Coilvault legal

Privacy Policy

Version 1.0 · Effective date: July 30, 2026

This Privacy Policy explains how COILVAULT LLC (“CoilVault,” “we,” “us,” or “our”) collects, uses, stores, discloses, and protects information through the CoilVault platform, applications, and websites (the “Platform”). CoilVault currently operates as a business-to-business software provider serving service companies in Florida.

1. Roles and Categories of Information

1.1 Account and Business Information

We collect company name, user names or nicknames, email addresses, authentication and account identifiers, role and permission settings, language preference, consent records, support communications, subscription status, and billing-related records. Authentication providers handle credentials. Stripe or another processor handles payment cards; CoilVault does not receive or store full card numbers.

1.2 Service Records Entered by Subscribers

Subscribers use the Platform to maintain records about their customers and jobs. These records may include property addresses and unit numbers; homeowner, tenant, property manager, or customer names and contact information; appointment information; equipment manufacturer, model, serial number, installation information, and photographs; diagnoses, repairs, parts, notes, estimates, invoices, deposits, and payment references; electronic signatures and associated audit information; and uploaded documents or communications.

For these Service Records, the subscribing business generally determines what information is collected and why. CoilVault hosts and processes the information to provide the Platform. Homeowners and other individuals should ordinarily contact the service business first regarding its records, although they may also contact CoilVault as described below.

1.3 Device, Usage, and Security Information

We may collect IP address, browser or device type, operating system, login and access timestamps, session identifiers, error logs, feature usage, security events, approximate location derived from IP, and similar technical information needed to operate, secure, troubleshoot, and improve the Platform.

1.4 Cookies and Local Storage

The Platform may use strictly necessary cookies, authentication tokens, local storage, and similar technologies to maintain sessions, remember language or interface settings, prevent fraud, and support security. We may use limited analytics only to understand and improve Platform operation. We do not use Service Records for behavioral advertising and do not display third-party advertising in the Platform.

2. Public Records and Lawful Data Sources

To reduce technician data entry, we may obtain county building and mechanical permit records, property-appraiser records, and public address datasets, initially from Miami-Dade and Broward Counties. We use this information to prefill or verify property and equipment information, improve search, and support service workflows. Public records can contain errors or become outdated, and we may refresh, correct, or remove them. We do not currently ingest MLS listings, broker-restricted listing content, or privately owned home-inspection reports. Any new source will be reviewed for access terms, intellectual-property restrictions, privacy impact, and permitted commercial use before ingestion.

3. How We Use Information

  • Provide, maintain, personalize, secure, and support the Platform.

  • Authenticate users, administer permissions, and isolate each subscriber’s records.

  • Process subscriptions, trial conversions, recurring billing, cancellations, and account notices.

  • Create records of agreement acceptance, homeowner authorization, electronic signatures, and other transactions.

  • Generate estimates, invoices, service histories, search results, equipment guidance, and other requested functions.

  • Create de-identified Derived Data and in-app reliability statistics under the Contributor Agreement.

  • Detect, investigate, and prevent fraud, abuse, unauthorized access, and security incidents.

  • Provide backups, disaster recovery, quality assurance, testing, debugging, analytics, and product improvement.

  • Comply with law, enforce agreements, resolve disputes, and protect rights and safety.

4. De-Identified Statistics

The Platform may compute de-identified statistics from records across subscribers, such as the frequency of a repair for an equipment model in a climate area. Before statistics are shown to other subscribers, CoilVault applies the minimum thresholds, contributor-diversity requirements, sparse-cell suppression, geographic generalization, query controls, and other safeguards described in the Contributor Agreement. Displayed statistics do not include names, contact details, street addresses, unit numbers, serial numbers, signatures, photographs, free-text notes, or other direct identifiers. If sufficient data is unavailable, the Platform uses baseline guidance or indicates that network data is insufficient.

We do not sell Personal Information. Under Version 1.0 of our agreements, we also do not sell or license de-identified statistics as a standalone third-party data product.

5. How Information Is Disclosed

  • Within a subscriber account, to Authorized Users according to configured roles and permissions.

  • To service providers that host, authenticate, store, secure, support, analyze, communicate, or process payments for the Platform, subject to contractual restrictions appropriate to their role.

  • To another subscriber only through the disabled-by-default cross-company property-history feature after documented, property-specific, recipient-specific, time-limited authorization is obtained and verified as described below.

  • When required by law, subpoena, court order, or valid governmental process, or when reasonably necessary to protect rights, security, safety, or the integrity of the Platform.

  • In a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets, subject to applicable law and continued protection of the information.

  • At the direction of the subscriber or individual, or with other valid authorization.

6. Cross-Company Property History

The cross-company history feature is disabled at launch. Before activation, CoilVault will implement the authorization requirements in the Contributor Agreement. Authorization must identify the property, recipient company, purpose, categories disclosed, duration, and revocation method. It will expire after ninety days unless a shorter period is chosen. Electronic signature images and payment-card information will not be disclosed. Photographs will be disclosed only if expressly authorized and necessary for the stated purpose. We will log authorization, revocation, and access events. Revocation blocks future access after processing but does not undo prior lawful access.

7. Storage and Security

Information is stored in access-controlled cloud systems. Structured records are maintained in a managed database. Photographs, signature images, and uploaded files are maintained in private file storage where practical, and the database stores references to those files. We use reasonable administrative, technical, and physical safeguards appropriate to the information, including role-based access, least privilege, authentication protections, encryption in transit, encryption at rest where supported and appropriate, private storage, logging, backups, vendor controls, access reviews, patching, and incident-response procedures. No system is perfectly secure, and we cannot guarantee that unauthorized access will never occur.

8. Retention

We retain information only for as long as reasonably necessary for the purposes described here, subscriber instructions, legal compliance, dispute resolution, fraud prevention, security, and enforcement. Our launch retention schedule is:

  • Account information: while the account is active and afterward as needed for billing, legal, security, support, and recordkeeping purposes.

  • Service Records: while the subscription is active, followed by a thirty-day export window. Unless a longer period is required, active records are targeted for deletion within ninety days after that window.

  • Photographs and signature images: generally follow the related Service Record. They are targeted for deletion from active storage within ninety days after the export window unless the subscriber deletes them sooner or lawful retention is required.

  • Encrypted backups: may retain deleted data until overwritten in the ordinary backup cycle, targeted within one hundred eighty days after active deletion. Backup data is not restored except for disaster recovery, security, or legal necessity.

  • Agreement acceptance, homeowner authorization, electronic-signature audit, billing, and transaction records: retained for at least five years after the relevant transaction or account closure, or longer when reasonably necessary for legal claims or compliance.

  • Security and access logs: retained for a period reasonably appropriate to investigation, system integrity, and legal obligations.

De-identified Derived Data may be retained indefinitely because it no longer reasonably identifies a natural person, household, property, or subscriber. A deletion request does not require reconstruction or recalculation of a previously de-identified statistic, but we will suppress or re-generalize an output if it no longer meets our de-identification standard.

9. Access, Correction, Deletion, and Other Requests

Subscribers may access, correct, export, or delete much of their information through the Platform and may contact us for assistance. Homeowners and other individuals may request access, correction, or deletion of Personal Information by contacting the service business that collected it or CoilVault. We may verify identity, authority, and the applicable subscriber relationship before responding. Because a subscriber controls many Service Records, we may coordinate with or refer the request to that subscriber. We may deny or limit a request where permitted by law, including to protect another person’s information, preserve legal claims, prevent fraud, maintain security, or comply with legal obligations.

10. Florida Privacy Law and Expansion

CoilVault is not presently expected to meet the revenue and business-model thresholds that generally trigger the Florida Digital Bill of Rights. We nevertheless use reasonable data minimization, purpose limitation, security, transparency, and request-handling practices appropriate to our operations. If CoilVault expands, materially increases revenue, begins selling digital advertising, operates an app distribution platform or search engine, sells or shares Personal Information, or enters states with broader privacy statutes, we will reassess applicability, update this Policy, implement any required consumer-rights workflow, and enter required controller-processor agreements.

11. Security Incidents and Florida Notices

We investigate suspected incidents and provide notices required by applicable law. Under Florida law, covered entities must take reasonable measures to protect electronic Personal Information. Depending on the information and circumstances, notice to affected Florida individuals and to the Florida Department of Legal Affairs may be required, generally no later than thirty days after determining that a reportable breach occurred or there is reason to believe one occurred, subject to statutory exceptions and authorized delay. We maintain incident-response and escalation procedures and will coordinate with subscribers where an incident involves information processed on their behalf.

12. Children

The Platform is a business tool and is not directed to children under eighteen. We do not knowingly create accounts for children. Service Records should not contain information about a minor unless the subscriber has a lawful business need and authority to provide it. Contact us if you believe a minor’s information was submitted improperly.

13. Changes to This Policy

We may update this Policy. We will update the effective date and provide email or in-app notice of material changes before they take effect where practicable. Changes materially expanding use or disclosure of Service Records may also require updated contractual acceptance or authorization.

14. Language

We may provide English and Spanish versions. The versions are intended to be equivalent. The English version controls in the event of inconsistency to the maximum extent permitted by law, but we will not rely on that clause to enforce a materially different practice that was not fairly disclosed in the language presented.

15. Contact

COILVAULT LLC
17479 SW 21 Ct
Miramar, Florida 33029
coilvault.app@gmail.com