Privacy Policy
Last updated: October 2, 2026
The short version.
- We collect what is needed to run All Hands Ops: your sign-in details, what your company enters into its workspace, and basic billing and technical information.
- We do not sell personal information, and we do not use it for advertising.
- Each company's workspace is private to that company. Within a company, admins see everything; regular users see their own personnel record, not other people's.
- A few providers handle data for us (hosting, sign-in, payments, email). They are listed below.
1. Who we are
All Hands Ops is operated by [legal business name to be added] ("we", "us"). This policy covers allhandsops.com and the All Hands Ops application.
2. Two kinds of information, two roles
Your account with us. If you sign up, sign in, or pay for a plan, we decide how that information is used, as described here.
What a company puts in its workspace. Companies use All Hands Ops to keep records about their own operations and people, such as crew names, contact details, and certifications. That information belongs to the company, and we handle it on the company's instructions. If your employer or client uses All Hands Ops and you have a question about your record, or want it corrected or removed, ask that company's admin first; they can change or delete it directly.
3. What we collect
| Information | Examples | Why |
|---|---|---|
| Sign-in details | Email address, name, a password (stored only in scrambled form by our sign-in provider), or your Google account's name and email if you use "Continue with Google" | To sign you in, keep your account secure, and show who did what |
| Workspace records | Company name, logo, and contact details; assets; jobs, including client names and email addresses; job safety analyses and sign-offs; quotes and invoices; daily logs and entries; maintenance work orders; personnel records including name, job title, phone, email, start date, and certifications with expiry dates | To provide the service to that company |
| Who has access | Which email belongs to which company, and whether it is an admin or a regular user | To keep each company's data private and apply permissions |
| Billing | Plan, billing period, payment status, and a Stripe customer reference. Card details are entered on Stripe's pages and are not received or stored by us | To charge for plans and apply plan limits |
| Technical information | IP address, browser and device type, dates and times of requests, and error logs | To run, secure, and fix the service, and to block abuse |
| Messages to us | Emails you send us | To answer you |
We do not ask for, and the service is not meant to hold, government ID numbers, health information, or payment card numbers. Please do not enter them in free-text fields.
4. How we use it
- To provide the service: showing and saving your company's records, enforcing who can see and change what, and applying your plan.
- To send emails a company asks us to send to its own clients: daily reports, quotes, and invoices. These carry the company's name, and replies go to the company.
- To send service emails: invitations, email confirmation, password resets, certification reminders to the person concerned, a weekly summary and end-of-day reports to a company's admins, and notices about billing or changes to the service.
- To keep the service secure, prevent abuse, and fix problems.
- To meet legal obligations, such as keeping billing records.
We do not sell personal information, share it for advertising, or use it to build profiles. We do not send marketing email without your agreement.
5. Who can see workspace data
- Only people the company's admins have given a login to.
- Admins can see and change all of the company's records, including every personnel record.
- Regular users can see assets, jobs, logs, JSAs, and maintenance, but not quotes or invoices, and their own personnel record. They cannot see other people's personnel records.
- We access workspace data only when needed to run, secure, or fix the service, or when the company asks us for help.
6. Providers that help us
These companies process information for us so the service can run. They may only use it to provide their service to us.
| Provider | What it does for us | What it handles |
|---|---|---|
| Google (Firebase, Google Cloud) | Sign-in, the database, backups, server code, and checks that requests come from real browsers (reCAPTCHA) | Sign-in details, all workspace records, technical information |
| Stripe | Your subscription; and, if you connect your own Stripe account, your clients' invoice payments, which go straight to that account | Billing contact, payment card, payment history. Your clients' card details are entered on Stripe's pages and never reach us. |
| Resend | Sending email | Recipient email addresses and the content of the emails listed in section 4 |
| US Census Bureau geocoder; OpenStreetMap (Nominatim) | Finding a job's location on the map for Today's Route | The text of a job's Location (usually a street address), sent from our servers, without names or other details |
| OpenStreetMap (map images); cdnjs by Cloudflare (the map's code) | Showing the map on Today's Route, only when you open it | IP address and browser type when the map loads |
| Netlify | Hosting the website | Technical information such as IP address |
| Google Fonts | The typefaces used on our pages | IP address and browser type when the fonts load |
Data is stored in the United States. We may also disclose information if the law requires it, to protect people's safety or our legal rights, or as part of a sale or reorganization of the business, in which case this policy continues to apply to it.
7. Cookies and storage in your browser
We do not use advertising or tracking cookies. The app stores information in your browser to keep you signed in and to keep a copy of your workspace so pages load quickly and work through brief connection drops. Our sign-in and security providers (Google, including reCAPTCHA) and Stripe's payment pages set their own cookies as needed for sign-in, security, and fraud prevention. The public demo saves its sample data only in your own browser.
If you allow it, Today's Route uses your device's location to put the day's jobs in order by distance. Your location is used only on your device; it is not sent to us or stored.
8. How long we keep it
- Workspace records are kept for as long as the company keeps its workspace. Records an admin deletes are removed from the live database right away.
- Backups are kept for up to 8 weeks and then overwritten, so deleted information can remain in backups for that long.
- After a workspace has been read-only or cancelled for 90 days, we may delete it. A company can ask us to delete it sooner.
- Billing records are kept for as long as tax and accounting rules require.
9. Security
Data is encrypted in transit and at rest. Access rules are enforced on the server, so one company cannot read another's data. Passwords are never stored in readable form. No system is perfectly secure; if we learn of a breach that affects your information, we will tell the affected companies without undue delay, and as the law requires.
10. Your choices and rights
- Your record at a company: ask that company's admin to correct or delete it, or to remove your login.
- Your own account or workspace: admins can edit, export, and delete records in the app, and can ask us to delete the whole workspace.
- Depending on where you live, you may have legal rights to see, correct, delete, or get a copy of your personal information, and to object to some uses. To make a request, contact us using the details below. We will not treat you differently for making one.
11. Children
All Hands Ops is a business tool for adults. It is not directed to children, and we do not knowingly collect information from anyone under 18.
12. Changes to this policy
We may update this policy. If a change is significant, we will tell each workspace's admins by email or in the app before it takes effect. The date at the top shows when it was last updated.
13. Contact
[legal business name and mailing address to be added]
Email: [contact email to be added]