Privacy Policy
Effective July 8, 2026
What we collect
Account data: your name, email, phone, and role within your company workspace.
Business data your company puts into ServePilot: parts, inventory, suppliers, procurement requests, quotes, approvals, and comments. Every record is scoped to your company.
Voice call data: when the AI calls a supplier on your behalf, we store the call record and transcript on the related request so your team has an audit trail.
Device data: if you enable notifications in the mobile app, we store a push token for your device.
What we don’t collect
Payment card details — subscriptions are processed by Stripe; card data never touches ServePilot servers.
We do not sell personal data, run third-party advertising, or use your business data to train AI models.
How we use it
To run the service: searching inventory, placing supplier calls, routing approvals, sending notifications your company configured.
Transactional email (password resets, service notices) is sent via Resend. Voice calls are placed via Vapi and Twilio. Billing runs on Stripe. These processors receive only what they need to perform their function.
Data isolation & security
ServePilot is multi-tenant: every database query is scoped to your company. Passwords are bcrypt-hashed; password-reset tokens are stored only as hashes and expire in 30 minutes.
Traffic is encrypted with TLS. Webhooks from payment and voice providers are signature-verified.
Retention & deletion
Your company’s data is retained while the workspace is active. On request from a workspace admin, we delete the workspace and its data. Dedicated business phone numbers are released 30 days after a subscription ends.
Contact
Questions or requests: privacy@servepilot.ai.