Legal

Privacy Policy

Version 1.1 · Effective August 30, 2026

This policy explains how the RestoraLink platform handles personal information. It covers the software itself, operated by ViableTeck(“ViableTeck”, “we”, “us”). It does not cover how an individual restoration franchise handles your information outside the platform — see that franchise's own privacy policy for that.

1. Who controls your data

RestoraLink is used by independently owned restoration franchises. The franchise you work with decides what information goes into the platform and why — it is the controller of that information. ViableTeckoperates the platform on the franchise's behalf as a processor, acting on its instructions.

US privacy law has two names for this one role. Most states with a comprehensive privacy law — including Virginia, Colorado, Connecticut, Oregon, Texas, Montana, and the others that have followed them — call ViableTeck a processor to each franchise. California calls the same role a service provider.

Under all of them the obligation is the same, and we apply it to everyone regardless of where they live: we process personal information only under our written contract with the franchise, only to provide the platform, and we do not retain, use, or disclose it for any other purpose — including for our own commercial purposes or those of anyone else. We do not combine it with personal information obtained from any other source, except where a law expressly permits a service provider or processor to do so.

In practice this means: to correct project details, change who can see what, or ask for your information to be deleted, contact your franchise first. We will help them action your request.

2. What we collect

Information you or your franchise provide

  • Account details — name, email address, phone number, the role assigned to you, and the franchise you belong to. Passwords are stored as cryptographic hashes and are never visible to us.
  • Project information — property address, property and damage type, job numbers, scope of work, status, and scheduling.
  • Photographs and documents — images of the property and its contents, estimates, work orders, reports, and other files uploaded to a project.
  • Communications — in-app messages, and email and SMS sent or received through the platform, including attachments and delivery status.
  • Signatures — signed documents, plus the signing evidence described in the EULA: time, signer identity, IP address, and browser.
  • Operational records — tasks, notes, equipment logs, timesheets, contractor assignments, appointments, and survey responses.
  • Billing figures— invoice totals, amounts paid, and amounts outstanding, where your franchise has connected its accounting system. Card and bank details are never entered into or stored by the platform; online payments are made on the payment provider's own site.

Information collected automatically

  • Authentication cookies — required to keep you signed in. See Cookies and opt-out signals.
  • Audit records — a log of significant actions taken in the platform, used for security and accountability.
  • Technical data — IP address, browser and device information, and server logs generated when you use the platform.

Sensitive information

The platform is not designed to collect sensitive personal information. We do not ask for Social Security numbers, government identifiers, financial account numbers, health information, precise geolocation, or biometric data. Photographs of a damaged property and documents uploaded to a project may incidentally contain such details; where they do, we treat them with the same protections as everything else and never use them to infer characteristics about anyone or to build a profile.

Categories under US state privacy law

Expressed in the statutory categories those laws use, the above amounts to: identifiers; personal information listed in the California customer-records statute; commercial information; internet or other electronic network activity; geolocation at the level of a property address; audio, electronic, or visual information in the form of uploaded photographs and documents; and professional or employment-related information. We do not collect biometric information, education information, or genetic data.

3. Where it comes from

  • From you — what you enter, upload, sign, or send through the platform.
  • From your franchise and its staff — project records created about the work being done for you.
  • From subcontractors assigned to your project.
  • From systems your franchise has connected — for example invoice totals and balances from an accounting system, or entries from a scheduling calendar.
  • Automatically — from your device and browser as you use the platform.

4. How we use it

  • To provide the platform and the features you and your franchise use.
  • To authenticate you and enforce the permissions attached to your role.
  • To send notifications you or your franchise have configured — job updates, messages, reminders, and signature requests.
  • To keep records of documents signed electronically.
  • To secure the platform, investigate misuse, and diagnose faults.
  • To meet legal, tax, and insurance obligations.

5. What we never do with it

  • We do not sell personal information, and we have not sold any in the preceding twelve months.
  • We do not share it for cross-context behavioral advertising, as California uses that term, and we have not shared any in the preceding twelve months.
  • We do not process it for targeted advertising or for profiling that produces legal or similarly significant effects.
  • We do not use Customer Data to train machine learning models.
  • We do not disclose it to third parties for their own direct marketing.

Because we do not sell or share personal information, there is no “Do Not Sell or Share My Personal Information” choice to make — the answer is already no, for everyone, without you having to ask.

6. Who we share it with

  • Your franchise and its staff — according to the roles and permissions it has configured.
  • Subcontractors assigned to your project, limited to what they need to do the work.
  • Service providers that operate parts of the platform on our behalf, listed below.
  • Systems your franchise has connected, such as accounting or scheduling software.
  • Authorities or advisers, where we are legally required to disclose, or need to establish or defend legal claims.
  • A successor, if the business is sold or reorganized — subject to this policy continuing to apply.

Data is separated by franchise. Access controls are enforced in the database itself, not only in the interface, so one franchise cannot read another's records.

7. Service providers

These providers process data on our behalf, under contracts limiting them to that purpose. Those marked optional apply only where a franchise has enabled the corresponding integration.

ProviderPurposeApplies
VercelApplication hosting and scheduled jobsAlways
SupabaseDatabase, authentication, and file storageAlways
ResendTransactional and notification emailAlways
Google Maps PlatformAddress geocoding and map displayAlways
Google Cloud VisionText recognition in uploaded documentsAlways
Intuit QuickBooks OnlineReading invoice totals to show billed and outstanding amountsIf enabled
TelnyxSMS messaging and delivery receiptsIf enabled
SmartsheetTwo-way project schedule synchronizationIf enabled
TeamupShared scheduling calendarIf enabled
Microsoft 365Calendar synchronizationIf enabled

These providers may store or process data in the United States and in other countries where they operate. Wherever it is held, it remains subject to this policy and to our contracts with those providers.

8. Cookies and opt-out signals

The platform uses only cookies that are strictly necessary to operate it: the cookies that keep you signed in, and a short-lived cookie that secures the hand-off when an administrator connects an external system. There are no advertising cookies, no third-party tracking pixels, no web beacons, and no analytics or session-recording services. Nothing about your use of the platform is tracked across other websites.

Blocking the necessary cookies in your browser will stop you from signing in.

Global Privacy Control and Do Not Track

We honor opt-out preference signals such as Global Privacy Control. In practice such a signal changes nothing here: it asks a business to stop selling or sharing personal information, and we do neither for anyone. There is no accepted standard for Do Not Track browser signals, so we do not respond to them separately — but, again, we do not track you across sites in the first place.

9. Text messages

Where your franchise has enabled SMS, the platform sends text messages about your project — appointment and schedule updates, messages from your project team, and signature requests. These are service messages about work you have asked for, not marketing. Message frequency varies with activity on your project.

  • To stop — reply STOP to any message. For help, reply HELP, or contact your franchise.
  • Costs — message and data rates may apply, depending on your mobile plan. Neither we nor your franchise charges you for these messages.
  • Your number — phone numbers collected for text messaging are not sold, and are not shared with third parties for their marketing. They are shared only with the messaging provider that delivers the message on our behalf.
  • If you opt out — your franchise will still need to reach you about your project by another means, such as email or a phone call.

10. How long we keep it

We keep information for as long as your franchise needs it for the project, and for as long afterwards as is required by law, insurance, warranty, or dispute-resolution needs. When none of those apply any longer, the information is deleted or anonymized. Indicative periods:

  • Project records, photographs, and documents — 180 days after project completion.
  • Signed documents and their signing evidence — 180 days after signing.
  • Account records — for as long as the account is active, then 180 days.
  • Audit and security logs — 180 days.

11. How we protect it

  • Data is encrypted in transit and at rest by our infrastructure providers.
  • Access is restricted by role, enforced by row-level security in the database rather than by the interface alone.
  • Passwords are hashed by our authentication provider and are never stored in readable form.
  • Significant actions are recorded in an audit log.

We maintain security measures appropriate to the nature of the information we hold. No system is completely secure, however, and no safeguard eliminates every risk. If a breach affects your personal information, we will notify the affected franchise and, where required, you and the relevant regulator.

12. Your privacy rights

Depending on where you live, you may have the right to know what personal information is held about you and how it is used, to get a copy of it, to correct it, to delete it, to restrict or object to its processing, to receive a portable copy, and to withdraw a consent you gave. Some states also give a right to opt out of the sale of personal information, of sharing it for cross-context behavioral advertising, and of targeted advertising or profiling — none of which we do, as set out in What we never do with it.

How to make a request

Because your franchise controls the information, send your request to them first. You can also write to us at compliance@viableteck.com and we will route the request to the right franchise and help them action it. Tell us what you are asking for and the email address or phone number your records are under.

Verification

Before acting on a request we need to be reasonably sure it is really you, so we may ask you to confirm details we already hold. We will not use anything you give us for verification for any other purpose. If we cannot verify you, we will say so rather than act on the request.

Timing

We acknowledge requests within 10 business days and respond within 45 days. If we need longer we will tell you why within that period and may take up to 45 further days. An opt-out request is actioned within 15 business days. Requests are free unless they are manifestly unfounded or excessive, in which case we will tell you before doing anything.

Authorized agents

You may use an authorized agent to make a request. We will ask for written, signed permission from you, and may still ask you to verify your own identity and to confirm that you gave the agent permission.

If we say no

If we decline a request, we will tell you why. Residents of states including Virginia, Colorado, Connecticut, Oregon, Texas, and Montana may appeal that decision by replying to our response or writing to compliance@viableteck.comwith “Appeal” in the subject line. We will respond to an appeal within 45 days with our decision and reasons. If the appeal is denied you may contact your state Attorney General.

Non-discrimination

Exercising a privacy right will never result in discriminatory treatment. You will not be denied service, charged a different price, or given a lower standard of service for doing so. We offer no financial incentives in exchange for personal information.

California “Shine the Light”

California residents may ask once a year about personal information disclosed to third parties for those parties' own direct marketing. We make no such disclosures, so the answer to that request will always be none.

13. Children's privacy

The platform is intended for business use and is not directed at children. We do not knowingly collect personal information from anyone under 18. We do not sell or share the personal information of anyone under 16 for behavioral advertising — we do not do so for anyone of any age. If you believe a child has provided us information, contact us and we will delete it.

14. Other websites

The platform links out to sites we do not run — your franchise's own website, and the payment provider's page where an invoice is paid online. This policy does not govern how those sites collect or use personal information. Read their own policies before giving them information, particularly payment details, which are never entered into or stored by RestoraLink.

15. Changes to this policy

We may update this policy. The version and effective date above will change, and we will give notice of material changes through the platform or by email before they take effect.

16. Contact

  • Legal entity: ViableTeck
  • Address: 2355 State St, Ste 101, Salem, OR 97301-4541
  • Privacy inquiries and requests: compliance@viableteck.com

RestoraLink operates entirely online, so privacy requests are handled by email and through your franchise rather than by post or telephone.

See also the End User License Agreement.