Privacy Policy
Effective: September 1, 2026
This policy explains what Coordinator (operated by Coordinator, "we", "us") collects, why, and what control you have. We've written it to be read, not skimmed past. The short version: your business data belongs to you and your organization; we collect what's needed to run the service; we never sell personal data; and the money-moving services you connect run on your own accounts, not through ours.
1. What we collect
- Account data — name, email address, password (stored hashed), optional phone and avatar, and your public profile fields if you enable a profile.
- Organization content — the data you and your organization create in the product: contacts, invoices and other financial records, projects and tasks, messages, records and files, schedules, and settings. This content is controlled by your organization; we process it to provide the service.
- Connected-service credentials — if you connect your own providers (payments such as Stripe, PayPal or Wise; video such as Google Meet, Zoom or Teams; calendar such as Google or Microsoft; mail servers; SMS providers; AI keys), we store the tokens or credentials needed to act on your behalf, encrypted at rest. They are used only to perform the actions you configure and are never shown back in full.
- Usage and log data — technical logs (IP address, browser type, timestamps, actions) kept for security, rate limiting, abuse prevention and debugging.
- Cookies — we use cookies for sign-in sessions and interface preferences (such as theme). We do not use third-party advertising cookies.
2. How we use it
- To provide, maintain and secure the service.
- To perform the actions you configure with your connected providers.
- To send service messages (for example invoices and reminders your organization configures, sign-in and security notices).
- To prevent abuse: rate limiting, spam prevention and fraud detection on public surfaces.
- To improve the product using aggregate, de-identified usage patterns.
We do not sell personal data. We do not use your organization's content to train AI models. Where AI features run, they run against the AI provider account you connect, under that provider's terms.
3. Sharing you control: how cross-organization features work
Coordinator is built for collaboration between organizations, and sharing is always an explicit act. When your organization shares work with another organization (or sends a network invoice), only the specific synced fields described in the product cross the boundary; your internal data — costs, time entries, private records, internal notes — does not. Hosted pages you send (invoices, estimates, forms, booking pages, portals) show the recipient exactly what the page displays. Public profiles show only the fields you mark public. Ending a collaboration leaves each side with its own copy of its own data.
4. Who else touches the data (subprocessors)
We use a small set of infrastructure providers to run the service — hosting and database infrastructure, email delivery for service messages, and error monitoring. A current list is available on request at support@coordinator.one. Providers you connect (your Stripe, your Zoom, your Twilio, your AI key) are your own relationships under their terms; we pass data to them only to perform the actions you configure.
5. Legal bases (EEA/UK users)
Where GDPR or UK GDPR applies, we process personal data on these bases: performance of a contract (running the service you signed up for), legitimate interests (security, abuse prevention, product improvement), consent where required (optional communications), and legal obligations. Your organization is the controller of the business content it puts into the service; we act as processor for that content and as controller for account and usage data.
6. Retention and deletion
We keep data while your account or organization is active. If you delete your account or organization, we delete or de-identify associated data within a reasonable period, except where retention is required for legal, security or accounting-integrity reasons (for example, records another organization holds of documents you sent them — their copy of an invoice you issued remains theirs, exactly as a paper invoice would).
7. Your rights
You can access, correct, export and delete your data. Export is built into the product; for anything you can't do in-app, email support@coordinator.one. EEA/UK users additionally have rights of restriction, objection and portability, and the right to complain to a supervisory authority. We respond to verified requests within the timelines the applicable law requires.
8. Security
Server-enforced, role-based permissions on every action; connected-provider credentials encrypted at rest; audited actions; rate-limited public surfaces; and unguessable high-entropy tokens for hosted pages. See our security overview for detail. No system is perfectly secure; if we learn of a breach affecting your personal data, we will notify you as the applicable law requires.
9. International transfers
The service is operated globally; data may be processed in countries other than yours. Where required, we rely on appropriate safeguards such as standard contractual clauses.
10. Children
The service is for business use and not directed to children under 16. We do not knowingly collect their data.
11. Changes and contact
If we change this policy materially, we'll notify you in the product or by email before the change takes effect. Questions or requests: support@coordinator.one.