Privacy Policy
This Privacy Policy explains how SacredOps ("SacredOps," "we," "us") collects, uses, and shares information when you use the SacredOps platform and website (the "Service"). By using the Service, you agree to this Policy.
Business vs. worker data. SacredOps is a business tool. When a contractor ("Customer") uses the Service to manage their crew, the Customer decides what worker information to enter and is the "controller" of that data; we process it on the Customer's behalf. Workers should direct requests about their information to their employer first.
1. Information We Collect
- Account & company info — name, email, phone, company name, company code, subdomain, role, and password (stored only as a secure hash).
- Customer Data you enter — worker profiles, certifications and documents, safety and compliance records, forms and permits, toolbox talks, sign-ins, inspections, schedules, incident reports (which may include injury details and body-location information), signatures, and project details.
- Billing info — subscription and plan details. Card payments are handled by Stripe; we receive limited billing metadata (e.g., plan, status, last four digits) but not full card numbers.
- Lead / contact info — if you request a demo, we collect the name, email, and (if provided) phone you submit.
- Usage & device data — pages viewed, actions taken, approximate location (from IP), browser and device type, and similar analytics.
2. How We Use Information
- To provide, operate, secure, and improve the Service and generate your documents/PDFs.
- To process subscriptions and payments, and to send transactional messages (receipts, account and billing notices).
- To respond to support requests and, where you've expressed interest, to send marketing you can opt out of.
- To understand usage and improve the product, and to detect fraud, abuse, and security issues.
- To comply with legal obligations.
3. Cookies, Analytics & Session Recording
We use cookies and similar technologies, including:
- Essential cookies — for login sessions and core functionality.
- Google Analytics (GA4) — to measure traffic and usage. Google may set cookies and process data per its own policies.
- Microsoft Clarity — we partner with Microsoft Clarity to capture how you use and interact with our website through behavioral metrics, heatmaps, and session replay to improve our products and advertising. Website usage data is captured using first- and third-party cookies and other tracking technologies to determine the popularity of products and online activity. We and Microsoft may use this information to improve site operations, for fraud/security purposes, and for advertising. See the Microsoft Privacy Statement for more details. Clarity may mask sensitive fields, but you should avoid entering information you don't want captured.
You can control cookies through your browser settings; disabling some may affect functionality.
4. How We Share Information
We do not sell your personal information. We share it only with:
- Service providers that run the Service — including Stripe (payments), Vercel (hosting), Neon (database), and analytics providers (Google, Microsoft) — under agreements that limit their use of the data.
- Within your organization — Customer Data is visible to authorized users of your company account (e.g., administrators and supervisors) per the role you're assigned.
- Legal & safety — when required by law, to enforce our Terms, or to protect rights, safety, and security.
- Business transfers — in connection with a merger, acquisition, or sale of assets, subject to this Policy.
5. Data Retention
We retain information for as long as your account is active and as needed to provide the Service, then for a reasonable period to meet legal, tax, and recordkeeping obligations. Customers may request export or deletion of their Customer Data as described below; some records (e.g., safety and compliance documents) may be retained by the Customer or as required by law.
6. Security
We use administrative and technical safeguards — including encrypted connections (HTTPS), hashed passwords, and access controls — to protect information. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
7. Your Choices & Rights
Depending on your location, you may have rights to access, correct, delete, or export your personal information, or to object to certain processing. To make a request, contact us at Kelly@sacredops.app. If your data was entered by an employer using the Service, we may direct your request to that Customer. You can unsubscribe from marketing emails using the link in those emails.
8. Children
The Service is intended for businesses and users 18 and older. It is not directed to children, and we do not knowingly collect information from anyone under 16.
9. International Users
The Service is operated in the United States. If you access it from outside the U.S., you consent to processing your information in the U.S., where privacy laws may differ from those in your location.
10. Changes to This Policy
We may update this Policy from time to time. We will post the new effective date and, for material changes, provide reasonable notice.
11. Contact
SacredOps
Kelly@sacredops.app