Privacy Policy

Effective August 18, 2026

We collect the minimum needed to run your account. The client data you store in your workspace is yours — we process it only for you, never for ourselves, and never sell it. One session cookie, no ad trackers. Data lives in a US-region Postgres database at Supabase, the app runs on Vercel, and you can export or delete everything whenever you want.

1Two kinds of data, two different roles

NVAR Systems is used by businesses, and those businesses store information about their own clients in it. That means there are two distinct kinds of personal data here, and our role is different for each:

Your data — the account and usage information we collect about you, the subscriber. For this, we decide what to collect and why, and this policy describes it in full below.

Your clients' data — the names, emails, phone numbers, addresses, project details, proposals, agreements, and invoices you enter about the people you work with. You decide what goes in and what it is for; we store and process it purely on your instructions, to provide the service to you. In privacy-law terms, you are the controller of that data and we are your processor. We do not use it for our own purposes, mine it, or sell it — and when you delete it or close your workspace, it goes.

One consequence worth stating plainly: if one of your clients asks about data you hold on them, that request is yours to answer — the data is in your workspace under your control. We will help you honor it (export and deletion are built in), but we won't reach into your workspace uninvited.

2What we collect about you

When you use NVAR Systems as a subscriber, we collect:

Account basics — your email address, your name, and your business's name and branding details, because the service needs them to exist and to put your name on the documents you send.

Usage and logs — standard operational records: sign-in events, actions taken in the app (the activity log your workspace itself shows you), and server logs with IP addresses and timestamps. We use these to keep the service working, investigate problems and suspicious sign-ins, and understand which features are actually used. We do not build advertising profiles from any of it.

Email you send us — if you write to support, we keep the correspondence so we have context next time.

That is the list. We do not collect anything else about you.

3Cookies

The app sets an authentication session cookie so you stay signed in. That is the only cookie we set. There are no third-party analytics scripts, ad pixels, or cross-site trackers on the site — if we ever add an analytics tool, we will name it here first.

4Who else touches the data

We don't run our own datacenter. A small set of infrastructure providers process data on our behalf to make the service work:

Supabasedatabase and authentication

All workspace data lives in a Postgres database hosted by Supabase in a US region. Supabase also handles sign-in.

Vercelapplication hosting

The app itself runs on Vercel's servers, which see requests in transit and keep standard server logs.

Resendtransactional email — only if you connect it

If you connect Resend to your workspace, the emails you send through the service (proposals, invoices, portal invites) go out through it. If you don't connect it, Resend sees nothing.

Stripepayments — only if you connect your own Stripe account

Payment links on your invoices go to Stripe Checkout on your own Stripe account. Card numbers are entered on Stripe's pages and handled entirely by Stripe — we never see or store them.

Beyond these providers, we share data with no one — we don't sell it, rent it, or trade it. The only other circumstance in which we would disclose data is a legally binding demand we cannot refuse, and we would tell you about it unless the law forbids us to.

5How the data is protected

Rather than list certifications we don't have, here is what is actually in place:

Workspace isolation. Every workspace is isolated at the database level with row-level security — the database itself, not just the application, refuses to hand one workspace's rows to another.

Encrypted credentials. Third-party API keys you save (like a Resend key) are encrypted at rest with AES-256-GCM.

Tamper-evident agreements. Signed agreements are content-hashed at signing, so any later alteration of the document is detectable.

Encryption in transit. Connections to the app are encrypted with HTTPS.

We hold no SOC 2, ISO, HIPAA, or PCI certification, and we won't imply otherwise. If your business needs those guarantees, the honest answer is that we are too early to give them yet.

6How long we keep things

Workspace data stays as long as your workspace does — the product is your system of record, so we don't expire your data out from under you. Delete a record and it is soft-deleted immediately (hidden and recoverable briefly, then removed); close your workspace and, after an export window of at least 30 days, its data is deleted from the live database and ages out of routine backups over the following weeks. Operational server logs are kept only as long as our providers' standard short retention windows.

7Getting data out — or gone

Export: you can export your workspace data at any time, while your account is active or during the wind-down window after closing it.

Deletion: you can delete individual records in-app, or ask us to delete your entire workspace and account by emailing nvarsinclair@nvarstudios.com from your account email. We will confirm and complete the deletion, and tell you when it is done.

8Changes to this policy

If we change what we collect, who processes it, or how long we keep it, we will update this page, change the effective date above, and notify you by email or in the app before the change applies to your data.

9Contact

Privacy questions go to nvarsinclair@nvarstudios.com. NVAR Systems is operated by NVAR Studios LLC, Lincoln, Nebraska.