Legal
Privacy Policy
How Navon collects, uses, and protects your information, on our website and in the platform.
Last updated: August 25, 2026.
Introduction
Navon Solutions LLC (“Navon,” “we,” “our,” or “us”) runs an operational system of record. Organizations put their projects, approvals, documents and financial records into it, and a good deal of that is personal information about their people and the people they work with. We take that seriously, and this policy is where we say exactly what we do with it rather than asking you to take our word for it.
It covers what we collect, what we use it for, who else sees it, how it is protected, and how long we keep it, across both:
- our marketing website at https://www.usenavon.com (the “Website”), and
- the Navon platform at app.usenavon.com and its related services and subdomains (the “Platform”).
Your commercial relationship with Navon is governed separately by the Monthly Usage Fee Terms, the Build Fee Terms, or a signed agreement between us. This policy describes how data is handled, not commercial terms.
Our role: two different relationships
Two different things are going on, and they carry different obligations. For information collected through the Website, and for the account details of Platform users, Navon decides why and how it is used. In data protection terms we are the controller of that information.
For the operational content your organization puts into the Platform (records, documents, financial data, and any personal information contained in them, together “Customer Data”), your organization decides what is collected and why. We process it on your organization's instruction in order to run the service, and nothing more. It is your organization's data, not ours. We do not mine it, sell it, or put it to any purpose of our own beyond operating, securing and supporting the Platform.
If you are an individual whose information appears in a customer's Navon workspace, for example a vendor contact, a subcontractor, or a project participant, the organization that entered that information is responsible for it, and requests about it should be directed to that organization. We will refer the request and assist them in responding.
Information we collect
From Website visitors
- Information you voluntarily provide through a form: name, email address, company name, phone number, and the content of your enquiry.
- Information collected automatically: IP address, browser type and version, device information, pages viewed and time spent, and referring URLs.
From Platform accounts
- Account and identity information: name, email address, the organization you belong to, your role and permissions, your settings and preferences, and a profile picture if you upload one.
- Authentication information. Passwords are held by our authentication provider and are never stored by us in readable form. If you sign in with Google, we receive the basic identity information Google returns for sign-in, and never your Google password.
- Security and activity records: sign-in and password-reset events, including the IP address and browser user agent associated with them, and an activity log of actions taken on records in your workspace.
- Usage information: pages viewed within the Platform and product analytics events, used to operate, secure, and improve the service.
Customer Data stored in the Platform
The Platform is an operational system of record. What it holds is determined by your organization, and includes:
- Organization and project records: organizations, members and invitations, projects and project membership, schedules, deadlines, daily reports, notes, and permit and insurance details.
- Operational records: RFIs, change orders, approvals and approval steps, workflows, and any custom record types your organization defines, with the fields and statuses you configure.
- Financial records: invoices, purchase orders, job cost codes and job cost ledger entries, budget and cost data, and the approval history attached to them.
- Documents and files: files your organization uploads or syncs, together with their names, types, sizes, and the records they are linked to.
- Communications: messages and comments recorded against projects and records, notifications sent, and email delivery records.
- Information about people who are not Navon users: details your organization enters about third parties, including vendor and subcontractor contact names, email addresses and phone numbers, client and project contacts such as project managers and superintendents, and, where your organization uses those features, candidate and staffing records.
- AI conversation data: described in the AI processing section below.
Some fields, including uploaded documents, imported email content, and free-text and custom fields, can contain whatever your organization or a third party places in them. We do not inspect or classify that content.
The Platform does not collect or store payment card numbers, bank account or routing numbers, government identification numbers, Social Security numbers, or dates of birth. Payment details for your Navon subscription are collected and held by our payment processor; we receive a customer reference and the status of your subscription.
Data from connected third-party accounts
The Platform can connect to accounts you already hold with other providers. A connection is only ever established by an administrator of your organization, through that provider's own authorization screen, and it can be disconnected at any time from the Platform's integration settings. We request the narrowest permissions that allow the feature to work. What we receive, and what we do with it, is set out per provider below.
Google Drive
- Permission requested: https://www.googleapis.com/auth/drive.file. This grants access only to the specific files and folders you select for Navon. It does not grant access to the rest of your Google Drive.
- What we receive: the identifiers of the files and folders you select, the file name and last-modified time, and the contents of those files.
- What we store: a copy of the file is downloaded into Navon's own document storage so it can be linked to your records and viewed inside the Platform. Google-native formats (Docs, Sheets, Slides) are converted to a standard document format when copied. We also store the Google file identifier so the copy can be matched back to its source.
Google Calendar
- Permission requested: https://www.googleapis.com/auth/calendar.readonly. Read-only. Navon does not create, change, or delete anything in your calendar.
- What we receive and store: event titles, descriptions, and start and end times, which become schedule items in your workspace.
Google Sign-In
If you choose to sign in with Google, we receive the basic identity information Google provides for authentication, which we use to identify your account.
Intuit QuickBooks Online
- Permission requested: com.intuit.quickbooks.accounting, together with the identifier of the QuickBooks company you authorize.
- What we receive and store: when you connect a QuickBooks company, Navon retrieves bills, invoices, vendors, customers, and chart-of-accounts entries that have changed, and uses them to create and update invoice and vendor records in your Navon workspace. Vendor and customer details are used to identify and label those records. We store the QuickBooks identifier of each item so it can be matched to its Navon record.
- Navon reads from QuickBooks. It does not post entries back into your accounting file.
Access credentials
Access and refresh tokens for connected accounts are encrypted before they are stored, and are never exposed to other organizations, to other users, or anywhere in the Platform interface. See Security below.
Limited use of connected-account data
When you connect an outside account, the data we get from it is used for one thing: running the feature you connected it for, and keeping that feature working and secure. Nothing else. To be specific about what that rules out:
- We do not sell it, and we do not transfer it to third parties except to the sub-processors listed below that operate the service on our behalf, where you direct us to, or where the law requires it.
- We do not use it for advertising of any kind, and we do not use it to serve, target, or measure advertising.
- We do not use it to train or improve any artificial intelligence or machine learning model. This applies without exception, and no opt-in changes it.
- Our personnel do not read it, except where you have asked us to (for example, a support request), where it is necessary for security purposes or to comply with the law, or where the data has been aggregated and anonymized.
Navon's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
AI processing
The Platform includes AI features, which we call Nova. Nova cannot work without reading your records, and answering a question means sending some of them to an outside model provider. That is worth being direct about, so this section sets out which features do it, what leaves the Platform when they run, and what happens to it afterwards.
Where AI is used, and what is sent
- Nova chat. When you ask Nova a question, we send your message, the recent messages in that conversation, your first name and role, your organization's name, the page you are on, facts Nova has previously saved about how you work, and the records Nova retrieves in order to answer. Those records can include RFIs, change orders, invoices, documents, projects, and the names of team members.
- Record summaries. Selected fields from a change order, RFI, or invoice, including project name, vendor name, amounts, dates, and status, are sent in order to produce a short summary.
- Document and invoice import. When an invoice is imported, the invoice file itself is sent to a model provider so that its contents can be read and turned into a record.
- Inbound email intake. Where your organization has enabled email intake, the subject and body of messages sent to your Navon intake address are sent to a model provider so the request can be classified and turned into a record.
- Help search. The text of your question is sent to a model provider so that matching help articles can be found.
Who the providers are
AI processing is performed by Anthropic, OpenAI, and NVIDIA, depending on the feature and the model in use. Each is listed as a sub-processor below. Data reaches them through their commercial APIs.
What is kept
Nova conversations, the messages within them, the facts Nova saves about how you work, and any actions Nova proposes are stored in your organization's workspace so that you can return to them. Conversation history is deleted on the schedule described under Retention. You can delete saved facts at any time from your Nova settings.
Model training
We do not use your data to train AI models. Navon builds no models and fine-tunes none, so there is nothing for your records to be absorbed into.
The providers we send your data to are held to the same line by their own contracts. Anthropic's commercial terms state that Anthropic may not train models on customer content. OpenAI states that data sent to its API is not used to train or improve its models unless the customer opts in, and we have not.
If we ever offer a programme that uses your data to make Nova work better for your own organization, it will stay off until you switch it on, and we will tell you exactly what it covers before you do. Data from a connected account is never part of it, and is never used to train a model under any circumstances.
Your controls
- AI features can be switched off for an entire organization, in which case no data is sent to a model provider.
- Nova's ability to write to records is controlled separately from its ability to read them, and stays off unless your organization enables it.
- Nova can only read what the signed-in user is already permitted to see. It does not have a wider view of your data than you do.
How we use your information
- To provide, operate, maintain, and support the Platform
- To authenticate users and secure accounts
- To respond to inquiries and contact requests
- To communicate with you about Navon services
- To send transactional and service messages, including notifications, approvals, and account emails
- To bill for the service and manage subscriptions
- To monitor reliability and performance, diagnose faults, and improve the product
- To analyze usage trends and business metrics
- To comply with legal obligations
We do not sell or rent your personal information to third parties.
Mobile information and SMS messaging
When you provide your phone number through our Website or intake forms, we may use it to contact you by phone or text message (SMS) about your inquiry and our services. Message frequency varies, and message and data rates may apply. You can opt out of text messages at any time by replying STOP, or reply HELP for assistance.
We do not share or sell mobile information or SMS opt-in and consent data to third parties or affiliates for marketing or promotional purposes. No mobile information will be shared with third parties for their own marketing purposes. Mobile data may be shared only with the service providers that help us operate our messaging program (such as our SMS provider), and only as needed to deliver that service.
Data sharing and disclosure
Navon may share information only in the following circumstances:
- With the sub-processors listed below, who assist in operating the Website and the Platform, under confidentiality obligations
- To comply with legal requirements, court orders, or lawful requests
- To protect the rights, property, or safety of Navon or others
- In connection with a merger, acquisition, or sale of assets, in which case we will give notice before Customer Data becomes subject to a different privacy policy
We do not share personal information for marketing purposes without consent.
Sub-processors
We use the following service providers to operate the Website and the Platform. Each is bound by confidentiality obligations and may use the data only to provide services to us.
| Provider | Purpose | Data it can access |
|---|---|---|
| Supabase | Database, file storage, and authentication (US East, Ohio) | All Platform data, including documents and account identities |
| Vercel | Application hosting and delivery, and website analytics | Data in transit through the application, and usage telemetry |
| Anthropic | AI model processing | Content submitted to AI features, as described above |
| OpenAI | AI model processing and help search | Content submitted to AI features, as described above |
| NVIDIA | AI model processing | Content submitted to AI features, as described above |
| Resend | Transactional email delivery | Recipient addresses and the content of emails we send |
| Sentry | Error monitoring and diagnostics | Error reports and the technical context attached to them |
| Stripe | Subscription billing and payment processing | Billing contact details, and payment information you provide to Stripe directly |
| Sign-in, and the Drive and Calendar connections you authorize | Only the account data you grant, as described above | |
| Intuit | The QuickBooks Online connection you authorize | Only the accounting data you grant, as described above |
| HubSpot | Our own sales and marketing records, Website enquiries only | Name, email, and company submitted through Website forms. No Platform data. |
This list is kept current on this page. If you would like advance notice of changes to it, contact us and we will add you.
Data security
We implement reasonable administrative, technical, and organizational safeguards to protect information from unauthorized access, misuse, loss, or disclosure. In particular:
- Encryption in transit. All traffic to the Website and the Platform is encrypted with TLS, and browsers are instructed to refuse unencrypted connections to our domains.
- Encryption at rest. The database and the file storage holding Platform data are encrypted at rest by our infrastructure provider.
- Connected-account credentials. Access and refresh tokens for third-party connections are additionally encrypted by Navon using AES-256-GCM before being written to the database, with a key held outside the database. They are readable only by the service that uses them, and are never returned to a browser or to another organization.
- Access control. Access to Customer Data is limited to authorized personnel who need it to operate and support the service.
- Application hardening. We enforce a content security policy, strict transport security, and clickjacking and content-type protections, and we rate-limit password reset and our AI endpoints.
While we strive to protect your data, no method of transmission over the internet or electronic storage is completely secure. Navon cannot guarantee absolute security.
Tenant isolation and data residency
Navon is a multi-tenant service, and separation between customers is enforced in the database itself. Tenant-scoped tables carry row-level security policies keyed to organization membership, so a query made on behalf of a signed-in user can only return rows belonging to organizations that user is a member of. Isolation does not depend on application code remembering to filter.
Within an organization, access is further limited by the role assigned to each member, and members with view-only roles cannot write.
Platform data, including the database and all uploaded and synced documents, is stored in the United States, in our infrastructure provider's US East (Ohio) region. Sub-processors listed above may process data in other locations in the course of providing their services.
Data retention and deletion
As a rule, we keep information for as long as we need it to run the service and for as long as your account is active, unless the law requires us to keep it longer. In more detail:
| Data | How long we keep it |
|---|---|
| Records, documents, and financial data | Kept while your organization's account is active |
| Anything you delete in the Platform | Marked deleted straight away and removed from everyday use. Erased permanently when your account closes, or sooner if you ask |
| AI conversation history | Deleted automatically after 90 days by default. Your organization can change this window |
| Facts Nova has saved about how you work | Until you delete them, or the account closes |
| Operational, security, and email delivery logs | Kept while we need them to run and secure the service, and to meet our legal obligations |
| Website enquiries | Kept while we are in contact with you about your enquiry, and deleted on request |
| After your subscription ends | 30 days to export your data, then we delete it |
You can ask us to delete your organization's data at any time, and we will action the request within 30 days. Deletion is permanent. We may keep a limited record where the law requires it, for example a billing record retained for tax purposes.
When you disconnect a connected account
Disconnecting a third-party account has two distinct effects, and we want to be precise about both.
- We revoke the authorization with the provider where the provider supports revocation, and we delete the stored access and refresh tokens immediately. No further data is retrieved from that account.
- Records and documents already brought into your workspace are kept. They have become part of your organization's operational record, and removing them would delete work your team relies on. If you want them removed, you can delete them in the Platform, or ask us to delete them for you.
Your privacy rights
Depending on your jurisdiction, you may have rights regarding your personal information, including the right to:
- Access the data we hold about you
- Request corrections or updates
- Request deletion of your information
- Object to or restrict certain processing
- Withdraw consent where applicable
To exercise these rights in relation to the Website or your Navon account, contact us using the information below. Where a request concerns Customer Data held in an organization's workspace, that organization is responsible for responding, and we will refer the request to them and assist them in answering it.
Cookies and tracking technologies
Navon uses cookies and similar technologies to keep you signed in, to remember your preferences, and to understand how the Website and Platform are used.
Cookies help us:
- Keep your session active and secure
- Understand user behavior
- Improve site navigation
- Optimize content and functionality
You can control or disable cookies through your browser settings; however, doing so may prevent you from signing in or otherwise affect functionality.
Third-party services
The Website may contain links to third-party websites or tools. Navon is not responsible for the privacy practices or content of third-party sites. We encourage you to review their privacy policies before providing personal information. This is separate from the connected accounts and sub-processors described above, which are governed by this policy.
Children's privacy
Navon is a business product and is not intended for use by individuals under the age of 13. We do not knowingly collect personal information from children.
Changes to this privacy policy
Navon may update or modify this Privacy Policy. Any changes will be posted on this page with a revised date at the top. For material changes affecting Customer Data or our sub-processors, we will give notice before the change takes effect.
Contact
If you have questions or concerns regarding this Privacy Policy or how your information is handled, please contact us at: