Privacy Policy
Effective Date: September 25, 2026
This Privacy Policy explains how Village Home Cleaning LLC, doing business as Serviche (“Serviche,” “we,” “us,” or “our”), collects, uses, discloses, retains, and protects information in connection with Sergio, including sergio.serviche.com, related software, APIs, integrations, artificial intelligence features, and services (collectively, the “Service”). Sergio is the name of the product and is not a separate legal entity.
This Policy applies to businesses and authorized users who interact directly with Serviche and, where applicable, to individuals whose information Serviche processes on behalf of a business using Sergio (a “Customer”).
1. Our Roles
Account Data
“Account Data” is information relating to businesses and individuals who directly create, administer, purchase, evaluate, or use the Service or communicate with Serviche. For Account Data, Serviche generally determines the purposes and means of processing and acts as the business, controller, or equivalent entity under applicable privacy law.
Customer Data
“Customer Data” is information a Customer submits to, connects to, transmits through, or instructs the Service to process on its behalf. For Personal Information in Customer Data, the Customer generally determines why and how the information is processed, and Serviche generally acts as the Customer’s service provider, contractor, processor, or equivalent entity.
If your information was provided to Sergio by a business with which you interacted, that business’s privacy notice also applies and that business is generally responsible for responding to your privacy and communication requests.
2. Information We Collect and Sources
2.1 Account and Business-Relationship Information
We may collect names, business names, business and mailing addresses, email addresses, telephone numbers, login and authentication information, billing and subscription information, account settings, authorized-user information, communications with us, support requests, demonstration or beta-participation information, and other information provided directly to us.
Sources include Customers, authorized users, prospective Customers, payment providers, referrals, and other parties that communicate with us.
2.2 Customer Data
Depending on Customer configuration, Customer Data may include names, telephone numbers, email addresses, service addresses, appointment and scheduling information, service history, text messages, emails and other communications, quotes and estimates, invoices and transaction information, payment-related instructions, customer preferences, employee or contractor information, operational records, and information obtained from Customer-authorized integrations.
Sources include Customers, their authorized users, individuals who communicate or transact with those Customers, and systems and integrations the Customer authorizes.
2.3 Information Collected Automatically
When someone accesses or uses the Service, we may collect IP address, browser and device type, operating system, login and authentication events, pages and features accessed, timestamps, referring information, API activity, usage volume, diagnostic and crash information, security events, cookie or local-storage identifiers, and other technical and operational information.
2.4 Information from Integrations and Providers
When a Customer connects the Service to another platform, we receive information from that platform as authorized by the Customer. Integrations and providers may include communications, scheduling, CRM, payment, accounting, payroll, email, artificial intelligence, analytics, authentication, hosting, monitoring, and other business services.
2.5 Google User Data
This Section describes how Sergio handles information received from Google APIs (“Google user data”). Where it conflicts with any other part of this Policy, this Section controls for Google user data.
Data we access. When a Customer connects a Google account, Sergio requests only the following Google permissions: (a) Gmail read access, to read email messages in the connected mailbox, including their content, headers, labels, and attachments; (b) Gmail send access, to send email from the connected mailbox; and (c) basic account information, meaning the email address of the connected Google account. Sergio does not request permission to modify, organize, or delete email, and does not access Google Drive, Calendar, Contacts, or other Google services through this connection. Sergio also stores limited derived data it creates from Gmail messages, such as which client or job a message relates to, whether it needs a reply, and short summaries shown in the workspace.
How we use it. We use Google user data only to provide and improve the user-facing features the Customer has enabled: showing the connected mailbox’s email in the Customer’s workspace alongside its texts and calls; matching messages to the Customer’s clients and jobs; identifying messages that need a response; drafting replies for the Customer’s staff to review; sending replies the Customer’s authorized users approve, and messages the Customer has configured Sergio to send on its behalf to its own clients; and showing which Google account is connected. We do not use Google user data for advertising, retargeting, or interest-based advertising, to determine creditworthiness or for lending, to build profiles unrelated to the Customer’s use of the Service, or to sell to data brokers or any other party.
Who we share it with. We do not sell Google user data. We share it only with the following types of parties, and only as needed to provide the features described above: (a) infrastructure providers that host and store the Service, currently Vercel (application hosting) and Supabase (database); (b) artificial-intelligence model providers that process message content to classify messages, summarize them, and draft replies, currently Anthropic, OpenAI, and Google (Gemini API), each under API or enterprise terms that prohibit using the data we send to train their models; (c) authorized users of the Customer’s own Sergio account; and (d) others where required by applicable law, to protect the security of the Service, or as part of a merger, acquisition, or sale of assets, with prior notice to the Customer. Google user data is never shared with other Customers.
AI and machine learning. Sergio’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data, whether raw, aggregated, anonymized, or derived, to develop, improve, or train generalized or non-personalized artificial-intelligence or machine-learning models, and we do not transfer it to any AI provider that uses it to train its models.
Human access. Our personnel do not read Google user data except with the Customer’s express consent for a specific support request, as necessary for security purposes such as investigating abuse or a vulnerability, to comply with applicable law, or where the data has been aggregated and anonymized for internal operations and is used in accordance with this Section.
How we protect it. Google user data is encrypted in transit using TLS and encrypted at rest in our database. Google OAuth access and refresh tokens are additionally encrypted at the application level with a key held only by the Service. Every record is scoped to the Customer’s organization and protected by row-level access controls, so one Customer’s data cannot be read by another. Access to production systems is limited to authorized personnel who need it, protected by multi-factor authentication, and logged.
Retention and deletion. We keep Google user data only while the Customer’s Google account remains connected or the Customer continues to use the Service, and only as long as needed to provide the features described above. A Customer can disconnect a Google account at any time from Sergio’s settings or from the Google Account permissions page (https://myaccount.google.com/permissions). On disconnection, we immediately delete the stored access and refresh tokens, stop Gmail notifications, and stop accessing the account. Email already synced into the workspace remains available to the Customer until the Customer asks us to delete it. A Customer can request deletion of all Google user data we hold by emailing c@serviche.com (see Section 19); we delete it from active systems within 30 days of the request or of account termination, and from backups as they expire in the ordinary course, which is no later than 90 days. Section 7 (Aggregated and De-Identified Data) does not apply to Google user data.
3. How We Use Account Data
We may use Account Data to:
- create and administer accounts and authenticate users;
- provide, support, bill for, maintain, and improve the Service;
- communicate about accounts, requests, demonstrations, subscriptions, updates, and security;
- understand usage, test features, conduct research, and develop products;
- protect the Service, detect fraud or abuse, and investigate security events;
- enforce agreements, establish or defend legal claims, and comply with law; and
- conduct ordinary business operations, including accounting, audit, financing, and corporate transactions.
4. How We Process Customer Data
We process identifiable Customer Data primarily to provide the functions requested and configured by the applicable Customer, including:
- responding to communications and generating Customer-authorized messages;
- booking, rescheduling, scheduling, and dispatch;
- generating quotes, estimates, payment-related instructions, reports, and operational records;
- executing Customer-configured workflows and integrations;
- providing support and troubleshooting for the Customer;
- preventing fraud, abuse, and security incidents and maintaining the Service; and
- complying with law and the Customer’s documented instructions.
The Customer is responsible for its purposes for collecting Personal Information, its legal basis for using the information, its privacy notices, and consents or authorizations required from its customers, prospects, employees, contractors, and other individuals.
5. Artificial Intelligence and Automated Processing
5.1 AI Processing to Provide the Service
The Service uses artificial intelligence, machine learning, and automated systems. Identifiable Customer Data may be processed by AI systems to understand a request, generate a response, identify available appointments, prepare a quote, retrieve relevant business information, select a workflow, evaluate the Service for the Customer, or perform another Customer-authorized action.
AI systems can make mistakes. Customers are responsible for configuring automations, maintaining appropriate human oversight, and reviewing material outputs and decisions.
5.2 Training and Improving AI Systems
We may use properly Aggregated and De-Identified Data to develop, train, fine-tune, test, evaluate, secure, and improve artificial intelligence and machine-learning systems; create benchmarks; conduct research; and develop products and services.
Unless a Customer separately and expressly agrees in writing, we do not use identifiable Customer Data or the contents of identifiable Customer communications to train generalized artificial-intelligence models for use by unrelated Customers. We may use identifiable Customer Data to evaluate, troubleshoot, secure, or improve the Service provided to that Customer when consistent with our agreement and applicable law.
5.3 Significant Decisions
Serviche does not intend to use Account Data to make solely automated decisions that determine an individual’s eligibility or access in employment, housing, education, lending, credit, insurance, healthcare, or another area producing legal or similarly significant effects. Customers are responsible for their own decisions and uses of the Service. Where Serviche is legally required to provide additional notice, access, or opt-out rights concerning automated decisionmaking, we will do so.
6. How We Disclose Information
We may disclose Personal Information to:
- service providers and subprocessors that support hosting, databases, artificial intelligence, communications, authentication, security, monitoring, analytics, payment processing, billing, and customer support;
- third-party services and integrations selected or directed by a Customer;
- authorized users of the Customer account that controls Customer Data;
- professional advisers, auditors, insurers, financing sources, and transaction counterparties subject to appropriate confidentiality obligations;
- government authorities, courts, or other recipients when we reasonably believe disclosure is required by law or necessary to protect rights, safety, property, security, or the Service; and
- a buyer, successor, or other participant in a merger, acquisition, financing, restructuring, bankruptcy, sale of assets, or transfer of the Sergio business.
When a provider processes identifiable Customer Data on our behalf, we use contractual commitments or enterprise terms designed to restrict processing to authorized purposes, require confidentiality and security, and prohibit the provider from using Sergio-submitted identifiable Customer Data to train generalized or foundational models for the provider’s independent purposes.
7. Aggregated and De-Identified Data
We may use technical, organizational, and statistical measures to aggregate, anonymize, or de-identify information. Measures may include removing direct identifiers, masking or transforming identifiers, separating identifying information from operational information, generalizing data, combining records, and applying thresholds designed to reduce identification risk.
“Aggregated and De-Identified Data” means information that has been processed using reasonable measures so that it does not reasonably identify a Customer, authorized user, individual, or household and is not Personal Information under applicable law.
We publicly commit to maintain information we treat as de-identified in de-identified form and not intentionally attempt to re-identify it, except as permitted by law solely to evaluate whether our de-identification processes are effective. Where required by law, we contractually require recipients to maintain the information in de-identified form and not attempt re-identification.
To the maximum extent permitted by law and our contracts, we may retain Aggregated and De-Identified Data indefinitely and use, analyze, combine, disclose, license, distribute, commercialize, monetize, and otherwise exploit it for lawful purposes, including analytics, industry benchmarking, research, statistics, product development, artificial-intelligence and machine-learning training, model evaluation, and commercial products and services. These uses may continue after a Customer account is terminated or identifiable information is deleted. This Section 7 does not apply to Google user data described in Section 2.5.
Shared Systems. Sergio includes a library of operating systems (such as automated checks, workflows, procedure rules and training lessons) that Customers can view and adopt. We may create a Shared System from the systems a Customer configures after removing or generalizing information that identifies the Customer, its users, its personnel, its clients or prospects, or any location, and after automated checks designed to detect names, contact details, addresses, prices and other identifying details. A system that cannot be verified is not shared. We show how a Shared System performs only in aggregate, and only once at least three businesses other than its contributor use it. We never include in a Shared System, or show to other Customers, messages, calls, emails or their contents; client, prospect or personnel records; names, phone numbers, email addresses, street addresses or prices; photos, attachments or files; payment or financial information; or which Customer contributed it. Shared Systems are Aggregated and De-Identified Data under this Section 7. See Section 9A of the Terms of Service.
8. Sale, Sharing, and Targeted Advertising
We do not sell identifiable Personal Information for monetary or other valuable consideration. We do not sell identifiable Customer Data. We do not share identifiable Personal Information for cross-context behavioral advertising or use identifiable Customer Data for targeted advertising.
Use or commercialization of Aggregated and De-Identified Data is not intended to constitute a sale or sharing of Personal Information. If our practices materially change, we will update this Policy and provide any notice, consent, or opt-out rights required by law.
9. Data Retention
We retain Personal Information only for as long as reasonably necessary and proportionate for the purposes described in this Policy, as required by our agreements, or as otherwise permitted or required by law. The retention period depends on the nature and sensitivity of the information, the duration of the Customer relationship, the functions enabled, legal and contractual requirements, security and fraud-prevention needs, backup cycles, and the time needed to establish, exercise, or defend legal claims.
9.1 Account Data
We generally retain Account Data for the Customer relationship and afterward for periods reasonably necessary for billing, tax, audit, support, security, dispute resolution, contract enforcement, and legal compliance.
9.2 Identifiable Customer Data
We retain identifiable Customer Data while needed to provide the Service and as directed by the Customer. Following termination or a valid deletion instruction, we delete or de-identify identifiable Customer Data within a commercially reasonable period, subject to legal retention duties, security and fraud records, dispute or litigation holds, and backups that remain protected and expire in the ordinary course. Data in backups will not be restored for ordinary business use except for disaster recovery, security, or legal purposes.
9.3 Aggregated and De-Identified Data
Deletion of Personal Information does not require deletion of information that has already been properly aggregated or de-identified. We may retain and use Aggregated and De-Identified Data indefinitely as described in Section 7.
10. Cookies, Online Tracking, and Preference Signals
We may use cookies, local storage, and similar technologies to authenticate users, maintain sessions, remember settings, protect security, prevent fraud, measure performance, diagnose problems, and understand use of the Service. Service providers may collect technical information through these technologies for those purposes. We do not authorize those providers to use identifiable Customer Data for cross-context behavioral advertising.
Legacy browser “Do Not Track” signals are not standardized, and the Service does not currently respond to them. Where required by law, we recognize legally valid opt-out preference signals, such as the Global Privacy Control, for processing subject to an applicable opt-out right. Because we do not currently sell or share Personal Information or use it for targeted advertising, such a signal may not change our current practices.
Where applicable law requires consent before non-essential technologies are used, we will request that consent. Users may also control cookies through browser settings, although disabling essential technologies may impair the Service.
11. Data Security
We use administrative, technical, and organizational safeguards designed to protect Personal Information against unauthorized access, destruction, loss, alteration, misuse, or disclosure. These may include access controls, authentication, encryption, monitoring, logging, infrastructure controls, vendor requirements, and internal restrictions.
No method of transmission, storage, or processing is completely secure, and we cannot guarantee absolute security. Customers are responsible for their accounts, credentials, authorized users, endpoints, connected systems, and integrations.
12. Privacy Rights and Requests
Depending on location and our role, an individual may have rights to access, know about, correct, delete, or obtain a portable copy of Personal Information; opt out of certain sales, sharing, targeted advertising, or profiling; limit certain uses of sensitive Personal Information; withdraw consent where processing is based on consent; and appeal a decision concerning a request. These rights are subject to applicable exceptions and verification requirements.
12.1 Account Holders and Direct Contacts
If Serviche controls your Account Data, submit a request by emailing c@serviche.com with the subject “Privacy Request” or by writing to the address in Section 19. We may request information reasonably necessary to verify your identity and authority. An authorized agent may submit a request where permitted by law, but we may require proof of authority and direct verification with the individual.
12.2 Individuals Associated with a Customer
If your information is processed through Sergio for a business with which you interacted, submit privacy, deletion, correction, communication opt-out, and similar requests directly to that business. Because Serviche generally acts on the Customer’s instructions, we may direct you to the Customer, notify the Customer, or assist the Customer as required by law and our agreement.
12.3 Appeals and Non-Discrimination
Where applicable law provides an appeal right, you may appeal by emailing c@serviche.com with the subject “Privacy Appeal” and explaining the basis for the appeal. We will not discriminate against an individual for exercising an applicable privacy right.
13. U.S. State Privacy Notice
To the extent a comprehensive U.S. state privacy law applies to Serviche, this Section supplements the rest of the Policy. During the preceding 12 months, depending on use of the Service, we may have collected the following categories of Personal Information:
- identifiers, such as names, email addresses, phone numbers, business addresses, IP addresses, account identifiers, and authentication information;
- customer-record and commercial information, such as service history, subscriptions, invoices, quotes, estimates, and transaction information;
- internet or electronic-network activity, such as login, device, browser, feature-use, API, diagnostic, and security information;
- location information, such as business or service addresses and approximate location derived from IP address;
- professional or employment-related information concerning authorized users, employees, or contractors;
- communications, including support messages and, when processed for a Customer, texts, emails, and other communication contents;
- sensitive Personal Information, such as account credentials, message contents, payment-related information, or precise service-location information when included in Customer Data; and
- inferences generated from other information, such as workflow classifications, customer preferences, or operational predictions.
We collect these categories from the sources described in Section 2, use them for the business and commercial purposes described in Sections 3 through 5, and disclose them to the categories of recipients described in Section 6. We do not sell these categories or share them for cross-context behavioral advertising. We use sensitive Personal Information only for providing requested services, security, fraud prevention, legal compliance, and other purposes permitted without a right to limit; if that changes, we will provide the required choice.
Where California law applies, California residents may exercise the rights to know, access, correct, delete, and obtain information about use and disclosure; opt out of sale or sharing; limit certain uses of sensitive Personal Information; and receive equal treatment. Serviche has not sold or shared Personal Information as those terms are defined by the California Consumer Privacy Act during the preceding 12 months and does not offer a financial incentive for Personal Information.
The business-to-business and employee exemptions under California law have expired, so Account Data relating to business contacts and authorized users may be covered when the law applies. Submit requests using the methods in Section 12. We will confirm and respond within the periods required by applicable law.
14. International Processing
Serviche and its providers may process information in the United States and other countries where they operate. Those jurisdictions may have privacy laws different from the laws where an individual resides. Where applicable law requires a transfer mechanism or contractual safeguard, we will use an appropriate mechanism.
15. Children
The Service is a business-to-business product and is not directed to children. We do not knowingly collect Personal Information directly through Sergio accounts from children under 13. Customers are responsible for ensuring that any Customer Data involving a minor is collected and processed lawfully and for obtaining any required parental authorization. If you believe a child provided Personal Information directly to Serviche without appropriate authorization, contact us at c@serviche.com.
16. Sensitive and Regulated Information
Customer Data may contain information considered sensitive under applicable law. We process sensitive Personal Information only as necessary to provide the Service, follow Customer instructions, maintain security, prevent fraud, comply with law, or for another permitted purpose. Customers should not provide sensitive information that is unnecessary for their use of the Service.
Unless we expressly agree otherwise in writing, the Service is not designed to process protected health information subject to HIPAA, consumer-report information subject to the Fair Credit Reporting Act, or other information requiring specialized regulatory agreements.
17. Third-Party Services
The Service may link to or integrate with third-party websites, applications, and platforms. Those third parties operate under their own privacy policies and terms. We are not responsible for their independent privacy, security, or data practices, except to the extent required by law or an agreement governing a provider acting on our behalf.
18. Changes to This Policy
We may update this Policy as the Service, business, or law evolves. If we make material changes, we will provide notice through the Service, by email, through an account notice, or another reasonable method. The Effective Date indicates when the Policy was last updated.
We will not retroactively use identifiable Personal Information for a materially different purpose, including generalized AI-model training, in a manner inconsistent with prior commitments unless we provide any additional notice or obtain any consent required by law.
19. Contact Us
Questions and requests concerning this Policy may be sent to:
Village Home Cleaning LLC d/b/a Serviche
418 Broadway, Suite N
Albany, NY 12207
United States
Email: c@serviche.com
If your request concerns information controlled by a business using Sergio, please contact that business directly. If you contact us, identifying the relevant business may help us route your request.
© 2026 Village Home Cleaning LLC. All rights reserved.