OpsNote

Privacy Policy

Last updated: 29 July 2026

Who We Are

OpsNote is operated by OpsNote LTD. OpsNote helps businesses capture enquiries, organise leads, manage customer conversations, book work, track finance signals, manage stock, and store receipts or invoices in one workspace.

For privacy questions, contact us at hello@opsnote.co.uk.

Information OpsNote Processes

Depending on the features you use, OpsNote may process account details, business profile details, workspace settings, connected channel status, OAuth tokens, customer messages, message metadata, customer names, email addresses, phone numbers, attachments, lead details, notes, booking details, finance values, stock items, uploaded receipts or invoices, billing status, subscription records, support messages, and AI-generated summaries or suggested replies.

OpsNote also processes operational data such as sync status, webhook delivery logs, error logs, device/browser information, security events, and usage information needed to run, secure, and improve the service.

Meta, Facebook, Instagram, And WhatsApp Data

If you connect Meta services, OpsNote may process Meta business asset identifiers, Facebook Page details, Instagram professional account details, WhatsApp Business Account details, business phone number identifiers, access tokens, webhook subscriptions, message IDs, sender IDs, customer names where provided by Meta, timestamps, message text, attachments, and delivery metadata.

OpsNote uses this data only to provide the business messaging features you authorise: connecting business channels, receiving customer enquiries, creating or updating lead records, displaying message history, routing replies to the correct channel, showing sync or connection status, and sending replies that you choose to send from OpsNote.

OpsNote does not use Meta data for unsolicited bulk messaging, unrelated advertising, or access to business assets that you have not authorised. Your use of Meta services remains subject to Meta's own terms and policies.

Gmail And Google User Data

Gmail features are not part of the general public v1 release while Google verification and CASA requirements are being completed. If Gmail is later enabled for your account and you choose to connect Gmail, OpsNote uses Google OAuth access only to provide the Gmail features you authorise.

The Google user data OpsNote may access or process includes your connected Gmail address, Google account identifiers, OAuth access and refresh tokens, Gmail message IDs, Gmail thread IDs, sender and recipient email addresses, subject lines, timestamps, snippets, message body content, sent-message details, labels or mailbox query results needed for sync, and attachments included in relevant customer enquiry threads.

OpsNote uses this data only to operate Gmail features you enable: showing which Gmail account is connected, syncing relevant customer enquiries, creating and updating lead records, grouping messages into conversation threads, deduplicating imported messages, displaying message history, identifying missing lead information, generating lead summaries, drafting suggested replies, detecting reply language, showing sync status, and sending replies that you choose to send from within OpsNote.

OpsNote does not send emails automatically on your behalf. Gmail send access is used only when you take an action in the app to send or reply to a message.

OpsNote's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. OpsNote does not sell Google user data, use Google user data for advertising, or use Google user data to develop, improve, or train generalized AI or machine-learning models.

AI Processing

OpsNote uses AI to classify enquiries, extract lead details, identify missing information, estimate lead value, summarise conversations, detect language, draft suggested replies, and analyse receipt or invoice images for stock suggestions.

To provide these features, relevant message text, lead details, attachments, or receipt images may be sent to AI infrastructure providers. AI output is generated for your review and should be checked before you rely on it, send it to a customer, or use it for business decisions.

Receipts, Invoices, Stock, And Finance Data

If you upload receipts or invoices, OpsNote stores the uploaded file privately and may analyse it to suggest stock materials, supplier names, totals, and notes. Uploaded files can be viewed through temporary signed links and deleted from the app.

Finance and stock features are operational tools. They are not a replacement for formal bookkeeping, accounting, tax advice, or professional financial advice.

Payments And Service Emails

OpsNote uses Stripe for checkout, payment method collection, subscription management, billing status, invoices, payment events, and customer portal access. OpsNote does not store full card numbers. Stripe processes payment information according to its own terms and privacy policy.

OpsNote may send transactional emails, such as welcome emails, access notices, billing-related notices, and important service messages, using trusted email infrastructure providers.

Service Providers And Processors

OpsNote uses trusted service providers to host, secure, and run the product. These may include Supabase for authentication, database, and file storage; Vercel for hosting and deployment; Stripe for payments and subscriptions; OpenAI or other AI infrastructure for AI features; Resend or similar providers for transactional email; Meta and Google APIs for connected channel features; and GitHub or similar tools for source control and operational deployment.

These providers process data only as needed to provide, secure, maintain, support, or improve OpsNote's service. Some providers may process data outside the United Kingdom or European Economic Area, using contractual, technical, and organisational safeguards where required.

Data Protection And Security

OpsNote uses technical and organisational safeguards designed to protect personal data and sensitive business data. Data is transmitted over encrypted HTTPS connections. Application data and uploaded files are stored with infrastructure providers that use access controls and encryption at rest for hosted database and storage systems.

OAuth tokens, API keys, webhook secrets, database credentials, and environment secrets are stored server-side and are not exposed in the browser. Access to production systems is restricted to authorised OpsNote operators and service components that need that access to run, support, secure, or troubleshoot the service.

OpsNote applies account and workspace-based access controls so users can access only their own workspace data. Administrative access is limited and used for support, security, legal compliance, and service operation. OpsNote uses least-privilege configuration where practical, keeps production secrets outside the codebase, validates signed webhooks where supported, and reviews access when troubleshooting or maintaining the service.

No method of transmission or storage is completely secure, but OpsNote takes reasonable steps to protect data from unauthorised access, disclosure, alteration, or destruction. If a security issue affects personal data, OpsNote will investigate and take appropriate action in line with applicable legal requirements.

Retention, Deletion, And Your Choices

You can disconnect supported channels, update settings, delete leads, delete uploaded receipts or invoices, and manage billing from within OpsNote where those controls are available. Disconnecting a channel stops future sync for that connection, but previously synced lead and message records may remain in your workspace until you delete them or ask OpsNote to delete them.

We retain account and workspace data while your account is active or as needed to provide the service. Some records may be retained where required for legal, tax, accounting, payment, security, abuse-prevention, backup, or service-integrity reasons. Backup copies are removed through normal backup expiry processes.

You may contact OpsNote to request access, correction, export, or deletion of account data. We may need to verify your identity and your authority over the relevant workspace before completing a request.

Contact

For privacy, security, access, or deletion questions, contact OpsNote at hello@opsnote.co.uk.