This policy explains what AX3L collects about you, why, who else touches it, how long we keep it, and how to get it deleted. It covers the AX3L web app and the AX3L mobile apps for iPhone and Android.
It is written to be read, not to be survived. Where something might surprise you — your phone's location, the microphone, the AI assistant — it says so plainly rather than burying it in a list.
1. Who is responsible for your information
AX3L is operated by Mivo Technologies [REGISTERED FORM — to be confirmed] (“we”, “us”), at [ADDRESS — to be confirmed]. Mivo Technologies owns AX3L and runs it, and it is the company accountable for the information described in this policy.
You may have been sold your subscription by Mivo North America LLC, a separate company that sells AX3L as an authorised broker under licence from Mivo Technologies. It does not operate the platform. It holds the ordinary commercial record of its own customers — who bought what, and the contact details you gave it — and it does not get access to the contents of a workspace: your clients, jobs, invoices, photos and messages are not visible to it.
Almost everything in AX3L belongs to a business: your employer, or your own company. That business decides who gets a login, what goes into its workspace and how long it stays there. In Canadian privacy language, the business is the organisation responsible for the personal information in its workspace and we handle that information on its behalf and on its instructions.
For a few things we are responsible ourselves rather than on a business's behalf: your login and the security record attached to it, our billing records, and the logs we keep to run and protect the platform. This policy covers both.
Questions, access requests and complaints go to [privacy contact email].
2. What we collect, and why
Account details — your name, email address, username, phone number, your role in the business, and your password stored as a one-way hash. We need them to sign you in, to show your name on the work you do, to contact you about your account, and to send a code or a link when your account needs one. If two-factor authentication is turned on, we also hold the sealed secret behind your authenticator app and your unused recovery codes.
The business records the customer enters — clients and contacts, jobs, schedules, quotes, contracts, change orders, invoices and payments, photos, receipts, expenses, time entries, notes and messages. This is the substance of the product. We collect it because you put it there, we hold it so the business can use it, and we do nothing else with it.
Location — collected only while you are clocking in or out and while you are on the clock, and only in the mobile app with your phone's permission. It is used for two things: stamping a time entry with where it was made, and showing the crew map to your managers while a shift is running. It is not collected when you are off the clock, and it is not collected in the background when the app is closed.
Camera and photos — only the pictures and documents you choose to attach to a job, a receipt or a message. The app does not read your photo library beyond what you pick.
Microphone — only when you dictate instead of typing, and during calls made inside the app. Where you have turned transcription on, the audio is transcribed and the text is stored with the record it belongs to; otherwise the audio is used for the call and not kept.
Push notification tokens — the anonymous handle Apple's or Google's push service gives us so a notification can reach your device. It identifies the device, not you.
Device and session information — a friendly device name, IP address, browser or app version, and when a session was last seen. It powers the “where you're signed in” list, the security log, and our ability to tell a stranger's sign-in from yours.
Use of the AI assistant — what you ask Axel, what it answered, and which action it took under which setting. Kept so the business has an attributable record of what the assistant did, and so we can investigate when something looks wrong.
We do not collect advertising identifiers, we do not track you across other apps or websites, and there is no analytics SDK in the mobile apps that follows you off AX3L.
3. Who else handles it
We use a small number of service providers to run the platform. Each of them acts as our processor: they handle the data to provide their service to us, under contract, and are not permitted to use it for their own purposes.
Vercel — hosting for the web app and the API. Neon — the PostgreSQL database where your records live. Anthropic — the AI provider behind Axel; the content you submit and the records needed to answer are sent there to generate a response. SignalWire — the telephony provider that carries texts and calls. Stripe — card payments, which handles the card details directly so we never see or store a card number. Google — optional sign-in and optional calendar sync, only if you connect it. Apple, Google and Expo push services — delivery of notifications to your device.
Where a business connects its own accounts (its own email mailbox, its own phone number, its own payment processor), messages and payments go out through those accounts, and the terms between that business and its provider apply to them.
Some of these providers operate outside Canada, mainly in the United States, which means your information may be stored or processed there and be subject to that country's laws, including lawful access by its authorities.
We may also disclose information where the law requires it, or where it is necessary to protect the platform, our customers or someone's safety. We would rather tell you when that happens, and we will where we are allowed to.
4. What we do not do with it
We do not sell your information, and we do not rent it, trade it or share it with data brokers.
We do not use your business data, your messages or your conversations with Axel to train AI models — not ours, not Anthropic's, not anyone else's. Our agreement with Anthropic is that content sent for a response is not used for model training.
We do not use one customer's data to answer another customer's question. Every business has its own isolated workspace, and the platform refuses a query that has no business attached to it rather than guessing.
We do not show you third-party advertising, and we do not build a profile of you for anybody's marketing.
5. How long we keep it
Business records are kept for the life of the business's account, because that is the point of them — a job from three years ago is still the record of a job. After an account is closed we keep the data available for a short window so it can be exported, then delete it from the live platform; it drops out of our backups on the normal backup cycle. The Terms of Service set out those windows.
An account we have been asked to delete is permanently deleted within 30 days of the request being approved. See section 7.
The security log — sign-ins, failed attempts, lockouts, two-factor changes, role changes — is kept for up to 12 months and then aged out. It exists to answer “who got into this account, and when”, and a log that is deleted on request is not evidence.
Billing records are kept as long as tax and accounting law requires us to keep them.
6. Keeping it safe
Every connection to AX3L is encrypted in transit, and the database is encrypted at rest by our provider. Passwords are stored as one-way hashes and never in a form anybody can read back.
Credentials you give us for your own services — a mail app password, a telephony token, a two-factor seed — are encrypted with a key held only on the server, are never sent back to the browser, and are never shown in a log or an error message.
Each business's workspace is separated at the data layer, not by a filter somebody remembered to add: a query with no business attached to it fails rather than returning everything.
You can turn on two-factor authentication for your own account at any time, and a business owner can require it for everybody. If we become aware of a breach affecting your information we will tell you and the affected business without undue delay.
7. Your choices, and deleting your account
Phone permissions are yours. Location, camera and photos, microphone and notifications are each requested by your phone's operating system, are each refusable at the prompt, and can each be revoked afterwards in your phone's settings. None of them is required to use the rest of the app — refusing one turns off the feature that needs it, and nothing else.
You can ask for your own account to be deleted from Settings → Security → Delete my account. We record the request, tell the business owner, and the owner deactivates the account; we then permanently delete the account and the personal details attached to it within 30 days.
The business records you created — jobs, quotes, invoices, messages, time entries — stay with the business. They are the business's records of its own work, not personal profiles of you, and the business needs them for its books. If you want those removed as well, that request goes to the business, and we will act on the business's instruction.
If you are the owner of the business account and you want the whole workspace deleted, tell us at [privacy contact email] and we will delete it on the timeline in the Terms of Service.
8. Access, correction and complaints
Canadian privacy law applies to us — the federal Personal Information Protection and Electronic Documents Act (PIPEDA) and Alberta's Personal Information Protection Act (PIPA).
You have the right to ask what personal information we hold about you, to be told how it has been used and who it has been disclosed to, and to have it corrected if it is wrong. Most of it you can already see and edit in the app; for the rest, write to [privacy contact email] and we will respond within 30 days.
Where the information belongs to a business's workspace we will point the request at that business, tell you we have done so, and help them answer it.
If you are not satisfied with how we have handled a request, you can complain to the Office of the Privacy Commissioner of Canada, or to the Office of the Information and Privacy Commissioner of Alberta. We would rather you came to us first, but we are not going to pretend that route does not exist.
9. Children
AX3L is a tool for businesses and is not for anyone under 18. We do not knowingly create accounts for minors and we do not knowingly collect their information. If you believe a minor has an account, tell us at [privacy contact email] and we will remove it.
10. Changes to this policy
This policy is versioned the same way the Terms of Service are. When it changes we publish a new version with a new effective date rather than editing the old words, so it is always possible to see what was in force when.
If a change is material we will say so in the app. The current version and its effective date are shown at the top of this page.
End of Privacy Policy, version 1.1.
Questions about your information, or a request to see, correct or delete it: [privacy contact email].