Privacy Policy
Effective date: September 17, 2026
AysOps ("AysOps", "we", "us", or "our") is operated by At Your Service Operations, a trade name of 14289650 Canada Inc.. We provide business-management software for consultants and small businesses at aysops.com. This policy explains what information we collect, how we use it, and the choices you have. By using AysOps you agree to this policy.
Information we collect
- Account information — your name, email address, company name, and password (stored only as a secure hash), provided when you create an account.
- Sign-in identities — if you sign in or connect Google or Microsoft, we receive your basic profile from that provider: name, email address, and profile picture. We do not receive your Google or Microsoft password.
- Business data you enter — information you and your team add while using the service, such as customer records, estimates, work orders, invoices, expenses, mileage logs, notes, and uploaded files. This data belongs to you.
- Approvals from your customers — when one of your customers approves an estimate through the link you send, we record the name they type, the signature they draw, the date and time, their IP address, and their browser's user-agent string, as evidence of the approval for you and them.
- Addresses and location for mileage — when you look up an address or plan a trip, the address text (or, if you press Current location, your device's location at that moment) is sent to OpenStreetMap-based lookup and routing services to find the place and the driving distance. We use your device location only when you press that button, and store it only as the starting point of a trip you save. We never track your location in the background.
- Payment information — subscription payments are processed by Stripe. We store your subscription status and billing history; we never see or store full card numbers. If you use the optional online payments add-on to let your customers pay invoices, Stripe collects the identity and bank details it needs to verify your business, and processes your customers' card or bank payments; we receive only the payment's status, amount, and method type — plus, when a customer saves a card for automatic payments, its brand and last four digits so you can see which card will be charged (never the full number, expiry date, or security code).
- Technical information — session cookies, security events (such as blocked requests and login attempts), error reports, and standard server logs used to keep the service secure and reliable. We also measure page performance and page views with Vercel's privacy-focused analytics, which does not use cookies or identify you.
- Activity log — to give businesses an audit trail, we record who in your account created, changed, sent, or deleted what, and when. The owners and administrators of your company account can see this log.
- Device and sign-in activity — for each browser you sign in from we record an anonymous device identifier, the IP address, the country (and, where available, the approximate city) that address resolves to, and the browser's user-agent string. We use this only to detect a compromised or shared login — for example the same account being used from two countries within minutes. It is never used for advertising or profiling, and we do not track precise location. These records are deleted automatically after 90 days of not being seen.
- Calendar availability — if you connect the optional Calendar Sync add-on, we periodically read busy/free intervals from your own calendar so your team's work calendar can show when you are unavailable. You can also choose additional calendars of your own to be treated the same way; none are included unless you tick them, and you can untick one at any time, which removes the times it contributed. From any calendar — your default one or any you add — we store only the start time, end time, and which calendar the interval came from — never event titles, locations, descriptions, or attendees. Intervals are refreshed on a rolling 60-day window and deleted shortly after they pass; disconnecting your calendar stops the collection.
- Meeting transcripts — if you use the AysOps for Zoom add-on and switch on the optional transcript import, then for meetings you chose to record in Zoom we download the transcript Zoom produces and store it as an ordinary file in your account, filed against the relevant customer. We store the text only — never the audio or video recording. This is off unless you switch it on, we never start or request a recording ourselves, and transcripts are kept, deleted, and access-controlled exactly like any other file you hold. Switching the setting off stops any further import. If the Zoom integration ends for any reason — you disconnect in AysOps, cancel the AysOps for Zoom add-on, remove the app in Zoom, or the add-on lapses because a trial or subscription ended — we delete the transcripts we imported.
- Google Meet transcripts — if you connect Google Calendar through the Calendar Sync add-on and switch on the optional Google Meet transcript import, then for your appointments that used a Google Meet link, and only where transcription was turned on in the Meet call, we read the transcript Google produced (with the permission to read Meet meeting records you approve for that feature) and store its text only as an ordinary file in your account, filed against the relevant customer. We never access the audio or video recording or any other Google Drive file. This is off unless you switch it on, and it requires a Google Workspace edition that offers transcripts. Switching it off stops further imports. If you disconnect your Google calendar — or the add-on ends — we delete the Meet transcripts imported through that connection.
- Microsoft Teams transcripts — if you connect a Microsoft 365 calendar through the Calendar Sync add-on and switch on the optional Teams transcript import, then for your appointments that used a Microsoft Teams link, and only where transcription was turned on in the Teams call, we read the transcript Microsoft produced (with the permissions to find your Teams meetings and read their transcripts that you or your Microsoft 365 administrator approve for that feature) and store its text and speaker names only as an ordinary file in your account, filed against the relevant customer. We never access the audio or video recording, chat, or any other Teams or OneDrive content. This is off unless you switch it on, and it requires a Microsoft 365 plan that includes Teams. Switching it off stops further imports. If you disconnect your Microsoft 365 calendar — or the add-on ends — we delete the Teams transcripts imported through that connection.
- Events on the AysOps calendar — the Calendar Sync add-on creates a separate calendar in your account for your work appointments. That one is two-way: if you add or change an event on it, we read and store the event's title, description, and times so it appears in AysOps and can be edited from either side. This applies only to the calendar AysOps created — we never read the contents of your personal or other calendars. Deleting the AysOps calendar, or disconnecting, stops it.
Google user data
When you sign in with Google, we request only your basic profile information (name, email address, and profile picture) to create and secure your account. We do not request access to your Gmail, Google Drive, Contacts, or any other Google service data.
If you choose to connect the optional Calendar Sync add-on with a Google account, we additionally request two narrow Calendar permissions: the ability to manage only the calendar AysOps creates (where your work appointments are pushed — we read and write the events on that one calendar, including their titles and descriptions, and we cannot see or change your other calendars), read-only free/busy access, which tells us when you are busy but not what any event is, and permission to see the list of your calendars — their names only, so we can offer them for you to choose from. We do not read the events in them. With the optional AysOps for Google Meet and Microsoft Teams add-on, when you ask for a Meet link on an appointment we add a Google Meet conference to the appointment on the calendar AysOps created. You can revoke this at any time by disconnecting in AysOps or from your Google account's security settings.
If you additionally switch on Google Meet transcript import (part of the optional AysOps for Google Meet and Microsoft Teams add-on; off unless you enable it), we ask for one more permission at that moment: read-only access to your Google Meet meeting records. We use it for exactly one thing — for your own appointments that used a Google Meet link, and only where transcription was turned on in the call, we read the transcript text and the participants' display names and save that text as a file in your account, filed against the relevant customer, so you have a written record of the conversation. We never access the audio or video recording, any Google Drive file, or any meeting that was not held from your own appointment. Transcripts are stored like any other file in your account, are never used to train AI models, and are deleted automatically when you disconnect your Google calendar from AysOps (or when the add-on ends). You can turn the import off at any time in Settings → Calendar Sync, or revoke the permission from your Google account's security settings.
The use and transfer by AysOps of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Microsoft user data
When you sign in with Microsoft, we request only your email address and basic profile to create and secure your account. We do not request access to your mail, files, contacts, or Teams data (the optional Teams transcript import below is the only exception, and only if you switch it on).
If you connect the optional Calendar Sync add-on with a Microsoft account, we request permission to read and write your calendars (Calendars.ReadWrite, with offline access so the connection keeps working when you are not signed in). We use it for three things: we create a separate calendar named for AysOps and manage the appointments on it (both ways — changes you make to that calendar in Outlook come back into AysOps); we read when you are busy from your own calendars so your team can see your availability — start and end times and busy/free status only, never the title, location, or attendees of any event; and, with the optional AysOps for Google Meet and Microsoft Teams add-on, when you ask for a Teams link on an appointment we set the appointment we created to be a Teams meeting. Additional calendars are included only if you tick them, and unticking one removes the times it contributed. Microsoft does not let an app withdraw its own permission, soafter disconnecting in AysOps you can also remove AYS Operations at myapplications.microsoft.com.
If you choose to send invoices and documents from a Microsoft mailbox, we request permission to send mail as you (Mail.Send) and to read your basic profile. We send only the messages you choose to send; we never read your inbox. The tokens for every Microsoft connection are stored encrypted and deleted when you disconnect.
If you additionally switch on Teams transcript import (part of the optional AysOps for Google Meet and Microsoft Teams add-on; off unless you enable it), we ask for two more permissions at that moment: OnlineMeetings.Read (to find the Teams meeting behind an appointment's link) and OnlineMeetingTranscript.Read.All (to read that meeting's transcript). Microsoft requires a Microsoft 365 administrator to approve the second one for the organisation. We use them for exactly one thing — for your own appointments that used a Teams link, and only where transcription was turned on in the call, we read the transcript text and speaker names and save that text as a file in your account, filed against the relevant customer. We do not read recordings, chats, or any other meeting content, and imported transcripts are deleted when you disconnect.
Apple Calendar
Apple has no app-specific permissions for calendars: connecting an iCloud calendar uses an app-specific password that Apple issues for your whole account. We use it only to manage the AysOps calendar and to read when you are busy (times and busy status only) — nothing else, and never your mail, contacts, or files. The password is stored encrypted and deleted when you disconnect; you can also revoke it at any time at appleid.apple.com, which ends our access immediately.
Zoom data
If you enable the AysOps for Zoom add-on, you connect your own Zoom account — either through the AYS Operations app in the Zoom App Marketplace, or by entering your own Zoom Server-to-Server credentials. Either way the permissions are the same: to create, view, update, and delete meetings on your Zoom account, and — only if you switch on transcript import — to read your cloud recordings' transcripts. We use them to create a Zoom meeting for each remote appointment (its topic and time), to give you the join and start links, to move the meeting when you reschedule, and to remove it when you cancel. We never create a Zoom meeting you did not schedule, and we never start or join one.
Transcript import is off unless you switch it on. When it is on, for meetings you chose to record in Zoom we download the transcript Zoom produced and save it as a file in your account, filed against the relevant customer. We store the text only — never the audio or video recording — and we never use Zoom content to train AI models. Your Zoom credentials are stored encrypted. If the Zoom integration ends for any reason — you disconnect in AysOps, cancel the add-on, remove the app in Zoom, or the add-on lapses — we withdraw our access from your Zoom account and delete every transcript we imported.
QuickBooks (Intuit) data
If you enable the QuickBooks Sync add-on, you connect your own QuickBooks Online company through Intuit's sign-in; we never see your Intuit password. We request the QuickBooks accounting permission, which covers the records the feature syncs: customers (names, companies, emails, phones, and billing and shipping addresses), vendors, products and services with their prices, tax rates, invoices and estimates with their line items and payments, and expenses. The sync is two-way for those records — we read them from your QuickBooks company and write the ones you choose to send — nightly and when you run it by hand. We do not read payroll, banking, or any other part of your books.
When AysOps needs to decide whether a QuickBooks record and an AysOps record are the same thing, it may ask our AI provider to compare the names only — customer, vendor, item, and account names, never contact details or amounts — and you confirm every link before it is made. Your Intuit tokens are stored encrypted; disconnecting withdraws our access at Intuit and deletes the tokens. Records already in your QuickBooks company stay there — they are your books, not ours.
How we use your information
- To provide, maintain, and improve the service.
- To authenticate you and secure your account (including two-factor authentication).
- To process subscription billing and send transactional emails (such as invoices you choose to send, receipts, and security notices).
- To respond to support requests.
- To detect, investigate, and prevent abuse, fraud, and security incidents.
We do not sell your personal information, and we do not use your data for third-party advertising.
Cookies
We use only cookies necessary to operate the service: your login session; your two-factor verification state, including a "trusted device" cookie that skips the code on that browser for 30 days; a short-lived re-confirmation cookie for sensitive actions; an anonymous device identifier used for the sign-in security checks described above; and your selected company. Some screens also remember display preferences (such as which list sections you left open) in your browser's own storage; this never leaves your device. We do not use third-party advertising or cross-site tracking cookies.
Where your data lives and who processes it
We rely on a small number of service providers to run AysOps:
- Supabase — database, authentication, and file storage.
- Vercel — application hosting and privacy-focused page analytics.
- Amazon Web Services — delivery of the emails AysOps sends on its own behalf, such as sign-in codes, account and billing notices, and reminders. (Invoices and documents you send go through the email account you connect, or through this service if you have not connected one or your own mailbox fails.)
- Stripe — subscription payment processing.
- Google / Microsoft / Apple — optional sign-in providers (Google, Microsoft) and, if you connect the Calendar Sync add-on, the calendar provider you choose to link.
- Zoom — only if you connect the AysOps for Zoom add-on; see "Zoom data" above.
- OpenStreetMap-based services — address search (Nominatim) and driving-distance routing (OSRM) for mileage and address lookups. Only the address or location being looked up is sent, never your name or account details.
- Cloudflare — Turnstile bot protection on our public contact form, which checks the visitor's browser to block automated spam.
- Anthropic — optional AI features. When you actively use an AI feature, the content it works on is sent to Anthropic for processing: documents and images you upload for reading (such as receipts, invoices, and odometer photos, including the values on them), — for QuickBooks matching suggestions — customer, vendor, and item names only, never their contact details, and — for public-holiday suggestions — your business's country, province or state, and city. Anthropic is a US processor; it does not train on this data, and retains it only briefly for abuse monitoring before deletion.
- Intuit (QuickBooks Online) — only if you connect the QuickBooks Sync add-on to your own QuickBooks company. Syncing is two-way for the data the feature covers: customer, vendor, item and tax-rate records, and the invoices, payments and expenses you choose to send, are exchanged between AysOps and your QuickBooks company. This only ever involves the QuickBooks company you authorize, and you can disconnect it at any time.
If you connect your own email account (SMTP) to send invoices and documents, those emails are sent through your configured email provider; your email credentials are stored encrypted.
Your account data and uploaded files are stored in Canada (Supabase, on Amazon Web Services' Montréal region). Some of the providers above — including our application host, email delivery, and AI provider — may process information in the United States or other countries, where it may be accessible to the authorities of those countries under their laws.
Your customers' data
The customer records, invoices, and other business data you enter may contain personal information about your own customers. You control that data: you decide what to enter, and you are responsible for having the right to store it. We process it only to provide the service to you and never use it for our own purposes.
Data retention and deletion
Your data is retained while your account is active. If you delete records in the app they are removed or marked deleted (some records, such as deleted work orders, are retained in a recoverable state so our support team can restore them at your request). If you close your account, we delete your data within a reasonable period, except where we must keep records to meet legal, tax, or accounting obligations. Backups expire on a rolling schedule.
Security
All traffic is encrypted in transit (HTTPS). Data access is enforced per account at the database level, uploaded files are scanned against unsafe file types, two-factor authentication is required on every account (setting it up can be postponed a week at a time), and security-relevant events are logged. Passwords stored in the optional Password Vault, and the credentials for every integration you connect, are encrypted with keys kept separate from the database; revealing a vault password requires your vault passphrase and is logged.
Your rights
You may access, correct, export, or delete your personal information. Most of this is available directly in the app; for anything else, contact us at [email protected] and we will respond within 30 days. You can withdraw consent to any optional integration at any time by disconnecting it, which stops further collection. Depending on where you live, you may have additional rights under local privacy law (such as PIPEDA in Canada or the GDPR in the EU). If you are not satisfied with our response, you may complain to your local privacy regulator, such as the Office of the Privacy Commissioner of Canada.
Children
AysOps is a business tool and is not directed to children under 16. We do not knowingly collect personal information from children.
Changes to this policy
We may update this policy as the service evolves. Material changes will be announced in the app or by email before they take effect, and the effective date above will be updated.
Contact
AysOps is operated by At Your Service Operations, a trade name of 14289650 Canada Inc.. Questions about this policy or your data: [email protected]