Legal

    Privacy Policy

    Last updated: July 10, 2026

    Introduction and scope

    This Privacy Policy describes how Praevisio Consulting LLC ("we," "us," or "our") collects, uses, and shares personal information when you use Bounty CRM (also branded as Bounty CRM), our websites, and related services (collectively, the "Service").

    This policy applies to two groups of people:

    • Business customers (tenants): contractors and service businesses that create a Bounty account, subscribe to the Service, and add staff users.
    • End customers (portal visitors): individuals who interact with public portals hosted by a tenant without creating a Bounty account, such as paying an invoice, accepting or declining an estimate, or signing a contract.

    By using the Service, you acknowledge this Privacy Policy. If you do not agree, do not use the Service.

    Who we are

    Praevisio Consulting LLC operates Bounty CRM, a multi-tenant business software platform for service contractors (for example, HVAC, plumbing, and electrical businesses).

    Marketing website: http://127.0.0.1:4179. CRM application: https://go.bountycrm.app (mobile: https://go.bountycrm.app/m/).

    For privacy questions or requests, contact us at customerservice@praevisio.co.

    Information we collect

    The information we collect depends on how you use the Service.

    Account and authentication information (tenants and staff users):

    • Name, company name, email address, and password (stored in hashed form)
    • Role, permissions, and team membership within a tenant account
    • Passkey credentials if you register WebAuthn passkeys at /auth/passkeys
    • Password reset tokens and related email activity

    Tenant business data (entered or uploaded by tenants and their staff):

    • Contacts and customers (name, email, phone, address, and related notes)
    • Jobs, scheduling, visits, and operational notes
    • Estimates, invoices, line items, payment terms, and related documents
    • Contracts, e-signatures, and signature capture data
    • Communications history (SMS and email sent through the Service)
    • Team and user records, projects, and reports
    • Company branding, logos, and files stored in our file storage (for example, PDFs and photos)

    Portal visitor information (collected when an end customer uses a tenant's public portal):

    • Name, email, phone, billing details, and signature data provided on pay-invoice, accept-estimate, or sign-contract flows
    • Payment method details processed through Stripe (we do not store full card numbers or full bank account numbers)
    • IP address, browser type, device information, and interaction logs related to the portal session

    Payment and billing information:

    • For SaaS subscriptions: billing contact details, subscription plan, payment history, and Stripe customer identifiers
    • For tenant invoice payments (Stripe Connect): payment status, amounts, transaction metadata, and limited payment method details as provided by Stripe

    Usage, device, and log data:

    • Log data such as IP address, browser type, operating system, pages viewed, and timestamps
    • Authentication events, API requests, and security-related activity
    • Error reports and diagnostic information needed to operate and secure the Service

    Cookies and similar technologies: we use essential cookies for authentication and session management (for example, httpOnly cookies for login sessions). We do not use third-party advertising or analytics cookies on the marketing site at this time.

    How we use information

    We use personal information to:

    • Provide, operate, maintain, and improve the Service
    • Create and manage tenant accounts and user access, including role-based permissions
    • Authenticate users, including via email/password and passkeys
    • Process SaaS subscriptions and facilitate invoice payments through Stripe
    • Send transactional email and SMS on behalf of tenants (for example, invoice links, reminders, receipts, estimate notifications, and contract signing requests)
    • Store and display tenant business data within isolated tenant environments
    • Provide customer support and respond to inquiries
    • Monitor, detect, and prevent fraud, abuse, and security incidents
    • Comply with legal obligations and enforce our Terms of Service
    • Communicate with tenants about the Service, including product updates and billing notices

    We do not sell personal information. We do not use tenant customer data for our own marketing to end customers.

    How we share information

    We share personal information only as described below.

    Service providers (subprocessors): we use trusted vendors to host and operate the Service. They process data on our behalf under contractual obligations.

    SubprocessorPurpose
    SupabasePostgreSQL database hosting (control plane and tenant operational data)
    Amazon Web Services (S3)File and logo storage (invoices, estimates, contracts, job photos, branding assets)
    StripeSaaS subscription billing and payment processing for tenant invoice payments (Stripe Connect, cards, US bank accounts, Link, Financial Connections)
    SendGridTransactional email delivery on behalf of tenants and the platform
    TwilioSMS delivery on behalf of tenants
    VercelHosting for the marketing website and API infrastructure

    Tenant-directed sharing: when a tenant uses the Service to email or text their customers, or when an end customer pays an invoice through a tenant's portal, information is shared as directed by the tenant to complete that transaction.

    Legal and safety: we may disclose information if required by law, court order, or governmental request, or when we believe disclosure is necessary to protect rights, safety, and security.

    Business transfers: if we are involved in a merger, acquisition, financing, or sale of assets, personal information may be transferred as part of that transaction, subject to appropriate protections.

    Stripe and payment data

    We use Stripe for two distinct payment flows:

    • SaaS subscriptions: tenants pay Praevisio Consulting LLC for access to Bounty through Stripe Checkout and subscription billing on our platform Stripe account.
    • Tenant invoice payments: a tenant's end customers pay invoices through Stripe Connect. The tenant is the merchant of record for those invoice payments. Bounty facilitates the technical integration and records payment status in the CRM.

    Card payments, US bank account (ACH) payments, Stripe Link, and Stripe Financial Connections are processed by Stripe. We do not store full card numbers, CVV codes, or complete bank account credentials on our servers.

    ACH payments may take several business days to settle. Payment timing, returns, and disputes are subject to Stripe's and the relevant financial institutions' rules. Stripe's privacy policy and terms apply to payment processing: https://stripe.com/privacy

    Tenant vs. end-customer roles

    For tenant business data and end-customer data entered into the CRM by a tenant, the tenant is generally the controller of that data and determines the purposes and means of processing their customer and contact information.

    Praevisio Consulting LLC acts as a processor (or service provider) processing that data on the tenant's behalf to provide the Service.

    For portal visitors: when an end customer uses a pay-invoice, accept-estimate, or sign-contract link, we process their information on behalf of the tenant to complete that specific interaction. Portal visitors should contact the contractor (tenant) that sent the link for questions about how that business uses their data. Portal visitors may also contact us at customerservice@praevisio.co for platform-related privacy requests where applicable.

    For our own account, billing, and platform operations data (for example, tenant signup and subscription records), Praevisio Consulting LLC is the controller.

    US state privacy rights

    Depending on your state of residence, you may have rights regarding your personal information, which may include:

    • Right to know what personal information we collect, use, and disclose
    • Right to access and obtain a copy of certain personal information
    • Right to correct inaccurate personal information
    • Right to delete certain personal information, subject to exceptions
    • Right to opt out of the sale or sharing of personal information (we do not sell personal information)

    Tenants can submit requests regarding their account by emailing customerservice@praevisio.co. Portal visitors should contact the relevant tenant first for requests about data that tenant controls. We will respond to verifiable requests as required by applicable law.

    We will not discriminate against you for exercising privacy rights permitted by law.

    Data retention and deletion

    We retain personal information for as long as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce agreements.

    Platform retention: While your subscription is active, we retain tenant data as needed to operate the Service. Canceling your subscription stops future billing and may end CRM access when your billing period ends, but it is not the same as deleting your account—tenant operational data remains until account deletion is confirmed as described below. We do not retain tenant data as long-term archival storage after they leave. Upon confirmed account deletion, tenant operational data is soft-deleted (hidden from the product and inaccessible to you) and scheduled for permanent deletion or anonymization within 90 days. During that soft-delete window, data may be retained briefly only where it directly benefits you (for example, to reverse an accidental deletion request, honor an in-flight data export, or allow backup snapshots to roll off on schedule) or where required for fraud prevention and dispute resolution related to the deletion. After 90 days, all tenant operational data—including invoices, estimates, contacts, jobs, and uploaded files—is permanently deleted or anonymized. We may retain longer only narrow records required of Praevisio as the platform operator, such as our own subscription and billing records, payment dispute and chargeback records, and security and audit logs where legally required—not tenant CRM content for our convenience.

    Tenant-configurable retention: while your account and subscription are active, you may configure file retention policies in Settings > Retention (for example, for job photos, invoices, estimates, and documents) to manage cleanup for your business needs. These settings apply only while your account is active and do not apply after confirmed account deletion; upon confirmed deletion, all tenant operational data is handled as described under Account deletion below.

    Data export: Tenant administrators with company settings access can submit a data export request from Settings > Security > Data and privacy in the CRM. We will verify your identity and provide a copy of your tenant data in a standard machine-readable format within 30 days. You may also email customerservice@praevisio.co from your account owner email with the subject line "Data Export Request".

    Account deletion: To request deletion of your Bounty CRM account and tenant data, first cancel your subscription in Settings > Billing so billing is settled. Then submit an account deletion request from Settings > Security > Data and privacy, or email customerservice@praevisio.co from your account owner email with the subject line "Account Deletion Request". We verify ownership, confirm billing is settled, and confirm your request within 30 days. Upon confirmation, your account is deactivated immediately (login and CRM access end) and all tenant operational data—including invoices, estimates, contacts, jobs, and uploaded files—is soft-deleted and becomes inaccessible to you and your staff in normal use. Data is not permanently purged right away; copies may exist briefly in backups during the soft-delete window, then are deleted or anonymized on a defined schedule within 90 days after confirmation. Accidental deletion requests may be reversed during that window if we have not yet completed permanent deletion. Confirming deletion does not instantly and irreversibly erase every copy (for example, backups), but your data is inaccessible from your perspective right away. Only narrow platform-operator records described under Platform retention above may be retained longer where legally required.

    Security measures

    We implement technical and organizational measures designed to protect personal information, including:

    • Encryption in transit (HTTPS/TLS) for data transmitted between your browser and our services
    • Multi-tenant data isolation using tenant-scoped access controls
    • Role-based access controls for tenant staff
    • Authentication safeguards, including httpOnly session cookies and optional passkeys
    • Infrastructure hosted with reputable cloud providers

    No method of transmission or storage is completely secure. We cannot guarantee absolute security.

    Security incidents: If we become aware of a security incident that affects your personal information, we will notify affected tenant account owners by email without undue delay and within 72 hours where feasible. Notifications will describe what happened, what information was involved, and steps we are taking in response.

    We do not represent that the Service is HIPAA-compliant or SOC 2 certified unless we expressly confirm that in a separate written agreement.

    Children's privacy

    The Service is intended for business use and is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe we have collected such information, contact us at customerservice@praevisio.co and we will take appropriate steps to delete it.

    International transfers

    We are based in the United States and process information in the United States and in other countries where our service providers operate. If you access the Service from outside the United States, you understand that your information may be transferred to, stored, and processed in the United States and other jurisdictions that may have different data protection laws than your country.

    Changes to this policy

    We may update this Privacy Policy from time to time. We will post the updated policy on http://127.0.0.1:4179/privacy and update the "Last updated" date. Material changes may also be communicated through the Service or by email where appropriate. Continued use after changes become effective constitutes acceptance of the updated policy.

    Contact us

    For questions about this Privacy Policy or to submit a privacy request:

    See also our Terms of Service at Terms of Service.