1. Scope
This Privacy Notice applies to Control Axis Systems websites, account and onboarding services, and the Control Axis CRM, Estimator, Scan, Finance, Customer Portal, billing, support, and integration features (collectively, the “Services”).
Control Axis is a multi-tenant platform. Each subscribed company operates a separate company workspace. A subscribing company decides which employees, customers, records, files, and connected business accounts are placed in its workspace and is responsible for its own notices, permissions, and lawful use of that information. This notice describes Control Axis Systems’ handling of information as the platform provider.
2. Information we collect
Website, sales, and support information
We collect information you provide when you request a trial or demonstration, contact us, begin onboarding, or ask for support. This may include your name, company name, business email, phone number, requested products, workspace name, project details, and communications with us.
Account and workspace information
When a Control Axis account or workspace is created, we may collect account identifiers, name, email address, company and role information, password-derived authentication records, verification and recovery status, multifactor-authentication configuration, session and security records, invitations, product entitlements, and administrative activity. We do not ask users to send us passwords, recovery codes, bank credentials, API secrets, or full payment-card information through email or support messages.
Tenant business information
Depending on the products and features a tenant uses, the Services may process:
- customer and prospect contact details, addresses, notes, communications, service history, portal accounts, and consent or preference records;
- estimates, price books, measurements, proposals, approvals, jobs, schedules, invoices, payments, and service-catalog records;
- employee accounts, roles, assignments, time or work records, and operational permissions;
- inventory, equipment, purchase orders, QR records, scans, images, documents, and field activity;
- operational finance information such as receivables, purchases, account and transaction feeds authorized by the tenant, forecasts, reports, and exports; and
- configuration, audit, error, device, browser, IP-address, session, integration, and security-event information used to operate and protect the Services.
Billing information
Control Axis subscription checkout and billing may be processed through Square. Square receives the payment-card information entered in its checkout experience. Control Axis receives limited subscription and transaction information needed to administer access, such as the selected plan, billing status, payment or customer identifiers, amount, date, and receipt or failure information. Control Axis does not intend to store full payment-card numbers or card verification codes in its application records.
Information from connected services
A tenant administrator may choose to connect third-party business services such as Google Workspace, Microsoft 365, Square, Plaid, Twilio, Gusto, email, calendars, or document providers. We receive the account identity, authorization credentials, and business data permitted by the administrator and the provider’s authorization screen. The information available depends on the provider, permissions granted, features enabled, and actions taken by authorized users.
3. How we use information
We use information to:
- provide, configure, authenticate, support, and maintain the Services;
- create and administer accounts, company workspaces, trials, subscriptions, entitlements, and billing records;
- perform tenant-requested workflows, such as customer management, estimating, scheduling, communications, document access, inventory activity, payments, and reporting;
- connect and operate integrations selected by an authorized tenant administrator;
- send service, security, account, billing, support, and onboarding communications;
- monitor reliability, diagnose errors, prevent abuse, protect accounts, investigate incidents, and maintain audit records;
- improve product usability, workflows, and support based on service activity and feedback; and
- comply with applicable legal process and enforce our agreements and acceptable-use requirements.
We do not sell tenant business data or Google user data, and we do not use Google user data for advertising.
4. Tenant data and customer information
Tenant business information remains associated with the tenant workspace in which it was entered or connected. Authorized tenant administrators control employee access, customer-portal access, service visibility, and connected business accounts. Employees and customers receive access only through the workspace and product surfaces made available to them.
When an individual’s information was entered by a Control Axis tenant—for example, by that individual’s service provider or employer—the tenant is normally the best first contact for access, correction, or deletion requests. We may refer a request to the tenant or assist the tenant in responding, subject to account security, contractual obligations, recordkeeping needs, and applicable law.
Tenants should not use the Services to store passwords, bank-login credentials, API secrets, recovery codes, full payment-card information, or information that the applicable product and agreement do not support.
5. Google services and OAuth
Control Axis offers two separate Google authorization experiences:
- Google sign-in: requests basic identity information—such as email address, name, and profile information—to authenticate an existing authorized Control Axis user and match that user to the correct account.
- Tenant Google Workspace connection: an authorized tenant administrator may connect a company-controlled Google account to enable selected CRM workflows.
When a tenant administrator authorizes the Google Workspace connection, Control Axis may request access for the following purposes:
| Google service or data | How Control Axis uses it |
|---|---|
| Google account identity | Display and verify the connected business account and associate the authorization with the tenant workspace. |
| Gmail read access | Display authorized mailbox messages and message details inside CRM when an authorized user opens the connected inbox. |
| Gmail send access | Send tenant-directed business messages from the authorized Google mailbox. |
| Google Calendar | Read, create, and update calendar events used for tenant scheduling and job workflows. |
| Google Sheets | Read or update spreadsheets selected or configured by the tenant for supported CRM records and workflows. |
| Google Drive and Docs | Locate and read tenant-authorized files or documents needed for supported document workflows. |
| Google Forms | Read authorized form structure and responses used in configured tenant workflows. |
Control Axis stores the connected Google account identity and OAuth credentials needed to maintain the authorized connection. Application secrets and OAuth access and refresh tokens are treated as restricted configuration values and are not displayed to ordinary tenant users. Google content is accessed when needed to perform the connected feature selected by the tenant.
Control Axis Systems’ use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Google user data is shared only as needed to provide the user-directed feature, operate the Services through necessary service providers, respond to security or legal requirements, or with the user’s or tenant administrator’s direction. Human access to Google user data is limited to circumstances such as user-requested support, security investigation, legal obligations, or other access permitted by the Google API Services User Data Policy.
Disconnecting Google
An authorized tenant administrator can disconnect Google from CRM Secure Integrations. A user can also review or revoke Control Axis access from the Google Account third-party connections page. Disconnecting removes the active Google authorization from Control Axis and stops future Google API access. Business records already created in the tenant workspace—such as a calendar event reference, sent-message record, imported contact, or copied document metadata—may remain as tenant records until deleted under the tenant’s workspace and retention process.
7. Cookies, local storage, and similar technology
The public website and platform may use cookies, local storage, and similar browser features for essential functions such as sessions, security, preferences, product operation, and abuse prevention. Hosting and network providers may also process request information and use security or performance mechanisms when delivering the Services. If analytics or additional non-essential technologies are introduced, this notice will be updated to describe the relevant use.
8. Security
Control Axis uses administrative, technical, and operational safeguards designed to protect information, including tenant workspace boundaries, authentication, role-based access, restricted configuration values, encrypted transport, session controls, audit activity, and backup and recovery procedures. No service or transmission method is completely secure, and we cannot guarantee that unauthorized access, loss, or disruption will never occur.
Users are responsible for protecting credentials, using individual accounts, configuring appropriate roles, reviewing connected providers, enabling available security features such as multifactor authentication when appropriate, and reporting suspected compromise promptly.
9. Retention and deletion
We retain information for as long as reasonably needed to provide and secure the Services, administer an active account or subscription, maintain required business and billing records, resolve disputes, enforce agreements, and meet legal obligations. Retention depends on the type of record, the tenant’s status and instructions, connected-provider behavior, backup and recovery cycles, and applicable requirements.
Tenant administrators may remove records through available product controls or request account, export, or deletion assistance by contacting us. Disconnecting an integration stops future access by that connection but does not automatically delete tenant records previously created or imported. Some information may remain temporarily in protected backups, security logs, billing records, or records that must be retained for legitimate operational or legal purposes.
10. Your choices and requests
Depending on your relationship to Control Axis and applicable law, you may request access to, correction of, export of, or deletion of personal information. We may need to verify your identity and authority before acting. If the information belongs to a tenant workspace, we may coordinate the request with that tenant’s authorized administrator.
You can manage communications by following instructions in the message or contacting us. Service, security, account, and billing notices may still be sent when necessary to operate the Services. Provider permissions can be reviewed and revoked through CRM Secure Integrations and the provider’s own account controls.
11. Changes to this notice
We may update this Privacy Notice as the Services, integrations, or information practices change. The effective date above identifies the current version. Material changes may also be communicated through the website, product, account notice, or email when appropriate.
12. Contact Control Axis Systems
For privacy questions or requests, contact:
Control Axis Systems
Email: controlaxissystems@gmail.com
Phone: 734-436-1199
Website: www.controlaxissystems.com/contact.html
Do not send passwords, one-time codes, recovery codes, bank-login credentials, API secrets, or full payment-card information with a request.
