01
Who we are and what this covers
Acruxly is a service management platform. Businesses use it to keep client records, schedule and track jobs, assign work to their team, and follow what each job cost and earned.
This policy covers the Acruxly website and application. It does not cover the privacy practices of the businesses that use Acruxly to serve their own clients, or of any third-party website we link to.
02
Businesses, their teams, and their clients
Two different relationships run through Acruxly, and the distinction decides who answers a privacy request.
When a business signs up, we handle that business's own account information β the people who administer the workspace and the team members who work in it. We decide how that information is used, within this policy.
When that business then adds its clients, records their addresses and logs the jobs it performed for them, we are holding that information on the business's behalf. The business decides what is collected and how long it is kept; we process it to provide the service and follow the business's instructions.
If a business entered your details into Acruxly as one of its clients, that business is the right place to send an access, correction or deletion request. We will help them respond, and if you contact us directly we will pass the request along.
03
Information we collect
We collect the following categories of personal information:
- Account information β the email address you sign in with and the name on your account.
- Business profile β company name, tax identification number, contact email and phone, and business addresses, when an account owner provides them.
- Team information β the names, email addresses, phone numbers, addresses and working availability that a business records for its team members.
- Client records β the names, email addresses, phone numbers and service addresses that a business records for its own clients.
- Job and financial records β scheduled dates, job descriptions, assigned team members, line items and prices, labour hours, expenses, and the profitability figures calculated from them.
- Sign-in and session data β the one-time codes we email you, and the session tokens stored in cookies that keep you signed in.
- Security log data β for authentication events such as sign-in attempts, we record the event type, the email address used, the IP address and the browser user agent, with a timestamp.
- Diagnostic data β when the application errors, our monitoring provider receives a technical report that may include the page involved, browser details and the account identifier.
04
Where the information comes from
Almost all of it comes directly from you or from the business whose workspace you belong to. The rest is generated automatically as you use the service: session cookies, security log entries and error reports.
One feature draws on an outside source. When you type an address, we offer suggestions through the Google Places API, which means what you type into that field is sent to Google to return matches.
05
How we use information
We use personal information to:
- Provide the service β authenticate you, keep you signed in, and show you the records you are allowed to see.
- Send transactional email β sign-in codes, account notices and changes that affect your access.
- Keep accounts secure β detect and investigate suspicious sign-ins, enforce rate limits, and maintain the security log.
- Keep the service working β diagnose errors, monitor performance and fix defects.
- Administer paid plans, if and when your business subscribes to one.
- Comply with the law and enforce our Terms of Service.
We do not use your information, or your clients' information, to train advertising profiles or to build products for anyone else.
06
How we share information
We share personal information with service providers who process it on our behalf, under contract, only to perform the functions we hired them for:
- Resend β delivers our transactional email, including sign-in codes.
- Upstash β provides the rate-limiting layer that protects sign-in and other sensitive endpoints.
- Sentry β receives error and performance reports from the application.
- Google β returns address suggestions through the Places API when you type into an address field.
- Our hosting and database providers β run the application and store its data.
We also share information inside your own workspace, according to the role each person holds, and we may disclose it when the law requires it, to respond to valid legal process, to protect our rights or someone's safety, or in connection with a merger, acquisition or sale of assets β in which case this policy continues to apply to the information transferred.
07
We do not sell or share personal information
We do not sell personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under California law. We have not done so in the preceding twelve months, including for anyone under sixteen years of age.
We run no advertising network, no marketing pixels and no third-party analytics on the application.
08
Cookies and similar technologies
Acruxly uses cookies that are strictly necessary to operate: a session cookie that keeps you signed in (acruxly_auth) and a refresh cookie that renews that session (acruxly_refresh). Both hold signed tokens, and clearing them signs you out.
We also set a cookie that records the language you are browsing in (NEXT_LOCALE), so the interface loads in that locale. We do not use advertising or tracking cookies.
09
Do Not Track
Because we do not track you across other websites, we take no action on Do Not Track browser signals. There is nothing for them to switch off.
10
How long we keep information
Account and workspace records are kept for as long as the account is active. Sign-in codes expire within minutes of being issued, and sessions expire on their own schedule and are removed after that.
Security log entries are retained so we can investigate account compromise. Records that a business created about its own clients and jobs are kept until that business deletes them or closes its account.
After an account closes we delete or anonymize the information, except where we must keep it to comply with a legal obligation, resolve a dispute or enforce our agreements. Backups are overwritten on their normal cycle.
11
How we protect information
Sign-in uses one-time codes sent to your email address rather than stored passwords. Sessions are short-lived and signed. Access inside a workspace is checked on every request against your role, and sensitive endpoints are rate limited. Data is encrypted in transit, and our database provider encrypts it at rest.
No system is perfectly secure. We cannot guarantee that unauthorized access will never occur, and you are responsible for keeping access to your email account secure β anyone who can read your email can request a sign-in code.
12
Your choices
You can review and update the information in your profile at any time while signed in. Team members and client records can be corrected by an administrator of the workspace they belong to.
You can ask us to close your account and delete your information by writing to support@acruxly.com. Transactional email β sign-in codes and notices about your account β cannot be turned off while the account is open, because the service depends on it.
13
Your California privacy rights
If you are a California resident, the California Consumer Privacy Act gives you the right to know what personal information we have collected about you, the sources it came from, why we collected it and who we disclosed it to; to receive a copy of it; to correct inaccuracies; and to ask us to delete it.
You also have the right to opt out of the sale or sharing of personal information and to limit the use of sensitive personal information. We do neither, so there is nothing to opt out of. We will not discriminate against you for exercising any of these rights.
To make a request, email support@acruxly.com. We will verify your identity by confirming control of the email address on the account, or by matching the details you give us against our records. We respond within forty-five days and may extend that once when necessary. An authorized agent may act for you with written permission that we can verify.
14
Other US state privacy rights
Residents of states with comprehensive privacy laws β including Colorado, Connecticut, Virginia, Utah, Texas, Oregon and Montana, among others β have comparable rights: to confirm whether we process their personal information, to access and correct it, to delete it, and to obtain a portable copy.
These laws also grant the right to opt out of targeted advertising, the sale of personal information and profiling that produces legal or similarly significant effects. We do not engage in any of those activities.
Where the law provides one, you may appeal a decision on your request by replying to our response. Nevada residents may submit a request that we not sell their personal information, which we do not do in any case. Send any of these requests to support@acruxly.com.
15
Information we do not want
Acruxly is not built to hold sensitive personal information, and we ask you not to enter it. Do not record racial or ethnic origin, religious beliefs, health conditions, biometric data, precise geolocation, government identification numbers or payment card numbers in free-text fields such as job descriptions and notes.
The service has no need for that information and we do not request it.
16
Children's privacy
Acruxly is a business tool and is not directed at children. We do not knowingly collect personal information from anyone under sixteen. If we learn that we have, we will delete it. A parent or guardian who believes a child has given us information can write to support@acruxly.com.
17
Users outside the United States
Acruxly is operated from the United States and the information we hold is processed there. If you use the service from another country, you understand that your information will be transferred to and processed in the United States, where privacy law may differ from that of your own country.
18
Changes to this policy
We may update this policy as the product changes. When we do, we revise the date at the top of the page. If a change materially affects how we handle personal information, we will give notice by email or in the application before it takes effect. Continuing to use Acruxly after a change means you accept the revised policy.
19
Contact us
Questions about this policy, or requests about your personal information, go to support@acruxly.com.
If your request concerns records that a business entered into Acruxly about you as its client, tell us which business, and we will forward the request to them.