Bad Daddy Operations®

Privacy Policy

Effective September 17, 2026. Last updated September 17, 2026.

In short: Bad Daddy Operations is a private operating system used by construction, site-work, and trucking companies to run their own work. We collect business and workforce records needed to run that work. We do not sell personal information, we do not use it for advertising, and we do not share one connected company’s records with an unrelated company.

1. Who we are and what this covers

Bad Daddy Operations (“BDO”, “we”, “us”) is a software platform operated for construction, land-clearing, civil site-work, and trucking businesses. This policy covers the web application at app.baddaddyoperations.com, the marketing page at baddaddyoperations.com, the BDO Field mobile web app, and the application programming interfaces behind them.

BDO is not a consumer product and is not offered to the general public. Access is granted by an account owner to the workers, managers, and administrators of the businesses that use it. This policy does not cover any third-party system you separately connect, such as your accounting software, which remains governed by that provider’s own terms and privacy policy.

2. Information we collect

What follows is the full set of categories the platform is built to hold. Whether a given category exists in your company’s records depends on which parts of the platform you use.

CategoryExamplesWhere it comes from
Account and identityName, work email address, password (stored only as a hash by our authentication provider), role, which companies you belong to.You, or the account owner who invited you.
Workforce recordsEmployee and crew records, pay rates and labor burden, time entries, job assignments, training and orientation completion, employee handbook acknowledgments, personal protective equipment issuance, work restrictions, disciplinary and corrective-action records, injury and incident reports.Entered by managers and administrators; time entries may be entered by the worker.
Driver and DOT compliance recordsDriver qualification files, license and medical-certificate details, annual driver reviews, inspection and defect reports, hours and duty records, fuel and IFTA trip records.Entered by fleet and safety administrators.
Location dataGPS position, trip history, and geofence entry and exit events for vehicles, equipment, and crew members during a tracking session.The device running BDO Field, when a tracking session is active. See Section 4.
Photographs and documentsJob-site and proof-of-work photos, equipment and vehicle defect photos, daily-log photos, receipts, invoices, plans, permits, and signed documents. Photographs may incidentally include images of people.Uploaded or captured by users in the field.
Customer and vendor recordsBusiness and individual customer names, service and billing addresses, phone numbers, email addresses, contracts, change orders, invoices, and payment status; vendor contacts, bills, and purchase orders.Entered by your staff, or extracted from documents and emails you send into the platform.
Inbound email contentMessages, attachments, and sender details from a mailbox you connect for bill intake, together with the credentials needed to reach that mailbox.The mailbox you connect. See Section 4.
Accounting integration dataVendor, customer, account, and item references used to match a BDO record to the right entry in your accounting system, and a record of what was sent.Your accounting system, once you connect it.
Usage and technical dataPages and screens visited, IP address, browser and device type, timestamps, and an audit trail of significant actions such as approvals, exports, merges, and deletions.Automatically, as you use the platform. See Section 6.

Sensitive information. Injury and incident reports, medical-certificate status for drivers, and work restrictions can reveal information about a person’s health. We collect these only because occupational-safety and motor-carrier rules require them to be recorded and retained, and we restrict them to the roles that need them.

What we do not collect. We do not collect payment-card numbers, bank account credentials, or bank feed data. We do not collect Social Security numbers or government identification numbers as a designed feature; do not enter them into free-text fields. We do not knowingly collect information from anyone under 18, and the platform is not intended for them.

3. How we use information

  • To operate the platform: authenticate you, show you the records for the companies you belong to, and enforce role-based access.
  • To run the businesses that use it: estimating, procurement, job costing, billing, dispatch, fleet maintenance, safety, and field documentation.
  • To produce management summaries, alerts, and recommendations from your own records. See Section 5 for the third party involved in generating these.
  • To post approved bills, receipts, and customer invoices into your accounting system when you have connected one and approved the transfer.
  • To keep an audit trail, investigate problems, prevent misuse, and back up data.
  • To meet legal obligations, including occupational-safety and motor-carrier recordkeeping.

We do not use your information for advertising, we do not build advertising profiles, and we do not sell or rent personal information. We do not use one company’s records to build products or insights for an unrelated company.

4. Two collections that deserve their own section

Location tracking. Vehicle, equipment, and crew location is recorded only during an active tracking session. The platform records a consent decision before a session starts and keeps that record. Tracking is intended for dispatch, job costing, fuel and mileage reporting, and safety — not for monitoring people outside of working time. If you administer a company using this feature, you are responsible for telling your workers that tracking is in use and for complying with the law where they work, which in some places requires notice, written consent, or both.

Connected mailbox. If you connect a mailbox so vendor bills can be emailed in, the platform retrieves messages from that mailbox and stores the message content and attachments. The credential for that mailbox is encrypted before storage using AES-256-GCM, with the encryption key held in the application environment and never in the database, so a copy of the database alone cannot decrypt it. Use a mailbox dedicated to bill intake. Do not connect a personal mailbox or one that receives unrelated correspondence.

5. Who we share information with

We share information with service providers who process it on our behalf, under contract, for the purposes below and no others. This is the complete list as of the effective date.

ProviderWhat it doesWhat it receives
SupabaseManaged PostgreSQL database, authentication, and file storage. Hosted in the United States (region us-west-2).All stored platform data, including every category in Section 2.
VercelApplication hosting and delivery; also provides aggregate traffic analytics.Request data in transit, IP address, and page-level usage.
OpenAIReads uploaded bills and receipts to extract their fields, and generates management summaries and recommendations from your records.The contents of documents you submit for extraction, and the record summaries used to build a briefing. OpenAI states that data submitted through its business APIs is not used to train its models by default, and we do not enroll in any training program.
PostmarkReceives inbound bill email sent to a platform address.The inbound message, its headers, and attachments.
ResendSends outbound notification email for access requests made from the marketing page.The email address and message you submit in that form.
Plausible AnalyticsWebsite analytics. Cookieless and aggregate; it does not build cross-site profiles.Page views, referrer, and coarse device and country information.
U.S. National Weather ServiceSupplies weather for job-site daily logs.Job-site coordinates only. No personal information.
Intuit (QuickBooks)Accounting integration, when and if you connect it.Only the records you approve for transfer, and the references needed to match them. As of the effective date this integration is not live and no data has been transmitted.

We also disclose information when we are legally required to — in response to a valid legal process, to protect the safety of a person, or to establish or defend legal claims. If we are ever involved in a merger, acquisition, or sale of assets, information may transfer as part of that transaction, and this policy will continue to apply until it is replaced by one you are told about.

6. Cookies and local storage

The platform does not use advertising or cross-site tracking cookies. It stores your sign-in session and certain working data in your browser’s local storage, and registers a service worker so BDO Field can operate offline. Clearing your browser storage signs you out and removes any working data not yet saved to the server. Plausible Analytics is cookieless. Vercel Analytics collects aggregate page-level usage.

7. How we protect information

  • Traffic to and from the platform is encrypted in transit over HTTPS.
  • Every table holding company data has PostgreSQL row-level security enabled and is scoped by company membership, so the database itself refuses cross-company reads rather than relying on the application to filter them.
  • Integration secrets are stored in a table that is unreachable by any client role, and reversible secrets such as mailbox credentials are encrypted with AES-256-GCM using a key held outside the database.
  • Access to features and records is governed by role and by company membership. Significant actions are written to an audit trail.
  • Database privileges are audited on a schedule against a recorded baseline, and drift is reported.

No system is perfectly secure, and we do not claim otherwise. If we become aware of a breach affecting personal information, we will notify affected account owners and any regulator entitled to notice, within the time the applicable law requires.

8. How long we keep information

We keep records for as long as the account is active and afterwards for as long as needed to meet legal, tax, safety, and recordkeeping obligations — which for some categories, such as driver qualification and injury records, is set by regulation rather than by us. We do not currently run an automated deletion schedule; deletion is performed on request as described in Section 9. Backups may retain a copy for a limited period after deletion from the live system. Accounting and audit records are cancelled or reversed rather than erased, so that a financial history cannot be silently rewritten.

9. Your choices and rights

Depending on where you live, you may have the right to know what personal information we hold about you, to get a copy, to correct it, to delete it, and to not be discriminated against for asking. Residents of California and other states with comprehensive privacy laws have these rights by statute. We do not sell personal information or share it for cross-context behavioral advertising, so there is nothing to opt out of on that front.

If you are a worker, customer, or vendor of a business that uses BDO, that business controls the records about you and decides what happens to them. Send your request to that business first; if you send it to us, we will route it to them and support them in answering it. To make a request, contact us using the address at the foot of this page. We may need to verify your identity before we act.

10. Where information is processed

The platform and its database are hosted in the United States. If you access it from outside the United States, you are sending information to be processed there, under United States law.

11. Changes to this policy

We will update this page when our practices change, and we will change the effective date at the top. If a change materially reduces the protection of information already collected, we will give account owners notice before it takes effect.

This document was drafted for review by counsel and is not legal advice. Before it is relied upon, have a licensed attorney confirm it against the platform’s actual practices, the states you operate in, and any contract or insurance obligations you carry.

Bad Daddy Operations LLC · Duncan, South Carolina, United States

Questions about this document: craigs@baddaddyoperations.com

Privacy Policy · End User License Agreement