Rheo

Rheo CRM — Privacy Policy

Effective April 8, 2026

RHEO CRM — PRIVACY POLICY
Effective Date: April 8, 2026

ProFusion Solar LLC, a New York limited liability company doing business as Rheo CRM ("Company", "we", "us", or "our"), is committed to protecting your privacy. This Privacy Policy describes how we collect, use, disclose, and safeguard your information when you use the Rheo CRM platform ("Service").

By accessing or using the Service, you agree to the collection and use of information in accordance with this Privacy Policy.


SECTION 1 — INFORMATION WE COLLECT

1.1 Account Information
When you create an account, we collect personal information including your name, email address, phone number, and organizational affiliation.

1.2 Organization Data
We collect information about your organization, including company name, address, service areas, service types, team members, and subscription plan details.

1.3 Appointment and Scheduling Data
We collect data related to appointments you create, manage, or are assigned to, including scheduling times, service types, lead information, appointment notes, checklists, and attachments.

1.4 Lead and Customer Data
We collect information about leads and customers that you enter into the Service, including names, contact information, addresses, service interests, pipeline stages, notes, and communication records.

1.5 Google Calendar Data
With your explicit consent, we access your Google Calendar data in read-only mode to display your calendar availability and existing events for scheduling purposes. We do not modify, delete, or write to your Google Calendar.

1.6 Usage Data
We automatically collect certain information when you access the Service, including your IP address, browser type, pages visited, and timestamps.

1.7 Communication Data
We collect records of communications sent through the Service, including emails, SMS messages, and in-app chat messages.


SECTION 2 — HOW WE USE YOUR INFORMATION

2.1 We use the information we collect to:
(a) Provide, operate, and maintain the Rheo CRM Service;
(b) Manage appointments, scheduling, and lead tracking;
(c) Sync and display calendar data for scheduling coordination;
(d) Send transactional emails including appointment notifications, account invitations, and system alerts;
(e) Process payments and manage subscriptions;
(f) Improve, personalize, and expand the Service;
(g) Communicate with you about updates, security alerts, and support;
(h) Enforce our terms, conditions, and policies;
(i) Comply with legal obligations.


SECTION 3 — GOOGLE API SERVICES USER DATA POLICY

3.1 Rheo CRM's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

3.2 Specifically, we:
(a) Only access Google Calendar data that is necessary to provide scheduling functionality within the Service;
(b) Do not use Google user data for serving advertisements;
(c) Do not allow humans to read Google user data unless we have your affirmative agreement, it is necessary for security purposes, it is necessary to comply with applicable law, or our use is limited to internal operations and the data has been aggregated and anonymized;
(d) Do not transfer Google user data to third parties except as necessary to provide or improve the Service, as required by law, or in connection with a merger, acquisition, or asset sale with notice to users.


SECTION 4 — DATA SHARING

4.1 We Do Not Sell Personal Data
We do not sell, rent, or trade your personal information to third parties for marketing purposes.

4.2 Sharing Within the Platform
We share appointment and lead data between the platform operator (ProFusion Solar LLC) and the assigned installer organization as necessary to facilitate the services provided through the platform. This sharing is limited to the data required for appointment coordination and service delivery.

4.3 Third-Party Service Providers
We use the following third-party services to operate the Service:
(a) Supabase — database hosting, authentication, and backend infrastructure;
(b) Resend — transactional email delivery;
(c) Google Calendar API — calendar integration and scheduling;
(d) Stripe — payment processing and subscription management.

These providers only have access to your information as necessary to perform their functions and are obligated to maintain the confidentiality and security of your data.

4.4 Legal Requirements
We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., a court order or government agency).


SECTION 5 — DATA STORAGE AND SECURITY

5.1 Your data is stored on Supabase infrastructure with industry-standard security measures.

5.2 All data is encrypted in transit using TLS (Transport Layer Security) and encrypted at rest.

5.3 Access to your data is controlled by role-based permissions. Users can only access data appropriate to their assigned role (Super Admin, Org Admin, Org User, or Homeowner).

5.4 We implement reasonable administrative, physical, and technical safeguards to protect your information against unauthorized access, disclosure, alteration, or destruction.

5.5 While we strive to protect your personal information, no method of transmission over the Internet or electronic storage is 100% secure, and we cannot guarantee absolute security.


SECTION 6 — DATA RETENTION

6.1 We retain your personal data for as long as your account is active or as needed to provide you with the Service.

6.2 Upon account termination, we will retain your data for a reasonable period to comply with legal obligations, resolve disputes, and enforce our agreements.

6.3 You may request deletion of your data at any time by contacting us at the email address provided below. We will process deletion requests within thirty (30) days, subject to any legal retention requirements.


SECTION 7 — YOUR RIGHTS

7.1 You have the right to:
(a) Access — Request a copy of the personal data we hold about you;
(b) Correction — Request that we correct any inaccurate or incomplete personal data;
(c) Deletion — Request that we delete your personal data, subject to legal retention requirements;
(d) Portability — Request your data in a commonly used, machine-readable format;
(e) Objection — Object to the processing of your personal data in certain circumstances.

7.2 To exercise any of these rights, please contact us at ibrahim@profusion.solutions. We will respond to your request within thirty (30) days.


SECTION 8 — GOOGLE CALENDAR DATA

8.1 When you connect your Google Calendar account to Rheo CRM, we access your calendar data in read-only mode to:
(a) Display your existing calendar events alongside Rheo appointments for scheduling coordination;
(b) Show your availability to help with appointment booking;
(c) Prevent scheduling conflicts with your existing commitments.

8.2 We do not modify, delete, or create events on your Google Calendar through the read-only access.

8.3 We do not share your Google Calendar data with third parties.

8.4 You can disconnect your Google Calendar integration at any time from the Settings page within the Service. Upon disconnection, we will cease accessing your Google Calendar data and remove any cached calendar data from our systems.


SECTION 9 — COOKIES

9.1 We use minimal cookies strictly for authentication session management purposes.

9.2 These cookies are essential for the operation of the Service and are used to maintain your login session and verify your identity.

9.3 We do not use tracking cookies, advertising cookies, or any third-party analytics cookies.


SECTION 10 — CHILDREN'S PRIVACY

10.1 The Service is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children under 18.

10.2 If we become aware that we have collected personal information from a child under 18, we will take steps to delete such information promptly.


SECTION 11 — CHANGES TO THIS POLICY

11.1 We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons.

11.2 We will notify you of any material changes by posting the updated Privacy Policy on the Service and updating the "Effective Date" at the top of this page.

11.3 Your continued use of the Service after any changes to this Privacy Policy constitutes your acceptance of the updated policy.


SECTION 12 — CONTACT US

12.1 If you have any questions about this Privacy Policy, your personal data, or our privacy practices, please contact us at:

ProFusion Solar LLC
d/b/a Rheo CRM
Email: ibrahim@profusion.solutions