Information we use
We process account names, business contact details, user roles and authentication records to provide company workspaces. Quoting processes the report data you import, rates, machine and customer profiles, working drafts, reviewed quote revisions and the company/user details you choose to print on PDFs. Your company administrator controls workspace membership and module access.
Support and account activity
Bug reports, replies and screenshots you choose to submit are available to authorized support staff. The reporter can see their own reports and public replies. Staff-only notes are not shown to customers. Crop or redact confidential information before uploading a screenshot. Screenshots are reduced in size and re-encoded in the browser before upload.
For support and customer follow-up, we store the latest sign-in time and latest app activity timestamp/page category. A heartbeat is sent while the app is visible and recently used. “Recently active” is an estimate, not a guarantee that a user is online. We do not store a full browsing history through this feature.
Optional website analytics
With your permission, the public website measures page categories, broad traffic sources, form starts, trial-button clicks and successful form submissions. A random browser-tab visit identifier expires after 30 minutes of inactivity. Our event table excludes form contents, names, email addresses, query strings and raw IP addresses. A short-lived IP-derived hash helps limit abuse.
Choose Analytics preferences on the public website to allow, decline or withdraw consent. Global Privacy Control and Do Not Track disable optional analytics. Withdrawal stops new optional events. Essential account, security and support processing continues. Hosting providers also maintain operational logs under their own policies.
Website enquiries and communication
When you submit our contact form, we store your name, email, optional company, chosen topic and message in our internal CRM so staff can respond and manage follow-up. The form is not a marketing subscription. Staff can add private notes and record progress. An IP-derived hash limits repeated submissions and is removed through routine cleanup; the enquiry record does not store your IP address.
Support is provided through email, the contact form and in-app reports. We do not offer phone support. Business email correspondence may be handled through our Zoho Mail mailbox. Contact hello@getovrendi.com if you prefer email to the web form.
No sale of customer data
We do not sell customer data or use our website analytics to build advertising profiles. Customer records and quotations are used to provide, secure and support the service. We do not use this quoting workflow’s imported reports, customer rates or quotations to train an AI model.
Service providers and locations
Vercel hosts the website and application endpoints. Supabase provides the database and authentication; the current database project is in Canada Central. Resend delivers service emails. Stripe handles checkout and payment credentials; Ovrendi does not store full card numbers. Provider processing and support may occur outside Canada. Database location does not mean every service, log or email stays in Canada.
Notification emails may use delivery, open or link measurement through Resend. Secure authentication emails use a separate sender configured without tracking. Email measurements can be inaccurate and do not prove a person read a message.
Cookies and browser storage
Our own analytics uses browser storage rather than a traditional tracking cookie. Essential sign-in, display preferences and optional analytics have different purposes. See Cookies & browser storage for categories, durations and controls. You can use the site and contact us without allowing optional analytics.
Retention and deletion
Raw optional analytics events older than 30 days and expired abuse-limit records are removed by the daily cleanup. Working drafts remain until replaced or discarded. Quote revisions and operational company records are retained while needed to operate and support the workspace. Support messages and screenshots remain with their report. Website enquiries and staff follow-up notes are kept while needed for the enquiry and business relationship; no automatic enquiry-deletion deadline has been implemented. A broader deletion schedule is being finalized; no automatic deletion deadline is promised for these records.
You can ask us to access, correct, export or delete your information at hello@getovrendi.com. We verify identity and company authority before acting. Requests may require coordination with your company administrator. Some records may need to be retained for legal, accounting, security or dispute purposes; backup copies may persist beyond removal from the live application.
Security and changes
We use authenticated access, server-side company checks and restricted database permissions. No service can promise absolute security. Report suspected unauthorized access promptly to hello@getovrendi.com. Material changes to these practices will be reflected in an updated notice and communicated where required.
Requests, corrections and concerns
Contact hello@getovrendi.com or choose Privacy in our contact form. Tell us what you want to access, correct or delete, and the email/company involved. Do not send a password or identity document unless we first explain a proportionate verification requirement. We will explain any lawful reason we cannot fulfil a request in full. You may also raise concerns with the privacy regulator relevant to your location.
Ovrendi is designed for business use and is not directed at children. Company administrators should ensure they have authority to share information about their staff and customers.