Privacy Policy
Effective September 5, 2026
Kumivaro is contractor business software provided by Lumatra Technology LLC ("Lumatra," "we," "us," or "our"). This policy explains how information is processed when you use the Kumivaro web, iPhone, iPad, or Android application.
Information we process
- Account and contact information: names, email addresses, phone numbers, account identifiers, company details, billing addresses, customer contact details, and job-site addresses.
- Business and user content: estimates, invoices, contracts, change orders, notes, signatures, calendar entries, timesheets, crew information, item libraries, and related documents.
- Financial and subscription records: invoice amounts, expenses, payment records and methods, outstanding balances, subscription plan, and purchase status. Payment card and bank credentials entered into Stripe, Apple, or Google payment interfaces are handled by those providers and are not stored by Kumivaro.
- Photos and environment scans: job photos, receipt images, uploaded plans, floor plans, room measurements, LiDAR or camera-derived room geometry, and related captions or metadata you choose to save.
- Location: when you select Use My Location, the device provides its current coordinates so Kumivaro can look up and fill a customer or job-site address. Kumivaro does not continuously track your location.
- Technical information: limited security, request, synchronization, and diagnostic information needed to operate, protect, and troubleshoot the service.
Camera, Face ID, and device permissions
Camera and LiDAR access is requested only when you use photo, scanning, or floor-plan features. Location access is requested only while you use an address-fill feature. Face ID or Touch ID is performed by your device; Kumivaro receives only whether authentication succeeded and does not receive or store your biometric template.
How information is used
We use information to create and secure accounts, synchronize business records across devices, provide estimates and other contractor workflows, generate and share documents, extract reviewable expense drafts from receipt images when requested, process subscriptions and invoice payments, provide integrations you request, prevent fraud or abuse, respond to support requests, and maintain the reliability of the service. We do not use Kumivaro data for cross-app advertising or tracking.
Service providers
We use Supabase for authentication, database, storage, and server functions; Stripe for web and invoice payments; Apple and Google for mobile distribution and in-app purchases; Netlify for web hosting; Amazon Web Services Textract for user-requested receipt text extraction; and OpenStreetMap Nominatim for user-requested address lookup. Optional services such as QuickBooks are used only when you connect them. These providers process information under their own terms and privacy practices to provide services to us or to you.
Location lookup
When you choose Use My Location, precise coordinates are sent to OpenStreetMap Nominatim to return a street address. Kumivaro saves the resulting address only if it becomes part of a customer or job record; it does not save a continuous route or background location history. You can deny location permission and type the address manually.
Sharing
We do not sell personal information. Information may be shared with the service providers listed above, authorized members of your organization, recipients to whom you intentionally send documents or secure links, payment and accounting providers you choose to use, and authorities when disclosure is legally required or necessary to protect rights and security.
Retention
Account and business data is generally retained while your account is active. Data is deleted when you complete the in-app account-deletion process, subject to limited retention needed for legal compliance, fraud prevention, dispute resolution, financial records, security logs, and time-limited backups. Secure shared-document links expire according to the period shown when the link is created.
Security and your choices
We use encrypted transport, account-based database authorization, private storage, and expiring or signed links where applicable. You can update business records, remove team members, export available backups, deny optional device permissions, disconnect optional integrations, or permanently delete your account from Settings.
Delete your Kumivaro account and data
In Kumivaro, open Settings → Account & Privacy → Permanently delete my account. This starts permanent deletion of the account and its associated cloud data. Organization owners also delete their organization and shared company data.
If you cannot sign in, request deletion from the email address registered to your account:
We may ask you to verify account ownership. Limited records may be retained only where required for legal, fraud-prevention, backup, security, or financial-record obligations.
Children and international processing
Kumivaro is business software and is not directed to children under 13. Information may be processed in the United States and other locations where our service providers operate.
Changes to this policy
We may update this policy as Kumivaro changes. We will post the revised policy with a new effective date and provide additional notice when required by law.
Contact
Privacy questions may be sent to Lumatra Technology LLC at mike@lumatra.io.