Privacy

Last updated September 22, 2026 · How Thermal collects, uses, and protects your information.

Working draft — pending final legal review. This page is a thorough, good-faith draft prepared for Thermal FieldServ Software Inc. It is not yet counsel-approved and should not be treated as final legal advice or a binding commitment until outside counsel has reviewed and signed off on it.

Thermal FieldServ Software Inc. ("Thermal," "we," "us," or "our") builds field service management software for commercial and mechanical service contractors. This Privacy Policy describes what information we collect through trythermal.com and the Thermal product (our web and mobile apps, and the customer portal, vendor portal, and payment pages our Customers share with the people they work with), how we use and share it, and the choices available to you. It applies to visitors to our website, the people who sign up for and use the Thermal product ("Customers" and their authorized users), and anyone who submits information to us directly (for example, through a demo request).

1. Information we collect

Contact and lead information. When you request a demo or contact us, we collect what you submit — name, work email, phone number, company name, and details about your shop such as technician count and accounting platform.

Account and operational information. If your organization uses the Thermal product, we store the records you and your team create to run your business — customers, service sites, installed equipment, service agreements, work orders, and invoices. Service sites include geocoordinates used to place them on the dispatch map and calculate routes; this is site-level geocoding, not live location tracking of technicians or vehicles — Thermal does not track technician GPS location.

Payment information. Subscription payments are processed by our payment processor, Stripe. Card details are entered directly into Stripe's secure systems and do not pass through or get stored on Thermal's own servers.

Technical information. Our hosting and infrastructure providers automatically log standard technical data — browser type, device information, IP address, and pages visited — to operate, secure, and troubleshoot the Service.

Analytics. Our public marketing pages use Google Analytics (GA4) to understand site traffic. See "Cookies and tracking" below.

Product usage data. When you use the Thermal product — the web app, the mobile app, and the customer portal, vendor portal, and payment pages — we collect information about how it is used: pages and screens viewed, clicks and taps, features used, key actions (for example, creating a work order, sending an invoice, or completing a data import), and session recordings of those interactions. This comes with technical details such as browser and device type, operating system, screen size, approximate location derived from IP address, and cookie or device identifiers. We collect it with PostHog. Signed-in users are identified to PostHog only by an internal user id and organization id — we don't send your name or email. Portal, vendor portal, payment page, and mobile app usage is recorded without those ids. Session recordings mask everything typed and all on-screen text (the mobile app also masks images), so the business data your organization enters — customer names, addresses, dollar amounts, notes — is not readable in a recording. Separately, when an error occurs our error monitoring provider, Sentry, captures details of the error and, in the web app, a masked recording of the moments leading up to it.

Information about our Customers' customers. When a Customer uses Thermal to serve its own customers and vendors — for example, sharing a portal link or an invoice payment page — the records involved are that Customer's data, and we process them on the Customer's behalf and under its instructions. The Customer's own privacy practices govern that information. We also collect product usage data on those pages, as described above, which we use for the purposes in Section 2.

2. How we use information

We use the information above to: provide, operate, and support the Service; respond to demo requests and support questions; process payments; secure our systems and prevent abuse; and understand and improve the product and our marketing. We do not sell your information, and we do not use your Customer Data (the records your organization enters into Thermal) to train third-party models without your permission.

We use product usage data to operate and secure the Service, diagnose problems, support Customers, and understand which features are used so we can improve them. Inside Thermal, our team may connect usage data with account information we already hold — such as a user's name, email, role, and company — for example, to see which customers are actively using the product or to help someone who is stuck. We may also create aggregated or de-identified information from usage data (for example, how often a feature is used across all customers), which does not identify you or your organization.

3. Service providers we work with

We rely on the following providers to operate Thermal. Each processes information only as necessary to provide their service to us and is contractually restricted from using it for their own purposes:

  • Stripe — payment processing and billing.
  • Clerk — account authentication and login.
  • Supabase — our primary database (Postgres), hosted in the US (us-east-1).
  • Vercel — application hosting and file storage (Blob) for features like data exports.
  • Twilio — text message delivery.
  • Postmark — transactional and account email delivery.
  • Retell — inbound voice call booking. This integration is not yet active in production (no live configuration is currently deployed) and is listed here in case your organization enables it.
  • Intuit / QuickBooks Online — accounting sync, only if you connect your QuickBooks account.
  • Cloudflare (R2) — private document storage.
  • Google Maps Platform — geocoding service addresses and rendering the dispatch map.
  • Sentry — error monitoring, to help us find and fix bugs, including, in the web app, a masked recording of the moments before an error.
  • PostHog — product usage analytics and masked session recordings, hosted in the US. Web traffic reaches PostHog through our own domain.
  • Inngest — background job scheduling (for example, reminders and scheduled reports).
  • Automated data-processing providers (Anthropic, OpenAI, Google Gemini, and Zai) — power a small set of automation features, such as drafting suggested customer-service replies, reading equipment nameplate photos, and matching spreadsheet columns during data import. These are not yet primary, always-on features of the product.
4. Data retention

We retain your organization's account and operational data for as long as your account is active, so the Service works the way you expect. If you cancel or your account is terminated, we retain Customer Data for a reasonable period to allow for export and reactivation before deletion from active systems, except where a longer period is required by law or necessary to resolve disputes and enforce our agreements. Data export files you generate are automatically deleted 7 days after creation — you can generate a fresh export at any time before then.

We keep product usage data and session recordings only as long as we need them for the purposes described in this policy; they are also subject to the retention limits of the provider that stores them.

5. How we protect your data

Thermal uses Postgres row-level security so each organization's data is isolated at the database layer, not just in application code, including branch-level restrictions within multi-branch organizations. Data is encrypted in transit (HTTPS with HSTS). Integration credentials and secrets are encrypted at rest (AES-256-GCM). API keys are stored hashed, are revocable, and can be set to expire. Access within your organization follows role-based permissions (owner, dispatcher, office, technician), enforced server-side, and material actions are recorded in an append-only audit ledger.

To be direct about what we don't yet have: Thermal does not currently hold SOC 2, ISO 27001, HIPAA, or PCI DSS certification, and we have not published a specific backup interval or retention SLA. See our Security page for the full, current picture — including gaps we haven't closed yet.

6. Your rights and choices

If your organization uses Thermal, an account owner can generate and download a full export of your organization's data at any time from Settings — no penalty, no export fee.

You can request access to, correction of, or deletion of personal information we hold about you by emailing support@trythermal.com. We'll verify your request and respond within a reasonable time. Deletion requests are currently handled manually by our team rather than through an automated self-serve flow; deleting information may affect your organization's ability to use parts of the Service (for example, removing a customer record referenced by active work orders). The same address works for questions about, or requests to delete, product usage data linked to you.

If you reached Thermal through one of our Customers — for example, a service portal or an invoice payment link from your contractor — please send requests about the records that Customer holds to that Customer directly. We'll help them respond, and we may refer any request we receive about their records to them.

7. Cookies and tracking

Our public marketing pages use Google Analytics (GA4) to understand site traffic — pages visited, general location, and device/browser type. We do not currently use advertising or retargeting cookies. The authenticated Thermal product uses functional session cookies required for you to stay signed in and to secure customer/vendor portal access; these aren't optional, since the Service can't function without them. The Thermal product — including the customer portal, vendor portal, and payment pages — also uses PostHog's first-party cookies and browser storage for product analytics and session recordings (clicks, navigation, and feature usage — not readable business data, per the masking described above); the mobile app uses a device identifier for the same purpose. We don't use these for advertising. We don't currently operate a cookie-consent banner or an in-product analytics opt-out; you can clear or block cookies and site storage through your browser settings, use a Google Analytics opt-out extension for our marketing pages, or email us to ask about the usage data we hold about you.

8. Children's privacy

The Service is intended for business use by adults and is not directed at children. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us with personal information, contact us and we'll take appropriate steps to remove it.

9. International data transfers

Thermal is a Canadian company. Our infrastructure is hosted in the United States (our primary database runs in AWS us-east-1 via Supabase), and our product analytics provider, PostHog, stores usage data in the United States. If you access the Service from outside the United States, your information will be transferred to and processed in the United States, where it may be accessible to authorities under local law.

10. Changes to this policy

We'll update the "last updated" date above whenever this policy changes, and for material changes we'll provide reasonable notice to active customers (for example, by email or in-product notice) before the change takes effect.

Contact

Questions about this policy or your data? Email support@trythermal.com.