Privacy Policy

Last updated July 31, 2026

This policy explains what information LAM-OS (Living Asset Manager OS) collects, why we collect it, who we share it with, and the choices available to you. LAM-OS is a business application used by tree care and living-asset management companies to manage their own customer, site, and asset records.

1. Who we are

LAM-OS is operated by Living Asset Manager, based in Alberta, Canada. You can reach us at livingassetmanager@gmail.com.

LAM-OS is offered to organizations. When your employer or another organization invites you to LAM-OS, that organization decides what records are entered into the workspace and how they are used. We process those records to provide the service to that organization.

2. Our role depends on the information

LAM-OS handles two different kinds of information, and our responsibility is not the same for both.

Business information your organization enters. Customers, sites, assets, inspections, recommendations, photographs, work orders, visits, treatments, and the operational and billing records created by an organization are controlled by that organization. It decides what is recorded, who may see it, how long it is kept, and what it is used for. We handle that information to provide the service to them and on their instructions.

Platform information we manage ourselves. User authentication and sign-in, profiles and account administration, security and diagnostic logs, private beta access requests, platform administration records, abuse and fraud prevention, support and legal correspondence, and our internal quality-assurance and testing records are managed by us. We decide the purpose of that information, and no organization instructs us on it.

We describe this split in plain terms rather than asserting a particular legal classification. Where a request concerns business information an organization controls, we will normally need to work with that organization, as described in section 14.

3. Account and organization information

We collect the information needed to create and operate a workspace:

  • Your name, email address, and display name.
  • Your organization's name and workspace identifier.
  • Your role and permissions within the organization (for example owner, manager, or field technician).
  • Invitation records, including the email address an invitation was sent to and whether it was accepted.
  • If you request access to the private beta, the name, email address, company, phone number, organization size, and any notes you submit in that form, together with the IP address and browser user agent recorded when the form is submitted.
  • If you record professional credentials in your profile, such as a certification number and expiry date.

4. Google Sign-In

LAM-OS offers Google Sign-In as an optional way to authenticate. We request only Google's standard sign-in scopes — openid, email, and profile. If you choose Google Sign-In, Google asks for your permission and then provides:

  • Your email address and whether Google has verified it.
  • Your basic profile information, which includes your name and a link to your Google profile image.
  • A Google account identifier used to recognise you on subsequent sign-ins.

This information is stored in the account record held by our authentication provider (Supabase). From it, LAM-OS copies only your email address and a display name into your LAM-OS profile. The link to your Google profile image is retained in that authentication account record, but LAM-OS does not copy it into your profile and does not display a Google profile picture anywhere in the application.

We use this information only to create and secure your LAM-OS account, to sign you in, to match your sign-in to an existing invitation or membership, and to show your name to other members of your organization.

Google user data is used only to provide authentication and the user-facing features described in this policy. We do not sell Google user data, and we do not use it for advertising, ad targeting, or ad profiling. We do not use Google user data to train generalized artificial intelligence or machine learning models. Google user data is not sent to the optional accounting integration described in section 10.

Signing in with Google does not give LAM-OS access to your Gmail, Google Drive, Google Contacts, or Google Calendar. You can disconnect LAM-OS at any time from your Google account permissions page, and you can instead use an email-and-password sign-in.

5. Business records you enter into LAM-OS

The substance of LAM-OS is the operational data your organization records. Depending on how your organization uses the product, this can include:

  • Customers, including contact names, email addresses, phone numbers, and billing addresses.
  • Sites, including addresses and geographic coordinates.
  • Living assets such as trees, including species, measurements, condition and risk ratings, and map location.
  • Digital Passport history: inspections, assessments, notes, and other timeline events.
  • Photographs and documents uploaded against an asset, site, or job, together with any location or camera metadata the file contains.
  • Recommendations, estimates, work orders, visits, checklists, crew assignments, and time entries.
  • Treatment and plant health care records, product catalogues, inventory lots, and regulatory details such as pesticide registration numbers.
  • Billing records, including estimates, invoices, payment status, and approval signatures captured on public estimate links.
  • An audit history of who created or changed a record and when.

Much of this data describes property and vegetation rather than people, but customer contact details are personal information and are treated as such.

6. Technical information

We collect limited technical information necessary to run and secure the service, such as IP address, browser type and user agent, and application error and diagnostic logs. IP addresses are used for rate limiting on public endpoints, where they are held only temporarily and are not written to our database. An IP address is recorded and stored when a customer approves an estimate through a public link, as evidence of that approval, and when a private beta access request is submitted.

LAM-OS stores data on your device so it can work offline in the field, including a queue of changes made without a connection, cached records, and photographs waiting to upload. Signing out or clearing your browser storage clears this local data. Because signing out clears the offline queue, any changes that have not yet synchronised are discarded, so reconnect and let synchronisation finish before signing out. Application files such as page templates, scripts, and fonts may remain cached by your browser after you sign out; these contain no customer or personal information.

7. Location information

LAM-OS is used in the field, and some features can use your device's location. Your browser or device will ask for your permission the first time this happens.

  • We request your device location only when you start a location-enabled action, such as centring the map on where you are, or capturing the location of a treatment as you record it.
  • We use it to centre or orient the map and to help you place or select a site, asset, or treatment location.
  • Coordinates are saved as part of the records you create or update. In LAM-OS this can include a site's map position, an asset's position, the recorded position of a treatment, and location metadata attached to a photograph.
  • If you decline the permission, LAM-OS continues to work. You can still search for an address, pan the map, and place or adjust a location manually wherever that is supported.

LAM-OS does not track your location continuously and does not collect location in the background. Location is requested only while you are using the application and only after you begin an action that needs it. Photographs may also contain location information recorded by your camera; that metadata is part of the file you upload, and you can disable it in your device's camera settings.

8. Why we process information

  • To provide, maintain, and improve the LAM-OS service.
  • To authenticate users and keep each organization's data separated from every other organization's data.
  • To deliver the specific features your organization uses, such as mapping, scheduling, reporting, and invoicing.
  • To send service communications, including invitations, password resets, and estimate or invoice notifications.
  • To maintain audit history so that organizations can see who changed what.
  • To detect, investigate, and prevent abuse, fraud, and security incidents.
  • To comply with legal obligations that apply to us.

9. What we do not do

These statements describe how LAM-OS operates today. If any of them changes, we will update this policy and, where the change is significant, give notice as described in section 17.

  • We do not sell personal information, and we do not sell Google user data.
  • We do not run advertising in LAM-OS and have no advertising or ad-targeting integrations.
  • We do not use your data or your organization's data for advertising or ad profiling.
  • We do not operate third-party analytics, behavioural tracking, or session-recording tools in the application.
  • We do not send your organization's records to an artificial intelligence service for inference, and we do not use them to train artificial intelligence or machine learning models.
  • We do not use LAM-OS platform administrator status to browse an organization's business records: platform administration is limited to workspace, access-request, and internal testing tools, and our database access rules do not grant platform administrators visibility of an organization's customers, sites, assets, treatments, or invoices through the application.

10. Service providers and optional integrations

We rely on a small number of providers to operate LAM-OS. They process information only to provide services to us:

  • Supabase — authentication, database, and file storage for application data and uploaded photos. Our database and file storage are hosted in the United States (Amazon Web Services, US East / Ohio region).
  • Lovable — platform infrastructure for application hosting, build, and deployment; the sign-in brokering used for Google Sign-In; and the connector infrastructure through which optional third-party integrations are transmitted. The application runs on a global edge network, so the server handling a given request may be located in the country nearest to you.
  • Google — Google Sign-In, and Google Maps and Places for mapping, address search, and geocoding. Map and address searches are sent from your browser directly to Google as you use those features. Google operates globally, including in the United States.
  • Resend — delivery of transactional email such as invitations, estimates, and invoices. Resend is based in the United States.

Optional accounting integration. An organization may choose to connect its Wave accounting account. Where an organization enables it, relevant accounting information — such as customer contact details and estimate or invoice information — may be transferred to Wave, and that traffic is transmitted through connector infrastructure operated by Lovable. This integration applies only to organizations that enable it; if your organization has not connected Wave, no information is sent there. Google Sign-In information is never included in this integration.

Where your information is processed. LAM-OS is operated from Alberta, but your information is not stored in Canada. The database and uploaded files that hold your account, organization, customer, site, asset, and Digital Passport records are stored in the United States. Sign-in, email delivery, mapping, and the optional accounting connector are provided by organizations that operate in the United States and, in some cases, in other countries. Information held in another country is subject to the laws of that country and may be accessible to its courts, regulators, and law-enforcement authorities.

11. How information may be shared

  • With other members of your organization, according to the role and permissions assigned to them.
  • With your organization's own customers, where your organization sends an estimate or invoice through a shareable link. Those links show only that document and are limited in time and use.
  • With the service providers listed above, and with an optional integration your organization has connected.
  • Where required by law, legal process, or a lawful government request, or to protect the rights, safety, or property of LAM-OS, our users, or the public.
  • In connection with a merger, acquisition, financing, or sale of assets, in which case we will require the recipient to honour this policy or give you notice of any change.

We do not share personal information with third parties for their own marketing.

12. Security

We take reasonable measures to protect information in LAM-OS. Data is transmitted over HTTPS. Access to records is controlled by database row-level security policies scoped to your organization, so members of one organization cannot read another organization's data, and database-level checks reject attempts to link a record to another organization's data. Roles and capabilities limit what each member can do, changes to records are written to an audit log, and uploaded photos are stored in a private bucket and served through short-lived signed links rather than public URLs.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. We do not operate automated breach-detection or automated incident- response systems; incidents are identified and handled by people, using the audit log and our providers' logs. If we become aware of a security incident affecting personal information, we follow a written internal procedure to contain it, assess whether it creates a real risk of significant harm, and notify affected organizations, affected individuals, and the Office of the Information and Privacy Commissioner of Alberta where required by law.

13. Data retention

We retain information for as long as your organization's workspace is active and for as long as needed to provide the service. LAM-OS is designed around durable asset history: records such as inspections, treatments, completed work, time entries, and audit entries are kept as an append-only history and cannot be edited or erased in the application, because organizations rely on them for operational and regulatory purposes. A treatment record, for example, is corrected by voiding it and recording a replacement, so that both remain visible.

When a record is removed in the application it is normally marked as archived, retired, or voided rather than erased, so that history remains intelligible. We may retain information longer where we are required to do so by law or where it is needed to resolve disputes or enforce our agreements. We have not set fixed retention periods for every category of data; if you need a specific retention commitment, contact us.

14. Access, correction, export, and deletion

You can view and update much of your profile and your organization's records directly in the application. You can stop using Google Sign-In at any time and revoke LAM-OS access from your Google account.

To request access to the personal information we hold about you, to correct it, to request an export, to close a user account or an organization workspace, or to request deletion where it is available, email livingassetmanager@gmail.com. LAM-OS does not currently provide an automated self-service export or deletion tool. Requests are reviewed and carried out by us manually, and we will respond within a reasonable time and within any period required by applicable law.

Before we act on a request we need to confirm who you are and, where the request concerns an organization's records, that you are authorised to make it. If you are a member of an organization's workspace, many records were entered by that organization and belong to it. In those cases we will work with the organization, and we may direct you to them where they control the data.

It helps to distinguish the different outcomes a request can have, because they are not the same:

  • User account deactivation — your access is removed and your membership of a workspace ends. The organization's business records remain with the organization.
  • Organization workspace closure — an owner asks us to close the workspace and end access for all of its members.
  • Archiving — a record is marked archived, retired, or voided and is no longer active, but remains in the workspace history.
  • Permanent deletion — information is removed from the live system. This is possible for some information and not for others, as set out below.
  • Immutable records — append-only history such as Digital Passport events, treatment records, time entries, and audit entries cannot be altered or erased in the application by design.
  • Backups — copies may persist in encrypted backups and disaster-recovery snapshots for a period after deletion from the live system, and are overwritten on the ordinary backup cycle.

Some information may be retained after a deletion request where it is reasonably required for legal or regulatory obligations; financial, tax, and invoicing records; pesticide, treatment, and other regulated application records; security, abuse, and fraud prevention; establishing, exercising, or defending a legal claim; the integrity of audit history; immutable Digital Passport and operational history; backup and disaster recovery; or an organization's own legitimate recordkeeping. Where we cannot delete something, we will tell you what is being kept and why.

15. Canadian privacy considerations

LAM-OS is operated from Alberta, Canada. We aim to handle personal information consistent with Canadian federal and provincial private-sector privacy legislation, including the Personal Information Protection and Electronic Documents Act (PIPEDA) and Alberta's Personal Information Protection Act (PIPA).

As described in section 10, our database and uploaded files are stored in the United States, and several of our providers process information outside Canada. We remain accountable for that information while it is handled on our behalf. If you have a privacy concern or complaint, contact us first at livingassetmanager@gmail.com. You also have the right to raise the matter with the Office of the Information and Privacy Commissioner of Alberta, with the Office of the Privacy Commissioner of Canada, or with the privacy commissioner for your own province.

16. Children's privacy

LAM-OS is a business tool intended for use by adults acting for an organization. It is not directed to children, and we do not knowingly collect personal information from anyone under the age of majority in their province or territory of residence. If you believe a child has provided us with personal information, contact us and we will delete it.

17. Changes to this policy

We may update this policy as the product changes. We will revise the "last updated" date at the top of this page, and where the change is significant we will provide additional notice by email or by a notice on this page. Continuing to use LAM-OS after an update means you accept the revised policy.

18. Contact us

Questions, privacy requests, and complaints can be sent to livingassetmanager@gmail.com.