Introduction and scope
This Privacy Policy describes how Praevisio Consulting LLC ("we," "us," or "our") collects, uses, and shares personal information when you use Bounty CRM (also branded as Bounty CRM), our websites, and related services (collectively, the "Service").
This policy applies to two groups of people:
- Business customers (tenants): contractors and service businesses that create a Bounty account, subscribe to the Service, and add staff users.
- End customers (portal visitors): individuals who interact with public portals hosted by a tenant without creating a Bounty account, such as paying an invoice, accepting or declining an estimate, or signing a contract.
By using the Service, you acknowledge this Privacy Policy. If you do not agree, do not use the Service.
Who we are
Praevisio Consulting LLC operates Bounty CRM, a multi-tenant business software platform for service contractors (for example, HVAC, plumbing, and electrical businesses).
Marketing website: http://127.0.0.1:4179. CRM application: https://go.bountycrm.app (mobile: https://go.bountycrm.app/m/).
For privacy questions or requests, contact us at customerservice@praevisio.co.
Information we collect
The information we collect depends on how you use the Service.
Account and authentication information (tenants and staff users):
- Name, company name, email address, and password (stored in hashed form)
- Role, permissions, and team membership within a tenant account
- Passkey credentials if you register WebAuthn passkeys at /auth/passkeys
- Password reset tokens and related email activity
Tenant business data (entered or uploaded by tenants and their staff):
- Contacts and customers (name, email, phone, address, and related notes)
- Jobs, scheduling, visits, and operational notes
- Estimates, invoices, line items, payment terms, and related documents
- Contracts, e-signatures, and signature capture data
- Communications history (SMS and email sent through the Service)
- Team and user records, projects, and reports
- Company branding, logos, and files stored in our file storage (for example, PDFs and photos)
Portal visitor information (collected when an end customer uses a tenant's public portal):
- Name, email, phone, billing details, and signature data provided on pay-invoice, accept-estimate, or sign-contract flows
- Payment method details processed through Stripe (we do not store full card numbers or full bank account numbers)
- IP address, browser type, device information, and interaction logs related to the portal session
Payment and billing information:
- For SaaS subscriptions: billing contact details, subscription plan, payment history, and Stripe customer identifiers
- For tenant invoice payments (Stripe Connect): payment status, amounts, transaction metadata, and limited payment method details as provided by Stripe
Usage, device, and log data:
- Log data such as IP address, browser type, operating system, pages viewed, and timestamps
- Authentication events, API requests, and security-related activity
- Error reports and diagnostic information needed to operate and secure the Service
Cookies and similar technologies: we use essential cookies for authentication and session management (for example, httpOnly cookies for login sessions). We do not use third-party advertising or analytics cookies on the marketing site at this time.
How we use information
We use personal information to:
- Provide, operate, maintain, and improve the Service
- Create and manage tenant accounts and user access, including role-based permissions
- Authenticate users, including via email/password and passkeys
- Process SaaS subscriptions and facilitate invoice payments through Stripe
- Send transactional email and SMS on behalf of tenants (for example, invoice links, reminders, receipts, estimate notifications, and contract signing requests)
- Store and display tenant business data within isolated tenant environments
- Provide customer support and respond to inquiries
- Monitor, detect, and prevent fraud, abuse, and security incidents
- Comply with legal obligations and enforce our Terms of Service
- Communicate with tenants about the Service, including product updates and billing notices
We do not sell personal information. We do not use tenant customer data for our own marketing to end customers.
Legal bases (United States)
This Service is offered primarily to businesses in the United States. We process personal information based on:
- Contract: to provide the Service under our agreement with tenants and to process portal transactions at a tenant's direction
- Legitimate interests: to secure, improve, and support the Service, prevent abuse, and communicate about the Service
- Legal obligation: where required by applicable law
- Consent: where required for specific communications or optional features (for example, where a tenant or user opts in to certain messages)
Stripe and payment data
We use Stripe for two distinct payment flows:
- SaaS subscriptions: tenants pay Praevisio Consulting LLC for access to Bounty through Stripe Checkout and subscription billing on our platform Stripe account.
- Tenant invoice payments: a tenant's end customers pay invoices through Stripe Connect. The tenant is the merchant of record for those invoice payments. Bounty facilitates the technical integration and records payment status in the CRM.
Card payments, US bank account (ACH) payments, Stripe Link, and Stripe Financial Connections are processed by Stripe. We do not store full card numbers, CVV codes, or complete bank account credentials on our servers.
ACH payments may take several business days to settle. Payment timing, returns, and disputes are subject to Stripe's and the relevant financial institutions' rules. Stripe's privacy policy and terms apply to payment processing: https://stripe.com/privacy
Tenant vs. end-customer roles
For tenant business data and end-customer data entered into the CRM by a tenant, the tenant is generally the controller of that data and determines the purposes and means of processing their customer and contact information.
Praevisio Consulting LLC acts as a processor (or service provider) processing that data on the tenant's behalf to provide the Service.
For portal visitors: when an end customer uses a pay-invoice, accept-estimate, or sign-contract link, we process their information on behalf of the tenant to complete that specific interaction. Portal visitors should contact the contractor (tenant) that sent the link for questions about how that business uses their data. Portal visitors may also contact us at customerservice@praevisio.co for platform-related privacy requests where applicable.
For our own account, billing, and platform operations data (for example, tenant signup and subscription records), Praevisio Consulting LLC is the controller.
US state privacy rights
Depending on your state of residence, you may have rights regarding your personal information, which may include:
- Right to know what personal information we collect, use, and disclose
- Right to access and obtain a copy of certain personal information
- Right to correct inaccurate personal information
- Right to delete certain personal information, subject to exceptions
- Right to opt out of the sale or sharing of personal information (we do not sell personal information)
Tenants can submit requests regarding their account by emailing customerservice@praevisio.co. Portal visitors should contact the relevant tenant first for requests about data that tenant controls. We will respond to verifiable requests as required by applicable law.
We will not discriminate against you for exercising privacy rights permitted by law.
Data retention and deletion
We retain personal information for as long as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce agreements.
Platform retention: While your subscription is active, we retain tenant data as needed to operate the Service. Canceling your subscription stops future billing and may end CRM access when your billing period ends, but it is not the same as deleting your account—tenant operational data remains until account deletion is confirmed as described below. We do not retain tenant data as long-term archival storage after they leave. Upon confirmed account deletion, tenant operational data is soft-deleted (hidden from the product and inaccessible to you) and scheduled for permanent deletion or anonymization within 90 days. During that soft-delete window, data may be retained briefly only where it directly benefits you (for example, to reverse an accidental deletion request, honor an in-flight data export, or allow backup snapshots to roll off on schedule) or where required for fraud prevention and dispute resolution related to the deletion. After 90 days, all tenant operational data—including invoices, estimates, contacts, jobs, and uploaded files—is permanently deleted or anonymized. We may retain longer only narrow records required of Praevisio as the platform operator, such as our own subscription and billing records, payment dispute and chargeback records, and security and audit logs where legally required—not tenant CRM content for our convenience.
Tenant-configurable retention: while your account and subscription are active, you may configure file retention policies in Settings > Retention (for example, for job photos, invoices, estimates, and documents) to manage cleanup for your business needs. These settings apply only while your account is active and do not apply after confirmed account deletion; upon confirmed deletion, all tenant operational data is handled as described under Account deletion below.
Data export: Tenant administrators with company settings access can submit a data export request from Settings > Security > Data and privacy in the CRM. We will verify your identity and provide a copy of your tenant data in a standard machine-readable format within 30 days. You may also email customerservice@praevisio.co from your account owner email with the subject line "Data Export Request".
Account deletion: To request deletion of your Bounty CRM account and tenant data, first cancel your subscription in Settings > Billing so billing is settled. Then submit an account deletion request from Settings > Security > Data and privacy, or email customerservice@praevisio.co from your account owner email with the subject line "Account Deletion Request". We verify ownership, confirm billing is settled, and confirm your request within 30 days. Upon confirmation, your account is deactivated immediately (login and CRM access end) and all tenant operational data—including invoices, estimates, contacts, jobs, and uploaded files—is soft-deleted and becomes inaccessible to you and your staff in normal use. Data is not permanently purged right away; copies may exist briefly in backups during the soft-delete window, then are deleted or anonymized on a defined schedule within 90 days after confirmation. Accidental deletion requests may be reversed during that window if we have not yet completed permanent deletion. Confirming deletion does not instantly and irreversibly erase every copy (for example, backups), but your data is inaccessible from your perspective right away. Only narrow platform-operator records described under Platform retention above may be retained longer where legally required.
Security measures
We implement technical and organizational measures designed to protect personal information, including:
- Encryption in transit (HTTPS/TLS) for data transmitted between your browser and our services
- Multi-tenant data isolation using tenant-scoped access controls
- Role-based access controls for tenant staff
- Authentication safeguards, including httpOnly session cookies and optional passkeys
- Infrastructure hosted with reputable cloud providers
No method of transmission or storage is completely secure. We cannot guarantee absolute security.
Security incidents: If we become aware of a security incident that affects your personal information, we will notify affected tenant account owners by email without undue delay and within 72 hours where feasible. Notifications will describe what happened, what information was involved, and steps we are taking in response.
We do not represent that the Service is HIPAA-compliant or SOC 2 certified unless we expressly confirm that in a separate written agreement.
Children's privacy
The Service is intended for business use and is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe we have collected such information, contact us at customerservice@praevisio.co and we will take appropriate steps to delete it.
International transfers
We are based in the United States and process information in the United States and in other countries where our service providers operate. If you access the Service from outside the United States, you understand that your information may be transferred to, stored, and processed in the United States and other jurisdictions that may have different data protection laws than your country.
Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated policy on http://127.0.0.1:4179/privacy and update the "Last updated" date. Material changes may also be communicated through the Service or by email where appropriate. Continued use after changes become effective constitutes acceptance of the updated policy.
Contact us
For questions about this Privacy Policy or to submit a privacy request:
- Email: customerservice@praevisio.co
- Entity: Praevisio Consulting LLC
- Website: http://127.0.0.1:4179
See also our Terms of Service at Terms of Service.