FlagHawk App – Privacy Policy
ZavSoft LLC (“ZavSoft,” “we,” “us,” “our”) respects your privacy. This policy explains how we collect, use, and disclose personal information in the FlagHawk application (the “App“) — including the iPhone, Android, and web versions — and describes your rights under the California Consumer Privacy Act as amended by the California Privacy Rights Act (together, the “CPRA“).
This policy covers the App only. For the public marketing website, see the Website Privacy Policy.
Notice at Collection
| Category | Examples collected | Purpose | Retention | Sold / shared? |
|---|---|---|---|---|
| Identifiers | Email (app-store account or optional sign-in); anonymous account ID | Create account; restore purchases; support; link crash reports to your account without using your email | Account lifetime + 3 years | No |
| Professional info | Repair-order (RO) #, hours flagged, job descriptions | Generate technician productivity data | Until you delete the entry or close account | No |
| Photos (user-generated) | Images you attach to an RO | Document work performed; QA audits | Until you delete the photo or close account | No |
| Scan RO images | Photo of a repair order you capture when using the Scan Repair Order feature | Transmitted to Anthropic for AI text extraction; only the extracted fields are saved | Not stored by FlagHawk. Anthropic may retain the image up to 30 days for abuse monitoring, then deletes it. | No |
| Internet / network activity | Analytics events (PostHog); crash and performance diagnostics (Sentry) | Debugging; product improvement; app stability | 12 months | No |
| Sensitive PI | None collected | — | — | N/A |
We do not sell personal information or share it for cross-context behavioral advertising. We do not use your data to train any AI or machine learning model, and our third-party AI provider does not train on your data either.
1. Information We Collect
- Data you enter (RO #, hours, job descriptions, photos);
- Images you capture with the Scan Repair Order feature (processed by a third-party AI service — see Section 3);
- Analytics events from PostHog (anonymized account ID and usage events only — no email and no IP-based location enrichment);
- Crash reports, error diagnostics, and limited performance data via Sentry (device/app version, stack traces, and anonymized account ID — not your email).
2. How We Use Personal Information
- Provide core App functions and cloud backup (Supabase, U.S.);
- Extract structured repair-order data from scanned images using AI (Anthropic);
- Analyze aggregate usage to improve features (PostHog);
- Diagnose crashes and improve App stability (Sentry);
- Respond to support emails;
- Comply with legal obligations.
3. AI Features & Third-Party Service Providers
FlagHawk relies on a small number of carefully chosen third-party service providers. All data is processed in the United States.
Supabase (cloud backup & storage)
Supabase stores your account, repair-order records, and any photos you attach to an RO. Data in transit is encrypted with TLS 1.2+. Data at rest is encrypted with AES-256.
PostHog (product analytics)
PostHog collects anonymized usage events (for example screen views and feature taps) to help us improve the App. We identify events with an anonymized account ID only. We do not send your email address or other personally identifying content to PostHog, and we disable IP-based geo-location enrichment for PostHog events.
Sentry (crash reporting & diagnostics)
Sentry receives crash reports, error diagnostics, and limited performance data so we can fix bugs and keep the App stable. Reports may include device and App version information, technical stack traces, and your anonymized account ID. We configure Sentry not to send default personally identifying information (including email). See Sentry’s Privacy Policy.
Anthropic (AI processing for Scan Repair Order)
When you use the Scan Repair Order feature, the image you capture is transmitted over a secure (TLS) connection to Anthropic’s Claude API to extract structured data — the RO number, date, and job lines (description, hours, labor type). Key facts about this processing:
- We do not store the image. The image exists only in-memory during the API call and is discarded immediately after extraction completes.
- Only the extracted fields are saved to your FlagHawk account — not the image itself and not any customer-identifying information visible on the RO.
- Anthropic does not use your data to train its models.
- Anthropic retention: Anthropic may retain the request for up to 30 days for trust and safety purposes, after which it is deleted. See Anthropic’s Privacy Policy.
- AI results may be imperfect. You review and confirm all extracted data on a confirmation screen before it is saved. The App also shows a one-time disclosure before you first use Scan Repair Order.
4. Photographs of Repair Orders & Customer Information
Repair-order images may incidentally contain information about the dealership’s customers (names, addresses, phone numbers, VINs). By using the Scan Repair Order feature, you confirm that:
- You have the authority to capture and submit the image in the course of your work; and
- You are complying with your employer’s data-handling policies and any applicable law (including, where relevant, the Gramm-Leach-Bliley Act).
FlagHawk extracts only non-identifying repair-order metadata (RO #, date, and job information). Customer names, addresses, phone numbers, and VINs are never saved to your FlagHawk account.
5. Your CPRA Rights & Account Deletion
You may know, delete, correct, port, or opt out (sale/share — none) by emailing help@zavsoft.com. We verify identity via your account email.
You can also delete your FlagHawk account yourself in the App: open Settings → My Account → Delete Account. This works on iPhone, Android, and the FlagHawk web app. Deleting your account permanently removes your repair orders, jobs, photos, and account data from FlagHawk. It does not cancel an App Store or Google Play subscription — cancel that separately in your store account if you no longer want to be billed. More detail is on our Delete Account page.
6. Data Security
Data in transit: TLS 1.2+. Data at rest: AES-256 (Supabase). Scan RO images are transmitted over TLS and are not stored at rest on FlagHawk servers.
7. Children
The App is for U.S. users 18+. We do not knowingly collect data from minors.
8. Changes
We will notify users of material changes in-app; changes take effect upon publication unless otherwise specified.
9. Contact
Email help@zavsoft.com
or write to:
ZavSoft LLC
1175 Avocado Ave
Ste 101 #A38
El Cajon, CA 92020