PianoOps Privacy Policy

Effective Date: December 8, 2025

This Privacy Policy describes how 3Strand LLC ("Company," "we," "us," or "our") collects, uses, stores, and protects information in connection with the PianoOps Platform, including the PianoOps web application, dashboard, APIs, and the PianoOps Companion Mobile App used by technicians (collectively, the "Services").

This Privacy Policy is incorporated into and forms part of our Terms of Service. Capitalized terms not defined in this Privacy Policy have the meaning given in the Terms of Service.

The Services are intended for use by business entities and their Authorized Users, not by individual consumers for personal or household purposes.

By accessing or using the Services, you agree to the practices described in this Privacy Policy.

1. Scope & Role of the Parties

The Services enable business customers to manage piano service operations, including scheduling, technician workflows, customer records, instrument information, and related business data ("Customer Data").

For purposes of U.S. privacy and data protection laws (including the California Consumer Privacy Act ("CCPA") as amended by the CPRA), the Customer is the business that controls Customer Data, and we act solely as a service provider / processor on behalf of the Customer in relation to Customer Data.

We do not collect, retain, use, or disclose Customer Data for any purpose other than providing the Services, maintaining or improving the Services, or as otherwise permitted by applicable law.

2. Information We Collect

We collect the following categories of information to operate and provide the Services.

2.1 Account and Business Information

When a Customer creates an account, we collect information such as:

• Business name

• Business address, email, and phone number

• Account administrator name and contact information

• Login credentials (email and password)

• Whether the user is a Piano Technicians Guild (PTG) member (optional)

This information is used to create and maintain the Customer's account and provide access to the Services.

2.2 Authorized User Information

Customers may authorize technicians, staff, or contractors ("Authorized Users") to use the Companion Mobile App or other components of the Services.

We collect the Authorized User's name, role, and contact information as provided by the Customer.

The Customer is responsible for obtaining any necessary permissions from Authorized Users.

2.3 Customer Data

The Services allow Customers to input and manage business data such as:

• End-customer names, contact information, and service locations

• Appointment details and service history

• Piano details, tuning records, and maintenance notes

• Internal notes, tasks, and operational data

Customer Data is owned and controlled by the Customer. We process Customer Data only to provide and support the Services.

2.4 Optional Contacts Import

If an Authorized User chooses to import contacts, the Companion Mobile App will request permission to access the device's contacts directory.

Access is optional and limited only to the contacts selected by the user. We do not access or upload the user's entire contacts directory.

2.5 Technical and Usage Information

We collect limited technical data to ensure the functioning and security of the Services, such as:

• Device type and OS version

• App version

• Log files, crash reports, and diagnostic information

• IP address and basic usage metrics

We do not collect advertising identifiers or use tracking technologies for cross-site or behavioral marketing.

3. How We Use Information

We use Account Information, Authorized User Information, and technical data solely to:

• Provide, maintain, and improve the Services

• Authenticate users and secure accounts

• Facilitate technician workflows and scheduling

• Respond to support requests

• Ensure system integrity and prevent misuse

• Comply with legal obligations

We do not use Customer Data for:

• Advertising

• Marketing

• Selling to third parties

• Building profiles independent of the Customer's use of the platform

4. Data Sharing & Service Providers

We do not sell or share personal information or Customer Data for cross-context behavioral advertising or any commercial purpose.

We may disclose information to trusted service providers strictly to operate or support the Services. This includes providers of:

• Cloud hosting and infrastructure

• Authentication

• Error logging and diagnostics

• Data storage and backup

• Payment processing (Stripe)

All service providers act as service providers/processors and are contractually prohibited from using Customer Data for any purpose other than performing services on our behalf.

Customer Data is stored and processed in the United States.

If we add additional service providers, they will be required to meet or exceed these privacy and security requirements.

5. Payments

Subscription purchases are processed through Stripe using a secure, Stripe-hosted checkout flow.

We do not collect or store full payment card details. Stripe processes all payment information in accordance with its own privacy and security policies.

6. Data Security

We implement reasonable administrative, technical, and physical safeguards designed to protect information, including:

• Encryption in transit (TLS/SSL)

• Encryption at rest (LUKS or equivalent)

• Access controls

• Audit logs and monitoring

• Logical separation of Customer accounts

While we work to protect your information, no security method is infallible. We continually evaluate and enhance our security measures.

7. Data Retention & Deletion

We retain Account Information and Customer Data for as long as the Customer's account remains active or as needed to provide the Services.

A Customer may request deletion of its account and associated Customer Data by contacting us at privacy@pianoops.com. We will verify the request and process deletion within a reasonable period, typically within 30 days.

We are developing in-app tools that will allow Customers to download or delete their data directly from the Services. Once available, this Privacy Policy will be updated accordingly.

8. Customer Rights & Choices

Because PianoOps acts as a service provider, individual end-customers of our Customers should direct privacy requests (access, correction, deletion, etc.) to the Customer who controls their data.

Business Customers and their Authorized Users may:

• Access and update account information

• Download Customer Data

• Request deletion of their account

• Withdraw consent where applicable

We will assist the Customer in fulfilling end-customer requests to the extent required under applicable U.S. privacy laws.

9. Use by Minors

The Services are intended for use by businesses and their Authorized Users, who must be 18 years of age or older.

We do not knowingly permit children under 18 to use the Services or knowingly collect their personal information.

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Material changes will be communicated by updating the "Last Updated" date and posting the revised version on our website or within the Services.

Continued use of the Services after changes become effective constitutes acceptance of the updated Privacy Policy.

11. Contact Us

For questions about this Privacy Policy or our data practices, please contact us at: privacy@pianoops.com or through the contact form at PianoOps.