OrderDream, Inc. ("OrderDream," "we," "us") provides dispatch software for field-service businesses. This policy explains what information we collect, how we use it, and the choices you have. It applies to orderdream.com, the OrderDream application at app.orderdream.com, and our APIs.
1. Information we collect
Account information. Name, email address, password (stored as a salted hash), role, phone number, and workspace details you provide when you sign up or are invited to a workspace.
Business data you bring into OrderDream. Customers, properties, work orders, estimates, invoices, schedules, notes, photos, and signatures your team creates or imports. This data belongs to your business — we process it only to run the service for you.
Email content from connected mailboxes. If you connect a Gmail account (or forward email to your intake address), we process incoming messages to draft work orders. See "Google user data" below for the specific commitments that apply.
Payment information. Subscription billing and online invoice payments are handled by Stripe. We never see or store full card numbers.
Usage and device data. Log data (IP address, browser, pages viewed, timestamps) used for security, rate limiting, and debugging. We do not run third-party advertising trackers.
2. Google user data
When you connect Gmail, OrderDream requests read access to your mailbox solely to detect and extract service requests. We use that access to: identify new incoming messages, extract the customer, property, issue, and scheduling details needed to draft a work order, and link related threads to existing jobs.
OrderDream's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In particular:
- We do not use Gmail data for advertising.
- We do not sell Gmail data.
- We do not use Gmail data to train generalized AI or machine-learning models.
- Humans do not read your email except with your explicit permission (for example, a support request), where required for security or legal compliance, or where the data has been aggregated and anonymized.
- Personally identifying details are redacted before message text is sent to our AI extraction provider.
You can disconnect Gmail at any time from Settings, which revokes our access and stops all mailbox processing.
3. How we use information
- To provide, maintain, and improve the service.
- To process email intake into draft work orders using automated extraction.
- To send transactional messages: invites, password resets, appointment and invoice notifications, and service alerts.
- To bill subscriptions and process invoice payments through Stripe.
- To secure the service: authentication, fraud and abuse prevention, rate limiting, and audit logging.
- To comply with legal obligations.
4. How we share information
We do not sell personal information. We share data only with service providers who process it on our behalf under contract:
- Amazon Web Services — hosting, file storage, and email delivery.
- Heroku (Salesforce) — application hosting.
- Stripe — subscription billing and invoice payments.
- Anthropic — AI extraction of work-order details from redacted email text.
- Google — Gmail integration you choose to connect.
- Twilio — SMS delivery, if your workspace enables texting.
- Sentry — error monitoring.
We may also disclose information if required by law, to protect our rights or the safety of others, or as part of a merger or acquisition (with notice to you).
Integrations you enable yourself — QuickBooks, Xero, Slack, Microsoft Teams, Zapier, or webhooks to your own systems — send data to those services at your direction and are governed by their terms.
5. Data retention and deletion
We retain your data for as long as your workspace is active. You can export all workspace data (CSV or JSON) from Settings at any time, and you can delete your workspace, which permanently removes your data from production systems within 30 days and from backups on their rotation schedule. Audit logs are retained for up to 13 months.
6. Security
All traffic is encrypted in transit (TLS). Sensitive fields — including Gmail refresh tokens, webhook secrets, and MFA secrets — are encrypted at rest with application-level encryption on top of encrypted storage. We support two-factor authentication (TOTP), role-based permissions, and full audit trails. No method of transmission or storage is 100% secure, but we work to protect your data with industry-standard safeguards.
7. Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal information, or to object to certain processing. Workspace admins can exercise export and deletion directly from Settings; for anything else, contact us and we will respond within 30 days.
8. Cookies
The application uses a single encrypted session cookie for login and a CSRF token for request security. The marketing site sets no cookies. We do not use third-party advertising or analytics cookies.
9. Children
OrderDream is a business tool and is not directed to children under 16. We do not knowingly collect personal information from children.
10. Changes to this policy
If we make material changes we will notify workspace admins by email and post the updated policy here with a new effective date.
11. Contact
Questions or requests: support@orderdream.com.