Privacy Policy

Effective September 18, 2026 · Last updated September 18, 2026

This notice explains what information PestMetrics collects, why, who receives it, how long we keep it, how we protect it, and the choices you have. It is written in plain sentences and it is deliberately complete. If you only need a specific answer, use the contents below.

Contents

1Introduction and Scope

1.1 About this notice

This Privacy Policy (the "Policy") describes how we collect, use, disclose, retain, and protect information in connection with the PestMetrics performance analytics platform, the websites at pest-metrics.com and app.pest-metrics.com, and all related applications, application programming interfaces, reports, exports, notifications, and support services (together, the "Service").

Please read this Policy together with our Terms of Service, which govern your use of the Service. Where a written agreement signed by both parties, an order form, or a data processing agreement addresses a subject covered here, that agreement controls to the extent of any conflict.

1.2 The entity responsible

The Service is operated by Intelligent Performance Systems LLC, a Texas limited liability company doing business as PestMetrics, with a mailing address at 410 S Bibb Ave, Unit 5348, Eagle Pass, TX 78853, United States. In this Policy, "PestMetrics", "we", "us", and "our" mean Intelligent Performance Systems LLC.

1.3 Who this notice applies to

This Policy applies to information relating to four groups of people, and different parts of it apply to each:

  • Customers — the pest control companies and other businesses that subscribe to the Service.
  • Authorized Users — the individuals a Customer invites to use the Service, such as owners, branch managers, office staff, and analysts.
  • Website Visitors — anyone who visits our public websites, downloads a resource, uses a free calculator, subscribes to a report, or contacts us, whether or not they ever become a Customer.
  • Data Subjects within Customer Data — individuals whose information a Customer causes to flow into the Service through a connected system. This group typically includes the Customer’s own employees and service professionals, and the Customer’s end customers, such as the homeowners and businesses it services. We generally have no direct relationship with these individuals. Section 2 explains our role, and Section 12.8 explains how their requests are handled.

1.4 A business service

The Service is a business-to-business product sold to companies. It is not offered to consumers for personal, family, or household purposes, and it is not directed to children. See Section 16.

1.5 How to read this notice

Capitalized terms used and not defined where they first appear are defined in Appendix C. Examples introduced by "including", "such as", "for example", or "e.g." are illustrative and not exhaustive. Headings are for convenience and do not limit the text beneath them.

2Our Two Roles: Controller and Processor

Understanding which of two roles we occupy for a given piece of information is the key to the rest of this Policy, because it determines who decides how that information is used and who owes notices to the individuals concerned.

2.1 Information we control

For a limited set of information, we act as a controller (in some laws, a "business"). We determine the purposes and means of processing. This set includes account registration details for Customers and Authorized Users, billing and subscription records, support correspondence, security and audit logs, website analytics, and information about Website Visitors and prospective customers. Sections 3.1, 3.2, 3.6, and 5 describe what we do with it.

2.2 Information we process on a Customer’s behalf

For Customer Data, we act as a processor (in some laws, a "service provider"). Customer Data means the operational records that a Customer, or a system a Customer connects, transmits to or through the Service, together with the metrics, scorecards, forecasts, and reports we derive from those records for that Customer. The Customer determines the purposes and means of that processing. We process Customer Data to provide, secure, support, and improve the Service for that Customer, and for the other limited purposes described in this Policy and permitted by applicable law.

We do not sell Customer Data. We do not use Customer Data to serve advertising. We do not use one Customer’s Customer Data to benefit another Customer in any form that identifies the first Customer, its personnel, or its end customers. See Sections 5.7 and 5.8.

2.3 What this means for you as a Customer

Because you decide what data enters the Service, you are responsible for the lawfulness of that data. By connecting a system or uploading a file, you represent and warrant, on an ongoing basis, that:

  1. You are authorized to grant us access to the accounts, credentials, files, and data you connect or provide, and doing so does not breach your agreement with the provider of that system.
  2. You have provided all notices and obtained all consents, permissions, and authorizations required by applicable law from the individuals whose personal information you cause to flow into the Service, including your employees, contractors, and end customers.
  3. Where the Service ingests location, telematics, dashcam, or individual productivity data about workers, you have satisfied any workforce monitoring notice, consent, posting, or recordkeeping obligations that apply to you. Section 14 discusses this in more detail. Those obligations are yours as the employer; they are not ours.
  4. You will not upload or connect special categories of data, protected health information, payment card numbers, government identifiers, biometric identifiers, or data about children, unless we have agreed in writing in advance that the Service will handle it.
  5. You will respond to requests from your own personnel and end customers concerning their information, and you will use the Service’s access, export, correction, and deletion functions, or contact us, where you need our assistance to do so.

2.4 Requests from individuals inside Customer Data

If you are an employee or an end customer of a business that uses PestMetrics and you want to exercise rights over your information, your request should go to that business, which controls the data. If you contact us instead, we will, where we can reasonably identify the relevant Customer, refer your request to that Customer and tell you that we have done so. We will assist the Customer in responding as required by applicable law and by our agreement with them. We will not independently grant, deny, or act on such a request except on the Customer’s documented instruction or where the law requires us to act.

3Information We Collect

The categories below describe the information the Service may collect. Not every category applies to every Customer. What is actually collected depends on the plan you purchase, the integrations you choose to connect, the features you enable, the files you upload, and the settings you configure.

3.1 Information you provide to us directly

  • Account and profile information: your name, business email address, company name, job title or role, branch and view assignments, and account preferences.
  • Authentication information: a password, which we store only as a salted hash produced by a deliberately slow hashing function, and never in a form we can reverse to recover your password; multi-factor authentication secrets, which we store encrypted; and password reset and email verification tokens, which are short-lived.
  • Invitation information: when an administrator invites a colleague, we process that person’s name and email address in order to create their account and deliver an invitation message. Where an account is created with a system-generated initial password, that password is transmitted once to the invitee and must be changed on first use. We recommend administrators use the invitation flow rather than sharing credentials by other means.
  • Integration credentials: the API keys, tokens, secrets, office identifiers, base URLs, and OAuth authorizations you supply so that the Service can connect to your other systems. See Section 11.1 for how these are protected.
  • Configuration and content you create: branch and service professional records, scorecard weightings, targets, alert rules, report and export settings, dashboard layouts, saved notes, contact-attempt logs, dismissed suggestions, and any free-text you type into the Service, including questions you ask the AI analyst.
  • Uploaded files: timekeeping spreadsheets and similar files you import, together with the parsed contents, a file hash, the uploading user, and a timestamp, which we retain to support auditability and reconciliation.
  • Billing information: your billing contact, plan, subscription status, trial dates, and the customer and subscription identifiers assigned by our payment processor. Card numbers and bank details are entered directly into our payment processor’s systems. We do not receive, process, or store full payment card numbers.
  • Support and correspondence: the content of messages, tickets, screenshots, error reports, and call notes you send us, and our replies.
  • Marketing and event information: information you submit through newsletter forms, report requests, calculators, demo requests, and similar interactions.

3.2 Information collected automatically when you use the Service

  • Device and connection data: IP address, browser type and version, operating system, device type, screen and viewport characteristics, language, and time zone.
  • Usage and event data: pages and screens viewed, features used, buttons and filters selected, sync operations triggered, exports generated, search and query terms entered into the Service, referring and exit pages, and timestamps.
  • Authentication and security logs: sign-in and sign-out events, session identifiers, token issuance and revocation, failed authentication attempts, rate-limit events, and impersonation sessions initiated by our personnel for support purposes.
  • Audit records: records of administrative and configuration actions taken inside the Service, attributed to the acting user, which we use for accountability, troubleshooting, and security. Coverage of the audit trail varies by action type and is being extended over time; it should not be relied on as a complete record of every event.
  • Diagnostic and error data: application error messages, stack traces, request identifiers, the page or route where an error occurred, browser and device details, and related technical context, which may be captured automatically from both authenticated users and public website visitors and forwarded to our operations team.
  • Cookies, local storage, and similar technologies: see Section 7.

3.3 Customer Data ingested from systems you connect

When you authorize a connection, we retrieve records from that system on a schedule and on demand. The table below describes, by system, the categories of records the Service may retrieve. Availability of a given integration depends on your plan and configuration.

Connected systemCategories of records the Service may retrieve
FieldRoutes / PestRoutes (field service management)Appointments and their status, assigned and completing employee, and service dates; service tickets and invoices, including line items, service types, charges, totals, and invoice dates; subscriptions, including recurring and annual values, contract values, sold-by and added-by attribution, start dates, and cancellation dates; customer records, including account identifiers, office assignment, balances, responsible balances, and balance ageing; cancellation and reservice events; and employee roster records, including names, identifiers, office assignment, active status, and role type.
Everee (payroll and time tracking)Worker records, including names, work email addresses, worker identifiers, employment status, hire dates, and information from which a departure or termination date may be inferred for turnover analysis; and shift records, including clock-in and clock-out times, hours worked, and branch attribution.
Samsara (fleet telematics), where connectedVehicle and driver records, including driver names and identifiers and vehicle assignments; vehicle location data, including latitude and longitude coordinates, trip start and end points, and reverse-geocoded street addresses; trip and route data, including distance, odometer readings, idle time, and duration; and driver safety and behavior data, including speed, harsh braking, harsh acceleration and cornering events, safety scores, and references or links to dashcam media held in Samsara. See Sections 3.4 and 14.
QuickBooks Online (accounting), where connectedCompany profile information and financial records made available through the authorized connection, such as accounts, categories, and summary financial statement data used for reconciliation and reporting.
Google (business location and review data)Publicly available information about the business locations you identify, including place identifiers, ratings, review counts, review text, review timestamps, and the display names and profile image references of the people who left those reviews.
Manual importsTimekeeping and hours data you upload by file, together with the parsed values, the identity of the uploading user, a file hash, and a timestamp.
Additional connectorsWe add integrations over time. Where you connect a system not listed above, the categories retrieved will be those necessary to deliver the feature you enabled, and will be described in the Service at the point of connection and in the subprocessor page referenced in Section 8.9.

We store the records returned by connected systems, which may include complete records and fields the Service does not currently display or use, so that metrics can be recomputed and reconciled against your source system without repeatedly calling that system’s API. This improves accuracy, reduces API consumption, and lets us answer questions about how a number was derived.

3.4 Location, telematics, and workforce monitoring data

Where you connect a fleet telematics system, the Service ingests, stores, processes, and displays precise geolocation and driving-behavior information associated with identified drivers and vehicles. This information may be displayed on maps within the Service, summarized into route and safety metrics, incorporated into individual scorecards, included in exports and reports, and referenced in operational briefings. Precise geolocation is treated as sensitive personal information under several state privacy laws.

We also compute individual-level productivity and performance metrics about named workers from the data you connect. These include jobs per hour, revenue per hour, stops, sales attribution, cancellation and reservice attribution, and composite scores. Section 14 sets out the notice obligations these features may create for you as an employer.

3.5 Branch location and publicly available reference data

To provide weather, pest-pressure, seasonality, holiday, and market-penetration features, the Service transmits limited, non-sensitive identifiers such as a branch address, place name, or coordinate pair to public reference services, and stores the results, including geographic coordinates and census geography codes, on the branch record. See Section 8.2.

3.6 Information about Website Visitors and prospective customers

On our public websites, we may collect the email address, name, company, and any other details you submit through a form; the topic or resource you requested; the pages, tools, and calculators you used; and the automatically collected device, usage, analytics, and error data described in Sections 3.2 and 7. We use this information to send you what you asked for, to respond to you, to send you related information about the Service where permitted, and to measure and improve our websites. Every marketing email we send will identify us, include our mailing address, and provide a way to opt out. You may also opt out at any time by emailing the address in Section 20.

3.7 Statutory categories of personal information

Appendix B restates the categories above using the classification scheme used by the California Consumer Privacy Act, together with the sources, purposes, and recipient categories for each.

3.8 Information collected by our mobile application

PestMetrics offers a mobile application for managers and other Authorized Users. When you sign in, the app sends your business email address, your password, and, where you have enabled it, your multi-factor code, in the same way the website does, and it keeps your session in the device keychain. When you allow notifications, the app registers an Expo push notification token, delivered through Expo’s push service and Apple’s Push Notification service (APNs), together with the device platform, such as iOS, and the device name you have given your phone, so we can deliver alerts to that device; you can stop this at any time by turning notifications off for PestMetrics in your device settings, or by signing out. As on the website, your IP address and client string are recorded in the sign-in history described in Section 3.2 and retained as described in Section 10. Push notifications are delivered through the providers identified in Section 8.2. On supported devices, the app can display a home-screen or lock-screen widget with your own figures; that widget is drawn on the device from data already present on it, does not leave the phone, and is cleared when you sign out. The app does not use any information for tracking and does not request access to your location, camera, photos, or contacts.

4Where Information Comes From

We obtain information from the following categories of sources:

  1. Directly from you and from your Authorized Users, through the Service, our websites, and correspondence with us.
  2. Automatically from your devices and browsers as you interact with the Service and our websites.
  3. From the third-party systems you authorize us to connect to, using the credentials or authorizations you supply.
  4. From files you upload.
  5. From publicly available sources and public reference services, including business review information and public geographic, demographic, weather, and calendar data.
  6. From our own service providers, such as our payment processor, email delivery provider, hosting providers, and analytics provider, in connection with the services they perform for us.
  7. From information generated within the Service itself, including derived metrics, scores, forecasts, alerts, logs, and audit records.

5How We Use Information

5.1 To provide and operate the Service

  • Creating and administering accounts, authenticating users, and enforcing roles, branch scoping, and view permissions.
  • Connecting to the systems you authorize, synchronizing records on a schedule and on demand, backfilling historical periods, and repairing gaps.
  • Computing metrics, scorecards, composite scores, branch analytics, annual recurring revenue, accounts receivable views, forecasts, targets, and benchmarks for you.
  • Generating dashboards, reports, exports, share cards, alerts, notifications, and briefings, and delivering them through the channels you configure.
  • Performing write-back actions in a connected system where you have enabled that feature and confirmed the specific action.
  • Providing customer support, diagnosing synchronization problems, and reconciling figures against your source systems.

5.2 To secure the Service

To authenticate users, detect and investigate suspicious or unauthorized activity, enforce rate limits and plan limits, prevent and respond to fraud and abuse, maintain audit records, preserve evidence, and protect the rights, property, and safety of PestMetrics, our Customers, and others.

5.3 To maintain and improve the Service

To monitor performance and reliability, investigate errors, test changes, understand which features are used and how, size infrastructure and API budgets, and develop new features and integrations. Where we use Customer Data for these purposes, we do so as permitted by applicable law and by our agreement with the relevant Customer.

5.4 To communicate with you

To send service and transactional messages, which include invitations, password resets, email verification, security notices, billing and subscription notices, sync failure alerts, product announcements, and notices of material changes to this Policy or our Terms. You cannot opt out of service and transactional messages while you hold an account, because they are necessary to operate it. Marketing messages are separate and always carry an opt-out.

5.5 To bill and administer subscriptions

To process payments through our payment processor, manage plans, trials, upgrades, downgrades, renewals, and cancellations, enforce plan limits, and keep the tax and accounting records the law requires us to keep.

5.6 To comply with law and protect legal rights

To satisfy legal, regulatory, tax, accounting, and audit obligations; to respond to lawful requests from public authorities; and to establish, exercise, or defend legal claims.

5.7 To create de-identified and aggregated information

We may create de-identified and aggregated information from data processed through the Service, including industry benchmarks and statistical analyses. We maintain such information in de-identified form, do not attempt to reidentify it except as permitted by law to test our de-identification, and contractually require the same of anyone to whom we provide it. De-identified and aggregated information does not identify you, your company, your personnel, or your end customers, and we may use and disclose it for any lawful purpose, including product development, research, benchmarking, and marketing.

5.8 What we do not do

  • We do not sell personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined by applicable state privacy laws. We have not done so in the twelve months preceding the date of this Policy.
  • We do not use Customer Data to target advertising to you or to anyone else.
  • We do not authorize our artificial intelligence providers to use Customer Data or your prompts to train their general-purpose models. See Section 6.4.
  • We do not disclose one Customer’s identifiable Customer Data to another Customer.

6Artificial Intelligence and Automated Processing

The Service includes features that use third-party large language models. Because this involves transmitting information outside our own infrastructure, we describe it separately and in detail.

6.1 Where artificial intelligence is used

  • An operations analyst that produces written daily and periodic briefings summarizing branch and individual performance.
  • A question-and-answer feature that lets an Authorized User ask questions in plain language about their own data and receive a written answer, in which the model may issue read queries against that Customer’s own records and receive the results in order to compose its response.
  • Narrative commentary, explanation, and summarization attached to metrics, forecasts, alerts, and reports.
  • Suggestions, such as proposed matches between records, that a person reviews before anything is changed.

6.2 Which providers may receive information

Depending on our configuration at a given time, these features are served by one of the following providers: Anthropic, Google, or Groq. We select the provider for operational reasons such as capability, latency, availability, and cost, and we may change it. The current provider is identified on the subprocessor page referenced in Section 8.9.

6.3 What is transmitted

A request to a provider may include your company name; branch names and operational metrics such as revenue, hours, stops, revenue per hour, jobs per hour, cancellations, reservices, accounts receivable, and annual recurring value; the names of individual service professionals and their associated performance figures; review ratings and text; the text of the question an Authorized User typed; the conversation history for that session; and the rows returned by read queries against that Customer’s own records. Requests are transmitted over encrypted connections.

6.4 Training and provider retention

We use these providers under commercial terms that do not permit them to use our inputs or outputs to train their general-purpose models. Providers may retain request content for a limited period for abuse monitoring and legal compliance in accordance with their own terms. We do not control those retention periods.

6.5 Human oversight

These features are advisory. Model output may be incomplete, out of date, or wrong, and should be verified before it is relied on. The Service does not use automated processing to make decisions that produce legal or similarly significant effects concerning an individual. Employment decisions made with the assistance of information in the Service are made by you, not by us, and remain your responsibility, including compliance with any law governing automated or algorithmic tools in employment.

6.6 Your control

Artificial intelligence features can be disabled for your tenant on request. If you would prefer that no Customer Data belonging to you be transmitted to an artificial intelligence provider, contact us at the address in Section 20 and we will disable these features for your account. Doing so will remove the associated narrative and question-and-answer functionality; your metrics, dashboards, reports, and exports will continue to work.

7Cookies, Analytics, and Similar Technologies

7.1 What we use and why

TypePurposeCan it be disabled?
Strictly necessary storageKeeps you signed in, holds your session and authentication token, remembers your tenant and impersonation context, protects against abuse, and enables core navigation.No. The Service will not function without it.
Preference storageRemembers interface choices such as column order and visibility, selected summary cards, saved filters, chart preferences, and dismissed prompts. Stored in your browser.Yes, by clearing site data in your browser. Your preferences will reset.
AnalyticsWe use Vercel Analytics across our public websites and the signed-in application to measure page views, traffic sources, and aggregate usage patterns so we can understand what is used and improve it. It is configured to operate without cookies and to collect aggregate measurement data rather than to build advertising profiles.Yes, using a browser or extension that blocks analytics requests. The Service will continue to work.
DiagnosticsCaptures application errors and technical context so we can find and fix faults.Not individually. Data is minimized and used for reliability.
Third-party contentSome pages load fonts, map tiles, and similar assets. Where a map is displayed, your browser requests map tiles from a third-party tile service, which necessarily receives your IP address and the map area being viewed.Yes, by not using map views, or by blocking the relevant requests.

7.2 Advertising

We do not use advertising cookies, advertising pixels, or cross-context behavioral advertising trackers on the Service or our websites.

7.3 Do Not Track and Global Privacy Control

Because we do not sell personal information and do not share it for cross-context behavioral advertising, an opt-out preference signal has no data for us to act on. We nonetheless treat a Global Privacy Control or similar universal opt-out signal received from your browser as a valid request to opt out of any sale or sharing, should our practices ever change. There is no common industry standard for responding to Do Not Track browser signals, and we do not respond to them.

8How and With Whom We Share Information

8.1 Our approach

We disclose information to the categories of recipients described in this Section, and for the purposes described in this Policy. We disclose the minimum reasonably necessary for the relevant purpose, over encrypted connections, and, in the case of service providers, under written terms that restrict their use of the information to performing services for us.

8.2 Service providers and subprocessors

We rely on third parties to operate the Service. The table below identifies the categories of service provider we use and, as of the effective date of this Policy, the principal providers in each category. Providers change; the current roster is maintained as described in Section 8.9.

CategoryProviders as of the effective dateWhat they receive
Application and database hostingRenderAll application data stored by the Service, including Customer Data and account data.
Website and application deliveryVercelRequests for the web interface, together with associated connection and device data.
Product analyticsVercel AnalyticsAggregate page view and usage measurement data, including device and connection characteristics.
Payment processingStripeBilling contact details, plan and subscription information, and the payment details you enter directly with them.
Transactional and marketing email deliveryResendRecipient names and email addresses, message subject and body content, including invitations, password resets, verification links, alerts, and any initial credentials contained in an invitation.
Mobile push notification deliveryExpo (Expo Application Services); Apple Push Notification serviceA device push token, and the title and body of a notification, in order to deliver it to your mobile device. Android delivery, when offered, will additionally use Google’s Firebase Cloud Messaging, and this roster will be updated at that time.
Artificial intelligence and language model providersAnthropic; Google; GroqThe request content described in Section 6.3, which may include company and branch names, operational metrics, individual worker names and performance figures, review content, user-typed questions, and query results.
Notification and messaging delivery for channels you configureTelegram; Discord; ntfy.sh; any webhook endpoint you specifyThe content of the briefings, alerts, and events you route to that channel, which may include branch performance figures and the names of individual workers.
Public reference data servicesNational Weather Service; US Census Bureau; Nominatim / OpenStreetMap; Nager.Date; Google Maps PlatformBranch place names, addresses, or coordinates, and country or date parameters, in order to return weather, geographic, demographic, mapping, and public holiday information. No personal information about Authorized Users or end customers is sent to these services.
Systems you connectFieldRoutes / PestRoutes; Everee; Samsara; QuickBooks Online; Google; and any other system you authorizeAuthentication credentials you supplied and the parameters of the read requests we make on your behalf. Where you enable and confirm a write-back action, the specific change you requested.
Professional advisorsLegal, accounting, insurance, and security advisersInformation reasonably necessary for the advice or service being provided.

8.3 Channels and endpoints you configure

Where you configure an outbound destination, such as a webhook endpoint, a chat channel, or a push topic, the content you route to it leaves our control and is governed by that destination’s security and privacy practices, not ours. Some destinations, including public notification topics, may be readable by anyone who knows or guesses the address. You are responsible for choosing destinations that are appropriate for the sensitivity of the content, for using encrypted endpoints, and for restricting who can access them.

8.4 Within your own organization

Information in your account is visible to your Authorized Users according to the roles, branch assignments, and view permissions your administrators configure. Choosing who sees what inside your account is your responsibility.

8.5 Our personnel and support access

A limited number of our personnel hold administrative privileges that permit access to Customer accounts and data, and permit them to enter a Customer account in the context of a specific user in order to reproduce a fault, verify a fix, or provide support. Access is limited to personnel with a business need, is subject to confidentiality obligations, and is recorded. We do not use this access to view Customer Data for any purpose other than operating, securing, and supporting the Service, complying with law, or acting on your instructions.

8.6 Legal, safety, and compliance disclosures

We may disclose information where we believe in good faith that doing so is required or permitted by law; in response to a subpoena, court order, warrant, or other lawful request; to cooperate with regulators or law enforcement; to enforce our Terms or other agreements; to investigate suspected fraud, abuse, or security incidents; or to protect the rights, property, or safety of PestMetrics, our Customers, or any person. Where we are legally permitted to do so and it is practicable, we will notify the affected Customer before disclosing their Customer Data.

8.7 Corporate transactions

If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, receivership, sale of assets, or transition of service to another provider, information held by us may be transferred or disclosed as part of that transaction or as part of due diligence for it, subject to reasonable confidentiality protections. Any recipient will remain bound by commitments materially consistent with this Policy with respect to the information transferred, or will give you notice and a choice before materially changing them.

8.8 With your direction or consent

We may disclose information to any other party at your direction or with your consent.

8.9 Changes to our service providers

We add, remove, and replace service providers as the Service evolves. A current list of our service providers and subprocessors is maintained at pest-metrics.com/security and is updated when it changes. We will provide notice of material changes to our subprocessor roster as described in Section 19, and where a written agreement with a Customer specifies a different notice or objection process, that process applies.

9International Data Transfers

The Service is operated from and intended for use in the United States, and information is stored and processed in the United States. Some of our service providers operate globally and may process information in other countries. If you access the Service from outside the United States, you understand that your information will be transferred to, stored in, and processed in the United States, where data protection laws may differ from those of your jurisdiction. Where a transfer of personal information originating in the European Economic Area, the United Kingdom, or Switzerland requires a lawful transfer mechanism, we will implement an appropriate mechanism, such as the European Commission’s standard contractual clauses, and will make relevant information available on request.

10Data Retention

10.1 How we decide how long to keep information

We retain information for as long as needed for the purposes described in this Policy, and then delete it, de-identify it, or archive it. In deciding how long a category is needed, we consider the duration of the Customer relationship and how long the data must remain available to compute historical trends and comparisons; the volume, nature, and sensitivity of the information and the risk of harm from unauthorized use or disclosure; whether the purpose can be achieved by other means; the operating requirements of the Service, including reconciliation, auditability, and troubleshooting; and applicable legal, tax, accounting, regulatory, and limitation-period requirements.

10.2 General retention periods

CategoryTypical retention
Account, profile, and configuration dataFor the life of the account, then in accordance with Section 13.
Customer Data and derived metricsFor the life of the account, so that historical periods remain comparable, then in accordance with Section 13.
Stored copies of records retrieved from connected systemsRetained for the life of the account to support recomputation and reconciliation against your source system. These copies are de-duplicated to the latest version of each record rather than aged out, so apart from the annual-recurring-revenue ledger (90 days) they persist, including telematics trip records, until the account is deleted.
Audit and activity recordsRetained on a rolling ninety-day window and then pruned automatically, together with synchronization logs and notifications. Alerts you have read are pruned at ninety days; unread alerts are retained. API call counters are pruned at thirty days. These windows may change; they are not a commitment to indefinite retention.
Payment-provider webhook recordsWebhook events we receive from our payment processor are retained for the life of the account, so that a payment record can be reconciled or reconstructed, and are deleted when the account is deleted. Events we cannot attribute to any account are stored without their message body, keeping only the event identifier, the account identifier, the event type, and the timestamp, and are pruned at thirty days.
Synchronization logs and operational job recordsRetained for a limited rolling period sufficient for troubleshooting, then pruned automatically.
Authentication artifacts, including password reset tokens, verification tokens, and revoked session identifiersShort-lived; deleted or expired shortly after use or expiry.
Billing, tax, and accounting recordsRetained for the period required by applicable law, which is generally several years, and held by us and by our payment processor independently of account deletion.
Marketing and prospect informationUntil you opt out or ask us to delete it, and thereafter only a minimal suppression record so that we can honor your opt-out.
Security incident and legal hold recordsRetained for as long as necessary to investigate, respond, and establish, exercise, or defend legal claims.
De-identified and aggregated informationRetained indefinitely, as it no longer identifies any person or company. See Section 5.7.

10.3 Backups

We maintain encrypted backups for disaster recovery. When information is deleted from the live Service it may persist in backups for a period until those backups expire on their ordinary rotation cycle. Backups are not used to restore deleted individual records, and information persisting in a backup is not returned to active use except in a genuine restoration event, after which any pending deletions are reapplied.

11How We Protect Information

11.1 Technical measures

  • Traffic between your browser and the Service, and between the Service and the third-party systems and providers we call, is encrypted in transit using industry-standard transport layer security. Where the Service permits you to specify an outbound destination or a base URL, you should specify an encrypted endpoint; if you configure an unencrypted destination, transmission to that destination will not be protected in transit, and that choice is yours.
  • Integration credentials, OAuth tokens, webhook signing secrets, and multi-factor authentication secrets are encrypted at rest using AES-256-GCM with authenticated additional data binding each record to the account it belongs to.
  • Passwords are stored only as salted hashes produced by a deliberately slow, industry-standard password hashing function.
  • Data in our managed database and object storage is encrypted at rest by our infrastructure providers.
  • The application is designed so that queries for Customer Data are scoped to the requesting account, and we test and review for scoping defects. Access within an account is further constrained by role, by branch assignment, and by view permission.
  • We apply authentication controls, session token revocation, rate limiting, request validation, standard web security headers, and dependency monitoring.
  • Multi-factor authentication is mandatory for Admin accounts, which cannot use the Service until it is enrolled, and is available and recommended for other roles.

11.2 Organizational measures

We limit access to production systems and Customer Data to personnel with a business need, bind personnel and contractors to confidentiality obligations, log administrative actions, review our service providers, and maintain internal procedures for change management, key management, and incident response.

11.3 Your responsibilities

Security is shared. You are responsible for keeping credentials confidential, for enabling multi-factor authentication, for granting each user only the role and branch access they need, for removing users promptly when they leave, for choosing appropriate outbound destinations, and for notifying us immediately at the address in Section 20 if you suspect unauthorized access to your account.

11.4 No guarantee

We work continuously to protect information, but no method of transmission over the internet and no method of electronic storage is completely secure, and no set of safeguards can eliminate all risk. We cannot and do not guarantee the absolute security of information, and we cannot guarantee that the Service will be free of vulnerabilities. The measures described here are our current practices and may change as we improve them; they are a description of our program, not a warranty.

11.5 Incident response

We maintain an incident response process. If we determine that a security incident has resulted in the unauthorized acquisition of or access to personal information we hold, we will notify affected Customers without undue delay and in accordance with applicable law, provide the information reasonably available to us about the incident, and cooperate with the Customer’s own notification obligations. Where we act as a processor, notification to affected individuals is the Customer’s responsibility as controller.

12Your Privacy Rights and Choices

12.1 Rights that may be available to you

Depending on where you live and the role we occupy with respect to your information, you may have some or all of the following rights. We honor these rights as applicable law requires, and we extend the request mechanism below to anyone who asks, whether or not a statute compels it.

  • To know what personal information we collect, the sources, the purposes, the categories of recipients, and how long we keep it.
  • To access a copy of the personal information we hold about you, in a portable format where required.
  • To correct inaccurate personal information.
  • To request deletion of personal information, subject to exceptions the law permits.
  • To opt out of the sale of personal information, of sharing for cross-context behavioral advertising, and of profiling that produces legal or similarly significant effects. As stated in Sections 5.8 and 7.3, we do not sell or share personal information and do not conduct such profiling.
  • To limit the use and disclosure of sensitive personal information to what is necessary to provide the Service.
  • To be free from discrimination or retaliation for exercising a privacy right. We will not deny you service, charge a different price, or provide a different quality of service because you exercised a right.
  • To withdraw a consent you previously gave, without affecting processing already carried out.

12.2 How to make a request

Email support@pest-metrics.com with the subject line "Privacy Request". Tell us the right you wish to exercise, the account or company the request relates to, and an address at which we can reach you. You may also write to us at the postal address in Section 20.

12.3 Verification

To protect your information, we must verify that a request comes from you or from someone authorized to act for you. We will ask for information sufficient to match you to records we already hold, which may include the email address associated with an account and details of your relationship with the relevant company. We will use information you provide for verification only to verify the request. If we cannot verify a request, we will tell you why.

12.4 Authorized agents

You may use an authorized agent. We will require written proof of the agent’s authority, and we may also require you to verify your own identity with us directly and to confirm that you gave the agent permission to submit the request.

12.5 Timing

We will acknowledge a request promptly and respond within the period required by the applicable law, which is generally forty-five days from receipt of a verifiable request. Where permitted, we may extend that period once, by up to an additional forty-five days, and we will tell you before we do.

12.6 Appeals

If we decline a request in whole or in part, we will explain why. You may appeal by replying to our decision or by emailing support@pest-metrics.com with the subject line "Privacy Appeal" within a reasonable period. We will review the appeal and inform you in writing of the outcome, with reasons, within the period the applicable law requires, generally sixty days. If we deny the appeal, we will provide a method by which you may contact your state attorney general to submit a complaint.

12.7 State-specific disclosures

Residents of California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Florida, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, Rhode Island, and other states with comprehensive privacy laws may have the rights described in Section 12.1, on the terms and subject to the exceptions their state law provides. The categories of personal information we collect, the sources, purposes, and categories of recipients are set out in Appendix B. We have not sold or shared personal information, and we have not knowingly collected or sold the personal information of anyone under sixteen. Nevada residents may submit a request regarding the sale of covered information to the address in Section 20; we do not sell covered information.

12.8 Requests about Customer Data

If your request concerns information a business submitted to the Service about you, such as information about you as an employee or as an end customer of a pest control company, that business controls the information and your request should go to it. See Section 2.4 for how we handle such requests if you send them to us.

13Export, Account Closure, and Deletion

13.1 Access and export

While your subscription is active and in good standing, Authorized Users with appropriate permissions can view data in the Service and export reports in CSV, Excel, and PDF formats. The reports available for export are those provided by the Service, and some are associated with particular plan tiers. If you need a copy of data in a form the built-in exports do not provide, or if your subscription has lapsed and you need an export, contact us at the address in Section 20 and we will work with you in good faith to provide a reasonable export of your Customer Data in a commonly used machine-readable format.

13.2 Deletion

You may close your account at any time. On termination, and on request, we will delete or de-identify Customer Data associated with your account within a reasonable period, and in any event within ninety days of your request, subject to Section 13.3. We will confirm when deletion is complete. If you ask us to delete your account data while your subscription is active, we will do so, and you should understand that deletion is irreversible and that we cannot restore deleted data afterward.

13.3 What survives deletion

The following may be retained after account deletion, as permitted or required by law: de-identified and aggregated information, as described in Section 5.7; billing, tax, and accounting records, which are also held independently by our payment processor; records necessary to comply with a legal obligation, to resolve a dispute, to enforce an agreement, or to establish, exercise, or defend legal claims; security, fraud prevention, and suppression records, including records of your opt-out preferences so that we can continue to honor them; and copies within encrypted backups until those backups expire on their ordinary rotation cycle, as described in Section 10.3.

14Workforce Data and Employee Monitoring

The Service is designed to measure the performance of individual workers. Depending on the features and integrations you enable, it may collect, store, and display information about identified employees and contractors, including hours worked, jobs completed, revenue attributed, sales attributed, cancellations and reservices attributed, composite performance scores and rankings, hire and departure dates, and, where telematics is connected, precise vehicle location, trip routes and addresses, speed, and driving-behavior events.

This is information about your workforce, and you are the employer. Several states impose obligations on employers who monitor employees electronically or who track vehicle or employee location. Examples include New York’s requirement to give written notice of electronic monitoring on hiring and to post a notice; Connecticut’s and Delaware’s electronic monitoring notice requirements; and California’s rules on notice and, in some circumstances, consent for location tracking, together with its requirements concerning notice to employees about personal information collected in the employment context. Other states have adopted or are adopting similar rules, and some jurisdictions regulate automated decision-making tools used in employment.

We do not assess, and cannot assess, whether you have met those obligations. Providing the required notices, obtaining any required consents, and complying with any applicable collective bargaining agreement or workplace policy is your responsibility as the employer, as you agreed in Section 2.3. We recommend you take advice before enabling telematics ingestion or individual monitoring features, and that you tell your workforce plainly what is measured and why.

If you would prefer that telematics or individual location data not be ingested at all, do not connect a telematics system, or contact us and we will disable that integration for your account.

15Information About Your End Customers

The records the Service retrieves from your field service management system include information about the people and businesses you service. Depending on your configuration, this may include account identifiers, service locations, balances and responsible balances, how long a balance has been outstanding, subscription and contract values, cancellation status and dates, appointment and service history, invoice detail, and free-text notes recorded in the Service about collections and contact attempts concerning a named account.

We process this information solely as your processor, to compute the metrics and views you use, in accordance with Section 2.2. We do not contact your end customers, we do not market to them, and we do not use their information for any purpose of our own other than operating, securing, and supporting the Service and complying with law. Your privacy notice to your own customers should account for the fact that you use a third-party analytics provider, and you should ensure that your agreements and notices permit the transfer described here.

16Children’s Privacy

The Service is a business tool intended for use by adults acting in a business capacity. It is not directed to children, and we do not knowingly collect personal information from anyone under the age of eighteen, or under the age of sixteen for the purposes of laws that use that threshold. We do not knowingly sell or share the personal information of minors. If you believe a child has provided personal information to us, contact us at the address in Section 20 and we will delete it. Customers must not upload information about children to the Service.

17Third-Party Systems, Sites, and Links

The Service connects to systems operated by third parties and our websites link to third-party sites. Those systems and sites are not ours. Their availability, functionality, terms, and privacy practices are theirs and can change without notice to us. When information is transmitted to a system you connect or a destination you configure, that information is handled under that party’s privacy policy, not this one. We are not responsible for the practices of third parties and we encourage you to read their notices. Nothing in this Policy alters your agreement with any third-party provider.

18Accessibility

We aim to make this notice readable on any device and usable with assistive technology. If you need this notice in an alternative format, contact us at the address in Section 20 and we will provide one.

19Changes to this Policy

We may update this Policy from time to time to reflect changes to the Service, our providers, our practices, or the law. When we do, we will revise the date at the top of this page. Where a change is material, we will provide additional notice before it takes effect, which may include an in-application announcement, an email to account administrators, or a prominent notice on our websites. We will give at least the notice period required by any applicable law or by a written agreement with you. Your continued use of the Service after a change takes effect constitutes acceptance of the revised Policy. If you do not agree to a change, you should stop using the Service and may close your account under Section 13.

We maintain the current roster of our service providers and subprocessors at pest-metrics.com/security. Because that roster changes more frequently than this Policy, please treat that page as the authoritative current list within the categories described in Section 8.2.

20How to Contact Us

For any question about this Policy, to exercise a privacy right, to appeal a decision, to request a data processing agreement, or to report a security concern:

  • Email: support@pest-metrics.com
  • Privacy requests: email support@pest-metrics.com with the subject line "Privacy Request"
  • Appeals: email support@pest-metrics.com with the subject line "Privacy Appeal"
  • Postal mail: Intelligent Performance Systems LLC, d/b/a PestMetrics, 410 S Bibb Ave, Unit 5348, Eagle Pass, TX 78853, United States

Our Data Processing Addendum is published at pest-metrics.com/dpa and applies automatically to every customer; no signature is required. Customers who require a countersigned copy, a security questionnaire response, or a subprocessor notification arrangement should contact us at the address above.

AAppendix A — Service Providers and Subprocessors

The categories and providers listed in Section 8.2 form our subprocessor disclosure. The current roster, including the artificial intelligence provider in use at any given time, is maintained at pest-metrics.com/security. Providers whose services are configured but not enabled for your account do not receive your information.

BAppendix B — Statutory Categories of Personal Information

The following restates Section 3 using the categories used by the California Consumer Privacy Act. For every category listed, the sources are those in Section 4, the business purposes are those in Section 5, the categories of recipients are those in Section 8, and the retention approach is that in Section 10. We do not sell any category and we do not share any category for cross-context behavioral advertising.

Statutory categoryCollected?Examples in the Service
IdentifiersYesName, business email address, company name, account and user identifiers, IP address, device identifiers, employee and worker identifiers, end-customer account identifiers.
Personal information under Cal. Civ. Code s.1798.80YesName, employment information, account balances and financial obligation information relating to end customers.
Protected classification characteristicsNoWe do not intentionally collect these. Customers should not upload them.
Commercial informationYesSubscription and plan records, transaction and billing history, service and invoice records, subscription values, cancellation records.
Biometric informationNoNot collected.
Internet or network activityYesPages and features used, sign-in events, search and query terms entered in the Service, referring pages, error and diagnostic data, aggregate analytics.
Geolocation data, including precise geolocationYes, where telematics is connectedVehicle latitude and longitude, trip start and end points, reverse-geocoded addresses, route and idle data, speed. Also branch coordinates.
Sensory or audio-visual informationLimitedReferences and links to dashcam media held in a connected telematics system. We do not host the media.
Professional or employment-related informationYesJob title and role, branch assignment, hours worked, shifts, hire dates and inferred departure dates, jobs and revenue attributed, individual performance metrics, scores and rankings, driver safety scores.
Education informationNoNot collected.
InferencesYesComposite performance scores, rankings, forecasts, risk and attention flags, market penetration estimates, and narrative assessments generated with the assistance of artificial intelligence.
Sensitive personal informationYes, limitedAccount credentials, multi-factor authentication secrets, and precise geolocation where telematics is connected. We use sensitive personal information only to provide and secure the Service and for the purposes permitted without a right to limit; we do not use or disclose it to infer characteristics.

CAppendix C — Definitions

  • "Authorized User" means an individual a Customer permits to access the Service under the Customer’s account.
  • "Customer" means the business that subscribes to the Service.
  • "Customer Data" means the operational records a Customer, or a system a Customer connects, transmits to or through the Service, and the metrics, scores, forecasts, and reports derived from them for that Customer.
  • "controller" and "business" mean the party that determines the purposes and means of processing personal information.
  • "processor" and "service provider" mean a party that processes personal information on behalf of, and on the documented instructions of, a controller or business.
  • "de-identified" means information that cannot reasonably be used to infer information about, or otherwise be linked to, an identified or identifiable individual or household, and that we maintain and use in de-identified form.
  • "personal information" means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular individual or household, and includes "personal data" as that term is used in other privacy laws.
  • "sell" and "share" have the meanings given in applicable state privacy law, including the sharing of personal information for cross-context behavioral advertising.
  • "sensitive personal information" has the meaning given in applicable state privacy law and includes account credentials and precise geolocation.
  • "Service" has the meaning given in Section 1.1.
  • "Website Visitor" means any person who visits our public websites.