Privacy Policy
Effective July 13, 2026
Ventoxy (“Ventoxy,” “we,” “us”) is field-service software for HVAC contractors. This policy explains what we collect, why, and the choices you have. It is written to be read, not to hide behind legalese — if anything is unclear, email hello@ventoxy.com.
1. Who this covers
This policy covers our customers — the HVAC business owners and their team members who sign up for Ventoxy (“you”) — and the marketing visitors to ventoxy.com. Separately, you use Ventoxy to store information about your own customers (names, addresses, equipment, jobs). For that data you are the controller and we are your processor: we hold it on your behalf and only act on your instructions.
2. What we collect
- Account data — your name, email, phone, company name, and password (hashed, never stored in plain text).
- Business data you enter — customers, properties, equipment records, leads, jobs, quotes, invoices, payments, messages, photos, and your price book.
- Billing data — your subscription plan and status. Card details are handled by our payment processor (Paddle) as merchant of record; we never see or store your full card number.
- Usage & diagnostics — basic product analytics (pages viewed, key actions) and error reports, used to keep the app working and improve it.
3. How we use it
- To provide the service — run your account, send the quotes and invoices you create, draft AI follow-ups for your approval.
- To bill your subscription and support you.
- To keep the product secure, debug problems, and improve features.
- To send you service-related email (receipts, security notices, and — only if you opt in — product updates).
We do not sell your data, and we do not use your business data to train AI models for anyone else.
4. Sub-processors we share data with
To run Ventoxy we rely on a small set of vetted service providers, each acting under contract:
- Neon — database hosting.
- Vercel — application hosting.
- Cloudflare R2 — photo and file storage.
- Paddle — subscription billing (merchant of record).
- Stripe — processing card payments you collect from your own customers (Stripe Connect).
- Resend — sending quote and invoice emails.
- Twilio — sending text messages (as this rolls out).
- Anthropic — powering AI draft suggestions (content is not retained to train models).
- PostHog / Sentry — product analytics and error monitoring.
We do not share your data with anyone else except when required by law.
5. Your customers’ consent (TCPA)
You are responsible for having consent to text or email the customers you add to Ventoxy. We record consent status per contact, never assume it, and honor STOP replies immediately by revoking messaging consent.
6. Data retention & your rights
- It’s yours. Export all of your data as CSV at any time, for free.
- Deletion. Cancel and ask us to delete your account and we remove your data (backups age out on a rolling ~30-day cycle).
- Access & correction. You can view and edit your data in-app, or email us for help.
7. Security
Data is encrypted in transit (HTTPS) and at rest. Each account’s data is isolated at the database level with row-level security so one business can never see another’s. Access on our side is limited to what’s needed to operate and support the service.
8. Changes & contact
If we make a material change we’ll post it here and update the date above. Questions, requests, or concerns: hello@ventoxy.com.