← Back to Zonde.io

Privacy Policy

Anvil by Zonde · Last updated June 2026

This policy covers Anvil — the multi-tenant field service management platform operated by ZONDE LLC. It does not cover Zonde Monitoring (our IoT product); see zonde.io/privacy.html for that.

1. What We Collect

Tenant accounts. When a service business creates an Anvil account, we collect the account holder's name, work email, business name, and password. Tenants may optionally add additional team members, in which case we collect each user's name and email.

Customer data uploaded by tenants. Tenants use Anvil to manage their existing customers. Each customer record may contain: name, billing address, email, phone number, service site addresses, and a service history (visits, proposals, invoices, signoffs). All of this data is owned by the tenant; Anvil holds it as a data processor on the tenant's behalf.

SMS interaction logs. When Anvil sends an SMS on a tenant's behalf and the recipient replies (e.g. YES/NO to a confirmation request, or STOP to opt out), the reply text and timestamp are logged for audit purposes.

Operational data. We collect logs of API requests, errors, and authentication events to operate, secure, and debug the platform.

We do not collect payment information from end customers or data unrelated to operating the platform.

1b. Mobile Application Data

The Anvil iOS app requests additional device permissions to support field technician workflows. This data is used only within the app and is not transmitted to Anvil servers except where explicitly noted below.

2. How We Use It

We do not send marketing emails or SMS, and we do not sell or share data with third parties for advertising.

3. SMS Messaging

Anvil sends SMS to customers of tenant businesses (HVAC and similar service companies) for operational purposes only: appointment confirmations, proposals, invoices, and job signoff requests. Anvil does not send marketing or promotional SMS.

Consent model. Tenants are contractually required, under our Terms of Service, to obtain SMS consent from each of their customers (typically during service intake or appointment scheduling) before adding them to the platform with a phone number flagged for SMS messaging. Anvil acts as a service provider (data processor) to the tenant for SMS delivery; the tenant is the entity collecting consent and identifying themselves in every message.

Opt-out. Recipients can opt out at any time by replying STOP to any SMS — the carrier and our SMS provider (Twilio) immediately block all future messages to that number from the toll-free line, regardless of the tenant's state.

No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.

For full details on how SMS works on Anvil — including who sends what, opt-in / opt-out keywords, and message frequency — see our SMS Policy. Recipients can also visit the Anvil SMS Disclosure page for a plain-language explanation of why they're receiving messages.

4. How We Protect Your Data

5. Where Data Is Stored

Anvil tenant and customer data is stored on servers hosted on Amazon Web Services in the United States (us-east-1, AWS Lightsail + RDS). Data is retained while the tenant account is active. SMS interaction logs (sends, deliveries, replies) are retained for at least 12 months for audit purposes.

6. Third-Party Services

We use the following providers to operate Anvil:

These providers process data only as necessary to deliver their services. Each is bound by their own data-processing agreement. We do not share Anvil data with any other third parties.

7. Cookies

We use a single session cookie to keep tenant users logged in. We do not use tracking cookies, analytics cookies, or any third-party advertising cookies.

8. Tenant Rights

9. End-Customer Rights

If you are a customer of a tenant business and have data on Anvil:

10. Children's Privacy

Anvil is not directed at individuals under the age of 18. We do not knowingly collect data from children.

11. Changes to This Policy

We may update this policy as the platform evolves. Material changes will be communicated via email to registered tenants. Continued use of the service constitutes acceptance of the updated policy.

12. Contact

Questions about this policy: [email protected]