This policy covers Anvil — the multi-tenant field service management platform operated by ZONDE LLC. It does not cover Zonde Monitoring (our IoT product); see zonde.io/privacy.html for that.
Tenant accounts. When a service business creates an Anvil account, we collect the account holder's name, work email, business name, and password. Tenants may optionally add additional team members, in which case we collect each user's name and email.
Customer data uploaded by tenants. Tenants use Anvil to manage their existing customers. Each customer record may contain: name, billing address, email, phone number, service site addresses, and a service history (visits, proposals, invoices, signoffs). All of this data is owned by the tenant; Anvil holds it as a data processor on the tenant's behalf.
SMS interaction logs. When Anvil sends an SMS on a tenant's behalf and the recipient replies (e.g. YES/NO to a confirmation request, or STOP to opt out), the reply text and timestamp are logged for audit purposes.
Operational data. We collect logs of API requests, errors, and authentication events to operate, secure, and debug the platform.
We do not collect payment information from end customers or data unrelated to operating the platform.
The Anvil iOS app requests additional device permissions to support field technician workflows. This data is used only within the app and is not transmitted to Anvil servers except where explicitly noted below.
We do not send marketing emails or SMS, and we do not sell or share data with third parties for advertising.
Anvil sends SMS to customers of tenant businesses (HVAC and similar service companies) for operational purposes only: appointment confirmations, proposals, invoices, and job signoff requests. Anvil does not send marketing or promotional SMS.
Consent model. Tenants are contractually required, under our Terms of Service, to obtain SMS consent from each of their customers (typically during service intake or appointment scheduling) before adding them to the platform with a phone number flagged for SMS messaging. Anvil acts as a service provider (data processor) to the tenant for SMS delivery; the tenant is the entity collecting consent and identifying themselves in every message.
Opt-out. Recipients can opt out at any time by replying STOP to any SMS — the carrier and our SMS provider (Twilio) immediately block all future messages to that number from the toll-free line, regardless of the tenant's state.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
For full details on how SMS works on Anvil — including who sends what, opt-in / opt-out keywords, and message frequency — see our SMS Policy. Recipients can also visit the Anvil SMS Disclosure page for a plain-language explanation of why they're receiving messages.
Anvil tenant and customer data is stored on servers hosted on Amazon Web Services in the United States (us-east-1, AWS Lightsail + RDS). Data is retained while the tenant account is active. SMS interaction logs (sends, deliveries, replies) are retained for at least 12 months for audit purposes.
We use the following providers to operate Anvil:
These providers process data only as necessary to deliver their services. Each is bound by their own data-processing agreement. We do not share Anvil data with any other third parties.
We use a single session cookie to keep tenant users logged in. We do not use tracking cookies, analytics cookies, or any third-party advertising cookies.
If you are a customer of a tenant business and have data on Anvil:
Anvil is not directed at individuals under the age of 18. We do not knowingly collect data from children.
We may update this policy as the platform evolves. Material changes will be communicated via email to registered tenants. Continued use of the service constitutes acceptance of the updated policy.
Questions about this policy: [email protected]