Privacy Policy

Effective September 27, 2026

We collect the minimum needed to run your account. The client data you store in your workspace is yours — we process it only for you, never for ourselves, and never sell it. One session cookie (and a two-hour pass if you open the public demo), no ad trackers. Data lives in a US-region Postgres database at Supabase, the app runs on Vercel, you can export a copy of your workspace yourself whenever you want, and you can ask us to erase it.

1Two kinds of data, two different roles

NVAR Systems is used by businesses, and those businesses store information about their own clients in it. That means there are two distinct kinds of personal data here, and our role is different for each:

Your data — the account and usage information we collect about you, the subscriber. For this, we decide what to collect and why, and this policy describes it in full below.

Your clients' data — the names, emails, phone numbers, addresses, project details, proposals, agreements, and invoices you enter about the people you work with. You decide what goes in and what it is for; we store and process it purely on your instructions, to provide the service to you. In privacy-law terms, you are the controller of that data and we are your processor. We do not use it for our own purposes, mine it, or sell it — and when you delete it or close your workspace, it goes.

One consequence worth stating plainly: if one of your clients asks about data you hold on them, that request is yours to answer — the data is in your workspace under your control. We will help you honor it (export and deletion are built in), but we won't reach into your workspace uninvited.

2What we collect about you

When you use NVAR Systems as a subscriber, we collect:

Account basics — your email address, your name, and your business's name and branding details, because the service needs them to exist and to put your name on the documents you send.

Usage and logs — standard operational records: sign-in events, actions taken in the app (the activity log your workspace itself shows you), and server logs with IP addresses and timestamps. We use these to keep the service working, investigate problems and suspicious sign-ins, and understand which features are actually used. We do not build advertising profiles from any of it.

Email you send us — if you write to support, we keep the correspondence so we have context next time.

That is the list. We do not collect anything else about you.

3Cookies

The app sets an authentication session cookie so you stay signed in.

If you open the public demo, it also sets __Host-nvar_demo: a signed pass that lets your browser view the demo workspace for two hours without an account. It carries which demo you opened and when the pass ends — nothing about you. The cookie is kept for a day after the pass ends, only so an ended visit is sent back to the demo page instead of a login. Leaving the demo deletes it, and so does opening the app again after the visit ended; otherwise it expires a day after the pass does. To stop one network from flooding the demo, we count its entries and downloads per connection using a keyed one-way hash of your IP address (for IPv6, of its network prefix), never the address itself, and delete those counts within a few days.

Those are the only cookies we set. There are no third-party analytics scripts, ad pixels, or cross-site trackers on the site — if we ever add an analytics tool, we will name it here first.

4Who else touches the data

We don't run our own datacenter. A small set of infrastructure providers process data on our behalf to make the service work:

Supabase — database and authentication

All workspace data lives in a Postgres database hosted by Supabase in a US region. Supabase also handles sign-in.

Vercel — application hosting

The app itself runs on Vercel's servers, which see requests in transit and keep standard server logs.

Resend — email — on your own account or on ours

The emails you send through the service — proposals, invoices, portal invites — go out through Resend. Either on a Resend key you connect yourself, or, if you have not connected one, on our own Resend account once we switch your workspace to it. Either way the recipient's address and the message reach Resend; what differs is whose account carries them.

Stripe — payments — only if you connect your own Stripe account

Payment links on your invoices go to Stripe Checkout on your own Stripe account. Card numbers are entered on Stripe's pages and handled entirely by Stripe — we never see or store them.

Google — calendar sync — only if you connect a Google calendar

If you connect a Google calendar, the scheduler reads its busy times so it does not offer a slot you are not free for, and a calendar you set as the write target also receives each booking as an event carrying the invitee's name, email address and phone number. Connect no calendar and Google sees nothing.

Beyond these providers, we share data with no one — we don't sell it, rent it, or trade it. The only other circumstance in which we would disclose data is a legally binding demand we cannot refuse, and we would tell you about it unless the law forbids us to.

5How the data is protected

Rather than list certifications we don't have, here is what is actually in place:

Workspace isolation. Every workspace is isolated at the database level with row-level security — the database itself, not just the application, refuses to hand one workspace's rows to another.

Encrypted credentials. Third-party API keys you save (like a Resend key) are encrypted at rest with AES-256-GCM.

Optional two-factor. A workspace owner can enrol an authenticator app, and once they have, that account is asked for a six-digit code before the app will show it anything. It is not compulsory, and the security page sets out what it does not yet cover.

Tamper-evident agreements. Signed agreements are content-hashed at signing, so any later alteration of the document is detectable.

Encryption in transit. Connections to the app are encrypted with HTTPS.

We hold no SOC 2, ISO, HIPAA, or PCI certification, and we won't imply otherwise. If your business needs those guarantees, the honest answer is that we are too early to give them yet.

6How long we keep things

Workspace data stays as long as your workspace does — the product is your system of record, so we don't expire your data out from under you.

A record you delete in the app is hidden immediately and moved to a recycle bin you can restore it from. Nothing in that bin is emptied on a timer: a deleted lead, client, invoice or document stays recoverable until the workspace itself is erased. We would rather tell you that than let you believe a deletion inside the app is a destruction. A handful of small configuration objects — a note on a client, a recurring-invoice template, a one-off day on a calendar — are removed outright instead.

Closing your workspace suspends it first: the workspace becomes read-only — nothing can be created, changed or sent, automations stop and your public booking pages go dark — while you can still sign in, read everything and take a copy. That is deliberate: a window you cannot log into is not a window. After an export window of at least 30 days, the data is deleted from the live database and ages out of routine backups over the following weeks. That window is not only a promise — the tool that performs an erasure refuses to run before it has passed, and erasing sooner because you asked us to is recorded as an exception on the deletion record.

Operational server logs are kept only as long as our providers' standard short retention windows.

7Getting data out — or gone

Export: a workspace owner can build a complete copy of the workspace at any time from Settings → Data export, while the account is active or during the wind-down window after closing it.

The file you download is encrypted with our backup key rather than one you hold, so it is not readable as it arrives — ask and we return the plain text, in a format any spreadsheet or database can read. It carries what is in the database, and it names every file you uploaded — label, filename, size, and the record each belongs to — rather than carrying the bytes; those are handed over alongside it. Both of those are limits of how the export is built today, not conditions on your right to the data.

Spreadsheets: a workspace owner can also download five lists — leads, clients, invoices, expenses and time entries — as CSV files from the page each one lives on. These arrive as plain text, not encrypted, so any spreadsheet opens them as they are. They leave out deleted records, fields marked sensitive and payment links, and each download is recorded in the workspace's activity log with who took it.

Deletion: you can delete individual records in-app, or ask us to delete your entire workspace and account by emailing nvarsinclair@nvarstudios.com from your account email. We will confirm and complete the deletion, and tell you when it is done.

8Changes to this policy

If we change what we collect, who processes it, or how long we keep it, we will update this page, change the effective date above, and notify you by email or in the app before the change applies to your data.

9Contact

Privacy questions go to nvarsinclair@nvarstudios.com. NVAR Systems is operated by NVAR Studios LLC, Lincoln, Nebraska.