1. Agreement and business use
These Terms of Service govern access to PermitOps software, websites, and related services provided by Vanity Labs LLC, located in Philadelphia, Pennsylvania ("PermitOps," "we," "us," or "our"). "Customer" or "you" means the business accepting these Terms. An "Order" means a mutually accepted order form, checkout order, or statement of work identifying purchased services and commercial terms.
By expressly accepting these Terms or signing an Order incorporating them, you enter this agreement for your business. The individual accepting represents that they are at least 18 and authorized to bind that business. PermitOps is offered for business use, not personal, family, or household use.
A separately signed agreement controls over conflicting provisions of these Terms. An Order controls for its service scope, fees, subscription term, and expressly identified changes. A data processing agreement ("DPA") controls conflicting terms about its subject matter. Our Privacy Policy explains our handling of personal information and does not expand the rights to use Customer Data granted here.
2. Software and permit services
During the applicable subscription, we grant you a limited, nonexclusive, nontransferable right to use the purchased software for your internal business operations, within the users, projects, usage limits, and other entitlements stated in your Order.
Permit preparation, submission, coordination, and management services are included only when identified in an Order. That Order should identify the jurisdiction and project, deliverables, customer inputs, approval responsibilities, service fees, government fees, and any included revisions or follow-up work. Additional work requires mutual agreement.
PermitOps is not a government agency. Agencies control their requirements, fees, review times, inspections, and decisions. We do not guarantee permit approval, a particular approval date, or acceptance of any filing. Estimates and status information may depend on third-party systems and may become outdated. Our software and administrative services do not constitute legal, architectural, engineering, or other licensed professional advice.
3. Filing authority and customer responsibilities
For ordered submission services, you authorize us to act as your administrative representative only within the agreed scope and your documented instructions. You must obtain required owner, applicant, or other third-party permissions and supply any agency-specific authorization. These Terms alone do not authorize us to sign a professional certification, owner attestation, or other document requiring separate authority or a licensed professional.
You are responsible for the accuracy, completeness, lawful use, and timely delivery of customer-provided information. You must review and approve filings where the Order or law requires, respond to requests, maintain required licenses, and pay authorized government charges. We remain responsible for performing our agreed services with reasonable care.
Unless the Order assigns a deadline or monitoring task to us, you retain responsibility for that task. Customer delays or changes may affect delivery dates and require an agreed scope or fee adjustment. Submitted information may become accessible through government records or disclosure processes, depending on applicable rules; our confidentiality obligations do not control an agency's handling of a filing.
4. Accounts and acceptable use
You will maintain accurate account and billing information, designate authorized administrators, protect credentials, and promptly notify us of suspected unauthorized access. You are responsible for users you authorize and for managing their access when their roles change.
You must not use the services to violate law or another person's rights, submit fraudulent filings, introduce malicious code, bypass access controls or usage limits, access another customer's information without permission, or materially disrupt the services. You may not resell the software or reverse engineer it except as expressly permitted by us or applicable law. Security testing requires our prior written authorization and an agreed scope.
5. Fees, renewals, and cancellation
Your Order states the applicable subscription fees, billing interval, usage charges, service fees, and payment timing. You authorize charges to the payment method provided for amounts due under that Order. Taxes and government or third-party charges are additional unless expressly included; we remain responsible for taxes on our income.
A subscription renews automatically only if renewal terms are disclosed and accepted when purchased. Where authorized, it renews for the stated interval until cancelled before the next renewal. You may cancel through available account controls or by contacting danahtetaungbiz@gmail.com. Cancellation ordinarily takes effect at the end of the current paid subscription term. We will notify you of renewal price changes at least 30 days before they take effect; you may cancel before the affected renewal.
Subscription, usage, prepaid-credit, and managed-service fees are nonrefundable, including for unused subscription periods, unused credits, cancelled work, or an agency's delay or denial, except where required by applicable law or expressly provided in a separately signed agreement or Order. Cancellation does not create a refund or credit or eliminate amounts properly due. We will correct duplicate, erroneous, or unauthorized charges. This policy does not exclude remedies or payment-dispute rights that cannot lawfully be excluded.
An Order for prepaid AI or usage credits must disclose their price, consumption method, any expiration, and nonrefundability before purchase. We will not impose an undisclosed credit expiration retroactively. Unless the Order states otherwise, credits do not expire while the associated subscription remains active; access to unused credits ends when that subscription terminates without a refund, subject to the exceptions above.
If you cancel managed services, the Order determines any remaining fees and authorized nonrecoverable third-party costs. Funds held solely to pay government or third-party charges on your behalf are not our service fees. We will return unused funds and any amounts recovered on your behalf; charges already paid to a third party are subject to that recipient's refund rules. The no-refunds policy does not allow us to retain those unused or recovered customer funds as additional compensation.
We will give notice and a reasonable opportunity to resolve an overdue payment before suspending service, except where immediate action is justified under section 10. Cancellation does not erase valid amounts already incurred.
6. Ownership and Customer Data
"Customer Data" means information, documents, drawings, communications, prompts, and other materials you or your authorized users provide to the services, together with project-specific information and records we receive or create on your behalf through authorized integrations or performance of the services. It includes imported project correspondence and submission receipts, but excludes our underlying software and technology. As between you and PermitOps, you retain your rights in Customer Data. You grant us a limited right to host, copy, transmit, and process it as needed to provide and secure the agreed services, support you, follow your authorized instructions, and comply with law, subject to this agreement and any DPA.
You represent that you have the rights and permissions needed to provide Customer Data and instruct its processing, including information about employees, property owners, applicants, and other individuals. This does not relieve us of our own obligations as a service provider.
We retain ownership of the software, documentation, templates, technology, and improvements. Subject to third-party rights, you may use deliverables and outputs supplied for your project for your business purposes. You may voluntarily provide feedback; we may use that feedback without payment, but this permission does not authorize disclosure of Customer Data or confidential information.
7. AI, integrations, and sensitive information
Some features use AI or third-party service providers to process information and generate outputs. When you use those features or order a service that includes them, relevant Customer Data may be processed to perform the requested task, subject to our Privacy Policy, any DPA, and the applicable provider disclosures. AI outputs can contain inaccuracies or omissions and require appropriate human review before filing or reliance. No output replaces an agency determination or qualified professional judgment.
We will not use or permit our service providers to use Customer Data to train general-purpose AI models. We will limit information sent to AI providers to what is necessary for the requested feature and will not send full payment credentials, government ID images, or Social Security numbers to general-purpose AI features. Relevant documents must be redacted before that processing. Human review remains required for consequential filing decisions.
We will limit AI-provider retention of transient request content to no more than 30 days, using shorter available retention settings where appropriate, except where retention is legally required. Conversations and outputs saved in PermitOps follow section 11. Provider identities, permitted data categories, and processing practices must be disclosed in the applicable privacy and subprocessor information.
Provide only information necessary for the relevant workflow. IDs, Social Security numbers, and financial information should be supplied only where specifically requested for an authorized service and through designated collection methods. Do not place payment credentials in ordinary document uploads, prompts, support messages, or free-text fields. Use the designated payment process. These restrictions do not diminish our responsibility to protect information we receive.
You control whether to connect third-party accounts and must have authority to grant the requested access. Separate provider terms may apply. We are not responsible for third-party decisions or outages outside our control, but remain responsible for our contractual obligations concerning providers we engage to process Customer Data.
8. Confidentiality, privacy, and security
Each party will protect the other's nonpublic information that is identified as confidential or reasonably understood to be confidential, including Customer Data. A receiving party may use it only to perform or exercise rights under this agreement and may disclose it only to personnel, advisers, and service providers who need access and are subject to suitable confidentiality duties.
This obligation does not cover information the receiving party can demonstrate became public without breach, was already lawfully known, was independently developed, or was lawfully received without restriction. Legally required disclosure is permitted; where lawful, the receiving party will provide notice and limit disclosure to what is required.
We will maintain reasonable administrative, technical, and organizational measures appropriate to the Customer Data processed. We will notify the affected Customer without undue delay after becoming aware of a security incident involving unauthorized access to, disclosure, alteration, loss, or destruction of Customer Data in systems under our responsibility, provide available information and reasonable cooperation, and comply with applicable law and any more specific DPA obligations. A separate signed SLA or security addendum controls any additional commitments.
Where required by applicable law or mutually agreed, the parties will enter a DPA specifying processing instructions, subprocessors, security, incident assistance, retention, and other relevant obligations. No provision guarantees absolute security or represents that a particular audit or certification has been completed.
9. Service commitments and disclaimers
We will perform managed services with reasonable care and skill, and the purchased software will materially conform to the documentation applicable to that subscription. Notify us promptly of a material failure. We will use reasonable efforts to correct it or reperform the affected service. If we cannot do so within 30 days after notice, you may terminate the affected service. The refund policy in section 5 applies; nothing here excludes remedies that cannot lawfully be excluded.
Except for express commitments in this agreement and to the extent permitted by law, the services and AI outputs are provided without other warranties, including implied warranties of merchantability, fitness for a particular purpose, and noninfringement. We do not promise uninterrupted or error-free operation. These disclaimers do not reduce express confidentiality, data-protection, or service obligations, or rights that cannot lawfully be excluded.
10. Suspension and termination
We may suspend affected access when reasonably necessary to address a material security threat, unlawful activity, a material breach, or overdue payment after the notice described in section 5. We will limit suspension where reasonably practicable, provide notice unless legally prohibited or likely to worsen the threat, and restore access when the grounds are resolved.
Either party may terminate an affected Order for a material breach the other party fails to cure within 30 days after written notice, or immediately if the breach cannot reasonably be cured. The refund policy in section 5 applies without excluding other available contractual remedies or remedies that cannot lawfully be excluded. An Order may state additional termination rights. Termination of a software subscription does not automatically cancel separately ordered permit work; that work follows its Order and section 5.
When a managed-service engagement ends, we will promptly provide available submission receipts and project records, identify known outstanding filings, agency requests, and deadlines, and state when our monitoring and authority to act end. You assume responsibility for subsequent action from that point unless another arrangement is agreed. Any additional transition work and charges require agreement. Ending an engagement does not itself withdraw an existing filing or reverse an agency action.
11. Data return and deletion
We retain Customer Data while reasonably needed to provide your active ordered services. For each set of records, the periods below begin when the last active service that needs those records terminates or expires. Cancelling a software subscription does not trigger deletion of records still needed for separately active permit work, and ending permit work does not delete records still needed for an active software subscription.
You may request an export of available Customer Data for 30 days after that service end date. We will provide reasonable assistance, subject to identity and authority verification and any agreed charges for custom work. We will complete a timely requested standard export before scheduled deletion.
Except for the limited exceptions below, we will delete Customer Data from active systems no later than 60 days after the relevant service end date. Residual backup copies will expire no later than 90 days after active-system deletion, so they may remain for up to 150 days after the relevant service ends. Backup copies remain protected and restricted to recovery purposes; restored copies will have applicable deletions reapplied before ordinary use.
We apply these narrower retention rules and recordkeeping exceptions:
- Government ID images and Social Security numbers: remove or redact them from active systems within 30 days after the specific authorized purpose requiring them ends, including during an active subscription, unless retention is required by law. This shorter period does not promise later export of already deleted sensitive information. Residual backups follow the 90-day expiry limit after active deletion.
- Billing and transaction records: retain only necessary invoices, amounts, dates, tax information, and transaction references for seven years from the transaction date. This does not authorize retaining full payment credentials, ID images, or SSNs for ordinary billing records.
- Contract and filing-authority evidence: retain a minimal record of accepted terms, customer authorization, and submission receipts for seven years after the relevant Order ends, with unnecessary sensitive identifiers removed. This exception does not extend to entire project document sets or mailboxes.
- Security and access logs: retain necessary event metadata for 12 months from creation. Logs should not contain document bodies, full prompts, payment credentials, ID images, or SSNs.
- Legal obligations and disputes: retain specifically necessary records for the required period or a documented legal hold, restrict their use and access, and delete them when the obligation or hold ends unless another stated retention period still applies.
After a recordkeeping period ends, we will delete the affected records from active systems; residual backups follow the same 90-day expiry limit. Applicable law, an agreed DPA, or a valid deletion request may require earlier action or a specifically justified different period. Government records and copies independently controlled by customers or third parties are outside our deletion control. Providers processing information on our behalf remain subject to our applicable contractual deletion obligations. You should retain your own copies of essential project and filing records.
12. Liability
To the extent permitted by law, neither party is liable under this agreement for indirect, special, incidental, consequential, exemplary, or punitive damages, or lost profits, arising from the services, even if advised of their possibility.
Each party's aggregate liability arising from this agreement will not exceed the greater of $100 or the total fees paid or payable by Customer under the affected Orders during the 12 months before the event giving rise to the claim. Related claims do not multiply this limit.
These exclusions and limits do not apply to fraud, willful misconduct, gross negligence, or liability that cannot lawfully be excluded or limited. The aggregate cap does not reduce Customer's obligation to pay properly incurred fees. This section applies regardless of the legal theory of a claim and is subject to any different allocation expressly agreed in a signed Order or DPA.
13. Third-party claims
You will defend us against a third-party claim that Customer Data supplied by you infringes that party's rights, or that your instruction to submit a filing lacked required authority, and pay resulting finally awarded damages or an approved settlement, to the extent caused by that infringement or lack of authority. This obligation does not apply to the extent a claim results from our breach, unauthorized modification, negligence, or misconduct.
We must promptly notify you of the claim, reasonably cooperate at your expense, and allow you to control the defense. You may not settle a claim imposing an admission, payment obligation, or nonmonetary obligation on us without our written consent, which we will not unreasonably withhold. Section 12 applies to this obligation.
14. Changes, notices, and general terms
We may update these Terms prospectively. We will provide at least 30 days' notice of material changes. For an existing paid term, material changes take effect at renewal or when separately accepted, except changes required sooner by law. Updated terms will state their effective date. Changes requiring express consent will not take effect for you until that consent is obtained.
Pennsylvania law governs this agreement, excluding conflict-of-law rules. Subject to mandatory law, courts with jurisdiction in Philadelphia, Pennsylvania are the agreed venue for disputes. The parties will first try in good faith to resolve a dispute after written notice; this does not prevent urgent court relief or suspend legal filing deadlines.
Neither party may assign this agreement without the other's written consent, except to an affiliate or in a merger or sale of substantially all relevant assets if the successor assumes the obligations. Neither party is liable for delays caused by circumstances beyond its reasonable control, provided it takes reasonable steps to mitigate them; this does not excuse accrued payment duties or eliminate data-protection obligations.
The parties are independent contractors, except for the limited filing representation expressly authorized in an Order. This agreement creates no general agency, partnership, employment, or joint venture. If a provision is unenforceable, the remaining provisions continue to apply. Failure to enforce a provision is not a waiver. These Terms and applicable Orders and addenda constitute the agreement for their subject matter. Provisions intended to survive, including payment obligations, confidentiality, data handling, ownership, liability, and dispute provisions, survive termination.
15. Contact
Vanity Labs LLC — PermitOps
1717 West Berks St
Philadelphia, Pennsylvania
Email: danahtetaungbiz@gmail.com
We may send account and contractual notices to your designated administrator or billing contact. Maintain current contact information. You may send legal notices to the contact above.