novo SOLUTION - Privacy Policy
This Privacy Policy describes how novo SOLUTION ("novo SOLUTION", "we", "us") collects, uses, discloses, and protects information when you use our iOS app, associated websites, and related services (collectively, the "Services").
novo SOLUTION is developed and operated by Mohammad Reghabi, an individual located in Vancouver, British Columbia, Canada.
If you are using novo SOLUTION on behalf of a business, your business may be the "Customer" under a separate agreement (for example, an enterprise plan). In that case, we process information as described below and as required to provide the Services.
1. SCOPE
This Policy applies to:
The novo SOLUTION iOS app (including optional iCloud/CloudKit sync, if enabled on your device)Employee ("managed staff") access to a business account from an employee's own personal iPhone or iPadYour connected website, online store, and backend services (when you enable website integration/sync)Novo Market and client accounts, where enabled (see Section 2.12)The Novo App Clip and progressive web storefronts used to browse or order from a participating businessOptional integrations you connect (for example: Facebook/Instagram, TikTok, payment providers, email and SMS providers, accounting providers, shipping carriers, listing feeds, automation platforms)This Policy does not apply to third-party websites, platforms, or services that you connect to novo SOLUTION. Those third parties have their own policies.
1A. WHO THIS POLICY COVERS
Different parts of this Policy apply to different people:
Business owners and administrators — the person or entity that creates and controls a novo SOLUTION account, and the business records stored in it.Employees and staff — individuals invited by a business to access that business's account, including from their own personal device. See Section 2.11.Clients and shoppers — individuals who create a Novo Market client account, or who visit, book with, or buy from a business's public storefront. See Sections 2.12 and 2.14.Where a business stores information about its own customers, employees, suppliers, or other individuals in the Services, that business is responsible for that information and is the primary point of contact for requests about it. Our role is described in Section 2A.
2. INFORMATION WE COLLECT
The information we collect depends on which features you use and which integrations you connect.
2A. Access to Your Data and Your Control
On-device / iCloud-only data: If your data is stored only on your device and/or synced via Apple iCloud/CloudKit, that data is managed by Apple under your iCloud account. We do not have routine access to the contents of your iCloud data.Website/backend data (if enabled): If you enable website integration or backend services, some data is stored and processed on the connected backend to deliver those features (for example, website content, sync operations, integrations, security logs, and anonymous analytics). As the operator of that backend, we (or authorized personnel assisting with support/security) may be able to access limited server-side information as necessary to operate, secure, debug, and support the Services.Features that always use our backend: some features cannot work device-only and always involve our servers. These include employee access from personal devices, Novo Market and client accounts, the online store and public website, email and SMS delivery, and Novo-hosted AI. Where you use these, the relevant data is stored and processed on our backend as described in the sections below.Practical impact: Many privacy requests (for example, changes to customer records you entered) should be directed to the business owner/admin using the Services. Where we do have control over server-side data (for example, stored OAuth tokens, anonymous analytics, and security logs), we can help process requests as described below.
2.1 Account and Business Profile Information
We may collect and process:
Account information: name, username, email, role/permissions, authentication and session dataBusiness information: company name, address, phone, country/region, business type, stores/locations and related settingsAdministrative metadata: user roles, permissions, activity and configuration changes (for security and audit purposes)2.2 Business Data You Choose to Store in the Services
You (and your team) may store business records such as:
Inventory and catalog: products, images, categories/collections, pricing, stock historySales and finance: invoices, estimates, receipts/records, taxes, store credit, vouchers/gift cards, loyalty balances (as applicable)Customers and appointments: customer contact details, appointment/reservation data, communications, notes, activity history, and related recordsWebsite content: pages, media, documents, contact forms/subscribers (when using website features)Marketing records: subscriber lists, campaign content, consent records, and engagement history (see Section 2.13)Storefront records: product and vehicle reviews, wishlists and saved items, quote and inquiry submissions (see Section 2.14)Industry-specific records: property listings and saved searches, vehicle inventory and financing applications, restaurant reservations and shift/tip records, and similar records for the business type you have configuredStaff records: employee accounts, roles and permissions, assigned locations, and — where the business uses these features — shift, clock-in, and tip distribution dataImportant: Some of this data may include personal information about your customers or contacts. You control what you upload and how you use it.
2.3 Technical, Device, and Diagnostic Information
We automatically collect technical information needed to operate and secure the Services, such as:
Device and app data: device model, iOS version, app version/build, language and timezoneDiagnostic logs: crash reports, performance metrics, error logsSecurity signals: authentication events, suspicious activity indicators, integrity and security monitoring dataResource usage metrics: bandwidth consumption (bytes transferred per request type), storage usage (total file sizes), and related quota data, collected per account and aggregated on a calendar-month basis for subscription plan enforcement. Bandwidth counters reset on the 1st of each calendar month (UTC)We minimize collection of directly identifiable personal data in diagnostic and security logs; we also use redaction/sanitization where feasible.
2.4 Analytics and Usage Data (Privacy-First)
If you enable analytics and provide required consent in the app, we may collect:
Anonymous/aggregated usage events (for example: feature usage counts, screen views, and a hashed device identifier) to understand usage without directly identifying youBy default, analytics features are privacy-first and can be disabled in settings. Some minimal operational telemetry may still be necessary for security and reliability.
This section describes analytics about your use of the app. Analytics about visitors to your public storefront are described separately in Section 2.14, and analytics about your marketing messages are described in Section 2.13. Those are business records that belong to you, not anonymous app telemetry.
2.5 Integration Data (OAuth Connections and Webhooks)
If you connect third-party services, we may collect:
OAuth tokens (access tokens, refresh tokens, and related metadata such as expiration)Connected account identifiers (for example, a Facebook Page ID, Instagram Business Account ID, a connected mailbox address, an accounting organization ID)Connection metadata (for example, page/account display name, token expiration timestamps)API credentials you enter for services that do not use OAuth (for example, shipping carrier or listing feed credentials), stored encryptedWebhook events from third-party providers (for example, events delivered by Meta/Facebook webhooks)Integrations you may connect include:
Social media: Facebook/Instagram (Meta), TikTokEmail delivery and marketing: Resend, SendGrid, Amazon SES, Mailchimp, Gmail/Google Workspace (OAuth), and generic SMTP/IMAP mailboxesSMS: Twilio, Amazon SNSPayments and terminals: Stripe, Square, PayPal, and supported terminal providersAccounting: XeroAutomation: ZapierShipping carriers: USPS, UPS, FedEx, DHLReal estate listing feeds: CREA DDF and RESO-compatible MLS providersTax calculation: see Section 2.8We do not collect or store your third-party account passwords. Connections are established using OAuth or using credentials you supply, which are stored encrypted.
2.6 Payment Data
When you use payment features, payment processing is generally handled by third-party payment processors and/or terminal providers. Depending on the feature, we may process:
Transaction metadata needed for records and reconciliation (for example, invoice IDs, totals, timestamps, status)Payment processor references (for example, a payment intent identifier) linking a record to a charge held by the processorSaved payment method references for client accounts: a processor token plus card brand, last four digits, and expiry month/year — never a full card number (see Section 2.12)We aim to avoid storing full payment card numbers and other sensitive payment credentials on our systems; those are typically handled by the payment provider under their own terms.
2.7 AI Features Data (Optional — User-Initiated)
novo SOLUTION includes optional AI-powered features. All of them are opt-in, and the app is fully usable without enabling any of them. Current AI-assisted features include:
Product SEO titles and descriptions, and image alt textProduct image generation, background removal, and photo enhancementAd copy, ad images, ad video, and ad translationThe Advanced AI Page Editor and site-wide website design assistance, including analysis of a rendered screenshot of a page you are editingNewsletter and blog draft writing, and brand voice suggestionsAI cleanup of spreadsheet/CSV data during importNovo Voice and connected desktop assistants (see Section 2.10)AI ASSISTANTS AND YOUR DATA
Which AI options exist:
Siri AI / Apple Intelligence (on-device and, when available, Apple Private Cloud Compute)Bring-your-own-key ("BYOK") providers, where you supply your own API keyNovo-hosted AI (when enabled for your account), where we supply the key and route the request through our serversMCP-connected desktop assistants (ChatGPT Desktop / Claude Desktop) that you authorize to connect to your accountTier model:
Siri AI Full Access (opt-in): available on iOS 27 or later on devices that support Apple Intelligence. Processing is on-device or via Apple Private Cloud Compute (stateless, encrypted, not used for training). Full access still cannot exceed your signed-in role, plan feature flags, or demo-mode write blocks. API keys, credentials, and security settings remain blocked for all AI.External AI (Standard): BYOK providers, Novo-hosted AI, and MCP assistants receive only redacted, minimized prompt data. Financial/tax and analytics results are aggregates; customer contact details, street addresses, and payment identifiers are redacted from prompts. Page context sent to the Advanced AI Page Editor is stripped of pricing, supplier, customer contact, and payment fields. User management and bulk destructive operations are blocked. MCP-connected desktop assistants always operate at this tier.Consent and control:
Full access is off by default, requires an explicit consent disclosure, and can be revoked anytime in Settings → AI Access.BYOK API keys are encrypted at rest and are never CloudKit-synced.AI actions are logged locally on your device for review. That log holds a short redacted summary of each action and does not store raw prompt or response bodies, is capped at a fixed number of recent entries, and is never transmitted to us.HOW YOUR DATA REACHES AN AI PROVIDER
There are two different routes, and they have different privacy consequences.
Bring-your-own-key. The request is made using your own API key, under your own account with that provider. For features in the iOS app, the connection is made from your device directly to the provider, and we do not receive, store, or intercept the content of those requests. For features that run on the website side, the key you saved is stored encrypted on our backend and the request is made from our servers on your behalf; in that case the request passes through our systems, though we do not retain the prompt content.Novo-hosted AI (proxied). Your request is sent to our backend, which calls the provider using our keys. Because the request passes through our systems, we do process it. For hosted requests we retain: a usage record (operation type, provider, model, approximate token counts, credits consumed, and a hash of the input) used for metering and abuse prevention; a short-lived deduplication cache that stores the AI's generated output so an identical repeat request does not have to be re-run; and, for bulk operations you start, the job's inputs and results until the job is complete. Hosted AI is subject to per-plan credit limits, rate limits, and bulk job caps.Apple Intelligence requests are handled by Apple on-device or through Apple Private Cloud Compute and do not pass through our servers.
AI PROVIDERS
Depending on the feature and how you have configured it, content you provide (such as product names, descriptions, images, page content, and prompts) may be sent to:
TEXT AND VISION
OpenAI — models including GPT-4o, GPT-4o mini, and GPT-5. Used for SEO text, ad copy, page design, drafts, import cleanup, voice command interpretation, and image analysis. Available BYOK and Novo-hosted.Privacy Policy: openai.com/privacy
Google Gemini — models including Gemini 2.5 Flash and Gemini 2.5 Pro. Used for the same categories of text generation and image analysis. Available BYOK and Novo-hosted.Privacy Policy: policies.google.com/privacy
Apple Intelligence — on-device, or Apple Private Cloud Compute where available.Privacy Policy: apple.com/legal/privacy
IMAGE GENERATION AND PHOTO PROCESSING (bring-your-own-key only)
OpenAI DALL·E — image generation and editing. openai.com/privacyStability AI (Stable Diffusion / SDXL) — image generation. stability.ai/privacy-policyCanva AI — marketing image generation. canva.com/policies/privacy-policyRemove.bg — background removal. remove.bg/privacyPhotoroom — product photo enhancement. photoroom.com/privacyVIDEO GENERATION (bring-your-own-key only)
Runway — runwayml.com/privacy-policyKling AI — klingai.comZeely — zeely.appSynthesia — synthesia.io/privacy-policySPEECH AND VOICE
OpenAI text-to-speech and Google Gemini text-to-speech — used to speak Novo Voice replies aloud when you select a cloud voice. See Section 2.10.Murf AI — voice-over generation for marketing content (bring-your-own-key). murf.ai/privacy-policyCONNECTED DESKTOP ASSISTANTS
ChatGPT Desktop and Claude Desktop may be authorized to connect to your account through our MCP server using OAuth. In that case, the assistant vendor — not novo SOLUTION — operates the AI model, and their terms and privacy policies apply to the conversation. We log the tool calls the assistant makes (intent, result, timing), not the conversation content.Image, video, and voice generation are available only with your own API key. They are not offered through Novo-hosted AI credits, and you are billed by the provider directly.
Key facts about AI features:
Without a configured API key, and without Novo-hosted AI enabled for your account, no data is sent to that provider.All AI features are opt-in. The app works completely without enabling any of them.AI-generated content is a suggestion only — you are responsible for reviewing, editing, and approving all AI-generated content before it is used or published.We do not use your business data to train AI models, and we do not sell it.We cannot control how a third-party AI provider handles data you send under your own API key. Your agreement with that provider governs that relationship, including any data retention or training settings available in your provider account.There is no novo SOLUTION AI chatbot that talks to visitors on your public website. Where a chat widget appears on your storefront, it is a third-party service you enabled — see Section 2.14.
For more information on how each provider handles your data, please refer to their respective privacy policies linked above.
2.8 Tax API Provider Data (Optional — User-Configured)
novo SOLUTION includes optional integrations with third-party tax calculation services to assist with real-time tax calculations. These integrations are entirely optional and only active when you choose to configure them with your own credentials.
When you enable a Tax API Provider, transaction data may be sent to that provider to perform tax calculations. This data may include:
Product details (descriptions, tax codes, quantities, and prices)Shipping destination address (country, state/province, city, postal code)Order totals and line-item amountsThe Tax API Providers currently supported are:
TAX CALCULATION
TaxJar (by TaxJar, Inc.): Transaction data is sent to TaxJar's servers to calculate real-time sales tax amounts and rates based on shipping destination.Privacy Policy: taxjar.com/privacy
Avalara AvaTax (by Avalara, Inc.): Transaction data is sent to Avalara's servers for enterprise-grade tax compliance and real-time tax calculation.Privacy Policy: avalara.com/us/en/legal/privacy-policy.html
Stripe Tax (by Stripe, Inc.): Transaction data is sent to Stripe's servers to calculate tax amounts as part of the payment flow.Privacy Policy: stripe.com/privacy
Key facts about Tax API Provider integrations:
Every Tax API Provider integration requires you to configure your own API credentials. Without credentials configured, no transaction data is sent to that provider.Data is transmitted directly from our servers to the Tax API Provider using your credentials — we do not sell this data to third parties.Tax API Provider integrations are fully opt-in for in-store (POS) sales, which always use your manually configured tax rates. For the online store, at least one Tax API Provider or a payment provider with built-in tax handling (such as Stripe with Stripe Tax, or Square with Square Tax) must be configured to enable checkout. Without this, the online store operates in Showcase Mode — products are displayed publicly but customers cannot complete a purchase. See Section 4.4.5 of the Terms of Service.Enabling a Tax API Provider does not transfer your tax compliance responsibilities. You remain solely responsible for verifying that tax calculations are accurate for your jurisdiction. See Section 4.4 of the Terms of Service.Each provider operates under its own terms of service, privacy policy, and data processing practices.2.9 Subscription Data
If you purchase a subscription through Apple's App Store, Apple handles billing and payment processing. We receive limited subscription status information from Apple (such as subscription tier, expiration date, and renewal status) to provide you with the appropriate level of service. We do not receive or store your Apple ID password or full payment details.
2.10 Novo Voice and Speech Data (Optional)
Novo Voice is an optional in-app assistant that lets you operate novo SOLUTION by speaking. It is not a phone system: it does not answer, place, or record telephone calls. If you ask it to call a client, it hands the number to the iPhone Phone app and the call takes place outside novo SOLUTION.
Speech recognition:
Speech is converted to text by Apple's speech recognition on your device. On supported devices this runs entirely on-device. Audio is not sent to novo SOLUTION servers, and we do not store recordings.Audio is held only in memory for the length of the utterance and is discarded once recognition finishes.What happens to the recognized text:
A local matcher handles many commands entirely on-device with no AI provider involved.For anything the local matcher cannot handle, the recognized text — and, for questions, the business data needed to answer them — may be sent to Apple Intelligence, a BYOK provider, or Novo-hosted AI, exactly as described in Section 2.7 and subject to the same redaction and access tiers.Spoken replies:
By default, replies are spoken using Apple's on-device voices, and nothing leaves the device.If you choose a cloud voice, the text of the reply — which may include business figures or names that the reply mentions — is sent to OpenAI or Google to be synthesized into audio. The returned audio is played and the temporary file is deleted immediately afterward.Conversation memory:
A short conversational context (a handful of recent turns) is kept in memory so follow-up questions make sense. It is cleared when the session ends, when you sign out, and when you switch companies. It is not written to disk or transmitted.Failed command reporting:
When Novo Voice cannot understand or carry out a command, we collect the text of that failed command together with diagnostic context (failure type, the channel used, the screen you were on, app version, device model, OS version, language, and your company identifier and business type). We use this solely to find gaps in the assistant and improve it.Because it is the text of something you said, a failed command may incidentally contain words such as a name or an amount. It is encrypted at rest on our systems.Successful commands, complete conversations, and audio are not collected this way.Voice preferences and corrections you make are stored in an encrypted file on your device.
Novo Voice can change your business data — for example, creating an invoice — but only within the permissions of the signed-in user, only for features included in your plan, and, for higher-risk actions, only after you explicitly confirm. Questions answered by the assistant's answer engine are read-only.
2.11 Employee Access from Personal Devices ("Managed Staff")
A business can invite employees to access its account. An employee may sign in from their own personal iPhone or iPad. This section describes what we collect about the employee and their device, and is written primarily for employees.
How access is granted:
The business owner or an authorized manager sends an invitation to the employee's email address. The invitation link expires, and the token is stored only as a hash.The employee creates or signs in to an account and is issued a session limited to that business, that role, and the locations assigned to them.Multi-factor authentication is required or recommended depending on the role.What we collect about the employee:
Account details: name, email address, username, password (stored hashed), optional phone number, role, permissions, and assigned locationsAuthentication records: sign-in timestamps, the IP address of the most recent sign-in and of each refresh session, failed sign-in counts, account lockout state, and multi-factor secrets where enabledDevice records: an application-generated random device identifier stored in the device keychain, the platform, the app version and OS version, a push notification token, and a last-seen timestampSecurity event records: authentication and authorization events including event type, IP address, browser/app user agent, and device identifierWhat we deliberately do not collect from an employee's personal device:
Apple's advertising identifier or vendor identifier — the device identifier we use is randomly generated by the app and is not shared with anyone elseLocation or GPS dataBiometric data — Face ID or Touch ID, if the employee enables the app lock, is verified by iOS on the device and never leaves itPersonal photos, contacts, messages, browsing history, or any other app's dataAny inventory or scan of the device itselfSeparation from the employee's personal data:
Employer business data cached on the device is stored in a separate encrypted workspace scoped to that employer, and is marked to be excluded from the employee's device and iCloud backups.iCloud/CloudKit sync is disabled in employee mode. Employer data is never written into an employee's personal iCloud account.The employee's iCloud Key-Value Store is never read or written.If an employee works for more than one business, each employer's workspace is kept isolated from the others.Employer visibility and controls. The business can set and change an employee's role, permissions, and assigned locations; suspend or revoke access; and see the business records the employee creates or changes, since those are the business's own records. Where the business uses shift, clock-in, or tip features, those records are visible to the business as well. The business cannot use novo SOLUTION to remotely erase an employee's personal device, read their personal content, or track their location — those capabilities do not exist in the Services.
When access ends. When a business revokes an employee's access or the employee signs out, all server-side sessions and device registrations for that membership are deleted, and the employer's cached workspace, files, and queued work are deleted from the personal device. To avoid losing work, deletion waits until any unsent entries the employee created have been transmitted. Nothing else on the personal device is affected, and other employers' workspaces on the same device are untouched.
Employer responsibility. The employing business is responsible for telling its employees what it monitors, obtaining any consent required by local employment or privacy law, and complying with law when it reviews employee activity records.
2.12 Novo Market and Client Accounts
Where enabled, Novo Market lets an individual create a single client account and use it to discover, follow, join, book with, and order from participating businesses that use novo SOLUTION. Availability can be turned off by us at the platform level and by each business for its own store.
Important: each participating business sells its own goods and services and is the seller. novo SOLUTION provides the software and the directory. We are not the seller, and we do not take title to any goods.
What we collect for a client account:
Identity: email address (stored encrypted), password (stored hashed), first and last name, date of birth, and optionally a phone number (stored encrypted), profile image, and Sign in with Apple identifierVerification and security: email verification tokens, sign-in timestamps, failed attempt counters, and lockout stateDevices: a device identifier, platform, and push notification token for order and appointment notificationsWhat we collect per participating business you join:
Membership record: member number, status, how you joined, and any additional profile details that business requires as a condition of membershipLoyalty: points balance, tier, lifetime spend, and a transaction ledgerCommerce: saved addresses, cart contents, orders (items, totals, fulfillment method, delivery address or pickup time, status history), wishlists, appointments, table reservations, and notification preferencesSaved payment methods: a payment processor token plus card brand, last four digits, and expiry — never a full card numberWho sees what:
A business sees only its own relationship with you: your membership, your orders and bookings with that business, and the profile details you provided to it.A business cannot see which other businesses you belong to, or your activity with them.Your own aggregated view across businesses exists only in your client account.What is published publicly. A participating business that has opted in appears in the Novo Market directory with its business name, description, logo, business type, address and coordinates, business phone, email and website, hours, its catalog of products and services with prices and images, and aggregate counts such as number of members and followers. Individual client identities are not published, and Novo Market does not host public client reviews or profiles.
Payments and fulfillment. Payments are processed by the business's own payment processor account, either directly or through a connected account. Where a connected account is used, we may collect a platform fee, disclosed in the Terms of Service. The business is responsible for fulfilling orders, honouring bookings, and handling cancellations, returns, refunds, and disputes. Contact the business first about any order issue.
Age. Creating a client account requires a date of birth, and registration is refused for anyone under 13. See Section 10.
Your controls. From your client account you can export your data and request deletion. See Section 9.3.
2.13 Marketing Communications Data (Email and SMS)
If a business uses the marketing features, novo SOLUTION processes information about the recipients of that business's messages. The business decides who is contacted and is responsible for having a lawful basis and valid consent to contact them.
Email:
Subscriber records: email address, name where provided, subscription source, consent timestamp, and list membershipEngagement records: whether a message was opened (measured with a small tracking image embedded in the message), which links were clicked (measured by routing the link through our servers), delivery status, bounces, and complaintsUnsubscribe records: the fact and time of an unsubscribe, any reason given, and suppression list membership so the address is not contacted againMessages are delivered through whichever provider the business configured — for example Resend, SendGrid, Amazon SES, Mailchimp, a connected Gmail/Google Workspace mailbox, or the business's own SMTP server.If you receive marketing email sent through novo SOLUTION and do not want your opens and clicks measured, you can disable remote image loading in your mail app and avoid clicking tracked links, or unsubscribe using the link in the message.
SMS:
Phone number, the method and wording of the opt-in, the IP address recorded at the time of consent, message content and delivery status, and opt-out timestampsMessages are delivered through Twilio or Amazon SNS using platform or business-supplied credentialsAutomated messages. Businesses can configure messages that send automatically in response to events such as an order, an abandoned cart, an appointment reminder, or a birthday. This uses the customer record the business already holds.
Newsletter sign-up prompts on a business's website store a value in the visitor's browser so the prompt is not shown again for a period.
2.14 Public Storefront and Website Visitor Data
When someone visits a business's public storefront or website built with novo SOLUTION, we process the following on that business's behalf.
Reviews: reviewer name, email address, rating, review text, and any uploaded photos, together with moderation status and helpfulness or report flags. Approved reviews, including the reviewer's displayed name, are shown publicly. Where the business has enabled it, submitting a review may also add the reviewer to that business's newsletter list.Wishlists and saved items: for signed-in customers, the customer's identifier; for guests, an anonymous session identifier stored in the browser, together with the items saved and when.Storefront analytics: a session identifier, pages and products viewed, clicks, add-to-cart and similar events, referring URL, device and browser type, and coarse location derived from network information. These are business records belonging to the business, used to show it how its store is performing. They are not shared with other businesses.Forms and bookings: contact form submissions, quote and inquiry requests, appointment bookings, table reservations, and newsletter sign-ups, including the name, email, phone number, and message the visitor supplies.Customer accounts on a business's own website: name, email, username, password (hashed), phone, date of birth where collected, marketing preference, and — for business-to-business accounts — approval status and pricing tier.Saved property searches and alert preferences, where the business uses the real estate features.Cookies and similar technologies: see Section 8B.Third-party components that may appear on a business's storefront:
Crisp live chat, if the business enables it. Chat messages, and the email address and display name of a signed-in customer, are processed by Crisp. crisp.chat/en/privacyA WhatsApp contact button, which opens a conversation in WhatsApp (Meta). The conversation then takes place on WhatsApp under Meta's policies.Apple MapKit JS, used to render store location maps. Map requests are made from the visitor's browser to Apple. apple.com/legal/privacyMedia and images are served from Cloudflare R2 object storage and, where configured, a content delivery network.2.15 Financing and Credit Application Data (Where Enabled by a Business)
Some business types — for example vehicle dealerships — can enable financing or credit application features. Where a business enables them, an applicant may be asked to provide their full name, residential address, date of birth, contact details, employment or income information, and a government-issued identifier such as a Social Insurance Number or Social Security Number, together with the applicant's consent.
This information is submitted directly to the business that offers the financing. It is stored for that business and is visible to authorized users of that business.Identifiers of this kind are stored encrypted.This is a specific, limited exception to the general prohibition on storing government identifiers in Section 8E. It applies only to the financing and credit features, and only where the business has enabled them.The business offering financing is responsible for complying with all applicable consumer credit, lending, fair-lending, disclosure, and privacy laws, for obtaining valid consent before collecting this information, and for retaining and disposing of it lawfully. novo SOLUTION does not make credit decisions, does not act as a lender or credit reporting agency, and does not evaluate applications.3. HOW WE USE INFORMATION
We use information for purposes such as:
Provide and operate the Services: core business management features, syncing, website integration, and connected servicesSecurity and fraud prevention: authentication, access control, audit logging, abuse prevention, integrity monitoringSupport and communications: responding to requests, service notices, product updates, account-related messagesImprove and develop: bug fixes, performance improvements, feature development, analytics (when enabled/consented)Compliance and legal: meeting legal obligations, enforcing terms, and protecting rights and safetyContent safety and takedown enforcement: receiving and evaluating intellectual property infringement notices, prohibited-content reports, counter-notices, abuse reports, and related supporting materials; removing or disabling access to content where required or appropriate; preserving records needed to document our response; and enforcing the Terms of ServiceUsage monitoring and enforcement: tracking bandwidth and storage consumption per account to enforce subscription plan limits, including automated actions such as blocking uploads when bandwidth limits are reached (100%), automatically unpublishing websites when bandwidth exceeds 120% of the plan limit, and automatically republishing websites when usage drops below limits (either through a plan upgrade or the start of a new calendar month). Usage data is displayed to all account users (including staff) through the iOS app with exact GB figures and visual indicators. See Terms of Service Section 4.5 for full detailsAI metering and abuse prevention: recording which AI operations were run, by which account, using how many credits, to enforce plan limits and detect misuse of Novo-hosted AI (see Section 2.7)Voice assistant improvement: reviewing commands Novo Voice failed to understand so we can extend what it supports (see Section 2.10)Employee access administration and security: authenticating employees on their own devices, enforcing role and location scoping, and detecting credential misuse (see Section 2.11)Operating Novo Market: maintaining client accounts, matching clients with the businesses they join, delivering order and appointment notifications, and keeping each business's data isolated from every other business (see Section 2.12)Delivering and measuring communications a business sends: sending email and SMS a business has configured, recording delivery, opens, clicks, and unsubscribes, and honouring opt-outs (see Section 2.13)4. LEGAL BASES FOR PROCESSING
Where applicable (for example, under GDPR), we process information under one or more legal bases, including:
Contract: to provide the Services you requestLegitimate interests: to secure, maintain, and improve the ServicesConsent: for optional analytics and certain integrations where you choose to enable themLegal obligations: compliance with applicable laws and lawful requests5. HOW WE SHARE INFORMATION
We do not sell your personal information. We may share information:
With service providers that help us run the Services (hosting, storage, security, analytics, customer support tooling, email and SMS delivery, etc.) — see Section 8D for the current listWith integrated third parties you choose (for example, Meta/Facebook/Instagram, TikTok, payment processors, email and SMS providers, accounting providers, shipping carriers, listing feed providers, and automation platforms) to perform the features you enableWith Apple iCloud/CloudKit if you enable iCloud sync on your device (Apple's terms and policies apply). This does not apply to employee devices, where iCloud sync is disabled — see Section 2.11With AI providers when you use optional AI features, either using your own API key or through Novo-hosted AI — see Section 2.7 for the provider list and the two routing pathsWith connected desktop assistant vendors (OpenAI, Anthropic) if you authorize ChatGPT Desktop or Claude Desktop to connect to your account — see Section 2.7With Tax API Providers (TaxJar, Avalara, Stripe Tax) when you configure a tax API integration and use optional real-time tax calculation features — see Section 2.8 for detailsBetween a client and the businesses that client joins in Novo Market: a business receives the client's membership and order information for its own store only, and never the client's relationship with any other business — see Section 2.12For legal and safety reasons: to comply with law, respond to lawful requests, protect users, prevent fraud and abuse, and enforce our termsFor content enforcement and takedown handling: with affected account holders, rights holders, reporting parties, hosting providers, payment processors, app platform providers, law enforcement, courts, regulators, or legal advisors where reasonably necessary to investigate alleged infringement, prohibited content, illegal goods or services, threats to public safety, or misuse of the ServicesIn connection with a merger, acquisition, or sale of assets, subject to applicable safeguards6. SECURITY
We use administrative, technical, and physical safeguards designed to protect information, such as encryption in transit, access controls, and monitoring. Measures include:
Encryption in transit for all connections to our servicesEncryption at rest for particularly sensitive stored fields, including AI provider keys you supply, integration credentials, client account email and phone numbers, financing identifiers, and failed voice command textPasswords stored only as hashes, never in recoverable formRole-based access control, per-location scoping, and short-lived sessions with revocationOptional and, for some roles, required multi-factor authenticationAudit logging of authentication and administrative actionsIsolation of each business's data, and isolation of an employer's workspace on an employee's personal deviceNo method of transmission or storage is 100% secure; however, we work to meet enterprise-grade security expectations appropriate for the Services.
7. DATA RETENTION
We retain information for as long as your account is active or as needed to provide the Services, and as needed for backups, synchronization, dispute resolution, and compliance with legal obligations. Specific retention periods include:
Business data: retained while your account is active and as long as your business uses the ServicesAnonymous analytics events: if enabled/consented, anonymous analytics events (for example, event type, timestamp, session identifier, coarse device info, and an anonymized identifier) are retained for analytics purposes and periodically purgedSecurity and audit logs: retained as needed for security monitoring, incident investigation, and complianceTakedown, counter-notice, and content-enforcement records: retained as needed to document notices, responses, repeat-infringer determinations, legal compliance, dispute resolution, and prevention of abuseIntegration tokens: retained while the integration is connected and deleted upon disconnectionNovo-hosted AI records: usage and metering records are retained for billing, plan enforcement, and abuse prevention; the deduplication cache holding generated output expires automatically after a short period; bulk job inputs and results are retained until the job completes and for a limited period afterwardsVoice data: audio is never retained; conversation context is held in memory only and cleared at the end of a session; the on-device AI action log keeps a fixed number of recent redacted entries and is overwritten oldest-first; failed command reports are retained until they have been reviewed and acted onEmployee device and session records: refresh sessions expire on their own schedule, and all device and session records for a membership are deleted when that employee's access is revokedClient accounts (Novo Market): on a deletion request, the account is deactivated immediately and retained for 30 days before final deletion, so that an accidental request can be reversed and any open orders can be resolvedMarketing suppression records: unsubscribe and opt-out records are retained after the underlying subscriber record is removed, because we need them to keep honouring the opt-outEmployee and client audit records: retained as needed for security, dispute resolution, and legal compliance8. YOUR RIGHTS AND CHOICES
Depending on your jurisdiction, you may have the right to:
Access your personal informationCorrect inaccurate informationRequest deletion of personal information (subject to legal exceptions)Object to or restrict certain processingWithdraw consent (for example, for optional analytics)Data portability (export)You can also manage certain privacy settings directly in the app (for example, analytics toggles and integration connections).
8A. Operational Telemetry (Security and Reliability)
Even if you disable optional analytics, we may still process minimal operational telemetry strictly for security, abuse prevention, and service reliability. Examples may include:
Security logs: authentication attempts, session and token validation outcomes, CSRF and rate-limit events, suspicious activity signals, and audit logging of administrative actionsTechnical metadata: request identifiers, timestamps, device/platform info, and network metadata such as IP address and user agent (used for security and fraud prevention)We use this information to protect the Services (for example, detect abuse, enforce access controls, investigate incidents, and prevent fraud). We do not use operational telemetry for behavioral advertising.
8B. Cookies and Similar Technologies
When you use our web properties (for example, the admin portal or your connected website), we may use cookies, browser storage, or similar technologies for:
Essential operation (for example, authentication/session management, CSRF protection, security controls)Preferences (for example, tenant/company selection in multi-tenant setups, and remembering that a newsletter prompt has already been shown)Storefront measurement (a session identifier used to group a visitor's page and product views into a single visit, as described in Section 2.14)Guest features (an anonymous session identifier so a visitor who is not signed in can keep a wishlist or saved items)Third-party components a business enables, such as the Crisp chat widget, which sets its own storage in the visitor's browserWe do not intentionally use third-party advertising cookies by default. A business may add its own advertising or analytics tags to its website, in which case that business is responsible for providing notice and obtaining consent where required. If we introduce optional analytics or advertising cookies on our own web properties in the future, we will provide appropriate notice and choice mechanisms where required by law.
Do Not Track: Some browsers offer a "Do Not Track" setting. Because there is no consistent industry standard for DNT signals, our web properties may not respond to DNT signals.
8C. International Transfers
novo SOLUTION may process and store information in countries other than where you live (for example, where we or our service providers operate). Where required (for example, transfers from the EEA/UK), we use appropriate safeguards such as standard contractual clauses or other lawful transfer mechanisms.
8D. Subprocessors and Service Providers
We use vendors ("subprocessors") to help provide the Services. Categories and current principal vendors include:
Hosting, database, and application infrastructure: RailwayObject storage and content delivery for media and documents: Cloudflare R2, and a content delivery network where configuredApple services: iCloud/CloudKit (where you enable sync), APNs push notifications, App Store subscription processing, MapKit JS for mapsAI providers: as listed in Section 2.7Payment processing: Stripe, Square, PayPal, and supported terminal providersTax calculation: TaxJar, Avalara, Stripe Tax (only when you configure them)Email delivery: Resend, SendGrid, Amazon SES, Mailchimp, or a mailbox/SMTP server you connectSMS delivery: Twilio, Amazon SNSWebsite chat: Crisp (only when a business enables it)Accounting, automation, shipping, and listing feeds: Xero, Zapier, USPS, UPS, FedEx, DHL, and MLS/CREA DDF feed providers (only when you configure them)Error and performance monitoring: Sentry, where configuredSome of these are used only if you turn on the relevant feature or connect the relevant account. An up-to-date list can be requested by contacting us.
8E. Sensitive Data
Unless expressly agreed in writing, or unless a specific feature is designed to collect it as described below, you must not upload or store:
Government-issued identifiers (for example: Social Insurance Numbers, Social Security Numbers, passport numbers, driver's licence numbers)Precise geolocation, biometric identifiers, or other sensitive categories regulated by lawHealth/medical information, including Protected Health Information (PHI)Exception — financing and credit features. Where you enable the financing or credit application features described in Section 2.15, those features are designed to collect an applicant's date of birth and a government-issued identifier such as a Social Insurance Number or Social Security Number. That collection is permitted within those features only. You remain responsible for obtaining valid consent, for complying with all applicable consumer credit and privacy law, and for restricting access to that information within your own team.
The Services are not designed to support HIPAA compliance and should not be used to store Protected Health Information unless you have a separate written agreement with us that specifically covers such use.
8F. Marketing Communications
We may send service-related communications (for example, account, security, billing, and service notices). Where we send marketing communications, you can opt out using the unsubscribe mechanism provided in the message or by contacting us, subject to legal requirements.
This section is about messages novo SOLUTION sends to you. Messages a business sends to its own customers through the Services are covered by Section 2.13, and the sending business — not novo SOLUTION — is responsible for consent and for honouring opt-outs.
We may also send push notifications to your device (for example, order, appointment, and usage-limit notifications). You can turn push notifications off in iOS Settings at any time.
9. DATA DELETION (INCLUDING ACCOUNT DELETION)
9.1 Account Deletion
novo SOLUTION provides a complete account deletion feature directly within the app, in compliance with Apple App Store requirements.
How to Delete Your Account: 1. Open the novo SOLUTION app 2. Navigate to Settings > Account 3. Tap Delete Account 4. Confirm your decision when prompted
What Happens When You Delete Your Account:
Your user account and all data associated with your account (including companies, products, customers, invoices, appointments, and other records) will be permanently deletedAll connected integrations (social media, payment providers, etc.) will be disconnected and their OAuth tokens revoked with the third-party providersAll website content and backend data associated with your account will be permanently deleted from our serversiCloud/CloudKit synced data associated with your account will be removedAll local and iCloud Drive backup files (.novo, .store) created by the app will be permanently deletedAll locally cached data, temporary files, and app preferences will be clearedAny API keys associated with your account will be revoked and deleted, including AI provider keys you suppliedAll employee memberships, invitations, sessions, and device registrations for your business will be deleted, and employees will lose access; the employer workspace cached on each employee's personal device is removed the next time that device attempts to connectIf your business participated in Novo Market, your public listing and catalog mirror will be removed, and client memberships with your business will be deleted. Clients keep their own client accounts and their relationships with other businessesImportant Subscription Information:
Your Apple App Store subscription is managed by Apple and is NOT automatically cancelled when you delete your accountYou must cancel your Apple subscription separately through your Apple ID subscription settings (Settings > Apple ID > Subscriptions) or at https://apps.apple.com/account/subscriptionsIf you do not cancel your Apple subscription before deleting your account, Apple may continue to charge youYou will NOT receive a refund for any remaining time on your current billing periodWe recommend cancelling your subscription first, then deleting your account when the paid period endsImportant Notes:
Account deletion is permanent - this action cannot be undoneTemporary deactivation is not offered - we only provide full, permanent account deletionNo customer service required - you can complete account deletion entirely within the app without needing to call, email, or contact supportData recovery is not possible - once deleted, your data cannot be recoveredPlease export any data you wish to keep before initiating account deletionIf you create a new account using the same iCloud account after deletion, you will start with a completely fresh account - no previously deleted data will be restored (GDPR compliance)Timing:
Account deletion is processed immediately upon confirmationAll server data, local data, iCloud/CloudKit data, backup files, and associated records are deleted immediatelyApple App Store subscriptions are NOT automatically cancelled — you must cancel through Apple (see above)If server deletion fails due to a temporary network issue, the deletion will be retried automatically the next time you open the appOnce deleted, your data cannot be recovered9.2 Deleting Social Media Connection Data
You can disconnect social media integrations and delete associated connection data using the in-app "Delete All Social Media Data" option, which is designed to:
Disconnect connected social platformsRemove stored tokens and connection metadata from our systems where supportedClear local cached social media data on the device (for example, stored page/account IDs and last-post timestamps)Important notes:
Content you already posted to Facebook/Instagram/TikTok remains on those platforms unless you delete it from the platform directly.Token revocation is attempted where supported, but revocation may not always succeed (for example, if a token is already expired or provider-side revocation is unavailable). If you want to fully remove access, you can also remove novo SOLUTION's access from within the provider's security settings.Company deletion: removing a company from the app will also delete associated social media connection data.Backend deletion: if you enabled website integration, deletion may involve deleting data stored on your connected backend as well.Full account deletion: use the account deletion feature described in Section 9.1 for complete removal of all data.For deletion assistance beyond in-app controls, contact us (see "Contact").
9.3 Deleting a Novo Market Client Account
If you hold a client account (Section 2.12), you can export your data and request deletion from within your account.
Export provides your profile, your memberships, and your orders, appointments, reservations, loyalty history, saved addresses, and wishlist.On a deletion request, your account is deactivated immediately and you can no longer sign in. It is retained for 30 days and then permanently deleted. This window exists so that an accidental request can be reversed and so that open orders can be completed or resolved.Records a business is required to keep for its own legal, tax, or accounting purposes — for example a completed sales record — remain with that business as its own business record.Content you already sent to a business, such as a review you posted or a message you sent, is handled by that business. Contact the business to have it removed.9.4 Employee Offboarding
When a business revokes an employee's access, or the employee signs out, the effects described in Section 2.11 apply: all server-side sessions and device registrations for that membership are deleted, and the employer's cached workspace, files, and queued work are removed from the employee's personal device. The employee's own account record and the record of the business activity they performed remain with the business, because those are the business's records.
An employee who wants their personal account record deleted should contact the business they worked for. Where we control the record, we will assist as described in Section 12.
10. CHILDREN'S PRIVACY
The Services are intended for business use and are not directed to children.
The business management app is intended for use by adults operating a business, and is not directed to children under 13.Creating a Novo Market client account requires a date of birth. Registration is refused for anyone under 13, and we do not knowingly create client accounts for children under 13.A business's public storefront may be visited by anyone. Businesses are responsible for any age restriction required for their products or services, including any age verification gate they enable.If you believe a child under 13 has provided personal information, contact us and we will delete it.
11. CHANGES TO THIS POLICY
We may update this Privacy Policy at any time, without prior notice, to the extent permitted by law. The updated version will be posted in the Services and will be effective when posted (or as otherwise stated). If notice is required by applicable law for certain changes, we will provide the required notice.
12. CONTACT
For privacy questions or requests: Email: support@novosolution.org
For legal notices: Email: support@novosolution.org
Submitting Privacy Requests:
To submit a privacy request (access, deletion, correction, portability), email us with:
Your name and account/business identifier (if available)The type of requestThe email address associated with the account (if applicable)Any relevant details needed to locate the dataFor security, we may need to verify your identity before processing your request. If you are acting on behalf of a business account, we may require proof of authority. We aim to respond within applicable legal timeframes (commonly 30-45 days, depending on your jurisdiction and the nature of the request).
Where to direct your request:
If you are a customer of a business that uses novo SOLUTION, and your request concerns records that business holds about you (for example a purchase, an appointment, or a marketing list), contact that business directly. It controls those records. We will assist that business where we can, but we cannot change or delete its records on your behalf without its instruction.If you are an employee, contact the business that invited you regarding the business records and activity history it holds about you. Contact us regarding your account credentials and device session records.If you hold a Novo Market client account, use the export and deletion controls in your account (Section 9.3), or contact us.If you are a business owner or administrator, contact us directly.Last Updated: August 21, 2026
Novo Voice Command Improvement
When Novo Voice (our in-app voice assistant) is unable to understand or complete a command you ask it to perform, we collect only the text of that specific failed command or request — never your business data, customer data, or any other part of the surrounding conversation — so our team can review it and add support for new commands. This information is used solely to improve the Novo Voice feature.
Version 1.0.14 • Last updated: 8/22/2026