This Privacy Notice for Function Software, LLC (doing business as Corvin) (“we,” “us,” or “our”) describes how and why we might access, collect, store, use, and/or share (“process”) your personal information when you use our services (“Services”), including when you:
- Visit our website at https://runcorvin.com or any website of ours that links to this Privacy Notice
- Download and use our mobile application (Corvin), or any other application of ours that links to this Privacy Notice
- Use Corvin. Corvin is field service and operations software for trades that build things. It helps shops organize and run the business from the field and office—clients, jobs, scheduling, time tracking, materials/parts, estimates, invoices, and payments—with optional light inventory/MRP-style tools as you grow.
- Engage with us in other related ways, including any marketing or events
Questions or concerns? If you do not agree with our policies and practices, please do not use our Services. Contact us at support@runcorvin.com.
1. What information do we collect?
Personal information you disclose to us
We collect personal information that you voluntarily provide when you register on the Services, express interest in our products, participate in activities on the Services, or contact us. Depending on how you use Corvin, this may include:
- names
- phone numbers
- email addresses
- mailing / job-site addresses
- company / organization name
- account credentials (email/password) and multi-factor auth setup
We also process business content you and your organization enter or generate in Corvin to provide the Services, which may include:
- clients and contacts (names, phones, emails, addresses, vehicles)
- jobs, schedules, tasks, notes, time tracking / job timers, and materials used
- photos, attachments, barcodes, inventory/parts, tools, expenses, and receipts
- estimates, invoices, purchase orders, PDFs, taxes, and e-signatures (signer name and signature image)
- mileage / travel logs and manual billable call-time logs
- SMS/email message content you send through Corvin (for example client updates or review requests)
- client-portal / booking intake information when you enable those features
Sensitive information
When necessary, with your consent or as otherwise permitted by applicable law, we may process sensitive personal information such as account login information, precise geolocation (if you enable location features), contents of messages you store or send through the Services, and financial/billing information processed in connection with payments.
Optional device biometrics (for example Face ID or fingerprint) may unlock a locally stored session on your device. Biometric templates stay on the device operating system and are not collected or stored by Corvin.
Payment data
We use Stripe for Corvin subscriptions and for optional online invoice / customer payments (including Stripe Connect). Card numbers and similar payment instrument details are handled and stored by Stripe, not by Corvin. See https://stripe.com/privacy. If you paste third-party payment or financing links (for example Square, Wisetack, Affirm, Klarna), those providers process data under their own policies when a customer uses the link.
Account / sign-in data
You may create an account with email and password. If you sign in with Google (or another third-party sign-in we offer), we receive certain profile information from that provider (typically name and email, and other details you authorize). Optional authenticator-app MFA may be available for account security.
Application data
If you use our application(s), we may collect the following if you grant access or permission:
- Geolocation information — optional location-based features such as address geocoding and technician location sharing with your organization (for example dispatch maps). On some platforms this may include background location while location sharing is enabled. Change permissions in device settings.
- Mobile device access — camera (job/part photos and barcode scanning), photo library, storage, and optional cloud photo destinations you connect (for example Google Drive, Microsoft OneDrive, Apple Photos, or Immich).
- Mobile device data — device identifiers used for plan/device limits, OS and app version, IP address, and similar technical data for security, troubleshooting, and operations.
- Notifications — local or ongoing notifications (for example an active job timer); disable in device settings.
- Product analytics and diagnostics — first-party event and error logs (for example feature usage, crashes) stored in our systems to operate and improve the Services. We do not use third-party advertising SDKs.
Google API
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Information from other sources
We may receive limited information from other sources you connect or authorize (for example Google Sign-In profile details, QuickBooks Online sync if you enable it, or data you import). We do not purchase personal information from data brokers for Corvin.
2. How do we process your information?
We process personal information to provide, improve, and administer our Services, communicate with you, for security and fraud prevention, and to comply with law. Purposes include:
- Account creation, authentication, and account management
- Delivering and facilitating the Services you request
- Responding to inquiries and providing support
- Sending administrative information about the Services
- Fulfilling and managing subscriptions, invoices, and payments (including Stripe Checkout / Customer Portal and Connect flows)
- Syncing accounting data when you connect QuickBooks Online
- Sending SMS or email you initiate to clients (for example job updates, invoices, or review requests)
- Sharing technician location with your organization when that feature is enabled
- Enabling collaboration within your organization
- First-party product analytics, troubleshooting, and service improvement
- Requesting feedback about the Services
- Protecting our Services (including fraud monitoring)
- Protecting an individual’s vital interests when necessary
3. What legal bases do we rely on?
Where required (for example GDPR/UK GDPR), we rely on bases such as consent, performance of a contract, legitimate interests (for example diagnosing problems, preventing fraud, and improving the product), legal obligations, and vital interests. Canadian users may have consent-based and other statutory grounds as described by applicable law. You may withdraw consent where processing is based on consent, without affecting prior lawful processing.
4. When and with whom do we share personal information?
We may share personal information with vendors and service providers who perform services for us under contracts designed to protect your information. Categories include:
- Cloud backend — Supabase (authentication, database, storage, and related infrastructure)
- Payments — Stripe (subscriptions, Checkout, Customer Portal, and Stripe Connect customer payments)
- Authentication — Google Sign-In when you choose it; other sign-in providers if we offer and you enable them
- Email — Resend (transactional and, where applicable, marketing emails)
- SMS — Twilio (outbound client SMS you send through Corvin)
- Accounting — Intuit QuickBooks Online when you connect and sync
- Photo / file destinations you connect — for example Google Drive, Microsoft OneDrive, Apple Photos, or Immich
- Maps / geocoding — mapping and geocoding providers (for example platform geocoders or OpenStreetMap Nominatim) when you use address or map features
- AI providers — Google Cloud AI / Gemini when optional AI features are enabled
- Compliance / policy tooling — Termly.io (for example privacy request forms)
- Website hosting / edge — Cloudflare or similar hosting for runcorvin.com
- App distribution / testing — Google Play Console; Apple TestFlight / App Store
We may also share information:
- In connection with a business transfer (merger, financing, acquisition, or sale of assets)
- With affiliates, if any, who must honor this Privacy Notice
- With other users in your organization when you collaborate or when features such as dispatch location sharing are enabled
- With your clients when you send them invoices, portal links, SMS, email, or similar communications through the Services
We have not sold or shared personal information for cross-context behavioral advertising in the preceding twelve (12) months.
5. Do we use cookies and other tracking technologies?
We may use cookies and similar technologies to maintain security, keep you signed in, prevent crashes, save preferences, and support basic site functions. Details are in our Cookie Notice.
Corvin’s marketing site and app are not currently configured with third-party advertising networks. If that changes, we will update this Notice and the Cookie Notice.
6. Do we offer AI-based products?
We may offer optional AI features (for example text generation or image analysis) powered by providers such as Google Cloud AI / Gemini. When those features are enabled, inputs and outputs needed to run them may be processed by the AI provider under our agreements and this Notice. To opt out of AI features, contact us at support@runcorvin.com.
7. How do we handle social logins?
If you log in with a third-party account (for example Google), we receive profile information from that provider as described above. We do not control how the provider uses your information; review their privacy notice and settings.
8. Is your information transferred internationally?
Our servers are located in the United States. If you access the Services from another country, your information may be transferred to and processed in the United States and other countries where our providers operate. For EEA/UK/Swiss transfers we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses where applicable. Copies may be provided upon request.
9. How long do we keep your information?
We keep personal information only as long as necessary for the purposes in this Notice, unless a longer period is required or permitted by law. In general, we do not keep personal information longer than thirty-six (36) months after termination of the user’s account, subject to legal holds, backups, and fraud/security needs. When we no longer have a legitimate need, we delete or anonymize information, or securely isolate it until deletion is possible.
10. How do we keep your information safe?
We implement reasonable technical and organizational security measures. No method of transmission or storage is 100% secure; use the Services in a secure environment and protect your credentials.
11. Do we collect information from minors?
We do not knowingly collect data from or market to children under 18 (or the equivalent age required in your jurisdiction). If you believe we have collected such information, contact support@runcorvin.com.
12. What are your privacy rights?
Depending on where you live (including certain US states, the EEA, UK, Switzerland, and Canada), you may have rights to access, correct, delete, port, or restrict processing of personal information, and to withdraw consent where applicable. The easiest way to exercise rights is by submitting a data subject access request or emailing support@runcorvin.com.
You can also manage account information by logging into your account settings. Upon account termination we deactivate or delete account data from active systems, though some information may be retained as needed for fraud prevention, troubleshooting, legal compliance, or enforcement of our terms.
Marketing emails include an unsubscribe link. Service-related messages may still be sent as needed to operate your account.
13. Controls for Do-Not-Track features
There is no uniform standard for recognizing DNT browser signals. We do not currently respond to DNT signals. If a required standard is adopted, we will update this Notice.
14. Do United States residents have specific privacy rights?
Residents of certain US states may have additional rights (access, correction, deletion, portability, non-discrimination, and opt-outs related to sale/sharing/targeted advertising/profiling, where applicable). Categories we collect may include identifiers, customer records information, commercial information, geolocation, professional/employment-related information, internet or app activity (first-party product analytics and diagnostics), and audio / electronic / visual information such as job photos and signature images. Sensitive personal information may include account login information, precise geolocation, message contents you store or send, and financial account access details related to billing. We do not collect protected classification characteristics, biometric templates, education records, or advertising-profile inferences as a business practice, and we do not use third-party advertising networks.
We retain collected category data as needed to provide the Services, generally for as long as you have an account with us (subject to Section 9).
To exercise rights, submit a data subject access request or email support@runcorvin.com. We may need to verify your identity. Authorized agents must provide proof of authorization. Appeals of certain denied requests may be emailed to the same address.
California “Shine the Light”: California residents may request annual information about personal information disclosed to third parties for direct marketing purposes by contacting us using the details below.
15. Do we make updates to this notice?
Yes. The updated version will show a revised date at the top. For material changes we may post a prominent notice or notify you directly.
16. How can you contact us about this notice?
Email support@runcorvin.com or write to:
Function Software, LLC
625 E Desert Canyon Rd
Wickenburg, AZ 85390
United States
17. How can you review, update, or delete your data?
Depending on applicable law, you may request access, correction, or deletion of personal information by submitting a data subject access request.