., a Canadian corporation with its operating address at 679 Norfolk St. N, Simcoe, Ontario N3Y 3R2, operating under the name Operant360. “Operant360” refers to the software platform described in this policy. “You” means the person reading this, whether you are a customer, a customer’s employee, a customer’s client, or a visitor to our website.

2. The two different roles we play

This is the most important thing to understand about how your information is handled, so it comes first.

When we decide how information is used, we are responsible for it. This covers our own website visitors, people who sign up for accounts, billing contacts and anyone who contacts our support team. Canadian law calls us the organization responsible for that information; European law calls us the controller; California law calls us a business.

When a contractor decides how information is used, they are responsible for it and we act on their instructions. Everything a contractor puts into their Operant360 workspace falls into this category: their project records, the names and contact details of the property owners and insurance adjusters they work with, photographs of insured properties, scope notes, estimates, invoices and time entries. We store and process that information so the contractor can run their business. We do not decide what it is used for. European law calls us the processor here; California law calls us a service provider.

If you are a property owner, adjuster, subcontractor or employee and a contractor has entered your details into Operant360, that contractor is the organization accountable to you. Ask them for their privacy policy. If you contact us directly we will help, but in most cases we will refer your request to the contractor and support them in answering it, because the information is theirs to explain.

Subcontractors and suppliers whose information is entered into the platform should be aware that their data is controlled by the contractor who entered it. It is the contractor’s responsibility to notify you of this processing and to direct you to this policy.

3. Information we collect

Information you give us directly

When you create an account we collect your name, email address, a password (stored only as a cryptographic hash, never in readable form), and your organization’s name. If you turn on two-factor authentication we store the information needed to verify your codes. If you upload a profile photo we store that.

When you subscribe we collect billing contact details, your billing address and tax information. Card numbers go directly to Stripe and never touch our servers. We receive only the last four digits, the card brand and the expiry date so we can show you which card is on file.

When you contact support we keep the message and our reply.

Information your organization puts into the platform

Contractors enter and upload a great deal of information in the course of running jobs. Depending on how they use the platform, this can include:

  • Client and contact records: property owner names, addresses, phone numbers, email addresses, insurance carrier, claim number and adjuster contact details.
  • Project and phase records: loss type, cause of loss, dates, site notes and internal comments.
  • Room and scope records: dimensions, affected materials, moisture readings and equipment placement.
  • Photographs and video taken on site. These frequently show the inside of private homes and businesses, and can incidentally include people, personal belongings and documents.
  • Voice recordings. Field staff can dictate notes, scope entries and work orders instead of typing. The audio is transcribed and then discarded (see section 6).
  • Documents and files uploaded to a project.
  • Time entries, including start and stop times, and the hours crew members report.
  • Estimates, invoices, purchase orders, work orders and the record of when a document was sent, delivered, opened and paid.
  • Subcontractor and supplier records, and the tenders exchanged between organizations that connect on the platform.

We do not go looking for particularly sensitive categories of information, and the platform is not designed to hold health records, government identifiers or financial account numbers. Contractors should not put them into free-text fields.

Information we collect automatically

When you use the application we record standard technical information: IP address, browser and device type, operating system, the pages you visited, timestamps, and the referring page. We keep server logs for security and troubleshooting.

When something breaks, our error monitoring tool captures a diagnostic record: the error, the page it happened on, browser details and the account identifier involved. We configure it to strip out request bodies, tokens and passwords.

We also measure how the product is used, so we know which features earn their keep and where people get stuck. This covers pages viewed, features opened, actions taken and rough timings. By default it is anonymous and nothing is stored on your device. If you are signed in, we ask whether we may go further and connect it to your account. Section 13 explains how it works and how to change it. We have switched off IP storage in our analytics tool, so it keeps no IP address and collects no location data.

We do not use advertising cookies, tracking pixels or social media trackers, and we do not build advertising profiles.

Information from other services

If you connect your QuickBooks Online account, we receive customer records, invoices, payments and chart-of-accounts data from Intuit so the two systems stay in sync. You control the connection and can revoke it at any time.

If your organization takes payment through the platform, Stripe sends us the payment status, the amount, the last four digits of the card and any dispute or refund events. Stripe also collects identity and banking information directly from your organization during onboarding, under Stripe’s own privacy policy.

4. Why we use information, and our legal basis for doing so

What we do with personal information, why, and the legal basis for it where the GDPR applies
What we doWhyLegal basis where GDPR applies
Create and secure accounts, authenticate sign-ins, enforce roles and permissionsTo let you use the platform and keep other people out of your dataPerformance of a contract
Run the platform: store projects, generate estimates, send documents, sync integrationsTo deliver what the contractor signed up forPerformance of a contract
Bill subscriptions, collect payment, handle taxes and dunningTo get paidPerformance of a contract; legal obligation for tax records
Provide support and respond to questionsTo help youPerformance of a contract; legitimate interests
Monitor errors, investigate abuse, prevent fraud, maintain backupsTo keep the service working and secureLegitimate interests; legal obligation
Send service notices about outages, security and material changesTo keep you informed. You cannot opt out of these while you hold an accountPerformance of a contract
Send product news and marketing emailTo tell you about the product. Every message has an unsubscribe linkConsent, or legitimate interests where permitted
Measure how features are used, through product analyticsTo find where the product is failing people and decide what to build nextConsent where a non-essential cookie or similar technology is involved; otherwise legitimate interests
Improve the platform using aggregated, de-identified usage statisticsTo decide what to build nextLegitimate interests

We do not sell personal information, and we do not share it for cross-context behavioural advertising. We have never done so.

Marketing communications: If you unsubscribe from marketing emails, this will not affect transactional emails such as invoices, security alerts, or important service notices. You will continue to receive those as long as you hold an account.

5. Automated decisions

Operant360 generates draft estimates, suggested line items, cost figures and document text automatically. These are drafts. Every one of them is presented to a person who reviews, edits and approves it before it goes anywhere. Nothing the platform generates produces a legal or similarly significant effect on anyone without a human deciding to act on it.

If you are in Quebec and you want to know more about how a particular automated recommendation was produced, or you want to submit observations about it, write to our Privacy Officer at the address in section 16.

6. How we handle information in AI features

Several parts of the platform use AI models: drafting estimates from scope notes, matching descriptions to price-code library entries, transcribing dictated voice notes, summarizing room notes, drafting work orders and reading uploaded photographs.

Three commitments govern this:

We do not train models on your content. Not our own models, not anyone else’s. Your projects, photos, notes and documents are never used as training data.

Our AI vendors do not train on your content either. We use them under commercial terms that prohibit training on submitted data and that either disable retention or limit it to a short abuse-monitoring window.

Voice recordings are transitory. Audio is sent for transcription, the text comes back, and the audio file is discarded. We do not keep a library of recordings.

Where technically feasible, we anonymize or de-identify data before sending it to AI models. For example, personal identifiers are not required to transcribe audio or generate a draft estimate from a scope description. We strip or mask this information to the extent the model does not need it to perform the task.

Output is a draft. Estimates, cost figures and generated text can be wrong, and it is the contractor’s responsibility to review them. Nothing the platform produces is professional advice, and it is not a substitute for a qualified estimator, adjuster, engineer or hygienist.

7. Connected calendars (Google Calendar and Outlook)

A user can connect their own Google Calendar or Outlook account so that jobs they are booked on appear in their personal calendar, and so their personal events appear alongside the work schedule inside the platform. This is optional, per person, and can be disconnected at any time from the calendar settings page. Disconnecting deletes the dedicated calendar we created in the connected account and stops all syncing.

When a calendar is connected we access only what the feature needs: the list of calendars in the account (so the user can choose which ones to show), events from the calendars the user picks, and the ability to create and update events in the one dedicated calendar we make for their bookings. Personal events pulled in this way are visible only to the person who connected the account — never to their employer, their colleagues, or us in the ordinary course of operating the service.

Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular: we use Google Workspace API data only to provide the calendar sync feature described above; we do not transfer it to anyone except as needed to provide that feature, to comply with law, or as part of a merger or acquisition with prior notice; we do not use it for advertising; and humans at Operant360 do not read it except with the user’s permission for support, for security purposes, or where the law requires it.

We do not use data obtained through Google Workspace APIs to develop, improve, or train generalized artificial intelligence or machine learning models. Calendar data is not fed to the AI features described in the previous section, and it is never used as training data — ours or anyone else’s.

8. Who we share information with

We share information with the service providers listed below, and only to the extent each one needs it to do its job. Every one of them is under a written contract that limits them to our instructions and requires them to protect the information.

Service providers we share personal information with, what each one does, and where it processes data
ProviderWhat it doesWhere it processes data
SupabaseDatabase, file storage and authentication infrastructureCanada (Montréal)
VercelApplication hosting and content deliveryApplication code runs in Canada (Montréal). Static content is delivered from servers worldwide
StripeSubscription billing, and payment processing for contractors who collect from their clients through the platformUnited States, Ireland
Trigger.devCloud service that runs background jobs such as estimate generation, document rendering and integration syncUnited States
ResendSends transactional email (invitations, notifications, invoices, estimates)United States
SentryError and performance monitoringUnited States
OpenAITranscription and language modelsUnited States
Vercel AI GatewayRoutes requests to language model providersUnited States
PostHogProduct analytics. Anonymous unless you agree to more, and off entirely if you declineUnited States
Intuit (QuickBooks Online)Accounting sync, only if a contractor connects itUnited States

When this list changes. We add and replace service providers as the platform grows. Before a new provider starts handling personal information we will update this table, and where the change is material we will email account holders at least 30 days beforehand so an organization that objects has time to raise it with us. Anything that sets a cookie or similar technology in your browser also has to clear the consent rules in section 13 first.

We also share information in four other situations:

  • With other organizations you connect to. If your organization tenders work to a subcontractor through the platform, or accepts work from a general contractor, the project details you choose to share become visible to that organization. You control what you send.
  • With your own organization. Anything you enter is visible to the people in your workspace whose role permits it. Your organization’s owners and administrators can see, export and delete it.
  • When the law requires it. We will disclose information if we are compelled by a valid court order, subpoena, warrant or other lawful demand. Unless we are legally prohibited, we will tell the affected customer first so they can respond.
  • In a business transfer. If we are acquired or merge, information transfers with the business. The acquirer stays bound by this policy until you are given notice and a chance to object.

9. Where information is stored, and cross-border transfers

Your data is stored in Canada, and the application that reads and writes it runs in Canada. The database, the files you upload and the application code all sit in Montréal. We chose that deliberately.

Some things still leave the country, and we would rather tell you plainly than bury it:

  • Static parts of the website, such as images and scripts, are delivered from servers around the world so pages load quickly. These carry no personal information.
  • Several of the service providers in section 7 process data in the United States, and one in Ireland. Payments, transactional email, error monitoring, background jobs, AI features and the optional accounting sync all involve a provider outside Canada.

Where information does leave Canada, it can be accessed by that provider’s staff abroad and can be subject to lawful access requests by courts and government authorities in that country. This is true of any cloud platform. We limit it by contract, we send each provider only what it needs, and we keep the core of your data at home.

We remain accountable for your information under PIPEDA wherever it is processed. For transfers out of the European Economic Area or the United Kingdom we rely on the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum. Where Quebec’s Law 25 applies, we conduct a privacy impact assessment (PIA) and transfer impact assessment (TIA) for any new processing activity or service provider that involves a cross-border transfer. We maintain records of these assessments and make them available to supervisory authorities on request.

10. How long we keep information

While your organization’s subscription is active, we keep its data so the platform works.

When a subscription ends, the workspace stays available in read-only form for 30 days so you can export what you need. After that we begin deletion, and data is removed from live systems within 60 days of termination.

Encrypted backups roll off on a 35-day cycle. Deleted data can persist in a backup until that cycle completes, and it is not restored into live systems.

Some things we keep longer because we have to. Invoices, payment records and tax documentation are retained for seven years under Canadian tax law. Security and audit logs are retained for 12 months. Records connected to an actual or threatened legal claim are retained until the matter is resolved.

An individual user account that is deleted is removed within 30 days, though records of that person’s actions inside a customer’s workspace (who approved an estimate, who logged the hours) remain, because they belong to the contractor’s business records. Where these records remain, they are associated with a unique, non-identifiable user identifier (or a “deleted user” placeholder) rather than the individual’s name, so the data cannot be trivially re-associated with the individual’s identity.

11. How we protect information

Everything moves over TLS and sits encrypted at rest. Passwords are hashed. Access to production systems is restricted to the small number of people who need it, protected by multi-factor authentication and reviewed periodically. The platform enforces role-based permissions so people see only what their role allows, and it isolates each organization’s data at the database layer. We take encrypted backups, monitor for errors and abuse, and run security review over changes to the codebase.

No system is perfectly secure, and we will not pretend otherwise. If a breach occurs that creates a real risk of significant harm, we will notify affected customers and the Office of the Privacy Commissioner of Canada without unreasonable delay, along with the Commission d’accès à l’information du Québec, supervisory authorities in the EEA or UK, and state attorneys general, wherever those obligations apply. We maintain the breach records the law requires.

12. Your rights

Everyone, wherever they live, can ask us to:

  • confirm whether we hold information about them, and get a copy;
  • correct information that is wrong or incomplete;
  • delete information, subject to the retention rules in section 9;
  • receive their information in a portable format;
  • stop marketing email, at any time, with no consequence to their account;
  • withdraw consent where we relied on consent, understanding that some withdrawals mean we can no longer provide the service.

Write to privacy@operant360.com. We will confirm receipt promptly and respond within 30 days. If a request is complex we may take longer, and we will tell you why before the 30 days are up. We will ask you to verify your identity first, and we will not charge you unless a request is repetitive or excessive, in which case we will tell you the cost before doing the work.

If your request concerns information a contractor entered about you, we will route it to that contractor and support them in responding, because it is their record. Contact them directly for the fastest result.

Canada

You can complain to the Office of the Privacy Commissioner of Canada at priv.gc.ca. We would rather hear from you first.

Quebec

Law 25 gives you the additional right to ask that information about you stop being disseminated, and to ask for a hyperlink to it to be de-indexed, where the dissemination contravenes the law or a court order. Our Privacy Officer is named in section 16. You can complain to the Commission d’accès à l’information du Québec.

European Economic Area and United Kingdom

In addition to the rights above you can object to processing based on legitimate interests, ask us to restrict processing, and complain to your national supervisory authority or, in the UK, the Information Commissioner’s Office.

United States

See section 12.

13. United States state privacy rights

California

Under the California Consumer Privacy Act as amended by the CPRA, California residents have the rights set out below. These apply to information we handle in our own right. Where a contractor is the business and we act as their service provider, direct your request to that contractor.

What we collect and why. In the past 12 months we have collected identifiers (name, email, IP address, account ID), commercial information (subscription and payment records), internet activity (log and usage data), professional information (your role and employer), audio and visual information (photographs and voice notes uploaded by contractors), and inferences drawn from usage. We collect it for the purposes in section 4, from the sources in section 3, and we disclose it to the service providers in section 7.

We do not sell personal information, and we do not share it for cross-context behavioural advertising. We have not done so in the past 12 months, and we do not sell or share the personal information of anyone under 16.

Sensitive personal information. We do not use or disclose sensitive personal information for any purpose beyond those permitted without an opt-out under section 7027(m) of the CCPA regulations.

Your rights. To know, to access a copy, to delete, to correct, to opt out of sale or sharing (which does not apply, since we do neither), to limit use of sensitive personal information, and not to be discriminated against for exercising any of them. You may use an authorized agent, who must provide written proof of authorization.

Make a request at privacy@operant360.com. We will verify you by confirming control of the account email, or by matching identifying details you provide against our records.

Other US states

If you live in Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Florida, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Minnesota, Maryland, Tennessee, Indiana, Kentucky, Rhode Island or any other state with a comprehensive consumer privacy law in force, you have rights to confirm, access, correct, delete, obtain a portable copy, and opt out of targeted advertising, sale and profiling with legal effects. We do not conduct targeted advertising, sell personal data, or profile people in ways that produce legal effects.

Appeals. If we refuse your request, you can appeal by replying to our decision or writing to privacy@operant360.com with “Appeal” in the subject line. We aim to respond to all appeals within 30 days. If we need more time due to the complexity of the appeal, we will inform you within the initial 30-day period. If we deny the appeal, we will give you a link or a means to complain to your state Attorney General.

Note that most state privacy laws other than California’s apply only to individuals acting in a personal or household capacity, and exclude information about people acting in a commercial or employment context. Much of the information in Operant360 is commercial. We will not use that as a reason to refuse a request we can reasonably honour.

14. Cookies and similar technologies

Cookies and the technologies that behave like them, such as local storage and pixels, fall into three groups on Operant360.

Strictly necessary. A session cookie that keeps you signed in, a security token that prevents cross-site request forgery, and preference cookies that remember your language, theme and which panels you collapsed. These are all first-party, the platform does not work without them, and we set them without asking, as the law permits. Blocking the session cookie will sign you out and keep you out.

Product analytics. Measurement that tells us which features get used, where people abandon a workflow and how long things take. By default it stores nothing on your device and sets no cookie at all. Storing an identifier so we can recognise you across visits is non-essential, and we ask before doing it.

Advertising and cross-site tracking. We do not use these. No ad pixels, no social media trackers, no advertising profiles, and no sharing of your information with advertising networks. We have no plans to change this.

The analytics tool we use

Our product analytics runs on PostHog. It tells us which features get used, where people abandon a workflow and how long things take.

  • By default it runs anonymously. Nothing is stored on your device, no cookie is set, and visits are counted from a code PostHog works out on its own servers and cannot turn back into your details.
  • If you are signed in, we ask whether we may store an identifier so we can recognise you across visits and connect what we measure to your account. That is the only thing the banner asks for.
  • Saying no means we stop measuring you altogether, not merely that we stop storing the identifier. It costs you nothing and the platform works exactly the same.
  • You can change your mind at any time from your account settings, or from the link in the footer of our website.
  • We run no analytics at all on the pages your clients visit by emailed link — to review an estimate or inventory, look at photos, sign a document, or pay an invoice.
  • PostHog acts on our instructions only. It is not permitted to use your information for its own purposes.
  • We have switched off IP storage in PostHog, so no IP address is kept against any event and we collect no location data.
  • We do not repurpose any of it into advertising.

We picked a tool with no advertising business attached to it on purpose. Analytics here is for finding out where the product is failing you, and it will not become a route into ad targeting.

Do Not Track and Global Privacy Control

We honour Global Privacy Control signals and treat one as a valid instruction to switch off product analytics completely, including the anonymous measurement described above, without you having to do anything else. We interpret a Global Privacy Control (GPC) signal as a valid, legally binding opt-out preference signal, which we will honour to the extent required by applicable law (including the CCPA). We do not sell or share personal information and set no advertising cookies, so there is nothing further for the signal to switch off.

Your browser can also block or delete cookies directly, through its own settings.

15. Children

Operant360 is a business tool. It is not directed at children and we do not knowingly collect information from anyone under 16. If you believe a child’s information has ended up in the platform, write to privacy@operant360.com and we will delete it.

16. Changes to this policy

We will update this policy when the platform or the law changes. The effective date at the top always reflects the current version.

If a change materially affects how we handle personal information, we will notify account holders by email and post a notice in the application at least 30 days before it takes effect. Continuing to use Operant360 after that date means the new version applies to you.

17. Contact us

Privacy Officer: J. Bowyer
Purenvironmental Restoration Services Ltd. (operating as Operant360)
679 Norfolk St. N
Simcoe, Ontario N3Y 3R2

Email: privacy@operant360.com
For general questions: support@operant360.com

We will acknowledge privacy enquiries within five business days.

18. Data Processing Addendum

A Data Processing Addendum (DPA) incorporating the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum is available on request. Please contact us at privacy@operant360.com to request a copy.