Axiom Board GroupServiceOS

ServiceOS Privacy Policy

Effective and last updated: October 2, 2026

This Privacy Policy describes how Axiom Board Group LLC, an Iowa limited liability company ("Axiom," "we," "us," or "our"), collects, uses, discloses, retains and protects information in connection with ServiceOS, our cloud-based operations platform for service companies (the "Platform"). It applies to everyone who uses the Platform, including the owners, administrators, employees and contractors of the businesses that subscribe to it ("Subscribers"). It covers ServiceOS at serviceos.axiomboardgroup.com and its apps. It does not cover axiomboardgroup.com, which has its own privacy policy.

By accessing or using the Platform, you acknowledge that you have read and understood this Privacy Policy. If you use the Platform on behalf of a business, you represent that you have authority to bind that business. This Policy is part of the ServiceOS Terms of Service.

1. Our role and the Subscriber's role

Each Subscriber decides what information goes into its ServiceOS account and who in its company can see it. Under the ServiceOS Subscriber Agreement, the Subscriber owns its data and is the data controller, and Axiom processes the data on the Subscriber's behalf as a data processor. Subscribers are responsible for having a lawful basis, and any notices and consents required, for the personal information they put into the Platform, including information about their employees. If you are an employee of a Subscriber, your employer is the first place to go with questions about your information; you can also contact us at the address in section 15.

2. Information the Platform holds

2.1 Account information: names, email addresses, roles, sign-in records, and whether two-factor authentication is set up.

2.2 Employee records a Subscriber enters: contact details, start dates, job titles, licenses and certifications with their expiry dates, training and quiz results, performance reviews, and documents a Subscriber uploads, such as driver's licenses, tax forms and direct deposit forms. Pay details, where a Subscriber records them, are kept separately and are visible only to the Subscriber's administrators.

2.3 Safety records: hazard checks, toolbox talk attendance, and incident reports, which can include injury details a Subscriber records for its OSHA logs.

2.4 Vehicles and equipment: what the company owns and who holds it.

2.5 Billing information: the Subscriber's subscription and payment status. Card and bank details are entered with and held by Stripe on its PCI-DSS compliant systems; the Platform never receives or stores full card or bank account numbers.

2.6 Technical, security and activity information: IP addresses, browser and device type, sign-in times, error logs, and audit records of who opened sensitive documents and what administrators and Axiom staff changed.

2.7 Email and text message records: which emails the Platform sent, to whom, and whether they were delivered. Where a Subscriber enables text messages, the recipient's phone number, the consent recorded for it (including any opt-out), and a log of messages and their delivery status.

2.8 Support communications: records of messages you send us, kept to help you and improve our support.

2.9 QuickBooks Online data, only if a Subscriber connects it (section 3).

3. QuickBooks Online

A Subscriber's administrator can connect the Subscriber's own QuickBooks Online company from Settings, Integrations, by signing in to Intuit and approving ServiceOS. Once connected:

  • What the Platform reads: invoices (number, date and amount), payments (date, amount and which invoices they pay), and monthly profit and loss totals (income, cost of goods sold, gross profit, expenses and net income). It reads them once a day, and when an administrator chooses Sync now.
  • Read-only: ServiceOS never creates, changes or deletes anything in QuickBooks.
  • What it is used for: only to show that Subscriber its own figures in ServiceOS: the dashboard, the daily digest, and the check that its QuickBooks records agree with its field service system.
  • What it is never used for: it is never sold, never used for advertising, never shared with any other Subscriber, and never used to train artificial intelligence models.
  • Protection: the connection's access keys from Intuit are encrypted before they are stored, and no ServiceOS user, including the Subscriber's own administrators, can read them.
  • Disconnecting: an administrator can disconnect at any time from Settings, Integrations. Disconnecting asks Intuit to end the connection and deletes the QuickBooks information ServiceOS brought in for that Subscriber at the same time. If you disconnect from inside QuickBooks instead, ServiceOS can no longer read new information; disconnect in ServiceOS as well, or email us, and the information already brought in is deleted.

4. How we use information

We use information only to: (a) provide, operate, maintain and improve the Platform; (b) authenticate users and enforce role-based access, so each person sees only what their role allows; (c) send the emails and, where enabled, text messages the Platform sends for the Subscriber, such as sign-in links, reminders, safety notices and the daily digest; (d) bill Subscribers; (e) monitor performance, detect and prevent fraud and abuse, and protect the security of the Platform; (f) provide support; (g) communicate with Subscriber administrators about the service, pricing and changes; and (h) comply with law and respond to lawful requests. We do not sell personal information, and we do not use it for advertising.

5. How we share information

We do not sell personal information, and we do not share it with anyone for their own marketing. We share it only as follows.

5.1 Service providers. These companies process information on our behalf to run the Platform, are bound to protect it, and may use it only to provide their services to us:

  • Supabase, Inc.: database, file storage and sign-in, on Amazon Web Services infrastructure.
  • Lovable and Cloudflare, Inc.: application hosting, serverless computing and network security.
  • Resend: email delivery. Recipient addresses and email content are sent to Resend only to deliver the email.
  • Stripe, Inc.: subscription payments, under Stripe's own privacy policy.
  • Intuit Inc.: only for a Subscriber that connects QuickBooks Online (section 3), under Intuit's own privacy policy.
  • Twilio Inc.: text message delivery, only where a Subscriber enables text messages. Phone numbers, message content and delivery status are sent to Twilio only to deliver messages; registration details required by mobile carriers are shared with Twilio and The Campaign Registry.

5.2 Text messaging. We do not sell or share your SMS opt-in data or personal information with third parties for marketing purposes. Mobile phone numbers and text messaging consent are never shared with third parties or affiliates for their marketing or promotional purposes. Text messaging consent is not shared with anyone except the service providers that deliver the messages.

5.3 The Subscriber. A Subscriber's administrators can see the information in its own account, according to the roles it sets.

5.4 Axiom staff. Axiom personnel access a Subscriber's account only as needed to provide support, maintain the Platform, or comply with law. When Axiom staff view a Subscriber's account, the session lasts at most two hours and is logged, and pay details, offer letters and employee documents stay closed to them.

5.5 Business transfers. If Axiom is involved in a merger, acquisition, financing, reorganization or sale of assets, information may be transferred as part of that transaction, subject to this Policy. We will notify Subscriber administrators before their information becomes subject to a different privacy policy.

5.6 Legal requirements. We may disclose information if required by law or valid legal process, such as a court order or subpoena. Where the law allows, we will make reasonable efforts to notify the affected Subscriber first.

5.7 Protection of rights. We may disclose information where we believe it is necessary to investigate, prevent or act on illegal activity, suspected fraud, threats to anyone's safety, or violations of our Terms of Service or the Subscriber Agreement.

6. How each Subscriber's information is kept separate

ServiceOS serves many independent Subscribers. Every table that holds a Subscriber's information is protected by row-level security enforced by the database itself, so a request made for one Subscriber cannot return another Subscriber's information, whatever the application asks. Access by Axiom staff is limited, requires two-factor authentication, and is recorded in a dedicated audit log.

7. Security

We use technical and organizational measures to protect information, including: encryption in transit (TLS) for all network traffic and encryption at rest; database-enforced separation of Subscribers; role-based access with least privilege; two-factor authentication, required for all Axiom staff and available to every user; stored documents opened only through short-lived links, with every opening logged; secrets kept in managed secret stores, never in code; audit logging of administrative and privileged actions; and regular security reviews and scanning. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a confirmed security breach affects a Subscriber's information, we will notify that Subscriber without undue delay, as the Subscriber Agreement provides, and as applicable law requires.

8. How long we keep information

We keep a Subscriber's information while its subscription is active. When a subscription ends, the Subscriber may request an export within 30 days; after that 30-day period we may permanently delete the Subscriber's information, including from backups as they are replaced in the normal course. QuickBooks information is deleted when the Subscriber disconnects QuickBooks (section 3). Audit logs, billing records and records of consent may be kept for up to seven years where needed for legal, security, tax or accounting purposes.

9. Data export

A Subscriber may request an export of its information during its subscription and within 30 days after it ends, as described in the Subscriber Agreement. Exports are provided in CSV format, with copies of stored documents. Contact [email protected].

10. Your rights

Depending on where you live, you may have the right to: access the personal information held about you; correct it; delete it, subject to legal exceptions; receive it in a portable format; restrict or object to certain processing; and not be discriminated against for exercising these rights. California residents have additional rights under the California Consumer Privacy Act, including the right to know what personal information is collected and whether it is sold or disclosed. We do not sell personal information.

Because each Subscriber controls its account, we will usually pass your request to the Subscriber you work for and help it respond. You can also contact us at [email protected]. We respond to verifiable requests within 30 days, and may need to verify your identity before acting on a request.

11. Cookies and similar technologies

The Platform uses only what it needs to work: cookies that keep you signed in, a cookie that remembers a display preference, and storage on your device for an unfinished hazard check and for signing staff out after a period without activity. It does not use advertising cookies, tracking pixels, analytics trackers, cross-site tracking or behavioral advertising.

12. Children

The Platform is a workplace service for businesses. It is not directed to children under 16, and we do not knowingly collect personal information from children under 16. If you believe we have, contact us and we will delete it.

13. Visitors outside the United States

The Platform is operated from the United States and offered to businesses in the United States. If you use it from elsewhere, your information will be transferred to and processed in the United States, where privacy laws may differ from those where you live.

14. Third-party sites and changes to this Policy

The Platform may link to third-party sites and services, such as QuickBooks. This Policy does not apply to them; please review their privacy policies.

We may update this Policy to reflect changes in our practices, technology or legal requirements. When we make material changes, we will update the date at the top and notify Subscriber administrators by email before the changes take effect. Your continued use of the Platform after changes take effect means you accept the updated Policy.

15. Contact

Axiom Board Group LLC, an Iowa limited liability company, Carroll, Iowa
[email protected]

Axiom Board Group LLC, Carroll, Iowa