Legal
Friday Falcon Privacy Policy
This Privacy Policy explains how Ravenna Technologies LLC processes information in connection with Friday Falcon.
1. Who we are
Friday Falcon is a contractor-operations product provided by Ravenna Technologies LLC, a New Jersey limited liability company (“Ravenna,” “Friday Falcon,” “we,” “us,” or “our”). Contact us at hello@fridayfalcon.com or at 15 John St, Passaic, NJ 07055, United States.
2. Our role
Organizations use Friday Falcon to manage their contractors, workers, agreements, time, approvals, expenses, invoices, payment records and related operational data. For that Customer Content, the organization generally decides why and how information is used, and Ravenna processes it to provide the service. Ravenna separately determines how it uses account, billing, security, support and product-administration information for its own purposes. Particular legal roles may vary by jurisdiction and context, and an enterprise customer may enter a separate data processing addendum.
3. Information we process
- Account and contact information: name, email, authentication, session and organization-membership details.
- Contractor operations: profiles, teams, manager relationships, agreements, acknowledgments, compensation terms, time, schedules, time off, approvals, expenses, invoices, amount-review records, amounts owed and external payment evidence.
- Files and communications: documents, receipts, remittance evidence, support communications and information users choose to submit.
- Service and security information: configuration, permission, audit, request, error, device and operational event records needed to operate and protect the service.
- Billing information: plan, subscription, invoice, transaction and provider-reference information if paid billing is activated. A billing provider, rather than the Friday Falcon application, collects full payment-card details.
Friday Falcon is not designed to collect government identification numbers, tax identifiers, raw bank credentials, continuous location or other restricted information unless an active workflow specifically requests it.
4. Sources
We receive information from account holders, organizations and their authorized users; invited people; use of the product; configured service providers; and customer-directed integrations. An organization may provide information about a contractor before that person creates an account.
5. How we use information
- Provide, authenticate, secure and support Friday Falcon.
- Carry out Customer- and user-requested contractor workflows.
- Maintain version, approval, agreement, financial and audit evidence.
- Administer plans, billing and transactional communications.
- Prevent abuse, investigate incidents and diagnose reliability problems.
- Comply with applicable obligations and establish or defend claims.
- Improve the product using limited operational information.
We do not sell customer operational data or use confidential Customer Content for targeted advertising. Restricted financial data, credentials, agreement text, private notes and authenticated workflow content are not sent to general product-analytics systems.
6. Cookies and public-site measurement
Friday Falcon uses storage necessary to authenticate sessions and protect requests. On production public pages, Ravenna uses Vercel Web Analytics and Speed Insights only when enabled through the reviewed production configuration. The implementation excludes authenticated product routes, authentication and invitation routes, policy-acceptance routes, dynamic identifiers, query strings, fragments and sensitive workflow data. Vercel describes Web Analytics as cookieless and aggregated; Friday Falcon does not currently use PostHog.
7. When information is shared
We disclose information to providers that host, secure, communicate and operate Friday Falcon; when Customer directs an integration or disclosure; when required by law; when reasonably necessary to protect people, rights or the service; or in a corporate transaction subject to appropriate safeguards. Providers process information for the services they provide under the applicable relationship.
The Subprocessors page identifies current operational providers and separates them from planned or disabled capabilities. Supabase supports the database, authentication, private file storage and server-side data operations. Vercel supports hosting, application runtime, deployments, Web Analytics, Speed Insights and operational telemetry. Resend supports transactional email. For Companies where paid billing is enabled, Stripe Billing receives the account and subscription information needed to provide hosted checkout, subscription invoices and subscription status.
We update the Subprocessors page when the active provider set materially changes. Where an applicable data processing addendum or order form requires notice of, or an opportunity to object to, a provider change, Ravenna follows that agreement. Emergency changes may occur when reasonably necessary to protect the service or comply with law, with notice as required by the applicable agreement or law.
8. Customer-directed integrations
If Customer connects an available external system, Friday Falcon processes the information and credentials needed to carry out that instruction, and the external provider applies its own terms. A provider does not receive Customer Content merely because Friday Falcon contains disabled integration code or uses that provider in a development environment.
Connected Gmail and Microsoft mailboxes
When an authorized user chooses to connect a Gmail, Google Workspace, Outlook or Microsoft 365 mailbox for invoice email, Friday Falcon receives the provider account identifier, primary email address, display name, granted permission list, access and refresh credentials, and credential expiration information. Friday Falcon uses that information only to identify the selected sender, maintain the authorized connection, and send invoice email the user directs. Credentials are encrypted in server-only storage and are not exposed to ordinary browser code.
For a user-directed send, Friday Falcon transmits the selected recipient address, subject, message body and exact invoice PDF to Google or Microsoft. Friday Falcon keeps the connection metadata and the invoice-email command, attachment evidence, provider result, errors and reconciliation history needed to prevent duplicates, show what happened and support recovery. Friday Falcon does not request permission to read the user's inbox, contacts, files or calendar and does not use Google or Microsoft mailbox data for advertising.
Disconnecting removes Friday Falcon's usable stored credential and stops future sends through that connection. A user may also revoke Friday Falcon in the provider account. A provider may retain a sent message, delivery information or security records under the user's provider account and the provider's own terms. Provider acceptance means the provider accepted the request; it does not prove recipient delivery, opening or payment.
Friday Falcon's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
9. Retention and deletion
We retain personal information only for as long as reasonably necessary and proportionate for the purposes described in this Policy. The period depends on the type and sensitivity of the information, why it is used, the status of the account or Company workspace, Customer instructions, applicable agreements and legal requirements, and the risk of harm from continued retention.
- Customer Content: generally retained while the workspace is active and as needed to provide, secure and support Friday Falcon.
- Agreement and financial evidence: agreement versions, acceptances, approvals, invoices, payment records and related audit history may be retained as reasonably necessary to administer or enforce the applicable transaction, meet legal, tax, accounting or audit obligations, resolve disputes, and establish or defend claims.
- Ravenna billing and tax records: retained as reasonably necessary to administer billing and meet applicable legal, tax, accounting and audit obligations.
- Authentication and security records: retained based on the event, sensitivity and usefulness for operating and protecting the service, investigating incidents, and meeting applicable legal or preservation requirements.
- Support records: retained while a request is open and afterward as reasonably necessary to resolve follow-up issues or disputes, maintain relevant service history, protect the service, and meet applicable obligations.
- Failed or quarantined uploads: may be retained temporarily for retry handling, troubleshooting or security review. Ravenna does not promise one fixed period for every upload or provider.
A Company administrator may request a review of Company data, and individuals may submit privacy-right requests as described below. Submitting a request does not itself delete information or establish a deletion date. We verify identity and authority and, for Customer-controlled content, may refer the request to or coordinate with the Customer that controls it. We respond within the period required by applicable law or agreement and explain the action taken, any material limitation, and any information retained under an applicable exception.
Provider and backup handling varies by service, configuration, record type, contract and law. After eligible information is removed from an active system, residual copies may remain until the applicable provider process is completed. Such copies are not used for ordinary product operations. Ravenna does not promise one backup-deletion period across all providers.
We may preserve limited information to the extent reasonably necessary and proportionate to comply with law; perform a contract or complete a requested transaction; establish, exercise or defend legal claims; protect the security and integrity of the service; prevent fraud or illegal activity; or comply with a documented legal hold. Information retained under an exception is restricted to that purpose where reasonably practicable. A controlling data processing addendum or order form may provide additional requirements but cannot reduce rights that applicable law does not permit the parties to waive. Corrections to signed, financial, approval and security evidence are recorded without silently altering prior evidence.
When Ravenna reports that an active-system deletion is complete, it means the eligible information covered by that statement has been removed from Ravenna’s active systems and applicable providers have been instructed to take corresponding action. Ravenna separately identifies known information retained under an exception and known residual backup limitations. Nothing in this section authorizes retention or refusal beyond applicable law or a controlling agreement.
10. Security
Ravenna uses administrative, technical and organizational safeguards designed for the nature of the information processed. Controls include authenticated access, server- and database-enforced workspace authorization, private file handling, scoped short-lived file access, separated credentials and auditable evidence for important actions. No service can guarantee absolute security. See Security for current boundaries and reporting guidance.
11. Processing geography and transfers
The primary Supabase production project is configured in the U.S. East region, and Friday Falcon targets Vercel’s U.S. East runtime for the reviewed production deployment. Providers, support operations and customer-directed integrations may nevertheless process information in the United States and other locations where they operate.
Ravenna will use applicable provider data-processing terms and legally recognized transfer safeguards where required. Contact Ravenna at hello@fridayfalcon.com regarding an applicable customer data processing addendum.
12. Access, correction, deletion and other choices
To request access, correction, deletion, portability or another privacy right, email hello@fridayfalcon.com. Identify the account or organization and the request, but do not send identity documents, passwords, authentication codes, bank details or tax identifiers by ordinary email.
We may verify identity and authority using a proportionate secure method. When an organization controls the information, we may refer the request to that organization or assist it in responding. We respond within the period required by applicable law, subject to lawful exceptions and retention duties. The Data Requests page explains the intake route and current product limits.
13. Children
Friday Falcon is intended for business use by adults and is not directed to children under 13. Accounts may be accepted only by people who are at least 18. Contact us if you believe a child provided personal information without appropriate authorization.
14. Changes
This Privacy Policy identifies its version and effective date. We may update it as Friday Falcon and its data flows change and will provide notice where required. A material new production provider or restricted data flow must be reviewed before this policy describes it as active.
15. Contact
Ravenna Technologies LLC
15 John St
Passaic, NJ 07055
United States
Email: hello@fridayfalcon.com
Website: FridayFalcon.com