Current system status
The website is currently a local/LAN deployment. Public hosting, production customer login, payment providers, and third-party integrations should be enabled only after HTTPS and access control are complete.
Information collected
- Name, phone, email, service address area, preferred contact method, and scheduling notes.
- Issue summaries, device names, network details, smart-home goals, robot/lawn details, and hardware requirements.
- Uploaded service photos, yard photos, work order notes, customer-visible service logs, and invoice-prep records.
- Helpdesk chat messages and form submissions used for triage and follow-up.
How information is used
Information is used to triage requests, recommend service paths, prepare quotes, schedule work, document completed service, create invoices, and maintain customer history.
Where information is stored
Current operational records are stored on the Tri-Lutions local server and, where configured, in the preserved legacy CRM adapter. Taveryna Business is the target internal record authority. Uploaded photos are stored under the local project storage unless a future cloud storage workflow is enabled.
Diagnostics and retention
Anonymous page diagnostics are opt-in. If you allow them, the local preview may store the page path, page title, referrer origin, viewport, theme, anonymized IP prefix, and browser user-agent; form contents are not included. The durable intake store keeps requests for 730 days by default, audit records for 2,555 days, consent records for 2,555 days, and photo attachments for 730 days. These defaults are configurable and must be confirmed during legal and retention review.
Third-party services
Taveryna, Stripe, PayPal, Cloudflare, Amazon Associates, email providers, or AI tools may be used when configured. Those services have their own privacy and security terms. Payment details should be entered only through approved Taveryna/provider-hosted checkout pages, not into this Flask website.
Sensitive information
Customers should not submit passwords, card numbers, bank details, social security numbers, or unrelated private records through public forms or chat. Temporary credentials should be shared only through an agreed support process and changed after service.