YOUR RECORDS, HANDLED WITH CARE

Privacy notice

Server is operated by Jeb Farneth in New York, United States ("Server," "we," or "us"). This notice covers getserver.app, app.getserver.app and the hosted Server service. It explains our current practices, including information venues provide about their staff and operations.

1. Information we receive

2. Why we use it

We use information to authenticate accounts, separate venue workspaces, import and reconcile records, prepare operating recommendations, carry out the specific actions you approve, answer support requests, maintain billing records where applicable, prevent abuse and investigate problems. We may use service metrics to improve reliability without selling venue records or exposing one venue's data to another. We do not use uploaded venue records to train our own general-purpose AI model.

3. Venue instructions and staff information

The venue decides which business records to provide, who may access its workspace and how to use its operating recommendations. The venue must have authority to provide those records and give any notices or obtain any permissions required for employee or other personal information. We process venue records to provide the service and follow documented, lawful instructions. Staff with a request about an employer's records should contact the venue; they may also contact us so we can help direct the request. An account holder's acceptance is not consent on behalf of every employee for unrelated uses.

4. Service providers and disclosures

We use Amazon Web Services for hosting, the database, backups, sign-in and infrastructure. Square provides connected venue records when authorized. Stripe handles payments when enabled. If Ask Server is enabled, OpenAI receives the question, recent chat in that user's venue and a limited workspace summary to generate a response. The current hosted chat does not automatically send uploaded source documents, employee names or pay rates as workspace context; information a user types into chat is part of the message. Provider processing and retention are also governed by their applicable service terms and data policies.

We may disclose information to service providers performing these functions, to people the venue authorizes, as required by law, to protect lawful rights and security, or as part of a business transfer subject to appropriate confidentiality and notice. We do not describe a planned integration as an active recipient of your data.

5. Cookies and browser storage

We use session and security cookies for sign-in and request protection, and browser storage to remember setup progress. The current public site does not include advertising trackers or third-party analytics scripts. Blocking essential cookies may prevent sign-in.

6. Retention and deletion

Saved venue records, imported text, decisions and chat remain in the hosted account until removed through a supported workflow or a verified support request. Disconnecting Square stops access and removes the saved connection credentials; it does not erase records already imported. We retain information as reasonably needed to provide the service, resolve disputes, secure the system and meet legal obligations. We do not promise that every record automatically expires after a fixed number of days.

You may request access, correction, export or deletion by contacting us. We verify the requester and the venue authority before changing or releasing data. Some records may need to be retained for legal, security or transaction purposes. Deleted data can remain in restricted backups until their retention period ends; active automated database backups currently use a seven-day window, and separately retained recovery snapshots may remain longer. We will explain relevant limitations when handling a request.

7. Security and location

The hosted service uses encrypted connections, an encrypted private database, protected provider credentials and account/venue access controls. Hosting is currently in AWS's US East (Northern Virginia) region. Service providers may process information in other locations under their applicable terms. No service can promise perfect security. Please report suspected unauthorized access promptly; we will investigate and provide notifications when required by applicable law.

8. Your choices

You may stop uploading records, disable an optional feature, disconnect Square in Server, or revoke permissions with the provider. You can request help with records and account closure. Rights vary by jurisdiction; we will handle applicable requests as required by law and will not retaliate for exercising them. Server is intended for authorized adult business users, not a service directed to children.

9. Changes and contact

We will publish material changes with a new version and effective date and provide notice or obtain a fresh acknowledgement when appropriate. We will not treat an updated notice as retroactive permission for an unrelated use of previously collected information.

Contact Jeb Farneth, operating Server: support@getserver.app. Please start with your account email and venue name, not passwords, payment-card details or unnecessary employee records. Support messages are received through AWS email services and forwarded to the operator’s Microsoft Outlook business-support inbox. Cloud intake copies normally expire after seven days; forwarded correspondence is retained as reasonably needed to resolve requests and meet legal or security obligations.