Privacy Policy
Effective date: October 7, 2026
Last updated: October 7, 2026
This Privacy Policy explains how David Click, a sole proprietor in Littleton, Colorado ("Berm," "we," "us"), collects, uses, shares and protects personal information when you visit bermfsm.com or use the Berm field-service software at app.bermfsm.com (together, the "Service").
Berm is software for businesses. We sell it to heating, ventilation and air-conditioning contractors and similar service companies (our "Customers"). We do not sell it to individuals for personal or household use.
1. The two kinds of information we handle
We handle personal information for one of two purposes. What we may do with it depends on the purpose, not on who the person is. The same fact can serve both purposes: a technician's name is part of the Customer's records, and is also how we sign that technician in.
| Customer Data | Operational Data | |
|---|---|---|
| What it is | Information a Customer and its employees put into, or create in, the Customer's Berm workspace | Information we process to run the Service and our own business |
| Examples | The Customer's clients: names, contact details, service addresses, site access notes, equipment, jobs, estimates, invoices and payments received, including card payments made through Berm. Photos, documents and signatures added to jobs. The Customer's staff as they appear in the workspace: employee profiles, roles, job assignments and notes. The history of changes to those records. Records of what was sent to QuickBooks at the Customer's direction. | Sign-in details and security records, including two-step sign-in factors, sessions, IP addresses and request logs. Error reports and monitoring records. Billing contacts and billing records. Records of who accepted our Terms for a Customer, and when. Messages you send us. Visits to our website. |
| Who decides how it is used | The Customer. We are the Customer's service provider or processor. | Berm. We are the business or controller. |
| Where to send a request about it | The Customer. We help the Customer respond. | Berm (Section 8) |
| How long it is kept | As the Customer's subscription and our agreement with the Customer provide (Section 6) | As described in Section 6 |
If you are a client of one of our Customers, for example a homeowner who had a furnace serviced, the contractor you dealt with controls your information, and its own privacy notice applies. The same applies if you work for a Customer, as far as your workspace records are concerned. Please send requests about that information to the Customer. If you contact us instead, we will pass your request to the right Customer and help them respond. We will not act on it ourselves unless the law requires us to.
Most of this policy is about Operational Data. It also explains how we protect Customer Data while we hold it.
2. What we collect
Information you give us
- Account information. Your name, work email address and phone number, and the company you work for. Administrators at a Customer create accounts for their employees by invitation. The profile details a Customer keeps about its employees, such as job title, skills and certifications, are Customer Data.
- Sign-in information. Your password is handled by our authentication provider and is stored only as a one-way hash. We never see or store it in readable form. An administrator can add two-step sign-in to their own account. Once they do, that account cannot sign in without a code from their authenticator app, and we process the information needed to check the code.
- Billing information. Company name, billing contact, billing address, the plan chosen and the history of payments. If you pay by card, our payment processor, Stripe, collects and stores the card details. We see only limited details, such as the card brand and the last four digits. If you pay by check or money order, we keep a record of the payment.
- Communications. What you send us when you email support@bermfsm.com or otherwise contact us.
Information created as you use the Service
- Change history. When a record in a Customer's workspace is created, changed or deleted, we keep a copy of it as it was before and after the change, with who made the change and when. We also record when a workspace is exported, and when Berm support staff view one. This history is Customer Data. We keep it to protect the Customer's records and to investigate problems. It does not record which records a Customer's own staff view.
- Error reports. When a page or a server request fails, we record the kind of error, such as "TypeError", with the page or server address, the response status and the time. We do not record the error's own message, because it can quote what was being worked on. The only exceptions are a few fixed messages from web browsers, such as one saying that a connection failed. We use error reports only to find and fix problems. A summary of recent errors, with these same details, may be emailed to Berm.
- Acceptance of our Terms. When an administrator accepts our Terms for their company, we record which version they accepted, their name and email address at the time, and when.
- Connection information. When you connect, your device's IP address and basic request details pass through our hosting and database providers, and those providers record them in their logs. We use this information to limit abusive request volumes, keep the Service secure and investigate problems. We do not use it to build profiles of you.
Photos, documents and signatures
A Customer's staff can add photos and PDF documents to a job, and can capture a customer's signature on screen. These are Customer Data. They are stored privately, and are shown only to signed-in staff of that Customer, through links that expire after a short time. A signature is stored as an image. We do not analyze it or use it to identify anyone.
Photos are stored as they are uploaded. Depending on the phone's settings, a photo can carry details the phone adds to it, such as when and where it was taken.
Visits to our website
Our website, bermfsm.com, uses Cloudflare Web Analytics to count visits. It does not use cookies and does not follow you to other websites. Cloudflare processes your IP address and browser details to produce the counts. The Berm app at app.bermfsm.com does not use it.
Card payments from a Customer's clients
Where we offer it, a Customer can let its clients pay an invoice by card. The Customer sends a client a payment link. The page it opens shows only the Customer's name, the invoice number and the amount due. It gives no access to anything else in Berm, and the link expires and can be cancelled. The client then pays on a checkout page run by Stripe, into the Customer's own Stripe account.
Stripe collects the card details. Berm never receives or stores card numbers or bank account numbers. For each payment, refund or dispute, Berm keeps the amount, any card surcharge, the date, the status, Stripe's fee and Stripe's reference numbers, as part of the Customer's records. These are Customer Data.
What we do not collect
We do not use advertising cookies or tracking pixels. We do not track technicians' locations. We do not collect biometric information.
3. How we use information
We use Operational Data to:
- provide, maintain and support the Service, including signing people in and enforcing the roles and permissions each Customer sets;
- send service emails such as invitations, sign-in messages and security notices;
- keep the Service secure, investigate problems, and prevent fraud and abuse;
- keep encrypted backups, so that the Service can be restored after a failure;
- bill Customers and manage our business relationship with them;
- understand, in total, how many people visit our website;
- respond to requests and questions;
- comply with law and enforce our agreements.
We use Customer Data only to provide the Service to the Customer and as our agreement with the Customer allows. That includes syncing invoices and payments to QuickBooks Online when the Customer connects it, recording card payments against the Customer's invoices when Stripe confirms them, and including Customer Data in our encrypted backups.
We do not sell personal information. We do not "share" personal information for cross-context behavioral advertising, as California law defines that term. We do not use Customer Data for our own marketing. We do not use it to train artificial intelligence models, and we keep model training turned off in the AI tools we use.
4. Who we share information with
We share personal information only as follows.
Service providers who run parts of the Service for us. Each handles the information under its terms with us, to provide its service to us:
| Provider | What it does for Berm |
|---|---|
| Supabase, Inc. | Database, sign-in, account management and file storage |
| Cloudflare, Inc. | Hosting, network delivery, request-limit protection, counting website visits, and receiving email sent to support@bermfsm.com |
| Resend, Inc. | Sending service email, including invitations, sign-in messages, error and monitoring summaries sent to Berm, and our replies from support@bermfsm.com |
| GitHub, Inc. | Running our backup jobs and storing the encrypted backups |
| Stripe, Inc. | Card payments for Berm subscriptions, when a Customer pays by card |
| OpenAI and Anthropic, PBC | AI assistants we use to build, maintain and support the Service. While working on a problem, they may see Customer Data. We keep their use of our data for model training turned off. |
| Google LLC | Gmail, where we read, store and answer email sent to support@bermfsm.com |
This table is our current list of service providers. We will give Customers at least 30 days' notice, by email to account administrators, before adding a new provider that handles Customer Data.
Stripe, for card payments a Customer accepts. If a Customer connects its own Stripe account to accept card payments from its clients, Berm sends Stripe the amount and the invoice number for each payment, and Stripe processes the payment under the Customer's own agreement with Stripe. Stripe's handling of card details is governed by Stripe's privacy policy.
Intuit QuickBooks, at the Customer's direction. If a Customer connects its own QuickBooks Online company, Berm sends that Customer's invoices, customers and payments to QuickBooks as the Customer instructs. Intuit's handling of that information is governed by the Customer's own agreement with Intuit.
Within a Customer's company. Information in a Customer's workspace is visible to that Customer's employees according to the roles the Customer assigns. For example, technicians see only the jobs assigned to them.
Support staff. Berm support staff can be given temporary, read-only access to a Customer's workspace, to provide support or keep the Service running. They can view the workspace and, when support requires it, export it. They cannot change it. We record each time support staff view or export a Customer's workspace.
Legal and safety reasons. We may disclose information if the law requires it, or to respond to valid legal process. Where the law allows, we will tell the affected Customer first. We may also disclose it to protect the rights, property or safety of Berm, our Customers or others.
Business transfers. If the Berm business is moved into a company we form, or is involved in a merger, acquisition or sale of assets, information may transfer as part of that change. It stays subject to the commitments in this policy.
5. Cookies and information kept on your device
Berm uses only what is needed for the Service to work:
- Sign-in session. Your browser keeps your sign-in session, so that you stay signed in until you sign out or the session expires.
- Display preference. Your browser remembers your light or dark display setting.
- QuickBooks connection cookie. A short-lived cookie (ten minutes) protects the step where an administrator connects QuickBooks.
- Job updates not yet confirmed. A technician's update to a job might not reach our servers, for example because of a weak signal. Such updates include a status change, a checklist item, a note or a charge. Until our servers confirm the update, the phone or browser keeps a copy of it, so the update can be sent again without being duplicated. The copy can include the text of a note or the details of a charge. It is removed as soon as our servers answer. The app ignores copies more than 24 hours old, but it does not always erase them. A copy can stay in the browser's storage until the same employee makes another update on that device, or until the site's data is cleared. Signing out does not remove it. Copies are kept separately for each employee who uses the same device. Protect work devices with a passcode. If a device is lost, tell your administrator.
- Payment links. A payment page keeps the link only while the page is open, and removes it from the address bar. When a client goes on to pay, that browser tab keeps a receipt reference, so that the confirmation page can show whether the payment went through. It lasts only as long as the tab. Stripe's checkout page is Stripe's, and uses Stripe's cookies under Stripe's privacy policy.
- Offline demo. If you use Berm's offline demo, its sample records, and any changes you make to them, stay in your browser.
We do not use advertising or analytics cookies. The visit counts on our website are made without cookies (Section 2). Because we do not track you across websites, we do not change our practices in response to "Do Not Track" signals. For the same reason, a Global Privacy Control signal has nothing to opt you out of. We will honor both as opt-out requests if our practices ever change.
6. How long we keep information
Customer Data, including photos, documents, signatures and the change history, is kept for as long as the Customer's subscription lasts. Then:
- When a subscription ends, or a free trial ends without a paid plan, the Customer has 30 days to ask for an export of its data, or, after a trial, to choose a plan. If we end a subscription after suspending it for non-payment, the 30 days of suspension are that period (Terms and Conditions, Section 3.5).
- We then delete the Customer Data within 7 days, unless the law requires us to keep it.
- Our encrypted backups are kept for up to 30 days, so copies in backups are gone within 30 days after the deletion.
- A Customer can ask us to delete its data sooner by emailing support@bermfsm.com.
When a Customer's staff remove a photo, document or signature from a job, we delete the file from storage. Copies in backups are gone within 30 days.
Operational Data is kept as follows:
| Information | How long |
|---|---|
| Account information | While the account exists. If you ask us to delete your account, or your company's data is deleted, we delete it within 30 days, except what we must keep for billing or security records. |
| Billing records | As long as tax and accounting law requires |
| Records of who accepted our Terms | While the Customer's account exists. They are deleted with the Customer Data. |
| Error reports | Up to 30 days |
| Error and monitoring summaries | Up to 90 days in our records. Copies emailed to Berm are kept for up to one year. |
| Messages to support | Up to two years after the conversation ends |
| Our providers' connection and security logs | As long as each provider keeps them, typically days to weeks |
| Backups | Up to 30 days |
7. How we protect information
We use safeguards appropriate to the information we hold:
- every connection is encrypted;
- each Customer's data is kept apart from every other Customer's, and the database itself enforces that separation;
- role-based permissions apply;
- photos, documents and signatures are stored privately, and are shown only through links that expire;
- card details go only to Stripe, never to Berm;
- stored QuickBooks credentials are encrypted;
- backups are encrypted with a key only Berm holds;
- administrators can add two-step sign-in to their accounts;
- changes to Customer records, exports and support access are recorded.
No system is perfectly secure, and we cannot guarantee that information will never be accessed, disclosed or lost without authorization. If we learn of a security incident affecting personal information, we will notify affected Customers and individuals as the law and our agreements require.
8. Your choices and rights
Several states give their residents privacy rights by law. We offer the same rights to everyone in the United States, whatever state you live in. You may ask us to:
- tell you what personal information we hold about you, and give you a copy in a portable format;
- correct information that is inaccurate;
- delete your information, except what Section 6 says we must keep for billing or security records;
- tell you who we have disclosed it to. Section 4 lists every provider that receives it;
- opt out of the sale of personal information, sharing for targeted advertising, or profiling. We do none of these.
These rights apply to Operational Data. If your request is about Customer Data, we will refer it to the Customer who controls that data and help them respond (Section 1).
To make a request, email support@bermfsm.com with the subject "Privacy request." We will verify your identity before acting, usually by confirming that you control the email address on the account. You may use an authorized agent. We may ask the agent for proof that you authorized them. We will answer within 45 days. If we need longer, we will tell you why within those 45 days, and take no more than 45 days more.
If we deny your request, you may appeal by replying to our decision with the subject "Privacy appeal." We will answer the appeal within 45 days. If you disagree with the outcome, you may contact your state's attorney general.
Nevada residents may send a request to opt out of the sale of their covered information to the same address. We do not sell it.
We will not treat you differently or offer you a worse service for exercising these rights.
9. Additional information for California residents
This section applies to California residents and supplements the rest of this policy. It covers Operational Data, which Berm handles as a business. Customer Data is covered by the privacy notice of the Customer that controls it.
Categories of personal information we collected in the past 12 months, where they came from, and why. We disclosed each category only to the service providers listed in Section 4, for a business purpose:
| Category (Cal. Civ. Code § 1798.140) | Examples | Source | Purpose |
|---|---|---|---|
| Identifiers | Name, work email, phone, IP address | You; your employer | Accounts, security, support |
| Customer records (§ 1798.80(e)) | Billing contact name, address, phone | You; your employer | Accounts, billing |
| Commercial information | Plan, subscription and payment history; acceptance of our Terms | Our records | Billing; a record of the agreement |
| Internet or network activity | Request and security logs. Error reports: the kind of error, and where and when it happened. Visits to our website, counted without cookies. | Your use of the Service and our website | Security, fixing problems, counting visits |
| Sensitive personal information: account log-in | Email address and password (stored only as a hash) | You | Signing you in |
We use sensitive personal information only to provide the Service and keep it secure. That is a use the law permits without offering a right to limit it.
Sale and sharing. We have not sold or shared personal information in the past 12 months. We have no actual knowledge of selling or sharing the personal information of anyone under 16.
Your rights. California residents have the rights described in Section 8, plus the right to know the categories of sources, purposes and recipients described above. We answer verified requests within the times in Section 8.
"Shine the Light" (Cal. Civ. Code § 1798.83). We do not disclose personal information to third parties for their own direct marketing.
10. Children
The Service is for businesses and is not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe we have, contact us and we will delete it.
11. Where information is stored and processed
Berm is operated from Colorado, in the United States. Our database and file storage are in the United States, at our database provider's US West (Oregon) location. Our providers may process information in other places. For example, Cloudflare handles each request at a data center near the person making it. The Service is intended for use in the United States.
12. Changes to this policy
We will post any change here and update the "Last updated" date. If a change materially affects how we use personal information we already hold, we will tell account administrators by email before it takes effect.
13. Contact us
David Click 9157 W Cross Dr 05-204 Littleton, CO 80123 Email: support@bermfsm.com