Privacy Policy
We collect information you provide directly, including account details (name, email, phone), business information, customer data entered into the platform, and usage analytics to improve our services.
We distinguish between two types of data:
- Personal Data: Information that identifies you as an individual (name, email, phone, IP address)
- Business Data: Data you enter about your business operations (customers, jobs, estimates, invoices, inventory). This data is owned by you and your organization.
All data is encrypted at rest using AES-256 and in transit using TLS 1.3. API keys and sensitive credentials are stored in an encrypted vault and never exposed to the client application. We conduct regular security audits and penetration testing.
Your data is used to provide and improve KoreFSM services, process payments via Stripe, deliver AI-powered features (scheduling, communications), and send transactional notifications. We never sell your data to third parties.
Our AI assistant processes your prompts and business context to deliver intelligent recommendations. AI interactions are logged for quality improvement but are never used to train third-party models. You can request deletion of AI activity logs at any time.
Payments are processed through Stripe. KoreFSM never stores credit card numbers directly. All payment data is handled in compliance with PCI DSS Level 1 standards through Stripe's certified infrastructure.
We use essential cookies to maintain your session and authenticate you. We also use analytics cookies (Google Analytics) to understand how the Platform is used and improve our services. We do not use cookies for targeted advertising.
You can disable cookies in your browser settings, but some features of the Platform may not function properly without them.
By using KoreFSM, you consent to receive transactional SMS and email notifications related to your account and business operations (job assignments, appointment reminders, invoice notifications). These messages are sent through Twilio and our email infrastructure.
If you use KoreFSM to send SMS or email to your customers, you are responsible for obtaining proper consent from your recipients and complying with all applicable laws, including the Telephone Consumer Protection Act (TCPA) and the CAN-SPAM Act. KoreFSM is not liable for your failure to obtain proper consent.
You can opt out of non-essential communications at any time by updating your notification preferences in the Platform or replying STOP to SMS messages.
We comply with GDPR and CCPA requirements. You have the right to:
- Access your personal data
- Correct inaccurate personal data
- Export your data in a portable format
- Delete your personal data (subject to legal retention requirements)
- Object to processing of your data
- Restrict processing of your data
- Withdraw consent at any time
Data processing agreements are available upon request for enterprise customers. To exercise these rights, contact our data protection team.
Your data is stored on servers located in the United States. If you access KoreFSM from outside the United States, your data will be transferred to and processed in the United States. By using KoreFSM, you consent to this transfer.
We comply with applicable data protection laws regarding international transfers, including GDPR Standard Contractual Clauses where required.
Account data is retained for the duration of your subscription plus 90 days. Upon account deletion, all personal data is permanently removed within 30 business days. Anonymized, aggregated analytics may be retained indefinitely.
In the event of a data breach that compromises your personal data, we will notify affected users within 72 hours of confirming the breach, in accordance with GDPR requirements. Notifications will include the nature of the breach, the data affected, and steps you can take to protect yourself.
KoreFSM is not intended for use by anyone under 18 years of age. We do not knowingly collect personal information from children under 18. If we become aware that a child under 18 has provided us with personal data, we will delete that data immediately. If you believe a child has provided us with personal data, please contact us.
We integrate with third-party services that act as our subprocessors. Each provider maintains their own privacy policy and data handling practices. We only share the minimum data necessary for these integrations to function. Current subprocessors include:
- Stripe (payment processing)
- Twilio (SMS and voice communications)
- RingCentral (voice communications)
- Google (authentication and analytics)
- OpenAI / Anthropic (AI features)
- Supabase (database infrastructure)
We will update this list when we add or remove subprocessors. You can request a current list at any time.
While we implement reasonable measures to protect data integrity, we are not responsible for data loss. You are solely responsible for backing up your data. We recommend regularly exporting your business data. See our Terms of Use for full details on data loss liability.
For privacy inquiries, data requests, or to exercise your rights under GDPR or CCPA, contact us at [email protected].
© 2026 KoreFSM Inc. All rights reserved.