Legal

Privacy Policy

What we collect, what we deliberately do not, who else sees it, and how long we keep it. Written against what the software actually does, not against a template.

Effective 15 September 2026 · Version 1.1 (adds the Android app, error reports and account deletion) · Operated by Hanson & Bosley LLC, Omaha, Nebraska

01 · Scope

Who we are and what this covers

OnSight Payments (“OnSight”, “we”, “us”) is invoicing, estimating, scheduling and payment software for service businesses. It is operated by Hanson & Bosley LLC, whose principal place of business is 14216 Dayton Circle, Suite 8, Omaha, Nebraska 68137.

This policy applies to:

  • the merchant portal at portal.onsightpayments.com, and the same application served at my.onsightpayments.com and iso.onsightpayments.com;
  • the customer portal, the pay-by-link page and the estimate acceptance pages served from those hosts;
  • the OnSight iOS app for iPhone and iPad, which is a shell around the same portal;
  • the OnSight Payments Android app, distributed through Google Play, which is a shell around the same portal;
  • this website, onsightpayments.com;
  • the website capture snippet a business using OnSight may install on its own site — see section 10.

Together we call these the Services. Separate terms govern your use of them; this policy is only about information.

02 · The distinction everything rests on

Two different roles we play

Almost every question about OnSight and privacy turns on one distinction, so it comes before anything else.

  • Where we decide — our own account holders and visitors. When a business, a reseller or an ISO signs up for OnSight, we decide what to collect about that organisation and its staff, and why. The same is true of people who fill in a form on this website. For that information we are the controller, and this policy is the full account of what we do with it.
  • Where the business decides — the customer records it puts into OnSight. When a plumbing company loads its customer list, photographs a job, writes a note or takes a payment, the information is about that company’s customers. That company decides what goes in, who sees it and how long it stays. We hold and process it on their instructions. For that information we are the processor, and the business is the controller.

If you are a customer of a business that uses OnSight — you received an invoice, a text or a portal login from a landscaper, a shop or an accountant — that business is who holds your information. Ask them first to see, correct or delete it. If you ask us, we will pass the request to them and help them answer it; we will not change or delete their records on our own initiative unless the law requires it. Section 17 explains this further.

03 · Collection

Information we collect

This is a complete list of the categories of information the Services hold. Not every business uses every feature, so not every category applies to every account.

  • Account and staff information. Name, email address, phone number, the organisation you belong to, your role and permissions, your account status, and when you were last active. Passwords are held by our authentication provider as salted hashes; we never see or store your password in readable form. Where you enrol a second factor, we hold the authenticator or the mobile number used for it.
  • Business and organisation information. Business name, trade, branding and logo, settings, pricing programme, the reseller or ISO above it, and payment-gateway configuration. Gateway credentials are held encrypted and are never returned to a browser.
  • Customer and contact records. Entered by the business about its own customers: name, whether residential or commercial, company contact, email, phone and mobile, billing and service addresses, tags, notes, custom fields, communication preferences, lead source, merge history and import history.
  • Work records. Jobs, visits, estimates, projects, engagements, tickets and work orders; appointments and calendar events; checklists and inspection results; time entries recorded against a job, with start and end times and the pay and billing rates in force at the time; crews and crew membership; routes, and the sequence, drive time and arrival estimate for each stop; property records including addresses, facts, assets and a latitude and longitude derived from the address; vehicle records including VIN, make, model, plate and odometer readings.
  • Files, photographs and signatures. Photographs and PDFs uploaded to jobs, inspections, projects and customer records — including photographs taken with the device camera or chosen from the photo library — with the file name, size, type, caption, uploader and date. Where a customer approves work online or in a portal, we store the approval, the name of the person who gave it, what they approved, and where offered a signature image.
  • Financial and payment information. Invoices, estimates, line items, deposits, discounts, retainers, credits, statements and receipts; payment records including amount, date, method, channel, surcharge or dual-pricing amounts and the gateway’s own response; refunds, voids and dispute notes. Card and bank details are covered in full in section 6.
  • Communications. Emails sent through the Services — recipient address and name, subject, the document it related to, who sent it, and the delivery events the email provider reports back, which include delivered, opened, bounced and marked as spam. Text messages sent and received — the numbers, the message body, status and any error, including inbound replies such as STOP and HELP. Consent records for texting: the phone number, whether it is opted in or out, the exact wording agreed to, how consent was given, and when. A per-document history recording when an invoice or estimate was created, sent, viewed, reminded, paid, accepted or declined.
  • Security, audit and fraud records. We record administrative and security-relevant events. These may include the IP address and browser user-agent of the person acting, specifically in: the administrative audit log; online and portal approvals of work; and payment attempts, where the payer’s IP address is taken from the connection and stored on the charge as evidence in a dispute. IP addresses are also used transiently to rate-limit password resets. A separate activity log records ordinary changes to records. Businesses may configure fraud rules, which can include blocking particular IP addresses or email addresses.
  • Device information in the iOS app. The app asks for three permissions, each for one stated purpose: camera, to read a VIN from a vehicle; photo library, to attach photographs to inspections and appointments; and notifications. It also offers a Face ID or Touch ID app lock. Face ID and Touch ID data never reaches us and never leaves your device — iOS answers only yes or no, and the app stores nothing but your on/off preference. Any of these can be changed or revoked in iOS Settings.
  • Device information in the Android app. The app asks for each permission at the moment it is needed, for one stated purpose: camera and microphone, to take photographs and record video on a job; and, only where a business uses Tap to Pay on Android, NFC and precise location. NFC lets our payment partner’s certified reader read a contactless card at the moment of a tap; the card data goes from that reader to the processor and never reaches OnSight. Precise location is asked for once, when Tap to Pay is set up on a phone, because the card schemes require the reader to confirm where the device is before it can accept cards. We do not store or track that location, and it is never used for anything else. To link a merchant’s payment terminal ID to the right phone, the app sends us the device identifier Android assigns to the app. Any permission can be changed or revoked in Android Settings.
  • Error reports. When the portal or the apps hit an error, we record the error message, the page or screen it happened on, the time, and the browser or device type, so it can be fixed. Error reports do not include screen recordings, keystrokes or the contents of forms.
  • Copilot conversations. If your business uses the Copilot, we store the questions asked and the answers given, linked to your business and to you. See section 9.
  • Enquiries to us. If you contact us through this website or by email, we receive your business name, name, email, phone, reason for contact and message, and we keep the correspondence.

04 · The other half of the answer

What we do not collect

Stated plainly, because these are the things people most often assume software like this does.

  • We do not track the location of staff or vehicles. There is no GPS tracking in the portal or the apps. The only coordinates we hold are a latitude and longitude derived from a typed property address, for mapping and route planning. The one-time location check made when Tap to Pay is set up on an Android phone is described in section 3; it is not stored.
  • We do not collect Social Security numbers, dates of birth, driver’s licence numbers or taxpayer identification numbers. There are no fields for them.
  • We do not collect biometric data. Face ID and Touch ID are answered by the device; no face or fingerprint reaches us.
  • We do not store card numbers or full bank account numbers. See section 6.
  • We do not run advertising or analytics trackers. There is no analytics package, no advertising pixel, no session-replay tool and no third-party tracking cookie on the portal or on this website.
  • We do not sell personal data, or use it for targeted advertising or profiling. See section 12.

If any of this changes we will update this policy and give notice under section 21 before the change takes effect.

05 · Purposes

How we use information

  • To run the Services — creating and sending invoices and estimates, scheduling and dispatching work, recording time, taking payments, and showing customers what they owe.
  • To communicate — sending the documents, receipts, reminders and notices a business asks us to send on its behalf, and sending you service messages about your own account, such as password resets, invitations, sign-in verification and security notices.
  • To support you — answering questions, diagnosing faults, and, where permitted and logged, acting into an account to fix a problem.
  • To keep the Services secure and honest — authentication, access control, audit logging, fraud rules, rate limiting, and evidence for payment disputes.
  • To bill and account — for our own charges, reseller and ISO statements, and residual and volume reporting.
  • To improve the Services — using aggregated or de-identified information about how features are used. We do not use one business’s customer records to build features or models for anyone else.
  • To meet legal, tax, card-network and accounting obligations, and to establish or defend legal claims.
  • To market our own product to businesses and prospective businesses that have contacted us or hold an account. Every marketing email carries an unsubscribe link. We do not market to the customers of businesses that use OnSight.

06 · Payments

Card and bank payments

This section describes exactly what happens to a card number, because a general assurance would be less useful than the truth.

  • Cards entered online. When a card is keyed into a payment page in OnSight, the card number, expiry and security code are typed into a form on our page and posted directly from the browser to our payment processor’s tokenisation service. The processor returns a token. OnSight’s servers never receive, store or log the card number, the expiry or the security code. We describe this precisely because the card fields sit in our page rather than in an isolated frame belonging to the processor; under the PCI DSS that places OnSight at SAQ A-EP rather than SAQ A.
  • Cards taken on a terminal. Where a business uses a physical card terminal, the card is read by the terminal and goes from the terminal to the processor. The card number never passes through OnSight at all. We receive and store only the result.
  • What we store about a card. The processor’s token, which is meaningless outside that processor’s vault, together with the card brand, the last four digits, the expiry month and year, whether it is credit, debit or prepaid, and the billing name, street line and postal code given for address verification. The database itself refuses a value that looks like a card number where a token belongs.
  • Bank payments. For an ACH or cheque payment we store the name on the account, the nine-digit ABA routing number, and the last four digits of the account number. We do not store the full bank account number.
  • What the processor does with it. Card and bank details are processed by the payment processor and the card networks under their own terms and privacy policies, and by the merchant’s acquiring bank. Those parties are independent of us for that purpose. See section 11.

07 · Email

Email

Invoices, estimates, receipts, reminders, statements, portal invitations and staff invitations are delivered by our email providers, Resend and SendGrid. To send a message we pass them the recipient’s email address and name and the content of the message. They report back delivery events — delivered, opened, bounced, marked as spam — and we store those events against the message so a business can see whether what it sent arrived.

Open tracking means a business can see that a document was opened, and when. If you would rather not be tracked this way, most email clients let you block remote images.

Transactional email — an invoice you are being sent, a receipt for a payment you made, a password reset — is part of the service and carries no unsubscribe link, because switching it off would break the thing you asked for. Marketing email from us always does. Businesses using OnSight are responsible for their own compliance with the CAN-SPAM Act in what they send through it.

08 · Texting

Text messages

Text messaging is delivered by Twilio. To send a message we pass Twilio the recipient’s phone number and the message content.

  • Consent. OnSight will not send a text to a number that has not opted in, or that has opted out. Consent is recorded against the phone number — not the person — with the exact wording agreed to, how it was given (in the customer portal, by a staff member, by replying START, or carried in from a previous system), and when.
  • Message frequency. Message frequency varies; most recipients receive fewer than 10 messages per month.
  • Stopping. Replying STOP opts a number out immediately and permanently until it opts in again, whether or not we can match it to a customer record. Replying HELP returns contact information. Message and data rates may apply.
  • Mobile numbers and opt-in data are never shared. We do not sell, rent or share mobile phone numbers, text-message opt-in data or consent records with any third party or affiliate for marketing or promotional purposes, and we do not share them with lead generators. The only parties that receive them are the messaging providers who deliver the message on our behalf and subcontractors providing support services, and they may use them for nothing else.
  • Who is texting you. Texts sent through OnSight come from the business you deal with. The business decides what to send and is responsible for its own compliance with the Telephone Consumer Protection Act and carrier rules.

09 · Artificial intelligence

The Copilot and AI features

OnSight includes an assistant, the Copilot. When you ask it something, we send your question, the earlier turns of that conversation, and the results of the read-only queries it runs on your behalf to Anthropic, which provides the underlying model. Those results contain your business’s own data, which can include customer names, notes, and invoice and job details.

  • The Copilot runs as you. It can see only what your own permissions allow, and it cannot see another business’s data.
  • The Copilot is read-only. It cannot change or delete anything. When it works out an automation it proposes it, and a person presses the button.
  • We store the visible conversation — your questions and its answers. We do not store the intermediate query results.
  • Anthropic acts as our service provider for this feature and is not permitted to use the content for its own purposes.

10 · Websites

Website visitors and lead capture

On onsightpayments.com. This site carries no analytics, no advertising pixels and no tracking cookies. If you submit the contact form we receive your business name, name, email, phone, reason for contact and message, and email it to our sales address. Our hosting provider keeps standard server request logs, which include IP addresses, for security and operations.

On a business’s own website. A business using OnSight may install a capture snippet on its own site. Where it does, we record for that business: a first-party visitor identifier, the pages viewed and their titles, the time, the referring URL, the landing page, and any campaign parameters in the address. If the visitor submits an enquiry form we also record the name, email, phone and message they typed, and link it to that visitor.

Two things are worth being explicit about. First, this capture does not record IP addresses or browser user-agents. Second, the identifier is first-party and per-business: it does not follow a visitor across other businesses’ sites, and there is no cross-site advertising profile. The business whose site it is, is the controller of that information — its own privacy policy governs it, and requests about it go to that business.

11 · Disclosure

Service providers we share information with

We share information only with the providers needed to run the Services, and only to the extent each one needs. This is the complete list. All of them process the information in the United States.

  • Supabase — database, authentication, file storage and server functions. Receives all information held in the Services.
  • Vercel — hosting for the application and this website. Receives requests to the sites, and keeps server logs including IP addresses.
  • Dejavoo and iPOSpays — payment gateway and card vault, card-present and card-not-present. Receive card and payment details, amounts, the payer’s IP address and billing address.
  • Twilio — text messaging, inbound and outbound. Receives phone numbers and message content.
  • Resend and SendGrid — email delivery. Receive recipient name and address, and message content.
  • Anthropic — the model behind the Copilot. Receives Copilot questions, conversation history and query results.
  • Google Maps Platform — address autocomplete, geocoding and route optimisation. Receives address text and coordinates, not names or account details.
  • NHTSA vPIC — decoding a VIN into make, model and year. Receives the VIN only.
  • Apple — app distribution, and opening an address in Maps. App Store and device data under Apple’s own terms; an address when a map is opened.
  • Google — Android app distribution through Google Play. Google Play and device data under Google’s own terms.
  • Sentry — error monitoring. Receives the error reports described in section 3.

We also share information within the OnSight hierarchy as the product is designed to work: a reseller or ISO that boards a business can see that business’s account, volume and statement information, and can act into the account. Every such act is written to the audit log, and recorded as external rather than as the business’s own staff.

12 · Sale

We do not sell your information

We do not sell personal data, as “sale” is defined under the Nebraska Data Privacy Act or any comparable state law. We do not share personal data for cross-context behavioural or targeted advertising. We do not carry out profiling that produces legal or similarly significant effects about anyone. We do not disclose personal data to data brokers or lead generators.

Because there is no targeted advertising and no sale, there is nothing for a universal opt-out signal such as Global Privacy Control to switch off. We will honour such a signal if that ever changes.

13 · Other disclosures

Other disclosures we may make

  • At your direction — including sending a document to a recipient you name.
  • To professional advisers — our accountants, auditors, insurers and lawyers, under a duty of confidence.
  • To comply with the law — in response to a subpoena, court order or other lawful request. Where we are permitted to tell you, and it is not futile, we will.
  • To protect people — where we believe in good faith it is necessary to prevent fraud, physical harm or a crime, or to enforce our terms.
  • In a business transfer — if OnSight or its assets are acquired, merged or go through insolvency, information may transfer to the successor, which will remain bound by this policy or give notice before changing it.

14 · Cookies

Cookies and similar technologies

The portal does not set tracking cookies. It keeps your sign-in session in your browser’s local storage, which is what keeps you signed in, and it remembers a small number of interface preferences on your device. Signing out clears the session. Blocking site storage will prevent sign-in from working.

There are no advertising cookies, no third-party analytics and no cross-site tracking on any OnSight property. That is why we show no cookie consent banner: there is nothing to consent to.

15 · Retention

How long we keep things

Where the software enforces a specific period, it is stated here rather than described vaguely.

  • Uploaded project files — three years after the project is completed. The file itself is then deleted. The record of its name, size, uploader and date is kept, so the history does not appear to have gaps.
  • Activity log, recording ordinary changes to records — one year, then purged.
  • Administrative audit log, recording boarding, credentials and acting into an account — kept indefinitely as a security record.
  • Text-message consent records — kept indefinitely, as the evidence that consent existed, or that a STOP was honoured.
  • Invoices, payments and receipts — for as long as the account is open, then as required for tax, accounting, card-network and dispute purposes, after which they are deleted or de-identified.
  • Everything else in an account — for as long as the business keeps its account open, subject to the deletions it makes.

When a business closes its OnSight account we will delete or de-identify its data within 30 days, except where we are required to keep it by law, or need it to resolve a dispute or complete a financial obligation. Backups roll off on their own schedule and are not selectively edited; deleted data may persist in a backup for up to 90 days.

16 · Security

Security

We maintain administrative, technical and physical safeguards appropriate to the information we hold. In particular:

  • Traffic is encrypted in transit with TLS, and data is encrypted at rest by our infrastructure provider.
  • Every table in the database enforces row-level security, so one business cannot read another’s records. This is enforced by the database itself rather than by application code, and it applies to the Copilot as it does to a person.
  • Gateway credentials and other secrets are held encrypted and are never sent to a browser.
  • Card numbers are never stored, and the database rejects a value that looks like one where a token is expected.
  • Administrative actions, including acting into a business’s account, are logged and cannot be suppressed.
  • Access is granted by role and reviewed, and staff access is limited to what the role requires.
  • Accounts may enrol a second factor — an authenticator app or a mobile number — and the requirement is enforced in the database rather than only on screen.

No system is perfectly secure, and we cannot guarantee that information will never be accessed improperly. Keeping your password confidential, and turning on the app lock on a shared device, are the parts that are yours.

17 · Rights

Your privacy rights

Nebraska residents. Under the Nebraska Data Privacy Act, a Nebraska resident acting in an individual or household context has the right to: confirm whether we process their personal data and obtain a copy of it; correct inaccuracies; delete it; obtain a portable copy where processing is automated; and opt out of targeted advertising, the sale of personal data, and profiling with legal or similarly significant effects. As section 12 says, we do none of those last three.

To exercise a right, write to support@onsightpayments.com. We will respond within 45 days, and may extend once by a further 45 days where reasonably necessary, telling you why before the first period ends. We may need to verify your identity, and we may decline a request that is manifestly unfounded, excessive or repetitive.

If we refuse. You may appeal, free of charge, by replying to our decision and saying you are appealing. We will decide the appeal and write to you with the reasons within 60 days. If we deny the appeal we will give you a way to submit a complaint to the Nebraska Attorney General.

Residents of other states. We extend the same process to residents of every other US state, whether or not that state’s law requires it. Where your state grants a right this policy does not describe, tell us and we will honour it if it applies.

If your information is held by a business that uses OnSight, that business decides. Send your request to them. If you send it to us we will identify the business, pass the request on and assist them in answering it, but we will not decide it ourselves.

Communication choices, whoever holds the data:

  • Texts — reply STOP to any message. This works immediately and needs no account.
  • Marketing email from us — use the unsubscribe link.
  • Reminders and notices from a business — ask the business, or use the preferences on your customer portal where it offers them.
  • iOS permissions — camera, photos and notifications can be changed or revoked in iOS Settings.
  • Android permissions — camera, microphone, NFC and location can be changed or revoked in Android Settings.

Deleting an account. How to ask for your OnSight login, or a whole business account, to be deleted — and what is deleted and what the law makes us keep — is set out on Delete your account.

18 · Breach

Data breach notification

If we become aware of a breach of the security of the system involving personal information about a Nebraska resident, we will conduct a prompt, good-faith and reasonable investigation to establish whether the information has been or is reasonably likely to be used for an unauthorised purpose. If it has been or is likely to be, we will notify the affected residents as soon as possible and without unreasonable delay, consistent with the needs of law enforcement and with restoring the integrity of the system, and we will notify the Nebraska Attorney General no later than the time we notify residents. Where a breach affects information we hold for a business, we will notify that business without unreasonable delay so it can meet its own obligations. We apply equivalent notification standards to residents of other states under their laws.

19 · Children

Children

The Services are business software and are not directed to children. We do not knowingly collect personal information from anyone under 13, and there are no accounts for minors. If we learn we have collected information from a child under 13 we will delete it. If you believe a child has provided us information, contact support@onsightpayments.com.

20 · Location

Where information is held

OnSight’s database, file storage and server functions run in the United States, in our infrastructure provider’s US-East region. The providers in section 11 are US-based for the purposes described. We do not intend the Services for use outside the United States, and this policy does not describe rights under the GDPR or other non-US regimes.

21 · Changes

Changes to this policy

We will update this policy when what we do changes. The effective date at the top always tells you which version is current. For a change that materially affects how we handle personal information we will give notice in the portal or by email at least 30 days before it takes effect. Prior versions are available on request.

22 · Contact

How to contact us

For anything in this policy, including a request under section 17:

If you are unhappy with how we have handled a privacy request, you may complain to the Nebraska Attorney General’s office.

See also our Terms & Conditions.