Privacy Policy
Version 2026-08-14 · Last updated August 14, 2026
This policy explains what personal data Innovations App Lab LLC (“we”) collects through OmniLedger, why we collect it, who we share it with, and the choices you have. It is written to meet the notice requirements of the Texas Data Privacy and Security Act.
Two different roles
This distinction determines who you should contact about your data, so it comes first.
When a contractor signs up for OmniLedger, we decide how their account data is handled. For that data we are the controller.
When that contractor then adds their own customers, jobs, photos and invoices, the contractor decides what to collect and why. We only hold and process it on their behalf. For that data we are a processor and the contractor is the controller. If you are a homeowner or business who received an estimate or invoice from a contractor using OmniLedger, your request should go to that contractor. Contact us and we will help route it, but they control the record.
What we collect
- Account data. Email address, password (stored only as a cryptographic hash, never in readable form), and the organizations you belong to and your role in each.
- Business profile. Company name, logo, brand colour, trade, payment remittance instructions and reply-to email.
- Customer records your contractor enters. Names, email addresses, phone numbers, service addresses and free-text notes.
- Work records. Jobs, schedules, quotes, contracts, invoices, payment entries, expenses and the price book.
- Files and photos. Anything uploaded against a job or expense, including site photographs and receipts. Photographs may contain whatever was in frame.
- Electronic signature evidence. When someone signs a contract we record their typed or drawn signature, name, email, the time, and their IP address and browser user agent. This exists specifically so the signature can be shown to be genuine, as contemplated by the Texas Uniform Electronic Transactions Act.
- Agreement acceptance records. When you accept these documents we record your email, the document, its version, the time, your IP address and your user agent.
- Email delivery records. Recipient, subject, contents and delivery status of messages we send for a contractor.
- Technical data. Standard server and request information such as IP address, user agent and timestamps.
What we do not collect
We state these plainly because being specific about the absence is as important as describing the presence.
- No biometric identifiers. We do not capture face geometry, fingerprints, voiceprints, retina or iris scans. A drawn signature is an image of handwriting, not a biometric identifier under Texas Business & Commerce Code Chapter 503.
- No payment card data. No card, bank account or routing numbers pass through or are stored by OmniLedger. Payments are recorded by the contractor as bookkeeping entries — an amount, a date, a method and an optional reference such as a cheque number.
- Not intended for children. OmniLedger is a business tool and is not directed to children under 13. We do not knowingly collect their personal data.
- No advertising or analytics trackers and no third-party advertising cookies.
Why we process it
- To provide the service — authenticating you, showing your workspace, and generating the quotes, contracts and invoices you ask it to generate.
- To send email you have asked us to send on your behalf, such as an invoice to your customer or an appointment reminder.
- To keep the service secure, investigate abuse, and diagnose faults.
- To keep records we are required or reasonably need to keep, including signature and agreement evidence.
We do not use personal data for purposes incompatible with those disclosed here.
Selling, targeted advertising and sensitive data
The Texas Data Privacy and Security Act requires us to say these three things explicitly, so here they are without qualification.
- We do not sell personal data.
- We do not use personal data for targeted advertising and do not perform profiling that produces legal or similarly significant effects.
- We do not intentionally process sensitive personal data — no racial or ethnic origin, religious belief, health diagnosis, sexual orientation, citizenship or immigration status, genetic or biometric data, or precise geolocation. Free-text notes and uploaded photographs are typed and taken by contractors, so we cannot guarantee none is ever entered there; we ask that you do not. Phone cameras often embed GPS coordinates in a photo’s metadata, so we re-encode uploaded images in your browser before they reach us, which discards that metadata. On a browser too old to support this, the original file is uploaded rather than your upload being lost.
Who we share it with
We share personal data with service providers who help us run OmniLedger, under contracts limiting them to that purpose:
| Provider | Purpose | Data involved |
|---|---|---|
| Supabase | Database, authentication and file storage | All account and workspace data, including uploaded photos and files |
| Vercel | Application hosting and delivery | Request metadata such as IP address and browser user agent |
| Resend | Outbound email delivery | Recipient name and email address, and the contents of the message sent |
We may also disclose data where the law requires it, or to protect our rights or someone’s safety. If the business is sold or merged, data may transfer as part of that transaction.
Calendar subscriptions you choose to set up
OmniLedger can publish your schedule as a private calendar feed that you paste into Apple Calendar, Google Calendar or Outlook. If you do that, your calendar provider receives the job title, the appointment time, the service address and the client name for every appointment in that feed, and keeps its own copy under its own privacy policy. We have no relationship with that provider and no visibility into what it does next.
We are telling you this rather than listing them as a service provider because the choice is yours, not ours — nothing is sent anywhere until you subscribe. Two things follow. The feed link is a password. A calendar app cannot sign in, so the link itself is what grants access, and anyone who has it can read that schedule. Do not post it or share it. If it gets out, generate a new one from your settings; the old link stops working immediately.
Your rights
If you are a Texas resident, the Texas Data Privacy and Security Act gives you the right to confirm whether we process your personal data and to access it; to correct inaccuracies; to delete it; to obtain a portable copy of data you provided; and to opt out of sale, targeted advertising and certain profiling — none of which we do.
To exercise any of these, email privacy@innovationsapplab.com. We will respond within 45 days and may extend once by a further 45 days where reasonably necessary, telling you why.
If we refuse your request
You may appeal. Reply to our decision within 30 days and write “Privacy Appeal” in the subject line. A different person will review it and we will respond in writing within 60 days explaining the outcome and our reasoning. If we deny the appeal we will give you a way to complain to the Texas Attorney General, who can also be reached directly at texasattorneygeneral.gov.
Security
We maintain administrative, technical and physical safeguards appropriate to the data we hold. In practice that means encryption in transit, database-level row security so one contractor cannot read another’s data, private file storage reachable only through short-lived signed links, hashed passwords, role-based access within each workspace, and session expiry after inactivity.
One deliberate exception: your company logo is stored somewhere publicly readable, because it has to appear on a quote or invoice that your customer opens without signing in. Only administrators of your organization can upload one. Nothing else is stored there.
No system is perfectly secure and we do not claim otherwise. If a breach affects Texas residents we will notify affected individuals and, where Chapter 521 requires it, the Texas Attorney General.
How long we keep it
Workspace data is kept while the account is active and for a reasonable period afterwards so it can be restored or exported. Signature and agreement acceptance records are kept longer, because their value is precisely that they can be produced later. Deletion requests are honoured subject to records we are required to retain.
Changes
If we change this policy materially we will update the version below and ask you to accept it again the next time you sign in. Current version 2026-08-14, last updated August 14, 2026.
Contact
Innovations App Lab LLC, [ADD MAILING ADDRESS] — privacy@innovationsapplab.com
See also our Terms of Use.