Privacy Policy
This Privacy Policy describes how Pillar Software Solutions LLC ("Pillar," "we," "us," or "our") collects, uses, stores, and shares personal information when you use our field service management platform or visit our website. It is written plainly and describes what the software actually does.
Version 2.0 — Effective August 10, 2026
1. Who We Are and What This Covers
Pillar is field service management software operated by Pillar Software Solutions LLC, a Pennsylvania limited liability company. Our mailing address is c/o Northwest Registered Agent LLC, 502 W 7th St, Ste 100, Erie, PA 16502, USA. You can reach us about anything on this page at admin@pillarfsm.com.
We are a United States business serving United States businesses. Our servers and our providers are in the United States. See Section 14 for what that means for you.
There are three ways this policy may apply to you:
- You run a business on Pillar. We handle your account details and everything your team enters into the platform. You decide what goes in; we store and process it so the software works.
- You are a customer, employee, or contact of a business that uses Pillar. That business decides what is recorded about you and why. We process those records on its behalf. Requests about your information are best sent to that business first — see Section 12.
- You are visiting pillarfsm.com. See Section 7.
2. Information We Collect
2.1 Account information
When an account is created we collect:
- Full name, email address, and telephone number
- Company name, trade type, business address, and time zone
- User role — Owner, Dispatcher, Technician, Sales Rep, Subcontractor, or Customer
- A password, stored only as a one-way bcrypt hash. We never store or transmit plaintext passwords, and nobody at Pillar can read yours
2.2 The business records you enter
Most of what Pillar holds is what your team types in: customers and their contact details and service addresses, jobs and appointments, estimates, invoices and payment records, notes (internal and customer-facing), equipment and service history, price books, time entries, service agreements, projects, subcontractor records, sales leads, and canvassing records. Those records routinely contain personal information about your customers and your staff. You choose what to record; we store it, process it to run the features you use, and share it only as described in Section 5.
2.3 Usage, security, and diagnostic data
- Browser type, operating system, and device information, from standard HTTP request headers
- IP address, and the approximate location it implies
- Audit events — sign-in attempts, role changes, account modifications, password changes and other security-relevant actions — recorded with the actor, a timestamp, the IP address, and the user agent
- Error diagnostics when something breaks: the error and its stack trace, the request that failed, the account and user identifiers attached to it, and a short trail of the actions leading up to it. These reports go to Sentry, our error reporting provider
We do not load third-party analytics or behavioural tracking inside the signed-in platform. Our public marketing website is different — see Section 8.
2.4 Location data
Where a company switches these features on and the device grants permission, we collect location data from staff devices for:
- Live technician tracking — latitude, longitude, accuracy, heading, and speed
- Location-verified clock-in and clock-out on time entries
- Route planning and local distance calculations
- Sales rep breadcrumbs during an active canvassing session — see Section 6
We also convert addresses into map coordinates so map features work. That lookup sends the address text to the United States Census Bureau geocoder, falling back to the OpenStreetMap Nominatim service. The reverse also happens: for canvassing pins dropped by location rather than typed in, we send the latitude and longitude to Nominatim to get an approximate street address back. In both directions only the address or the coordinates are sent — no name, no contact details, no account information.
2.5 Payment information
Card and bank details are entered on Stripe's own pages and handled by Stripe. Full card numbers and security codes never reach a Pillar server. We retain payment method identifiers (tokens that reference Stripe records), the last four digits and brand for display, and billing history, invoice records, and payment status.
2.6 Communication data
When messages are sent through the platform we log:
- Email — subject, content, sender, recipient, delivery status
- Text messages — content, sender, recipient, delivery status, and opt-out records kept for messaging compliance
- Calls — duration, direction, outcome, and the recording where a company has turned recording on
2.7 Files and documents
Files uploaded to the platform — job photos, signed contracts, permits, equipment images, company logos, canvassing photos — are stored in cloud object storage (Cloudflare R2). We keep the file name, type, size, upload time, and who uploaded it. Files are served through short-lived signed links rather than public URLs.
3. How We Use Information
- Running the service: jobs, scheduling, dispatch, estimates, invoicing, payments, customer communication, and every other feature you use
- Authentication and security: verifying identity, managing sessions, enforcing role-based access, rate limiting, and keeping audit logs
- Billing: charging for seats, storage, and prepaid messaging credit, and producing your billing records
- Support and operations: answering your questions, reproducing and fixing faults, and keeping the platform running — see Section 4 for what that means in practice
- Sending messages you ask us to send: appointment reminders, invoice and estimate notifications, and other operational messages to your customers
- Reporting: generating the dashboards and reports inside your own account — profitability, technician performance, labor variance, and the rest
- Improving the product: understanding which features are used and where they fail, so we can fix and extend them
- Legal and compliance: meeting our legal obligations, responding to lawful requests, and keeping the messaging-consent and opt-out records that telephone-marketing rules require
We do not sell your personal information. We do not rent or trade it, we do not use the records you enter to advertise to your customers, and we do not hand your customer list to anyone.
4. Who Can See Your Data
4.1 People in your company
Pillar is multi-tenant, and every company's records are walled off from every other company's. Within your own account, what a person sees depends on their role. Customer portal users see only their own appointments, estimates, and invoices — never internal notes, never another customer's records, never the office side of the product. Technicians and subcontractors see the work assigned to them, with internal notes withheld.
4.2 Pillar personnel
This is the part most privacy policies leave vague, so we will be direct. Pillar personnel can access data held in the platform. That includes the records inside your account, application and error logs that span every company, user accounts, and billing details. We access it for support, troubleshooting, security investigation, fraud prevention, and keeping the platform running — and for nothing else.
The isolation described in Section 9 separates tenants from each other. It is not a barrier between you and us, and we will not pretend otherwise. Everyone with that access is bound by confidentiality obligations, and the commitments in Section 3 — no selling, no marketing use of your records — apply to us as much as to anyone.
4.3 Service providers
We share data with the providers listed in Section 5, each for the specific job named there. They are bound by their own agreements with us to use the data only to provide that service.
4.4 Legal requirements
We may disclose information where the law requires it, or where we believe in good faith that disclosure is necessary to comply with a legal obligation, enforce our agreements, prevent fraud, or protect someone's rights or safety.
4.5 Business transfers
If Pillar is merged, acquired, or its assets sold, information may transfer to the acquiring entity. We will notify account owners by email before your information becomes subject to a different privacy policy.
5. Service Providers We Share Data With
These are the third parties that receive data, what they do with it, and what they get. Each processes it under its own privacy policy as well as its agreement with us. Where a row says "only for companies that connect", nothing is sent unless that integration is switched on in your account.
| Provider | Purpose | Data Shared |
|---|---|---|
| Stripe | Card and bank payments, saved payment methods, subscription billing, and payouts (via Stripe Connect) | Card and bank details entered on Stripe’s own pages, billing address, transaction amounts, invoice records |
| Twilio | Text messaging, voice calls, call recording where a company turns it on, and carrier registration | Phone numbers, message content, call metadata and recordings, opt-out and compliance records |
| SendGrid | Email delivery and white-label sending-domain authentication | Email addresses, message subject and content, delivery status |
| Google (Calendar sync) | Two-way calendar sync, only for companies that connect a Google account | Appointment events written into the connected calendar, containing the job number, the customer’s name, the service description, the full service address, and the appointment notes |
| Intuit (QuickBooks Online) | Accounting sync, only for companies that connect a QuickBooks account | Customer names, email addresses, phone numbers and addresses, plus invoices, estimates, payments, and items, synchronized in both directions |
| Sentry | Error reporting and diagnostics for the platform and the API, so faults can be found and fixed | Error messages and stack traces, the request path and account identifiers attached to the failing request, and diagnostic breadcrumbs describing what happened just before the error |
| Cloudflare (R2 storage) | Storage for uploaded files and documents (photos, contracts, permits, logos) | Uploaded files and their metadata |
| Cloudflare (Turnstile) | The anti-abuse check on the platform sign-up form, when it is configured | IP address, browser signals, and a challenge token, sent to Cloudflare for verification |
| DigitalOcean | Cloud infrastructure hosting the application servers and the database | All platform data at rest and in processing |
| U.S. Census Bureau geocoder / OpenStreetMap Nominatim | Turning street addresses into map coordinates, and coordinates back into an approximate street address for canvassing pins | Address text on the way in; latitude and longitude on the way back, which are sent to Nominatim only. No name, contact details, or account information is attached |
| Google Analytics | Traffic measurement on our public marketing website (pillarfsm.com) only. Not loaded inside the signed-in platform | Pages viewed, session duration, referring source, approximate location derived from IP address, device and browser type |
| ipwho.is | Approximate city lookup on our marketing website, used to offer a link to a local page. Called from our server, never from your browser | The visitor’s IP address. Nothing is stored by us; only a two-value result is returned to the page |
Caching, rate limiting, background job queues, and the map tiles behind every map view run on infrastructure we operate ourselves, so no outside provider receives that data. If we add a provider that handles personal information, this table is where the change appears.
6. Door-to-Door Canvassing
Pillar includes door-to-door canvassing tools. Companies that use them record information about households that may never have contacted them and may never become customers. We are describing it plainly because it is the most sensitive category of data the platform holds.
For each property visited or marked, the company's reps can record:
- The street address, or the latitude and longitude of the spot where the pin was dropped, which we convert into an approximate address
- The outcome of each knock, the date and time, and which rep was there
- Free-text notes about the visit or the household
- Photos taken at the property
- A permanent, company-wide do-not-knock flag, which any rep can set and only an owner can clear
Separately, a company can switch on location breadcrumbs for its sales reps. When it is on and a rep has an active canvassing session running, the rep's device reports its position periodically, building a track of where that rep went during the session. Owners and dispatchers at that company can see it. It is off unless the company turns it on, it only records during an active session, and each company sets how long the breadcrumbs are kept — see Section 11.
The company using these tools is responsible for how it uses them. That includes giving employees any notice of location monitoring that the law where they work requires, honoring do-not-knock and do-not-contact requests, and complying with the rules that apply to canvassing and to contacting people who never asked to be contacted. Pillar provides the software; the company decides who it visits, what it records, and how long it keeps it.
If you are a resident and want a record about your property removed, contact the company that visited you — they control the record and can delete it. If you cannot identify them, write to us at admin@pillarfsm.com and we will help you get the request in front of them.
7. Website Visitors and Prospects
This section is about pillarfsm.com rather than the platform.
When you submit the demo request, contact, or newsletter form, we store what you typed — your name, email address, telephone number, company name, and whatever you wrote in the message — together with technical context captured at submission: your IP address, your browser's user agent, the referring URL, any UTM campaign parameters on the link that brought you, and the page you first landed on. We use that to reply to you, to understand which pages and campaigns bring people here, and to follow up about Pillar.
Marketing email is opt-in. The demo and contact forms carry an unticked box; leave it alone and you will get a reply to your request and nothing else. The newsletter form exists only to subscribe you, and says so above the button. Every marketing email has an unsubscribe link, and you can ask us to remove you at any time.
Two more things happen on this website. Google Analytics loads on every page — see Section 8. And a small pill sometimes offers a link to a page about your area: to decide whether to show it, our server looks up the approximate city for your IP address using ipwho.is, a third-party lookup service. The request is made by our server, not your browser, so ipwho.is never sees a request from you directly. All that comes back to the page is which local link to offer, or nothing at all, and that answer is held in your browser's session storage until you close the tab. No cookie is set, and we do not store the result.
9. Data Storage and Security
What we do:
- Tenant isolation: every record carries a company identifier, and the filter is applied automatically on every database query rather than being remembered query by query
- Encryption in transit: everything between your device and Pillar travels over TLS/HTTPS
- Password handling: passwords are stored as one-way bcrypt hashes, and session tokens live in HttpOnly cookies that page scripts cannot read
- Stored third-party credentials: the access tokens for connected accounts — QuickBooks, Google Calendar, messaging sub-accounts — are encrypted with AES-256-GCM before they are written to the database
- Access control: every API endpoint is guarded by role, checked on each request rather than only at sign-in
- Rate limiting: requests are limited globally and per endpoint, with stricter limits on sign-in and password reset
- Audit logging: security-relevant actions are recorded with actor, timestamp, IP address, and user agent
- Input validation: inputs are validated and sanitized, HTML is cleaned to prevent cross-site scripting, and unknown request properties are rejected
- File access: uploaded files are served through short-lived signed links; storage is never publicly browsable
What we do not claim: Pillar holds no SOC 2, ISO 27001, PCI, or HIPAA certification, and we do not publish uptime guarantees, penetration test results, or a backup schedule. No system is perfectly secure, and we would rather list what is actually in place than imply an audit that has not happened.
10. How Deletion Works
When you delete a record inside the platform — a customer, a user, a piece of equipment, a time entry — it is deactivated rather than erased. It disappears from lists, searches, and reports, but the underlying row is retained so the history attached to it stays intact: the invoices that reference it still add up, and the audit trail still makes sense. Treat in-app deletion as "remove it from my working data", not as erasure.
Uploaded files are different: deleting a document or photo removes the file itself from our file storage.
Permanent erasure is available on request. Write to admin@pillarfsm.com telling us what you want erased, and we will remove it. Two honest limits: financial and transactional records may be retained where the law requires us to keep them, and copies can persist in routine backups for a period after the live record is gone.
11. Data Retention
We keep information for as long as your account is active, except where a specific window applies:
- Sales rep location breadcrumbs: each company sets its own retention window, anywhere from 1 to 365 days. A nightly job deletes breadcrumbs older than that company's window
- Audit logs: retained for the period configured on each company's account
- Canvassing records: pins, knock outcomes, notes, and property photos have no automatic expiry today. They are kept until the company that recorded them deletes them
- Messaging and call logs: kept for the life of the account, because opt-out and consent records are what demonstrate compliance with messaging rules
- Accounts that are never verified: if you sign up and never confirm your email address, the account and everything in it are deleted about two weeks after sign-up. We email a warning before that happens
- After your account ends: for 30 days after termination the account owner can ask us in writing for an export of the account's data, and we will provide it. After that window the data may be permanently deleted, except where the law requires us to keep it
- Website form submissions: demo, contact, and newsletter records are kept while we may still be in touch with you about Pillar, and are deleted on request
12. Your Privacy Rights
You can ask us to do the following with personal information about you, whoever you are and wherever in the United States you live. We are not going to make you cite a statute.
- Access: ask what personal information we hold about you and get a copy of it
- Correction: ask us to fix information that is wrong or incomplete. Most account details you can edit yourself in the platform
- Deletion: ask us to permanently erase your personal information, subject to the limits in Section 10
- A copy to take away: account owners can export customers, jobs, invoices, estimates, and the price book to spreadsheet files from inside the platform, on any account
- Stop text messages: reply with a standard opt-out keyword to any message, or ask the business that contacted you. We record the opt-out and block further messages to that number
- Stop marketing email: use the unsubscribe link in any marketing email, or write to us
How to ask. Email admin@pillarfsm.com and say what you want. Include enough for us to find you — the email address or telephone number the records are under, and the name of the business you dealt with if you are its customer.
How we check it is you. Before we hand over or erase anything we confirm the request comes from the person it concerns, or from someone authorized to act for them. Usually that means replying from the email address already on the record, or answering a question about the account that only the right person could answer. If we cannot establish that to our satisfaction, we will tell you why rather than act on a request that could expose someone else's data. We do not ask for copies of identity documents and do not want you to send them.
How quickly we respond. We aim to respond within 30 days of confirming who you are. If a request is complicated enough to take longer, we will tell you and give you a timeframe. Making a request costs nothing, and we will not treat you differently for making one.
If you are the customer of a business that uses Pillar, that business decides what is held about you. Ask them first — they can act immediately, and they know why the record exists. If you come to us instead, we will pass the request to them and tell you we have done so, unless we are legally prevented from saying anything.
We do not sell your personal information.
13. Age Requirement
Pillar is a tool for running a business. You must be at least 18 years old to create an account, be given a login, or use the platform. Our website and our software are not directed at children, and we do not knowingly collect personal information from anyone under 18. If we learn that we have, we will delete it. If you believe a minor has given us information, write to admin@pillarfsm.com.
14. Where We Operate
Pillar is a United States product. Our company, our servers, our database, and the providers listed in Section 5 operate in the United States, and information you give us is stored and processed there. Our service is offered to businesses in the United States.
We do not offer international data transfer terms, and this policy does not promise protections under the data protection laws of other countries. If you are outside the United States, or you are subject to a regime that requires such terms from your software providers, Pillar is not the right product for you, and you should not send us personal information about anyone. If you visit this website from outside the United States, your information is processed in the United States.
15. Changes to This Policy
- Every revision carries a version number and an effective date at the top of this page
- For changes that materially affect how we handle personal information, we notify account owners by email at the address on the account
- Continuing to use the platform after a change takes effect means you accept the updated policy
16. Contact Us
Questions about this policy, requests about your information, and privacy complaints all go to the same place:
Pillar Software Solutions LLC
Email: admin@pillarfsm.com
Mailing address: c/o Northwest Registered Agent LLC, 502 W 7th St, Ste 100, Erie, PA 16502, USA
Website: pillarfsm.com
We aim to respond to privacy inquiries within 30 days.