ServiceRunner
HomeFeaturesPricingContactLog InSign Up
home
Home
auto_awesome
Features
sell
Pricing
mail
Contact

login
Log In
person_add
Sign Up

Privacy Policy

Last updated: September 13, 2026

This policy explains how Isles Mechanical LLC handles personal data in connection with ServiceRunner, our website and our mobile apps. It distinguishes the data we control ourselves (your account, billing and support data) from the data we process only on behalf of the organizations that use ServiceRunner (their field records, photos, technician locations and their own clients' contact details).

TermsPrivacyDPAAcceptable UseCookiesSubprocessorsEULA
On this page
1. Who We Are & Scope2. Controller vs Processor3. Data We Collect4. Sources5. Purposes & Legal Bases6. Sharing7. International Transfers8. Retention9. Security10. Breach Notification11. Rights: EEA, UK, Switzerland12. Rights: California13. Rights: Canada14. Rights: Other U.S. States15. Children & Automated Decisions16. Changes17. Contact & DPO

1. Who We Are and Scope

Isles Mechanical LLC ("Isles Mechanical", "we", "us") operates ServiceRunner, a field-service, maintenance and dispatch platform for businesses. This policy applies to the ServiceRunner website at app.servicerunner.app, the web application, the iOS and Android apps and related support channels (together, the "Service").

The Service is designed for use by organizations and their staff in a work context. It is not directed at consumers or children. If you are an employee, contractor or client of an organization that uses ServiceRunner, that organization decides what data about you goes into the Service and why; Section 2 explains what that means for your rights.

You can reach our Privacy Officer at privacy@app.servicerunner.app. Full contact details are in Section 17.

2. Controller and Processor Roles

Privacy laws distinguish who decides why and how personal data is used from who merely handles it on instruction. We act in both roles:

2.1 Where we are the controller

We are the controller (a "business" under California law) for personal data that we collect for our own purposes: account and login details, organization and billing records, support and feedback communications, website visits, usage and diagnostic telemetry, security logs and marketing preferences. This policy is the primary notice for that data.

2.2 Where we are the processor

We are a processor (a "service provider" under California law) for personal data that a customer organization ("Customer") and its users put into the Service or generate by using it: site and task records, photos and their metadata, forms, daily logs, time entries, technician location during shifts, chat messages, and the names, phone numbers, emails and addresses of the Customer's own clients, tenants and site contacts ("Customer Data"). We process Customer Data only on the Customer's documented instructions and under our Data Processing Addendum.

Customer Data also includes the Customer's invoices, accounting records, and end-client payment and agreement records. When a Customer enables QuickBooks Online or card collection, we process those records to operate the connection on its instructions. Intuit and the Customer's connected Stripe merchant account may process data under their own terms and privacy notices as well as any processor arrangements that apply to a particular activity.

If you are a technician, employee, contractor or client of a Customer, the Customer is responsible for telling you how your data is used and for answering your privacy requests. Please contact the organization directly. If you contact us instead, we will pass your request to the Customer and assist them as required by law.

3. Personal Data We Collect

3.1 Account data (controller)

  • Name, email address, password hash, phone number, trade or job title, and profile photo.
  • Single sign-on identifiers (Google, Microsoft or Apple subject ID) if you sign in that way; we do not receive your SSO password.
  • Two-factor authentication secrets, email-verification status and password-reset tokens (stored hashed).
  • Session records: session token, device type, browser or device description, IP address, last-active time.

3.2 Organization and billing data (controller)

  • Organization name, slug, address, plan, trial and subscription status, seat count, storage usage.
  • Our subscription billing contact, invoice history, Stripe payment-method reference and limited card details such as brand and last four digits. End-client invoices, payment records and agreement authorizations belong to Customer Data. We do not receive or store full card numbers or card security codes.

3.3 Usage, telemetry and device data (controller)

  • Server logs: request path, timestamp, IP address, user agent, response code, and the acting user and organization ID for authenticated calls.
  • Audit events (who created, changed or deleted a record and when) used for security and to give Customers an audit trail.
  • App diagnostics: app version, operating system, device model, crash and sync-error reports, offline-queue status, and whether persistent storage was granted. No third-party analytics SDK is installed today; if that changes we will update the Cookie Policy and gate it behind consent.
  • Push notification tokens (Firebase Cloud Messaging registration tokens) so we can deliver notifications you enable.

3.4 Precise geolocation of technicians (processor)

When a Customer enables time tracking or dispatch, the mobile app can record the device's precise GPS location (latitude, longitude, accuracy, timestamp) at clock-in and clock-out, periodically while clocked in or on an active dispatch shift (including in the background on native apps), when a proximity prompt fires near a site, and when a photo is taken. Location collection is off unless the Customer turns the feature on and the user grants the device permission; it stops when the user clocks out or ends the shift, or revokes permission. Location history is Customer Data: the Customer decides how long to keep it and who may view it.

3.5 Photos, files and their metadata (processor)

Photos, plans, documents and form attachments uploaded to the Service, together with capture time, device-supplied metadata and, where enabled, the capture location. Photos are automatically optimized on upload, which strips most embedded EXIF metadata other than orientation; the capture time and location, if recorded, are stored as separate fields under the Customer's control.

3.6 End-client and site contact data (processor)

Customers may record names, phone numbers, email addresses, service addresses, gate codes, access instructions and notes about their own clients, tenants, property managers and site contacts, and may send those people quotes, reports or SMS/email notifications through the Service. That data belongs to the Customer.

When enabled, invoice card collection records payment amounts and status, Stripe customer, payment and merchant-account references, limited card details (brand, last four digits and expiry), provider events, refunds or disputes where reported, and reconciliation history. A recurring agreement also records the signer's name and email, accepted wording, schedule, time and audit evidence. Stripe receives card details through its secure payment fields; we do not receive or store the full card number or security code.

A connected QuickBooks Online company supplies company identity, accounting settings, customer and transaction references, and matched payment information. If accounting sync is separately enabled, we may send end-client names and email addresses, issued invoices, recorded payments and supported credits to Intuit and import matched receipts. We retain encrypted OAuth credentials and connection, command, result and reconciliation history needed to operate and audit the integration.

Disconnecting QuickBooks stops new synchronization and removes the active credential from the connection. Revocation of the previous provider grant is queued and can remain uncertain; disconnecting does not erase records already sent to Intuit or the local accounting history. The Customer may also need to revoke access in QuickBooks. Turning off new Stripe collections does not cancel an existing agreement's accepted payment authority; the Customer can pause or cancel that collection separately.

3.7 Communications and support (controller)

  • Emails, in-app feedback and bug reports you send us, including any screenshots or diagnostics you attach.
  • Records of notifications we send (email, SMS, push), including delivery status.
  • Marketing preferences and, if you subscribe, newsletter engagement.

3.8 Cookies and local storage

The Service uses browser storage and app-local storage that is strictly necessary to keep you signed in, remember your organization, work offline and store your cookie choices. We do not use advertising cookies or cross-site tracking. Every key we set is listed in the Cookie Policy.

3.9 Sensitive data

Outside designated Stripe payment fields and provider verification flows, we do not ask for, and Customers should not enter in notes, uploads or messages, full payment card or financial account numbers, card security codes, government identifiers, health data, biometric data, or data about race, religion, union membership or sexual orientation. Precise geolocation is treated as sensitive personal information where the law requires; it is collected only for workforce and dispatch purposes described above and is not used for profiling or advertising.

4. Sources of Personal Data

  • You, when you register, fill in your profile, upload content, contact support or use the app.
  • Your organization, when an administrator invites you, assigns you to sites, sets your role or records your time and location settings.
  • Your device, through permissions you grant (camera, location, notifications) and diagnostic data.
  • Single sign-on providers, which pass your name, email and subject ID when you choose to sign in with them.
  • Stripe, which passes payment status, invoice events and the last four digits of a card.
  • Intuit QuickBooks Online, when your organization connects a company, which supplies company details, accounting settings, transaction references and eligible payment records used for matching and reconciliation.
  • Customers' clients, when a Customer records their details, or when a recipient opens a quote or report link we sent on the Customer's behalf.

5. Purposes and Legal Bases

Where the GDPR, UK GDPR or a similar law applies, we rely on the following legal bases. For Customer Data we act on the Customer's instructions and the Customer is responsible for its own legal basis.

PurposeData usedLegal basis (GDPR Art. 6)
Creating and administering your account and organization; authenticating you; syncing data between devicesAccount, organization, session dataPerformance of a contract (Art. 6(1)(b))
Billing, invoicing, collecting fees, preventing payment fraudBilling data, usage metricsContract; legal obligation (tax and accounting records) (Art. 6(1)(b), (c))
Providing the field-service features a Customer configures, including time tracking, dispatch and photo captureCustomer Data, including location and photosProcessor acting on Customer instructions; the Customer's own basis applies
Connecting accounting software and collecting Customer invoices or accepted agreement installmentsCustomer invoice, end-client, payment and accounting data; provider references and audit evidenceProcessor acting on Customer instructions; the Customer's own basis applies
Sending transactional notifications (task assignments, invites, password resets, receipts)Contact details, push tokensContract; legitimate interests in operating the Service (Art. 6(1)(b), (f))
Securing the Service, detecting abuse, rate limiting, audit logging, incident responseLogs, session data, audit eventsLegitimate interests in security and integrity; legal obligation (Art. 6(1)(f), (c))
Diagnosing errors and improving reliability and usabilityDiagnostics, aggregated usageLegitimate interests in improving the Service (Art. 6(1)(f))
Answering support requests and feedbackCommunicationsContract; legitimate interests (Art. 6(1)(b), (f))
Product news and marketing to business contactsName, email, preferencesConsent where required (Art. 6(1)(a)); otherwise legitimate interests, with opt-out in every message
Optional cookies or analytics (none today)Cookie dataConsent (Art. 6(1)(a)); ePrivacy rules
Precise location on your own deviceGPS dataDevice-level consent you give the app; the Customer's legal basis as employer
Complying with law, responding to lawful requests, establishing or defending legal claimsAny relevant dataLegal obligation; legitimate interests (Art. 6(1)(c), (f))
Corporate transactions (merger, financing, sale)Any relevant data, under confidentialityLegitimate interests (Art. 6(1)(f))

Where we rely on legitimate interests, we have assessed that the processing is necessary and that your interests and rights do not override ours; you can object under Section 11. We do not use personal data for purposes incompatible with those listed without telling you first.

6. How We Share Personal Data

We share personal data only as follows:

  • Subprocessors and service providers that host and operate the Service for us, bound by contracts that restrict their use of the data. The current list, with the purpose and location of each, is published on the Subprocessors page and is incorporated into this policy.
  • Customer-selected financial services, when the Customer enables them: Intuit receives accounting records for QuickBooks Online sync, and Stripe processes card payments and related end-client information for the Customer's connected merchant account. Intuit and Stripe may act as independent controllers for some activities and processors for others, under their own terms and notices. See the Intuit Privacy Statement and Stripe Privacy Policy.
  • Your organization. Administrators of the organization you belong to can see your profile, your role, your activity in the Service and, where enabled, your time entries and location history.
  • Recipients you or your organization choose, such as a client who is emailed a quote or report, or another user who is @-mentioned in chat.
  • Professional advisers (lawyers, accountants, auditors, insurers) under confidentiality.
  • Authorities where required by law, subpoena or court order, or to protect the rights, safety or property of Isles Mechanical, our users or the public. We will notify the affected Customer before disclosing Customer Data unless legally prohibited, and we challenge requests that appear overbroad.
  • Successors in a merger, acquisition, reorganization or sale of assets, under this policy, with notice to you.

We do not sell personal data and have not done so in the preceding twelve months. We do not share personal data for cross-context behavioral advertising and do not allow third parties to collect data on the Service for their own advertising. We do not use personal data for targeted advertising.

7. International Transfers

Our subprocessors process data primarily in the United States, and the hosting region for the production database and file storage is chosen by the deployment operator (see the Subprocessors page). If you are outside the country where data is stored, your data will be transferred internationally.

  • EEA and Switzerland. Transfers to countries without an adequacy decision are made under the European Commission's Standard Contractual Clauses (2021/914), including Module Two (controller to processor) and Module Three (processor to processor), supplemented by transfer impact assessments and the security measures in Section 9. Where a recipient is certified under the EU-U.S. Data Privacy Framework, we may also rely on that certification.
  • United Kingdom. Transfers are made under the UK International Data Transfer Addendum to the EU SCCs, or the UK IDTA, as applicable, or the UK Extension to the Data Privacy Framework.
  • Canada. PIPEDA and provincial laws permit transfers for processing provided the data receives comparable protection by contract; we use contractual safeguards with each subprocessor. Data may be subject to the laws of the country where it is processed, including lawful access by authorities there. Quebec residents: transfers outside Quebec are made after a privacy impact assessment as required by Law 25.
  • Other regions. We use the transfer mechanism recognized by the applicable law, or your consent where no other mechanism is available.

You can request a copy of the relevant transfer safeguards by contacting the Privacy Officer.

8. Retention

We keep personal data only as long as needed for the purposes above. Customer Data is retained for as long as the Customer keeps it in the Service and is then handled under the Terms of Service (Section 15). Representative periods:

DataRetention
Account profileLife of the account, then deleted within 90 days of account deletion
Customer Data (records, photos, location history, end-client contacts)Controlled by the Customer; after termination, 30-day export window, deletion from active systems within 90 days, backups expire within 6 months
Sessions and login tokensUntil expiry or sign-out; inactive sessions purged after 90 days
Password-reset and email-verification tokensUntil used or expired (hours), then deleted
Push notification tokensUntil the device unregisters or the token is reported invalid
Our own subscription billing records and invoices7 years, or longer if tax law requires
Customer invoices, payment authorizations, Stripe events and QuickBooks sync recordsCustomer Data under the Customer's account and the export/deletion schedule above; this system does not retain all such evidence for seven years after organization deletion. A legal hold or applicable recordkeeping requirement may require a separate retention arrangement.
Server, security and audit logsUp to 12 months, unless needed for an ongoing investigation
Support and feedback correspondence3 years after the last message
Marketing preferences and suppression listsUntil you change them; opt-out records are kept so we can honor them
Cookie consent recordStored in your browser for up to 12 months, then re-asked
Data subject request records3 years, to demonstrate compliance

Legal holds, disputes and regulatory investigations may extend these periods. Data in backups is not restored except to recover from a failure, and is overwritten as the backup cycle rotates.

9. Security

We apply technical and organizational measures appropriate to the risk, including: encryption in transit (TLS) for all connections; encryption at rest for databases, backups and object storage; salted password hashing with a memory-hard algorithm; optional two-factor authentication; role-based access control within organizations and sites; signed, expiring links for report and file downloads; API rate limiting; least-privilege access to production for our staff, with logging; separation of development, staging and production environments; automatic photo optimization that removes most embedded device metadata; vulnerability management and dependency updates; and encrypted, tested backups. The DPA's Annex II describes these measures in more detail.

No system is perfectly secure. You are responsible for keeping your credentials confidential, enabling two-factor authentication, securing devices used offline, and telling us at security@app.servicerunner.app about any suspected vulnerability or compromise.

10. Data Breach Notification

If we become aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data, we will: contain and investigate it; notify affected Customers without undue delay and in any event within 72 hours of becoming aware, with the information they need to meet their own obligations; notify affected individuals for data we control where the law requires or where the breach is likely to result in a high risk to them; and notify supervisory authorities as required (including the Office of the Privacy Commissioner of Canada and the Commission d'accès à l'information du Québec for breaches creating a real risk of significant harm, and U.S. state attorneys general where state law requires). We keep a record of every breach, its effects and the remedial action taken.

11. Your Rights: EEA, UK and Switzerland

If the GDPR, UK GDPR or Swiss FADP applies to you, you have the right to:

  • Access the personal data we hold about you and receive a copy;
  • Rectify inaccurate or incomplete data;
  • Erase data in the circumstances the law provides;
  • Restrict processing while a dispute about accuracy or lawfulness is resolved;
  • Data portability: receive data you provided in a structured, commonly used, machine-readable format;
  • Object to processing based on legitimate interests, and to direct marketing at any time;
  • Withdraw consent at any time where processing is based on consent, without affecting prior processing;
  • Not be subject to solely automated decisions with legal or similarly significant effects (we make none; see Section 15); and
  • Lodge a complaint with your supervisory authority (in the UK, the Information Commissioner's Office; in the EEA, the authority of your member state; in Switzerland, the FDPIC).

For data we hold as a processor, we will forward your request to the Customer. We respond to requests within one month, extendable by two further months for complex requests, and free of charge unless requests are manifestly unfounded or excessive. We may ask you to verify your identity, normally by replying from the email address on the account. We do not have an establishment in the EEA or UK; requests may be addressed to the Privacy Officer at privacy@app.servicerunner.app. If we appoint an EU or UK representative under Article 27, their details will be published here.

12. Your Rights: California (CCPA/CPRA)

This section applies to California residents and supplements the rest of this policy. In the preceding 12 months we collected the categories of personal information listed in Section 3, which map to the statutory categories of identifiers; customer records; commercial information; internet or network activity; geolocation data (precise, for technicians using the mobile app); audio or visual information (photos); professional or employment-related information (role, trade, organization); and inferences drawn only for operational purposes (for example, whether a device is offline). Sensitive personal information we collect is limited to account credentials and precise geolocation.

We collect it from the sources in Section 4, use it for the business purposes in Section 5, and disclose it for business purposes to the service providers on the Subprocessors page. We retain it as described in Section 8.

12.1 Your rights

  • Right to know what personal information we collect, use, disclose and sell or share, and to access it;
  • Right to delete personal information we collected from you, subject to exceptions;
  • Right to correct inaccurate personal information;
  • Right to opt out of sale or sharing. We do not sell personal information and do not share it for cross-context behavioral advertising, so there is nothing to opt out of; we honor the Global Privacy Control signal as a valid opt-out in any case;
  • Right to limit use of sensitive personal information. We use sensitive personal information only for the purposes permitted by regulation (providing the Service you requested, security, and, for geolocation, the workforce purposes the Customer configured), so no separate limit is needed;
  • Right to non-discrimination for exercising any right; and
  • Right to receive notice of financial incentives (we offer none).

12.2 Do Not Sell or Share My Personal Information

ServiceRunner does not sell or share personal information as those terms are defined in the CCPA. If we ever change that, we will add a "Do Not Sell or Share My Personal Information" link to our website and update this policy before doing so. Our website and apps recognize the Global Privacy Control (GPC) browser signal: when it is present we treat it as an opt-out of sale, sharing and non-essential cookies for that browser.

12.3 How to exercise your rights

Submit a request by emailing privacy@app.servicerunner.app with the subject "California privacy request", or through the contact page. We will verify the request by matching it to the account email and, where needed, asking for additional information. An authorized agent may submit a request on your behalf if they provide your signed permission and we can verify your identity directly. We respond within 45 days, extendable once by 45 days with notice. Requests about data we process for a Customer will be forwarded to that Customer, which is the "business" responsible for responding.

Notice at collection for job applicants, employees and contractors of Isles Mechanical is provided separately at the time of collection.

13. Your Rights: Canada (PIPEDA and Quebec Law 25)

If you are in Canada, PIPEDA and applicable provincial private-sector laws (including Alberta's and British Columbia's PIPA and Quebec's Act respecting the protection of personal information in the private sector, as amended by Law 25) govern our handling of your personal information.

  • Accountability. Our Privacy Officer is responsible for our compliance and can be reached at privacy@app.servicerunner.app. Under Law 25, this person exercises the function of the person in charge of the protection of personal information; their title and contact information are published here.
  • Consent. We rely on your express or implied consent, obtained at the time of collection, for purposes a reasonable person would consider appropriate in the circumstances, and on the Customer's authority for Customer Data. You may withdraw consent at any time, subject to legal or contractual restrictions and reasonable notice; withdrawal may mean we cannot continue to provide the Service.
  • Access and correction. You may ask what personal information we hold about you, how it is used and to whom it has been disclosed, and ask us to correct it. We respond within 30 days.
  • Cross-border processing. Your personal information may be stored and processed outside Canada, including in the United States, by us and our subprocessors, and may be accessible to the courts, law enforcement and national security authorities of those jurisdictions.
  • Quebec residents additionally have the right to be informed of and to object to decisions based exclusively on automated processing (we make none), to request de-indexing in the circumstances the law provides, to data portability in a structured technological format, and to file a complaint with the Commission d'accès à l'information du Québec. Privacy settings for optional features default to the highest level of confidentiality.
  • Complaints. You may complain to our Privacy Officer and, if unsatisfied, to the Office of the Privacy Commissioner of Canada or the relevant provincial commissioner.

14. Your Rights: Other U.S. States

Residents of states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Iowa, Delaware, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, Nebraska and Rhode Island, as those laws come into force) may have the right to confirm whether we process their personal data and to access it; to correct inaccuracies; to delete it; to obtain a portable copy; and to opt out of targeted advertising, the sale of personal data, and profiling in furtherance of decisions that produce legal or similarly significant effects. We do not engage in targeted advertising, sale or such profiling. Where the law requires consent to process sensitive data (such as precise geolocation), we obtain it through the device permission prompt and the Customer's configuration.

To exercise these rights, email privacy@app.servicerunner.app. We respond within 45 days, extendable once by 45 days. If we deny a request you may appeal by replying to our decision with the word "Appeal"; we will respond to the appeal within 45 days (60 in some states) and tell you how to contact your state attorney general if you are not satisfied. Most of these laws apply to data processed in an employment or business-to-business context only in limited ways; where we act as processor, your organization is the controller.

15. Children and Automated Decision-Making

15.1 Children

The Service is for use by adults in a work context. We do not knowingly collect personal data from anyone under 18, and never from children under 13 (or under 16 where that is the applicable threshold). Customers must not invite minors as users. If you believe a child has provided data to us, contact privacy@app.servicerunner.app and we will delete it.

15.2 Automated decision-making and profiling

We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects, and we do not profile users. Features such as route optimization, proximity prompts and maintenance reminders are tools that present suggestions to the Customer's staff, who decide what to do; they do not evaluate individuals.

16. Changes to This Policy

We may update this policy as the Service, our subprocessors or the law change. The "Last updated" date shows the current version. For material changes that reduce your rights or expand what we collect or share, we will notify account owners by email and post a notice in the Service at least 30 days before the change takes effect, and, where consent is required, ask for it. Prior versions are available on request.

17. Contact and Data Protection Officer

  • Privacy Officer / DPO: privacy@app.servicerunner.app
  • Privacy requests: privacy@app.servicerunner.app
  • Security: security@app.servicerunner.app
  • General support: support@app.servicerunner.app
  • Post: Isles Mechanical LLC, Attn: Privacy (postal address available on request from privacy@app.servicerunner.app)

Version 2026-09-13. This policy is written in English; where a translation is provided, the English text controls to the extent permitted by law.

ServiceRunner

Booking, dispatch, service history and billing for HVAC and mechanical service teams.

homeemail
Product
Features
Pricing
Start Free Trial
Company
Contact
Legal
Terms of Service
Privacy Policy
Data Processing Addendum
Acceptable Use Policy
Cookie Policy
Subprocessors
Mobile App EULA
Cookie preferences
Ready to get started?

New organizations start with a 30-day Pro trial. No credit card required.

Start 30-day Pro trialarrow_forward

© 2026 Isles Mechanical LLC. All rights reserved. ServiceRunner is a product of Isles Mechanical LLC.
TermsPrivacyCookiesContact
Cookies and local storage. ServiceRunner uses strictly necessary storage to keep you signed in, remember your settings and work offline. We do not use advertising or analytics cookies today. Optional categories are off unless you turn them on. Cookie Policy