OPSLY LEGAL
Privacy Policy
Last updated August 23, 2026
Opsly is business software used by field service companies to manage their own customers. This policy explains what Opsly collects, why, how long it is kept, and how to export or request deletion of it. If anything here is unclear, email david@opslyapp.com.
Who this covers
Two groups. First, the companies that subscribe to Opsly and their staff, referred to here as customers. Second, the people who contact those companies by DM, text, call or web form, referred to here as end users. A subscribing company controls its own end user data; Opsly processes it on that company's behalf.
What we collect
From subscribing companies we collect the account holder's name, email address, phone number, company name, and the settings and content they enter into the product, including price book entries, job records, photographs, invoices and message history.
From end users we receive only what they send to the company or what the company records about them: name, phone number, email address, service address, the content of their messages, photographs they send, and the record of jobs and payments.
From the marketing site we collect what is typed into the demo request form: name, company, phone number and a short description of where leads are being lost. When you allow optional analytics or marketing technologies, we also receive website-use information such as pages viewed, links or buttons selected, referring pages, browser and device information, approximate location derived from an IP address, and cookie or device identifiers. Demo request information is not sold or resold.
Instagram and Meta data
When a company connects an Instagram Professional account, Instagram issues Opsly an access token after that company signs in on Instagram's own page. Opsly never receives or stores an Instagram password. The token permits three things only: reading basic profile information for the connected account, reading and sending that account's direct messages, and reading and managing comments. Opsly cannot post to a feed, cannot see a follower list, and cannot access anything outside those messages and comments.
Instagram message content is used solely to display the conversation inside that company's own Opsly workspace, to generate a reply on that company's behalf, and to extract contact details into that company's lead pipeline. Every inbound message is routed by the Instagram account ID that received it, and each company's data is stored under its own separate namespace, so one company cannot read another company's messages.
Instagram data is not sold, not used for advertising, and not shared with any third party other than the infrastructure and AI providers described below that are required to operate the product.
How we use data
Data is used to operate the product: to show conversations and records to the company that owns them, to generate replies and lead summaries, to send quotes, invoices and reminders that the company initiates, and to support and troubleshoot accounts. Opsly does not sell customer or end-user content and does not use that content to train general-purpose AI models. With your permission, marketing-site usage data is used to understand website performance, measure advertising results and support relevant Opsly advertising.
Who we share it with
Opsly runs on third party infrastructure and shares only what those services need to function: cloud hosting and database providers, email delivery, AI providers that generate configured replies and summaries, telephony providers where calls or texting are enabled, and payment processors. Payment card numbers are handled by the payment processor and are not stored by Opsly. Optional integrations send data only when a customer connects or uses them. When you consent on the marketing site, Google receives analytics data and Meta receives advertising-measurement data. Our current provider list is published at Subprocessors. We may also disclose data where legally required.
How long we keep it
Account data is kept while a subscription is active and then according to the workspace retention policy and applicable legal or accounting obligations. Default operational retention periods are visible to workspace owners and can be changed within supported limits. A verified legal hold pauses deletion of covered records. Disconnecting an integration disables its connection and removes Opsly's usable credential; provider-side consent may also be removed in that provider's settings. Demo form submissions are kept for up to 24 months.
Deleting your data
A workspace owner can download a tenant-scoped export or record a deletion request from GA Readiness. Deletion requests use typed confirmation, a cooling-off period, legal-hold review, and an operator-reviewed execution step; submitting a request does not silently delete data. You may also email david@opslyapp.com from the address on the account. End users should normally contact the company they messaged, which controls their record. Include the company name and enough information to verify the request. Verified requests are handled within the period required by applicable law.
Instagram and Facebook users: you can also remove Opsly's access yourself from your Instagram or Facebook account settings under Apps and Websites. Removing access there revokes the token immediately. To additionally have stored message data erased, send the deletion request described above with your Instagram handle and it will be removed within 30 days.
Your rights
You may request a copy of the personal data held about you, request correction of anything inaccurate, request deletion, or object to processing. Send any of these to the email address above. Opsly does not charge for these requests. You can also reject optional website technologies or change a previous choice at any time by selecting .
Security
Data is transmitted over encrypted connections and access is restricted to the workspace that owns it. Provider credentials are server-only and, where stored in the database, are held in application-encrypted envelopes whose encryption key is deployment-owned and not stored in the database. Database backup and restore procedures are separate from media-object storage, which is covered by scoped object manifests and export procedures. No system is perfectly secure. Opsly maintains incident-response and recovery procedures and will notify affected customers as required by applicable law.
Children
Opsly is business software and is not directed at anyone under 18. We do not knowingly collect data from children.
Cookies and similar technologies
The marketing site uses necessary browser storage to remember your privacy selection. Optional technologies remain off unless you choose to allow the related category. Rejecting them does not prevent you from using the website.
Google Analytics. If you allow Analytics, Google Analytics loads and uses cookies or similar identifiers to measure visits, page views and interactions so we can understand and improve the site. Google Consent Mode defaults analytics storage to denied until you make a choice.
Meta Pixel. If you allow Marketing, Meta Pixel loads and uses cookies or similar identifiers to measure advertising results and may help Opsly reach or re-engage people interested in its services. Meta Pixel does not load before marketing consent.
You can accept, reject or change either optional category through . A browser Global Privacy Control signal keeps marketing tracking off. The Opsly application separately uses authentication session data strictly to keep authorized users signed in and protect workspace-scoped requests.
Business customers
When Opsly processes end-user personal data for a subscribing company, that company is the controller or business and Opsly acts as its processor or service provider. Our standard Data Processing Addendum describes those obligations.
Changes
If this policy changes materially, subscribing companies will be notified by email before the change takes effect, and the date at the top of this page will be updated.
Contact
Opsly, Orlando, Florida. Email david@opslyapp.com.