FIELD WORK SOFTWARE
HomePricingContact
LoginGet started →

VOXPOINT / LEGAL

Privacy Policy.

The details.
All in one place.

OUR POLICIES

Privacy PolicyTerms of ServiceCookie PolicyLicense AgreementAcceptable UseSubscriber AgreementDeveloper AgreementAPI TermsMarketplace TermsSMS Notifications
Questions about this policy? Contact our team →
On this page 0 sections

Last updated: September 14, 2026

This document is provided for informational purposes and does not constitute legal advice.

1. Introduction

Welcome to VoxPoint. We respect your privacy and are committed to protecting your personal data. This privacy policy explains how we collect, use, and safeguard your information when you use our services. This policy applies to all VoxPoint services, including the main application, Client Portal, Developer Portal, and Marketplace.

2. Information We Collect

We may collect the following types of information:

Account Information

  • Name, email address, and phone number
  • Profile avatar and display preferences

Organization and Team Data

  • Company name, address, and industry
  • Team member roles and permissions

Business Data

  • Contacts, estimates, work orders, invoices, and inventory
  • Expenses, vendors, and calendar events

Tax Identification Data

  • If you enable Stripe Connect for payment collection, you may be required to provide an EIN (Employer Identification Number) or SSN during Stripe's onboarding process. This information is transmitted directly to Stripe and is not stored on VoxPoint servers. See Section 5 for more on Stripe as a sub-processor.

Developer Program Data

  • Developer account details and app metadata
  • OAuth client credentials (stored hashed)
  • OAuth access and refresh tokens (stored hashed via HMAC-SHA256)
  • API request logs (endpoint, timestamp, response status)

Client Portal Data

  • Portal session activity and document views
  • Approvals, acceptance actions, and payment interactions

Technical and Usage Data

  • IP address, browser type, and device information
  • Feature usage patterns and error logs

Authentication Data

  • Login timestamps and MFA enrollment status
  • Session identifiers

Session Security Data

  • When you sign in, we log your IP address and device information (browser user agent) to detect suspicious logins and enforce session limits. This data is retained for the life of the session and purged when sessions expire.

Communications Data

  • Transactional emails (invoices, estimates, notifications) sent via our email provider may include tracking pixels that record whether the email was opened and whether links were clicked. This data is used to confirm delivery and improve notification reliability.

3. How We Use Your Information

We use your information to:

  • Provide and maintain our services
  • Process transactions and send related information
  • Send you technical notices, updates, and support messages
  • Respond to your comments, questions, and requests
  • Improve and personalize our services
  • Protect against fraudulent or illegal activity
  • Facilitate team collaboration within your organization
  • Provide Client Portal access to your customers
  • Process Developer Program applications and API access
  • Monitor platform security and enforce acceptable use policies
  • Generate anonymized, aggregate analytics to improve the service

4. Legal Bases for Processing

Where applicable law requires a legal basis for processing your personal data, we rely on:

  • Contract necessity: Processing required to provide you with VoxPoint services as described in our Terms of Service.
  • Legitimate interests: Improving our services, ensuring platform security, and preventing fraud.
  • Consent: Where you have opted in to optional integrations (such as QuickBooks or Google Calendar) or marketing communications.
  • Legal obligations: Where we are required by law to retain or disclose data.

5. Third-Party Services and Sub-Processors

We use the following third-party services to operate our platform. Each is a sub-processor that may receive personal data only as necessary to perform its function:

  • Supabase: Database hosting, authentication, and file storage (US-based). Supabase processes data on our behalf under a data processing agreement. The Supabase Privacy Policy governs their use of this data.
  • Stripe: Payment processing, subscription billing, and Stripe Connect for merchant payouts. Payment card data is handled directly by Stripe and is not stored on VoxPoint servers. The Stripe Privacy Policy applies.
  • Plaid: If you connect a bank account, we use Plaid to retrieve account and transaction data. Your banking credentials are never stored by VoxPoint; they are handled directly by Plaid. Bank account metadata and transaction records are stored in our database to power expense and reconciliation features.
  • Twilio: SMS delivery for business messaging (SMS addon only). When the SMS addon is enabled, phone numbers and message content are transmitted to Twilio for delivery. Twilio's use of this data is subject to A2P 10DLC regulations and the Twilio Privacy Policy.
  • Intuit QuickBooks Online and Wave: Optional accounting sync, connected at your discretion.
  • Google Calendar: Optional calendar sync for scheduling.
  • Resend: Transactional email delivery for invoices, estimates, magic links, and notifications.
  • Sentry: Error monitoring and performance tracking. Error reports may include your organization ID, the page or action that triggered the error, and browser/OS metadata. We do not send your name, email address, or customer data to Sentry.
  • Anthropic: We use Anthropic's Claude API to process receipt images when you use the expense receipt scanning feature. Receipt image data is transmitted to Anthropic's API and is subject to Anthropic's privacy policy. Anthropic processes and retains API inputs and outputs under its applicable commercial terms and our account arrangement. Its standard API retention policy provides for deletion within 30 days, subject to contractual arrangements, safety requirements, and legal exceptions. Do not include information in a receipt upload that is unnecessary for expense processing.
  • Google Fonts: The redesigned marketing and authentication pages use locally hosted fonts. Other surfaces may load fonts from Google's CDN (fonts.googleapis.com). When you visit VoxPoint, your browser may make a request to Google's servers, which may log your IP address. See Google's Privacy Policy.
  • Google Analytics: We use Google Analytics to understand traffic and measure conversions (such as contact form submissions and early-access signups) on VoxPoint's public marketing pages. It is loaded only on those public pages and is never loaded inside the authenticated application, so it never sees your account, customer, invoice, or other business data. See Google's Privacy Policy and our Cookie Policy.
  • Google Ads: We run advertising campaigns for VoxPoint on Google Ads. Conversion and remarketing cookies are set only on our public marketing pages, never inside the authenticated application. See Google's Privacy Policy and our Cookie Policy.

These services access only the data necessary to perform their function and are bound by their own privacy policies. We are not responsible for the privacy practices of these third parties. Optional integrations (QuickBooks, Wave, Google Calendar) only run after you explicitly enable them in Settings.

6. Cookies and Browser Storage

We do not use social media advertising trackers such as Meta Pixel. We may use strictly necessary cookies and browser storage for authentication and product functionality, plus Google Analytics and Google Ads cookies on our public marketing pages (never inside the authenticated application):

  • localStorage: UI preferences (sidebar state, theme, page size), draft data, recently viewed items, and export panel state.
  • sessionStorage: Temporary authentication context (cleared after use).
  • IndexedDB: We use your browser's IndexedDB to store session tokens locally, with a localStorage fallback if IndexedDB is unavailable, enabling you to stay logged in across browser restarts. This data never leaves your device except as part of authenticated API requests.

Authentication data may be stored in browser storage to keep you signed in. All browser storage is scoped to your VoxPoint session and is not shared with third parties. You can clear this data at any time through your browser settings. See our Cookie Policy for full details.

7. Data Security

We implement appropriate technical and organizational security measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction.

  • All data is encrypted in transit using TLS and at rest using industry-standard protocols.
  • API credentials and OAuth tokens are hashed using HMAC-SHA256 and are not stored in plaintext.
  • Multi-factor authentication (TOTP) is available for enhanced account security.
  • Least-privilege access controls are enforced across the platform.
  • Administrative access to user data is logged, auditable, and restricted to authorized personnel.

8. Multi-Organization Model and Team Access

VoxPoint uses an organization-based data model. All business data belongs to your organization, not individual user accounts.

  • Organization owners and administrators can invite team members with specific roles (Admin, Manager, Technician, Viewer), each with defined permissions.
  • Team members can only access data within organizations they belong to.
  • Organization owners can transfer ownership, deactivate members, and control all access to organization data.

9. Client Portal

If you use VoxPoint's Client Portal feature, your customers can view documents and make payments via secure, time-limited magic links without requiring a VoxPoint account.

  • Portal activity (document views, approvals, payments) is logged in your organization's records.
  • Your customers' email addresses are used solely to deliver portal access links and are not used for marketing.

10. Developer Program and API Data

If you participate in the VoxPoint Developer Program, additional data is collected as described in the Developer Agreement.

  • API request logs record endpoint, timestamp, and response status for security and rate limiting. We do not intentionally log request/response bodies or authentication headers.
  • OAuth client credentials are stored hashed. OAuth access and refresh tokens are hashed via HMAC-SHA256.

See also our API Terms of Use and Acceptable Use Policy.

11. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including to satisfy legal, accounting, or reporting requirements. When you delete your account, we will delete or anonymize your personal data within 30 days.

  • API request logs are generally retained for up to 90 days for security monitoring.
  • Platform audit logs may be retained as necessary for compliance and security purposes.
  • Client Portal session data is generally retained for the duration of the magic link validity period plus up to 30 days.

12. Data Deletion and Erasure

You may request complete deletion of your account and all associated data.

  • Upon verified request, all organization data, team associations, and personal information are permanently deleted.
  • Deletion is irreversible and includes all estimates, invoices, work orders, inventory, and customer records associated with your organization(s).
  • Anonymized, aggregate data that cannot identify you may be retained for analytics.

13. Your Rights

You have the right to:

  • Access your personal data
  • Correct inaccurate or incomplete data
  • Request deletion of your data
  • Export your data in a portable format
  • Opt out of marketing communications
  • Withdraw consent for optional integrations at any time by disconnecting them in Settings
  • Request a copy of all data we hold about you

14. California Privacy Rights (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) grants you additional rights regarding your personal information:

  • Right to Know: You have the right to request disclosure of the categories and specific pieces of personal information we have collected about you, the sources, the business purpose, and the categories of third parties with whom we share it.
  • Right to Delete: You have the right to request deletion of your personal information, subject to certain exceptions permitted by law.
  • Right to Correct: You have the right to request correction of inaccurate personal information we maintain about you.
  • Right to Opt-Out of Sale or Sharing: VoxPoint does not sell or share your personal information with third parties for cross-context behavioral advertising purposes.
  • Right to Non-Discrimination: You will not receive discriminatory treatment for exercising any of your CCPA/CPRA rights.

To submit a verifiable consumer request, contact us at privacy@voxpoint.org. We will respond to verifiable requests within 45 days. We may extend this period by an additional 45 days when reasonably necessary, with prior notice.

You may designate an authorized agent to make a request on your behalf. Authorized agent requests must be accompanied by written permission signed by you, and we may require verification of your identity directly with you.

15. Children

VoxPoint is not intended for use by individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child under 16, we will take steps to delete that information promptly.

16. International Data

VoxPoint's services are hosted in the United States. If you access our services from outside the US, your data may be transferred to and processed in the US. We comply with applicable laws, and we support requests consistent with GDPR and CCPA where applicable.

17. Contact Us

If you have any questions about this Privacy Policy or to exercise your privacy rights, please contact us at privacy@voxpoint.org or support@voxpoint.org or visit our contact page.

Back to top
FIELD WORK SOFTWARE

Work moves business.

PricingContactSign in