Privacy
Last updated 21 September 2026.
Kordyn is software that appliance-repair businesses use to run their work: appointments, technicians, customers, invoices. This page says what it stores, who else sees it, how long it is kept, and how to have it removed. It is written to be read rather than to be survived.
Two different roles
A repair business decides what goes into its own account — its customers, its jobs, its notes. For those records the business is in charge and we hold them on its behalf, and we do not use them for anything other than running the service for that business. For the accounts of the people who sign in, and for anything sent through this website, the decisions are ours.
So if you are a customer of a repair business that uses Kordyn and you want your details corrected or removed, ask that business: it is their record, and they can change it themselves. If they need us, we will help them.
What is stored
- The people who use Kordyn
- name, email address, telephone number, role, the hash of a password, and when the account was last signed in to — to sign somebody in, to show colleagues who did what, and to let a business see which of the seats it pays for are being used.
- A business's own customers
- name, address, telephone number, email address, and any notes the business writes about them — they are the records of the business using Kordyn — the appointments, the visits and the invoices are about them.
- The work itself
- appointments and their history, the machines being repaired, checklists, photographs taken on site, a customer signature, notes between the office and the technician — it is the job record: what was promised, what was done, and what was billed.
- Money
- invoices, estimates, amounts, payment method, and the identifiers Stripe gives a payment — to bill and to record what was paid.
- The phone
- a push-notification token for each device that signs in, and the device platform — so a technician is told when a job they are on changes.
- This website
- what a demo request or a sign-up form carries: name, email address, company name, telephone number, message — to reply to it, and to know which plan somebody asked about when they wrote.
- How a company found us
- the campaign, referral or advertisement-click parameters carried by the link somebody followed to this site — recorded once, when they sign up, and only when a link carried them — to know which of our own advertisements and referrals brought a business here, and later to tell that advertising platform that a click became a customer.
What is not
- Card numbers — Stripe takes those directly, and the product only ever sees the payment identifier it returns.
- A technician's location. The app records when work started and stopped; it does not follow a phone around.
- Advertising or cross-site tracking. There are no third-party analytics or advertising scripts on this site or in the app.
We do not sell data, and we do not share it with anybody except the services below, which are the ones doing the work you asked for.
Who else it reaches
- Cloudflare — carries every request to the service, and stores photographs, signatures and invoice PDFs in its object storage.
- Stripe — takes card payments and runs the subscription; card details are entered into Stripe and never reach us.
- Resend — delivers the email the product sends — invoices, receipts, appointment reminders and password resets.
- Expo — delivers push notifications to a technician’s phone.
- Sentry — receives error reports from the web console when a deployment turns it on; it is off unless configured.
How long it is kept
- Sign-in sessions
- a session ends when it is replaced or signed out; the record of it is deleted a week later
- Push-notification tokens
- deleted after ninety days without the device signing in
- The link a customer is emailed for their own job
- stops working ninety days after it is created
- Backups
- the last fourteen nightly copies are kept on the server, and copies off-site are deleted after ninety days
- A business's records
- kept until the business deletes them or closes its account — they are its records, not ours
Keeping it safe
Traffic is encrypted in transit. Passwords are stored as bcrypt hashes and never in a form anybody can read back. Sessions are short-lived and refresh tokens rotate, so a stolen one that is reused signs every session out rather than quietly continuing. Each business's data is separated by account, and that separation is checked automatically before every release. No system is perfect; this is what we do rather than a promise that nothing can go wrong.
Your choices
You can ask us what is held about you, ask for it to be corrected, ask for it to be deleted, or ask for a copy. A business using Kordyn can also export its own records at any time from the console, without asking anybody — including the customer, invoice and payment files, which are not behind a paid plan for exactly this reason.
Deleting an account is its own page: how to delete your account and data.
Children
Kordyn is a tool for businesses and is not meant for children. We do not knowingly collect anything from anybody under 16.
Changes
When this page changes, the date at the top changes with it. If a change affects what we do with data already held, we will say so to the businesses using Kordyn rather than only editing this page.
Contact
Write to [email protected]. We answer within 30 days, and usually much sooner.