← Back to Anvillo.com
Privacy Policy
Anvillo · Last updated September 2026
This policy covers Anvillo — the multi-tenant field service management platform operated by ANVIL PLATFORM LLC.
1. What We Collect
Tenant accounts. When a service business creates an Anvillo account, we collect the account holder's name, work email, business name, and password. Tenants may optionally add additional team members, in which case we collect each user's name and email.
Customer data uploaded by tenants. Tenants use Anvillo to manage their existing customers. Each customer record may contain: name, billing address, email, phone number, service site addresses, and a service history (visits, proposals, invoices, signoffs). All of this data is owned by the tenant; Anvillo holds it as a data processor on the tenant's behalf.
SMS interaction logs. When Anvillo sends an SMS on a tenant's behalf and the recipient replies (e.g. YES/NO to a confirmation request, or STOP to opt out), the reply text and timestamp are logged for audit purposes.
Operational data. We collect logs of API requests, errors, and authentication events to operate, secure, and debug the platform.
We do not collect payment information from end customers or data unrelated to operating the platform.
1b. Mobile Application Data
The Anvillo iOS app requests additional device permissions to support field technician workflows. This data is used only within the app and is not transmitted to Anvillo servers except where explicitly noted below.
- Location (when in use). Used to geotag job site photos and to record when a technician arrives at or leaves a job site. Location coordinates attached to photos are stored on Anvillo servers as part of the job record.
- Camera and photo library. Used to capture and attach job site photos to job records. Photos are uploaded to and stored on Anvillo servers (AWS S3) as part of the job record.
- Face ID / biometrics. Used to authenticate the technician when re-opening the app. Biometric data never leaves the device and is never transmitted to Anvillo servers — authentication is handled entirely by iOS.
- Microphone. Used only when a technician chooses to dictate a job note by voice. Audio is processed on-device by iOS speech recognition and is not recorded or stored by Anvillo.
- Speech recognition. Used to transcribe dictated job notes. Transcription is handled by iOS on-device speech recognition. The resulting text is stored on Anvillo servers as part of the job record.
2. How We Use It
- To provide and operate Anvillo for tenants and their staff
- To send transactional emails to tenant users (email verification, password reset, security alerts)
- To send appointment confirmation, proposal, invoice, and signoff SMS to customers on behalf of tenants who have enabled those features
- To display tenant-managed customer records, schedules, fleet data, and reports inside the platform
- To diagnose errors and improve reliability
We do not send marketing emails or SMS, and we do not sell or share data with third parties for advertising.
3. SMS Messaging
Anvillo sends SMS to customers of tenant businesses (HVAC and similar service companies) for operational purposes only: appointment confirmations, proposals, invoices, and job signoff requests. Anvillo does not send marketing or promotional SMS.
Consent model. Tenants are contractually required, under our Terms of Service, to obtain SMS consent from each of their customers (typically during service intake or appointment scheduling) before adding them to the platform with a phone number flagged for SMS messaging. Anvillo acts as a service provider (data processor) to the tenant for SMS delivery; the tenant is the entity collecting consent and identifying themselves in every message.
Opt-out. Recipients can opt out at any time by replying STOP to any SMS — the carrier and our SMS provider (Twilio) immediately block all future messages to that number from the toll-free line, regardless of the tenant's state.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
For full details on how SMS works on Anvillo — including who sends what, opt-in / opt-out keywords, and message frequency — see our SMS Policy. Recipients can also visit the Anvillo SMS Disclosure page for a plain-language explanation of why they're receiving messages.
4. How We Protect Your Data
- Passwords are hashed using bcrypt — they are never stored in readable form
- All connections to the platform are encrypted via HTTPS (TLS)
- Database access is restricted to the application server only
- Session cookies are HTTP-only and Secure
- Multi-tenant isolation is enforced at every database query — tenant data is never returned to a different tenant's session
- Two-factor authentication (TOTP) is available for tenant accounts
- Inbound webhook signatures (Twilio) are cryptographically validated before processing
5. Where Data Is Stored
Anvillo tenant and customer data is stored on servers hosted on Amazon Web Services in the United States (us-east-1, AWS Lightsail + RDS). Data is retained while the tenant account is active. SMS interaction logs (sends, deliveries, replies) are retained for at least 12 months for audit purposes.
6. Third-Party Services
We use the following providers to operate Anvillo:
- Amazon Web Services (AWS) — cloud hosting (Lightsail, RDS, S3) and email delivery
- Twilio — SMS delivery for appointment confirmations, proposals, invoices, and signoffs
- Resend — transactional email delivery
- Stripe — payment processing for web subscriptions and, for businesses that enable it, customer invoice payments (Stripe Connect / Tap to Pay)
- Apple (App Store) and RevenueCat — iOS subscription purchases are made through Apple In-App Purchase; RevenueCat receives the purchase receipt and the business account identifier so we can tell which business is subscribed. Neither receives customer records.
- Anthropic — the AI assistant, document and equipment-nameplate text extraction, and phone-call summaries are produced by Anthropic's Claude models. When a user asks the assistant a question, the question and the business records it needs to answer (for example customer names, job titles, invoice balances) are sent to Anthropic for processing. Scanned documents, nameplate photos, and call transcripts are sent for the same purpose. Anthropic processes this data to return a result and does not use it to train its models. Nothing is sent unless a user invokes one of these features.
- Google Maps Platform — address autocomplete and geocoding for service sites
- Sentry — error monitoring
- Let's Encrypt — TLS certificates
These providers process data only as necessary to deliver their services. Each is bound by their own data-processing agreement. We do not sell Anvillo data, and we do not share it with any third party other than those listed here.
7. Cookies
We use a single session cookie to keep tenant users logged in. We do not use tracking cookies, analytics cookies, or any third-party advertising cookies.
8. Tenant Rights
- Tenants can update account details and preferences at any time inside the platform
- Tenants can request a data export at any time by emailing [email protected] — we will provide a machine-readable export within 30 days
- Any user can delete their own account inside the iOS app (More → Settings → Delete account) or by emailing [email protected]. Deleting the only owner of a business closes the whole business account: every user is signed out immediately and all of its data is permanently deleted after a 30-day grace period. Deleting a staff account signs that person out immediately; their name, email, and phone number are removed from our systems within 30 days, while the business keeps its work records (time entries, visits, sign-offs) attributed to a de-identified user, as its employment and accounting records require.
- Tenants can also request deletion of the entire account and all associated data by emailing [email protected] — we will process deletion within 7 business days
9. End-Customer Rights
If you are a customer of a tenant business and have data on Anvillo:
- Reply STOP to any SMS to opt out of all future messages from the Anvillo toll-free number
- Contact your service business directly to update your contact information or request that they remove you from their records
- You may also email [email protected] with a data-access or data-deletion request; we will route it to the relevant tenant business
10. Children's Privacy
Anvillo is not directed at individuals under the age of 18. We do not knowingly collect data from children.
11. Changes to This Policy
We may update this policy as the platform evolves. Material changes will be communicated via email to registered tenants. Continued use of the service constitutes acceptance of the updated policy.
12. Contact
Questions about this policy: [email protected]