← back to sign in
Legal

Dashboard Privacy Policy

Last updated: October 9, 2026

This Privacy Policy describes how NovraScale LLC d/b/a Brevard Booked ("Brevard Booked," "we," "us," or "our") collects, uses, and protects information processed through Brevard Booked at my.brevardbooked.com (the "Portal"). It covers the Portal only. Data collected from visitors to our public marketing site is covered by the separate brevardbooked.com Privacy Policy.

1. Who This Applies To

This policy applies to individuals we invite to sign in to the Portal, typically the owners and staff of a Brevard Booked client business.

2. Information We Collect

Account information

Name, email address, password (hashed, so we never see it in plain text), role, and organization, collected when we invite you and create your account.

Authentication & security logs

Sign-in timestamps, IP address, and device/browser metadata, retained for account security and fraud detection.

Preferences

Notification settings you choose during onboarding (e.g. which events you want emailed to you).

Portal usage

Which pages and features you use inside the Portal, collected to provide support and improve the product.

Your business data

The Portal displays data about your own website and marketing systems, sourced from tools Brevard Booked operates on your behalf: website analytics, search performance, your Google Business Profile activity and reviews, page speed tests and uptime checks, and leads submitted through your site's forms. This may include personal information of your own customers or prospects (name, email, phone, message) and, from your Google reviews, a reviewer's first name and what they wrote. For that data, you are the data controller and Brevard Booked processes it solely on your behalf, as directed by you, in order to display it in the Portal.

3. How We Use Information

  • Operate, maintain, and secure the Portal
  • Authenticate accounts and enforce access controls
  • Send transactional notifications you opted into (e.g. new lead, uptime alert)
  • Respond to support requests you submit through the Portal's Requests feature
  • Diagnose issues and improve the Portal

4. Sub-Processors & Sharing

We do not sell your information or your customers' information, and we do not share it for third-party advertising. The Portal relies on the following sub-processors to operate:

  • Supabase: database, authentication, and file storage, with per-tenant row-level security
  • Resend: delivery of transactional and notification email
  • Google: read-only access to your Analytics, Search Console and Business Profile data, including reviews, and PageSpeed speed tests, via the Google APIs, to show your own performance
  • UptimeRobot: checks that your website is reachable; it sees only your public web address
  • Cloudflare: hosting, CDN, and DDoS protection
  • Sentry: error monitoring. When the Portal hits an error, a crash report (the error, its stack trace, and basic request details such as the page address and browser type) is sent to Sentry. We configure it to avoid sending personal information, and we strip request bodies, cookies, and headers on sign-in and webhook routes

5. Data Retention

Account and usage data is retained for the duration of your engagement, plus a limited period afterward to support the transition assistance described in Section 7 of the Master Terms, after which it is deleted or anonymized. Leads and records we keep for you are kept while we work together and exported to you under the Master Terms; data we read from your own accounts stays under your retention settings there.

6. Security

Data is encrypted in transit (TLS) and at rest. Per-tenant isolation is enforced with database row-level security, so one client's data is not visible to another. Account creation is invite-only. There is no public sign-up path into the Portal.

7. No Handling of Protected Health Information

The Portal is not designed to store or transmit Protected Health Information (PHI). If your business is a healthcare or health-adjacent operator, do not enter PHI into any Portal field, including Requests or notes.

8. Cookies

The Portal uses the strictly necessary session cookie set by our authentication provider to keep you signed in, plus two preference cookies that remember your theme and your sidebar choice. We do not use advertising or cross-site tracking cookies inside the Portal.

9. Your Rights

You may request access to, correction of, or deletion of your own account data by emailing privacy@brevardbooked.com or contacting your Brevard Booked representative.

Requests concerning your own customers' or prospects' personal information displayed in the Portal should be directed to your business, as the data controller for that information. Your business can in turn reach Brevard Booked to fulfill any such request.

10. Children

The Portal is a business tool intended for use by adults acting on behalf of a business. It is not directed to, and should not be used by, anyone under 18.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be posted on this page with a revised "last updated" date.

12. Contact

Questions about this policy? Email privacy@brevardbooked.com.