Privacy policy
Effective October 6, 2026
Restora is job management software for property restoration companies: the office web app and the iPhone app their crews use in the field. This policy explains what we collect, why, and who can see it. In short: we collect what the work needs, your company controls its data, and we never sell it or use it for advertising.
Who controls the data
A restoration company signs up for Restora and invites its team. The information that company enters (jobs, customers, properties, photos, readings) belongs to the company, and its owners and admins decide who on the team can see what. We store and process it on the company’s behalf.
What we collect
- Account details: your name, email address, role, and the company you belong to. Passwords are stored only as a one-way hash.
- Work your company records: jobs, customer and property details, insurance and claim information, notes, checklists, moisture and air readings, equipment, estimates, signatures, timesheets, and messages between team members.
- Photos, scans, and files: photos taken or added in the app (with the time they were taken and, when the photo carries it, its GPS position, which the iPhone app may print on the photo), LiDAR room scans, photos of hand-drawn floor sketches, and documents.
- Location, for technicians on the clock: when a technician clocks in, the iPhone app records where, and then the phone’s position every few minutes until they clock out, so the office can confirm time on job sites. It is not collected while clocked out. The app also notices arriving at or leaving a job site to offer a clock-in or clock-out reminder. A company’s owners and admins can see this location history; other team members can’t.
- Device details for notifications: if you allow notifications, a push token from Apple so we can deliver announcements and reminders to your phone.
- Basic service logs: request and error logs our hosting keeps to run and secure the service.
The iPhone app asks for camera, location, and notification access only when a feature needs it, and works without the ones you decline (for example, without location there are no job-site reminders).
How we use it
- To provide Restora: show your jobs, sync the field app, produce reports, send the notifications your company sends.
- To keep it secure and working, and to fix problems.
- To contact you about your account or the service.
We don’t sell personal information, don’t show ads, and don’t use advertising or cross-app tracking. We don’t use your company’s data to train AI models, and the service that reads hand sketches for us doesn’t either.
Who processes it for us
- Netlify hosts the service, its database, and stored files.
- Cloudflare keeps an encrypted backup copy of the database and stored files, so they can be restored if something goes wrong.
- Resend delivers the emails Restora sends, like sign-in links and invitations.
- Sentry receives error reports when something breaks in the web app: what failed and where, without request contents, cookies, or IP addresses.
- Apple delivers push notifications and, for TestFlight testers, crash reports and feedback you choose to send.
- Anthropic reads the photos of hand-drawn floor sketches you upload, so Restora can draw them as rooms for you to check. It sees only the sketch photo, and its API doesn’t use what it’s sent to train its models.
- OpenFreeMap serves the street-map images on timesheet route maps; your browser requests them directly, so they see your IP address.
Within your company, information is shared according to its roles (for example, only office roles see estimates). Each company’s data is kept separate from every other company’s. We disclose information to others only if the law requires it.
Keeping and deleting data
We keep a company’s data while its account is active. Office staff can export lists as CSV at any time. To delete an account or a company’s data, contact us and we’ll remove it, except where we must keep records by law. Some records, like signed documents and edited photo captions, are kept with their history on purpose, because they serve as evidence for insurance claims.
Security
Connections are encrypted, access to each company’s data is enforced in the database itself, and signed documents carry a fingerprint that shows they haven’t changed. No system is perfectly secure, and we’ll tell affected customers promptly if a breach affects their data.
Children
Restora is a business tool and isn’t meant for anyone under 16.
Changes and contact
If this policy changes, we’ll update the date above and, for significant changes, tell account owners. Questions or requests: support@meetrestora.com.