Privacy Policy

Effective date: August 20, 2026

This Privacy Policy describes how Vantis processes information through the Vantis public website and Vantis application and service.

1. Scope

This policy applies to information processed through the Vantis public website, application, and service. In this policy, “Vantis” refers to that website, application, and service.

2. Information Vantis processes

Depending on the features an organization uses, Vantis processes the following source-supported categories of information:

The public Vantis page in this candidate does not add third-party analytics, advertising, or tracking scripts, and it does not use browser local storage or session storage. Submitting the signup form necessarily sends the signup request to the Vantis API.

3. How Vantis uses information

Vantis uses information to provide the application functions an organization or authorized user requests, including account and session operation, tenant/business workflows, customer and work-order operations, scheduling, time and payroll-related workflows, inventory, billing and invoicing, configured outbound communications, and service/security administration. Vantis also persists configuration and operational records required for those functions.

4. Connected email providers

An authorized Vantis administrator can configure a tenant-selected outbound email provider. Vantis handles reusable provider credentials server-side and does not return stored provider passwords, OAuth refresh tokens, client secrets, or access tokens to the Vantis client interface.

Google / Gmail

When an authorized administrator connects Google, Vantis requests openid, email, profile, and https://www.googleapis.com/auth/gmail.send.

Google user data sharing and disclosure

Vantis does not sell Google user data. Vantis does not transfer or disclose Google user data to advertising platforms, data brokers, information resellers, or other third parties for advertising, marketing, creditworthiness, lending, or unrelated purposes. Vantis uses Google user data only to provide the connected-Google features described above. When an authorized Vantis user or workflow causes Vantis to send email, Vantis transmits the recipient and message content needed for that requested delivery to Google through the Gmail API. Vantis does not request or obtain Gmail mailbox-read data for this integration.

Protection of Google user data

Vantis protects Google-related credentials and connected-account information using tenant-scoped access controls, role and authorization checks, and server-side credential handling. OAuth refresh tokens are encrypted before persistence and handled server-side. Stored OAuth refresh tokens, access tokens, and OAuth client secrets are not returned to the Vantis client interface. Production authenticated sessions use HttpOnly cookies with strict same-site handling and secure cookies. These controls are designed to protect confidentiality and reduce unauthorized access.

Retention and deletion of Google user data

Vantis retains the connected Google account ID, email address, optional display name, connection timestamp, and encrypted OAuth refresh token while the Google connection remains configured and those data are needed to provide the requested outbound-email functionality. When an authorized administrator disconnects Google, Vantis clears the locally stored OAuth refresh token and connected Google identity fields from tenant Email Settings. Vantis does not retain Gmail mailbox-read data because this integration does not request Gmail read scopes. A user or organization may request deletion of Google-related data held by Vantis by contacting support@vantisops.com. Disconnecting Google does not automatically delete unrelated Vantis business, invoice, audit, or operational records created independently of the Google connection.

Google Workspace Limited Use. Vantis's use and transfer of information received from Google Workspace APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Vantis does not use information received from Google Workspace APIs to develop, improve, or train generalized or non-personalized artificial intelligence or machine learning models.

Microsoft / Outlook

When an authorized administrator connects Microsoft, Vantis requests openid, profile, email, offline_access, User.Read, and Mail.Send.

Yahoo Mail

Vantis's governed Yahoo integration uses SMTP with a Yahoo app password; it is not a Yahoo OAuth integration.

Custom SMTP

For Custom SMTP, an authorized administrator supplies the SMTP host, port, username, password, sender address and name, with an optional reply-to address supported by Email Settings.

5. Connected-service transmission

When an organization asks Vantis to send email through a configured provider, Vantis necessarily transmits the outbound addressing and message content needed for delivery to that selected provider or SMTP service. Google, Microsoft, Yahoo, and customer-selected SMTP services are separate services and may process delivered information under their own terms and privacy practices. This does not remove Vantis's responsibility for the Vantis-side handling described in this policy.

6. Security

Source-evidenced Vantis controls include tenant-scoped data access, role and authorization checks, server-side handling of provider credentials, encryption of reusable OAuth refresh tokens and SMTP passwords before persistence, password hashing, and authenticated-session controls that use HttpOnly cookies with strict same-site handling and secure cookies in production. Provider credentials are not exposed back to the client interface after configuration. These controls are intended to reduce risk, but no system can guarantee absolute security.

7. Data management, provider disconnect, and deletion help

Authorized administrators can manage Email Settings and disconnect the configured provider. Provider disconnect removes the local reusable connection credential and the specific connection fields described above; it is not a universal deletion operation for Vantis records created independently of that provider connection.

Vantis does not currently represent that the service has one universal self-service control that deletes every category of organization or user data. For help managing or requesting deletion of data held in Vantis, contact support@vantisops.com. No fixed deletion timetable or outcome is promised by this policy where the current product does not enforce one universal lifecycle.

8. Retention

Vantis retains records according to the operation of the service and the account, session, provider-connection, and record lifecycle controls implemented for the relevant feature. For Google connection data specifically, the retention and deletion behavior is described in Section 4: the connected-account identity and encrypted OAuth refresh token are retained while the Google connection remains configured and are cleared from tenant Email Settings when an authorized administrator disconnects Google. Vantis does not represent a single universal retention period for unrelated business records where the current product does not enforce one.

9. External services

Use of a connected Google, Microsoft, Yahoo, or other SMTP service is also subject to that provider's own terms, privacy practices, availability, and account controls. Organizations should review the practices of services they choose to connect.

10. Contact

For Vantis support, privacy questions, or data-management requests, email support@vantisops.com.

11. Changes to this policy

Vantis may update this Privacy Policy as the service or its data practices change. The effective date shown at the top of this page identifies the version presented here.