Ollify LLC
Privacy Policy
Effective September 15, 2026 | Last Updated September 15, 2026 | Version 1.0
This Privacy Policy explains how Ollify LLC ("Ollify," "we," "us," or "our") collects, uses, stores, and shares information when you use our platform at ollify.app and all related Ollify services (collectively, the "Service"). It also explains your rights and how to exercise them.
This policy applies to all users of the Ollify platform, including business account holders ("tenants") and any individuals whose data tenants process through the Service. If you use Ollify on behalf of a business, this policy applies to your use on behalf of that business.
Questions? Contact us any time at privacy@ollify.app.
1. What We Do Not Collect — Read This First
Before we describe what we do collect, here is what we do not collect. We think this matters and we want to be upfront about it.
We do not collect | Why it matters |
Payment card numbers | Payments are processed entirely by Stripe. We never see or store your full card number. |
Social Security Numbers or government IDs | We have no official fields for them, do not request them, and do not want them. However, you control the free-text fields you create in the Service, and we cannot guarantee what you or your users choose to type into them. |
Biometric data | We do not collect fingerprints, facial recognition data, or similar biometrics. |
Protected Health Information (PHI) | Ollify is not designed for healthcare data. Do not enter PHI into the Service. |
Children's data (under 13) | The Service is for businesses only. We do not knowingly collect data from anyone under 13. |
Data sold to third parties | We do not sell your personal information. Ever. |
Data shared for cross-context behavioral advertising | We do not share data with advertising networks or data brokers. |
PROTECTED HEALTH INFORMATION AND OTHER SENSITIVE HEALTH DATA — NOT SUPPORTED
Ollify does not collect or process Protected Health Information (PHI), substance abuse treatment records, mental health records, sensitive reproductive health information, or genetic information. Use of the Service to store or process any of these is prohibited by our Acceptable Use Policy.
Customers who require HIPAA-compliant data processing should not use Ollify for those workflows. Ollify is not a Business Associate under HIPAA and will not enter into a Business Associate Agreement (BAA).
2. Information We Collect
2.1 Information You Provide Directly. When you create an account, use the Service, or contact us, you may provide:
Account information — your name, email address, phone number, and password when you register.
Business information — your company name, business address, and other details about your organization when you set up your tenant account.
Customer Data — any data you enter into the platform as part of running your business, such as job records, client information, project and job site information, schedules, forms, documents, and files. Construction industry customers may store job site data, subcontractor records, equipment information, safety documentation, and client contracts as Customer Data. You control this data; we process it only to provide you the Service. You are responsible for complying with any industry-specific data retention requirements applicable to your business, including OSHA recordkeeping requirements and contract retention obligations.
Communications — messages you send us through support channels or feedback forms. We keep support communications to help resolve issues and improve the Service.
Payment information — your billing address and payment method details when you subscribe. Your full card number is processed and stored by Stripe, Inc. and is never transmitted to or stored on Ollify's servers. Business communications — business-line voicemail via our phone system, once selected; call recordings, where used, are handled by a separate third-party service, not by Ollify directly.
2.2 Information We Collect Automatically. When you use the Service, we automatically collect certain technical and usage information:
Usage data — how you interact with the Service, including features used, pages viewed, actions taken, search terms, and session duration. We use this to understand how the Service is used and where we can improve.
Device and technical information — your browser type and version, operating system, IP address, device identifiers, and general location derived from your IP address.
Cookies and similar technologies — see Section 6 for a full description of the cookies we use and your choices.
Location data — if you use mapping or routing features powered by Mapbox, we collect location data as necessary to provide those features. See Section 1.3 and Section 2 for how this data is used and shared.
2.3 Information from Third-Party Services. We receive limited information from third-party services we integrate with:
Mapbox — when you use mapping and routing features, location queries are processed by Mapbox and we receive geocoding results (e.g., a formatted address or coordinates). We do not receive Mapbox user data unrelated to your requests.
Stripe — when you make payments, Stripe processes your payment and we receive confirmation of the transaction, the last four digits of your card, and billing address. We do not receive your full card number.
3. How We Use Your Information
We use the information we collect for specific, limited purposes. Here is exactly what we use your information for:
To provide the Service | We use your account information and Customer Data to create and maintain your account, deliver the features you subscribe to, process jobs and workflows, and generally operate the platform. |
To authenticate and secure your account | We use your email, password, and device information to verify your identity, detect unauthorized access, and protect your account and data. |
To process payments | We pass your billing information to Stripe to process subscription payments. We use transaction records to manage your subscription and billing history. |
To provide customer support | We use your account information and communication content to respond to your support requests, troubleshoot issues, and follow up on open tickets. |
To improve the Service | We use aggregated and de-identified usage data to understand how the Service is used, identify bugs and performance issues, and develop new features. |
To send you communications | We send transactional emails (account confirmations, password resets, signing notifications, security alerts) that are necessary for the Service. We also send optional product update and marketing emails — you can opt out of marketing emails at any time. See Section 13. |
To comply with legal obligations | We process and retain certain information as required by applicable law, including tax records, audit logs, and data subject rights requests. |
To operate mapping features | Location data collected through Mapbox integration is used solely to provide routing and mapping functionality. We do not use location data for advertising or profiling. |
4. How We Share Your Information
We do not sell your personal information. We share information only in the following limited circumstances, or with your explicit, informed consent for any other purpose:
4.1 Service Providers and Subprocessors. We share information with third-party companies that help us operate the Service ("subprocessors"). These providers are contractually required to process data only on our instructions and in accordance with our Data Processing Agreement. Our current subprocessors include:
Stripe — payment processing. Stripe processes your payment card data directly and is independently regulated as a payment processor.
Mapbox — mapping, routing, and geocoding features.
AWS End User Messaging (Amazon Web Services) — text message delivery when messaging features are used.
Expo (Expo, Inc.) — mobile application build and delivery, and push notifications.
Amazon Web Services (AWS) — cloud infrastructure, hosting, and data storage.
Anthropic, PBC — planned subprocessor for an AI Agent feature that is not yet active as of this policy's Effective Date. When this feature launches, using it will send limited information (such as your prompts and related account context) to Anthropic for processing; your data will not be used to train Anthropic's models. We will provide notice consistent with Section 4 before this integration is activated.
Other subprocessors as listed at ollify.app/legal/subprocessors.
4.2 Legal Compliance. We may disclose information when we believe in good faith that disclosure is required to:
- (a)
comply with applicable law, regulation, court order, or government request;
- (b)
enforce our Terms of Service;
- (c)
protect the rights, property, or safety of Ollify, our users, or others; or
- (d)
respond to lawful requests from public authorities.
Where permitted by law, we will notify you before disclosing your information in response to legal process.
4.3 Business Transfers. If Ollify is involved in a merger, acquisition, asset sale, or other corporate transaction, your information may be transferred as part of that transaction. We will provide notice by updating this Privacy Policy and, where feasible, by sending you an email or in-app notification before your information is transferred and becomes subject to a different privacy policy.
4.4 Aggregated and De-Identified Data. We may share aggregated or de-identified data that cannot reasonably be used to identify you or your business. For example, we may publish aggregate statistics about platform usage. This data is not personal information and is not subject to this Privacy Policy.
5. Subprocessors
A current and complete list of our subprocessors is available at ollify.app/legal/subprocessors. We update this list when we add or change subprocessors.
We will provide at least thirty (30) days' advance notice of any new subprocessor that may materially affect the processing of your data. Notice will be provided by:
updating the subprocessor list at ollify.app/legal/subprocessors; and
sending an email notification to account holders.
Enterprise customers who have executed a Data Processing Agreement with us may have additional rights with respect to new subprocessors, including the right to object. See your DPA for details.
SUBPROCESSORS: The complete, current list of our subprocessors, including each provider's purpose and the data involved, is published at ollify.app/legal/subprocessors.
6. Data Retention
We retain data only for as long as necessary to provide the Service and comply with our legal obligations. Here is how we approach retention for different types of data:
Tenant Customer Data | Retained for the duration of your subscription plus the data export window after termination (60 days). Data is then removed from active systems, and remaining copies cycle out of backup and archive systems in accordance with our retention schedules. Enterprise customers may negotiate different retention terms in a signed Order Form or agreement with Ollify. |
Audit Logs | Two (2) years (730 days). Logs may be retained longer if required for an active security investigation or legal hold. |
Backup Copies | Retained for up to thirty-five (35) days following deletion from production systems, solely for disaster recovery purposes. Backups are not accessible for individual data requests and are not a substitute for using the Service's export tools. |
Account Information | Retained for the life of your account plus sixty (60) days after account deletion, to allow for account recovery and to resolve billing disputes. |
Support Communications | Retained for 3 years to support ongoing customer relationships and for quality assurance. |
Legal Hold | If your data is subject to a legal hold (e.g., litigation or regulatory investigation), we will retain it for the duration of the hold regardless of normal retention schedules. |
Messaging Consent & Message Records | Retained for at least four (4) years, to document that required consent was obtained and to support compliance with messaging laws. |
Messaging Opt-Out Records | Retained permanently. Once a recipient opts out, that record is never deleted, so the opt-out is honored indefinitely. |
When data reaches the end of its retention period, we anonymize or securely delete it from our systems. Anonymized data may be retained indefinitely for statistical and product improvement purposes, but cannot be linked back to you.
7. Cookies and Similar Technologies
We use cookies and similar technologies to operate the Service. A full description of the specific cookies we use is available in our Cookie Policy at ollify.app/legal/cookie-policy.
7.1 Types of Cookies We Use.
Strictly Necessary Cookies — These cookies are required for the Service to function. They enable authentication, session management, and security features. You cannot opt out of strictly necessary cookies without disabling the Service.
Functional Cookies — These cookies remember your preferences (such as your interface theme and map display settings) to improve your experience. Functional cookies are enabled by default but you may disable them in your browser settings or, on our marketing site, through the cookie preferences panel.
WHAT WE DO NOT CURRENTLY USE
We do not currently use analytics cookies, advertising cookies, or third-party tracking technologies. We do not use Google Analytics or similar services. We do not share data with advertising networks or data brokers. If this changes, we will update this policy and our Cookie Policy with at least 30 days' notice.
7.2 Your Cookie Controls. You can control cookies through your browser settings. Most browsers allow you to:
- (a)
view what cookies are set;
- (b)
delete existing cookies; and
- (c)
block new cookies.
Note that blocking strictly necessary cookies will prevent you from logging in and using the Service. Refer to your browser's help documentation for instructions on managing cookies.
COOKIES: The complete inventory of the cookies we use is published in our Cookie Policy at ollify.app/legal/cookie-policy. If analytics cookies are ever added, this section and the Cookie Policy will be updated with at least thirty (30) days' notice.
8. Your Rights and Choices
You have rights over your personal data. We honor these rights for all users, regardless of where you live in the United States — not just for users in states with specific privacy laws.
8.1 Rights Available to All Users.
Right to Know — You can ask us what personal information we hold about you and how we use it.
Right to Access and Export — You may request a copy of your personal information at any time by emailing privacy@ollify.app. We will verify your identity before fulfilling the request and provide your data in a structured, machine-readable format, in compliance with California Consumer Privacy Act portability requirements.
Right to Delete — You may request deletion of your account and personal information by emailing privacy@ollify.app, subject to certain exceptions. Upon a confirmed and verified deletion request, we remove your personal information from active systems promptly, and remaining copies then cycle out of backup and archive systems in accordance with our data retention schedules. Certain records are exempt from deletion: messaging opt-out records (retained permanently so opt-outs are never forgotten), billing records required for tax purposes, and information subject to a legal hold or other legal retention requirement.
Right to Correct — You can correct inaccurate personal information directly in the platform (Settings > Account) or by contacting us at privacy@ollify.app.
Right to Opt Out of Marketing Emails — Every marketing email includes an unsubscribe link. You can also opt out in Settings > Notifications. Opting out of marketing does not affect transactional emails, which are required for the Service.
8.2 California Residents. If you are a California resident, your rights under the California Consumer Privacy Act ("CCPA") and California Privacy Rights Act ("CPRA") are described in full in our California Privacy Notice, available at ollify.app/legal/california-privacy-notice.
8.3 Other State Privacy Laws. Users in states with enacted comprehensive privacy laws — including Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana (MCDPA), Iowa (ICDPA), Indiana (INCDPA), Tennessee (TIPA), New Hampshire, New Jersey, Kentucky, Maryland, Minnesota, Rhode Island, and other states with enacted or pending privacy legislation — generally have rights similar to those described in Sections 7.1 and 7.2, including rights to know, access, delete, correct, and opt out of certain data uses. We honor these rights for all users regardless of state. If your state has specific opt-out mechanisms, appeal rights, or other rights that differ from those described above, please contact us at privacy@ollify.app and we will assist you.
8.4 How to Exercise Your Rights. You may exercise any of the rights described in this Section by:
Email — Send a request to privacy@ollify.app from the email address associated with your account.
We will respond to verifiable requests within forty-five (45) days. If we need more time (up to an additional 45 days), we will notify you within the initial 45-day period. We may need to verify your identity before fulfilling a request. We will not require you to create an account to submit a request, but we may need to verify your identity to protect against unauthorized requests.
If you are a tenant's customer (i.e., a person whose data is processed through the Service by an Ollify business customer), please contact that business directly. Ollify processes that data on the business's behalf and cannot fulfill individual rights requests without the business's authorization.
8.5 Do Not Track Signals. As required by the California Online Privacy Protection Act (CalOPPA), we disclose how we respond to "Do Not Track" (DNT) browser signals: because we do not currently use analytics or advertising cookies of any kind, our data practices do not change based on whether your browser sends a DNT signal — we treat all visitors the same way regardless. If we introduce analytics or advertising technology in the future, we will evaluate and disclose our DNT response at that time. See our Cookie Policy at ollify.app/legal/cookie-policy for more detail on cookies and tracking technologies specifically.
9. Children's Privacy
The Service is designed for and marketed exclusively to businesses. We do not knowingly collect, use, or share personal information from individuals under the age of 13. If you believe a child under 13 has provided personal information to Ollify, please contact us immediately at privacy@ollify.app and we will promptly delete that information. The Service is not intended to be used by or to process data about children. Separately, under the California Consumer Privacy Act, we do not have actual knowledge that we sell or share personal information of consumers under 16 years of age — consistent with the fact that we do not sell or share personal information for cross-context behavioral advertising at all, regardless of age.
10. Security
We take the security of your data seriously and implement industry-standard technical and organizational measures designed to protect it from unauthorized access, disclosure, alteration, and loss. Our security practices include:
Encryption in transit — all data transmitted between your browser and our servers is encrypted using TLS (Transport Layer Security).
Encryption at rest — Customer Data stored on our servers is encrypted at rest using AES-256 or equivalent industry-standard encryption.
Authentication controls — we support strong password requirements, sign-in rate limiting with a CAPTCHA step-up after repeated failed attempts, and server-side session revocation. Multi-factor authentication for customer accounts is not available as of this policy's Effective Date. We may introduce MFA for customer accounts in a future release.
Access controls — access to Customer Data is restricted to authorized personnel on a need-to-know basis. Ollify employees and contractors may access Customer Data only as necessary to provide support, maintain the Service, or comply with legal obligations.
Incident response — we maintain a security incident response process and will notify affected users in accordance with applicable law and Section 14 of this Policy.
Our current security practices are described in more detail in our Security Documentation, available at ollify.app/legal/information-security-policy.
11. International Users
The Service is intended for use within the United States. Our servers and infrastructure are located in the United States. If you access the Service from outside the United States, please be aware that your information will be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your country.
By using the Service from outside the United States, you consent to the transfer and processing of your information in the United States in accordance with this Privacy Policy.
NOTE ON GDPR
We are currently a US-focused product and do not specifically target users in the European Economic Area (EEA), United Kingdom, or Switzerland. If you are accessing the Service from these regions, please contact us at privacy@ollify.app before using the Service to discuss applicable data protection requirements. We will address GDPR compliance in a future version of this policy as we expand internationally.
12. Text Messaging Features and Data Processing
The Service includes text messaging (SMS/MMS) functionality that Customers may use to communicate with their own clients, drivers, contractors, or other contacts ("Text Messaging Features"). This section explains how Text Messaging Features affect your data and the data of individuals you message. Text Messaging Features are being enabled following launch; until then, this section describes how they will work once available.
12.1 What Data Is Processed. When Text Messaging Features are used, we process:
- (a)
the phone numbers of message recipients;
- (b)
the content of text messages sent and received;
- (c)
delivery, read, and reply status; and
- (d)
opt-in and opt-out ("STOP") status for each recipient.
This data is processed through AWS End User Messaging (Amazon Web Services), our subprocessor for text message delivery, as identified in our Subprocessor List.
12.2 Consent and Opt-Out. Federal law (the Telephone Consumer Protection Act, or "TCPA") and applicable state law require prior express consent before sending text messages to an individual. Customer is solely responsible for obtaining and documenting the required consent from each message recipient before using Text Messaging Features to contact them, and for honoring any opt-out request (including replies of "STOP," "UNSUBSCRIBE," or similar). The Service automatically processes "STOP" replies and suppresses further messages to that number, but this is a safeguard only and does not relieve Customer of its own compliance obligations, which are further described in the Acceptable Use Policy.
12.3 Retention. Text message content and delivery logs are processed and retained by AWS End User Messaging (Amazon Web Services) on Ollify's behalf, in accordance with our data retention practices described in Section 5 of this Privacy Policy and Section 9 of our Data Processing Agreement.
12.4 Message and Data Rates. Standard message and data rates from the recipient's mobile carrier may apply to text messages sent through the Service. Ollify is not responsible for carrier charges incurred by message recipients.
13. Mobile Application Privacy
If you access the Service through a mobile application, the following additional privacy disclosures apply. The Ollify mobile application is being made available following launch; until then, this section describes how it will work once available.
13.1 Push Notifications. We may send push notifications to your mobile device for the following purposes:
- (a)
transactional alerts — job updates, form submissions, document activity, and account security events;
- (b)
operational reminders — scheduling reminders and dispatch notifications; and
- (c)
optional marketing notifications — product updates and feature announcements, sent only with your consent.
You can manage push notification preferences at any time through:
- (a)
your device's operating system notification settings (iOS: Settings → Notifications → Ollify; Android: Settings → Apps → Ollify → Notifications); or
- (b)
in-app settings under Settings → Notifications.
Disabling push notifications will not affect your ability to use the Service, but you may miss time-sensitive job or account alerts.
13.2 Third-Party Services Used in Mobile. Our mobile application may use the following third-party services for notification delivery and mobile infrastructure:
Firebase Cloud Messaging (FCM) / Apple Push Notification Service (APNs) — used to deliver push notifications to Android and iOS devices respectively. These services receive device tokens necessary to route notifications to your device.
Additional third-party mobile SDKs will be disclosed in this section as they are added. We will provide at least 30 days' notice before adding any new third-party service that accesses mobile device data.
13.3 Mobile-Specific Data. When you use our mobile application, we may collect:
- (a)
device identifiers (e.g., device model, OS version) for compatibility and security purposes;
- (b)
crash logs and performance data to improve app stability; and
- (c)
location data, if you grant location permission, solely for mapping features.
We do not collect location data in the background without your explicit permission and a disclosed business purpose.
14. Email Communications
We send different types of email and each is handled differently:
Transactional Emails | Account confirmations, password resets, email verification, payment receipts, signing notifications, and security alerts. These are required for the Service and cannot be unsubscribed from while your account is active. |
Notification Emails | Alerts about activity in your account (new jobs, form submissions, document activity). You can control these in Settings > Notifications. |
Marketing Emails | Product updates, new feature announcements, and Ollify news. These are optional. You can unsubscribe at any time using the unsubscribe link in any marketing email, or in Settings > Notifications > Marketing. |
In compliance with the CAN-SPAM Act, every marketing email we send includes:
a clear identification that it is from Ollify;
our physical mailing address: Ollify LLC, 901 N State St. STE N, Jackson, MS 39202; and
a clear and easy unsubscribe mechanism that we honor within ten (10) business days.
15. Data Breach Notification
In the event of a security incident that results in unauthorized access to or disclosure of your personal information, we will notify you in accordance with applicable law. Our notification practices by jurisdiction:
Mississippi (Miss. Code Ann. § 75-24-29) | Without unreasonable delay following discovery of a breach, as required by Mississippi's data breach notification statute. |
California (CCPA/CPRA) | In the most expedient time possible, generally within 30 days of breach discovery, or as required by California law. |
Other US States | In accordance with each applicable state's breach notification law and timeline. |
All Users | We will notify you by email to your registered address and post a notice on our website. Enterprise customers will receive direct notification per their DPA. |
Our breach notification will include, to the extent known at the time of notification:
a description of the nature of the breach;
the categories of personal information involved;
what we are doing to address the breach; and
steps you can take to protect yourself.
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make material changes, we will:
Post the updated Privacy Policy at ollify.app/legal/privacy with a new "Last Updated" date;
Send an email notice to the email address associated with your account at least thirty (30) days before the change takes effect; and
Display an in-app notification about the update.
Your continued use of the Service after the effective date of any updated Privacy Policy constitutes your acceptance of the changes. If you do not agree with the updated policy, you must stop using the Service before the effective date of the change.
For minor or non-material changes (such as correcting a typo, clarifying existing language, or updating contact information), we may update the policy without advance notice.
17. Contact Us
If you have questions, concerns, or requests related to this Privacy Policy or our data practices, please contact us:
Legal Entity | Ollify LLC, a Mississippi Limited Liability Company |
Mailing Address | 901 N State St. STE N, Jackson, MS 39202 |
Privacy Requests | privacy@ollify.app |
Legal / General | legal@ollify.app |
Designated Privacy Contact | support@ollify.app |
Response Time | We respond to all privacy requests within 45 days |
18. Quick Reference — Your Data at a Glance
This table summarizes key data practices described in this Privacy Policy.
Question | Short Answer |
Do you sell my data? | No. We do not sell personal information to anyone, ever. |
Do you share my data with advertisers? | No. We do not share data with advertising networks or for behavioral advertising. |
Do you store my payment card? | No. Stripe handles payment processing. We never store full card numbers. |
Do you use analytics cookies? | Not currently. We use only strictly necessary and functional cookies. |
Can I export my data? | Yes. Email privacy@ollify.app to request an export. We verify your identity and provide your data in a structured, machine-readable format. CCPA-compliant portability. |
Can I delete my data? | Yes. Email privacy@ollify.app to request deletion. Personal info is removed from active systems promptly and cycles out of backups per our retention schedules (legal exceptions apply, including opt-out records). |
How long do you keep my data? | Customer Data: active subscription + 60 days. See Section 5. |
Who can see my data at Ollify? | Only authorized personnel with a need to know, for support and operations. |
How do I contact you about privacy? | Email privacy@ollify.app |