Privacy policy.

What information is collected, why it is used, and how the local service system should handle customer records.

Current system status

The website is currently a local/LAN deployment. Public hosting, production customer login, payment providers, and third-party integrations should be enabled only after HTTPS and access control are complete.

Information collected

How information is used

Information is used to triage requests, recommend service paths, prepare quotes, schedule work, document completed service, create invoices, and maintain customer history.

Where information is stored

Current operational records are stored on the Tri-Lutions local server and, where configured, in the preserved legacy CRM adapter. Taveryna Business is the target internal record authority. Uploaded photos are stored under the local project storage unless a future cloud storage workflow is enabled.

Diagnostics and retention

Anonymous page diagnostics are opt-in. If you allow them, the local preview may store the page path, page title, referrer origin, viewport, theme, anonymized IP prefix, and browser user-agent; form contents are not included. The durable intake store keeps requests for 730 days by default, audit records for 2,555 days, consent records for 2,555 days, and photo attachments for 730 days. These defaults are configurable and must be confirmed during legal and retention review.

Third-party services

Taveryna, Stripe, PayPal, Cloudflare, Amazon Associates, email providers, or AI tools may be used when configured. Those services have their own privacy and security terms. Payment details should be entered only through approved Taveryna/provider-hosted checkout pages, not into this Flask website.

Sensitive information

Customers should not submit passwords, card numbers, bank details, social security numbers, or unrelated private records through public forms or chat. Temporary credentials should be shared only through an agreed support process and changed after service.