Privacy Policy
Effective September 17, 2026. Last updated September 17, 2026.
1. Who we are and what this covers
Bad Daddy Operations (“BDO”, “we”, “us”) is a software platform operated for construction, land-clearing, civil site-work, and trucking businesses. This policy covers the web application at app.baddaddyoperations.com, the marketing page at baddaddyoperations.com, the BDO Field mobile web app, and the application programming interfaces behind them.
BDO is not a consumer product and is not offered to the general public. Access is granted by an account owner to the workers, managers, and administrators of the businesses that use it. This policy does not cover any third-party system you separately connect, such as your accounting software, which remains governed by that provider’s own terms and privacy policy.
2. Information we collect
What follows is the full set of categories the platform is built to hold. Whether a given category exists in your company’s records depends on which parts of the platform you use.
| Category | Examples | Where it comes from |
|---|---|---|
| Account and identity | Name, work email address, password (stored only as a hash by our authentication provider), role, which companies you belong to. | You, or the account owner who invited you. |
| Workforce records | Employee and crew records, pay rates and labor burden, time entries, job assignments, training and orientation completion, employee handbook acknowledgments, personal protective equipment issuance, work restrictions, disciplinary and corrective-action records, injury and incident reports. | Entered by managers and administrators; time entries may be entered by the worker. |
| Driver and DOT compliance records | Driver qualification files, license and medical-certificate details, annual driver reviews, inspection and defect reports, hours and duty records, fuel and IFTA trip records. | Entered by fleet and safety administrators. |
| Location data | GPS position, trip history, and geofence entry and exit events for vehicles, equipment, and crew members during a tracking session. | The device running BDO Field, when a tracking session is active. See Section 4. |
| Photographs and documents | Job-site and proof-of-work photos, equipment and vehicle defect photos, daily-log photos, receipts, invoices, plans, permits, and signed documents. Photographs may incidentally include images of people. | Uploaded or captured by users in the field. |
| Customer and vendor records | Business and individual customer names, service and billing addresses, phone numbers, email addresses, contracts, change orders, invoices, and payment status; vendor contacts, bills, and purchase orders. | Entered by your staff, or extracted from documents and emails you send into the platform. |
| Inbound email content | Messages, attachments, and sender details from a mailbox you connect for bill intake, together with the credentials needed to reach that mailbox. | The mailbox you connect. See Section 4. |
| Accounting integration data | Vendor, customer, account, and item references used to match a BDO record to the right entry in your accounting system, and a record of what was sent. | Your accounting system, once you connect it. |
| Usage and technical data | Pages and screens visited, IP address, browser and device type, timestamps, and an audit trail of significant actions such as approvals, exports, merges, and deletions. | Automatically, as you use the platform. See Section 6. |
Sensitive information. Injury and incident reports, medical-certificate status for drivers, and work restrictions can reveal information about a person’s health. We collect these only because occupational-safety and motor-carrier rules require them to be recorded and retained, and we restrict them to the roles that need them.
What we do not collect. We do not collect payment-card numbers, bank account credentials, or bank feed data. We do not collect Social Security numbers or government identification numbers as a designed feature; do not enter them into free-text fields. We do not knowingly collect information from anyone under 18, and the platform is not intended for them.
3. How we use information
- To operate the platform: authenticate you, show you the records for the companies you belong to, and enforce role-based access.
- To run the businesses that use it: estimating, procurement, job costing, billing, dispatch, fleet maintenance, safety, and field documentation.
- To produce management summaries, alerts, and recommendations from your own records. See Section 5 for the third party involved in generating these.
- To post approved bills, receipts, and customer invoices into your accounting system when you have connected one and approved the transfer.
- To keep an audit trail, investigate problems, prevent misuse, and back up data.
- To meet legal obligations, including occupational-safety and motor-carrier recordkeeping.
We do not use your information for advertising, we do not build advertising profiles, and we do not sell or rent personal information. We do not use one company’s records to build products or insights for an unrelated company.
4. Two collections that deserve their own section
Location tracking. Vehicle, equipment, and crew location is recorded only during an active tracking session. The platform records a consent decision before a session starts and keeps that record. Tracking is intended for dispatch, job costing, fuel and mileage reporting, and safety — not for monitoring people outside of working time. If you administer a company using this feature, you are responsible for telling your workers that tracking is in use and for complying with the law where they work, which in some places requires notice, written consent, or both.
Connected mailbox. If you connect a mailbox so vendor bills can be emailed in, the platform retrieves messages from that mailbox and stores the message content and attachments. The credential for that mailbox is encrypted before storage using AES-256-GCM, with the encryption key held in the application environment and never in the database, so a copy of the database alone cannot decrypt it. Use a mailbox dedicated to bill intake. Do not connect a personal mailbox or one that receives unrelated correspondence.
7. How we protect information
- Traffic to and from the platform is encrypted in transit over HTTPS.
- Every table holding company data has PostgreSQL row-level security enabled and is scoped by company membership, so the database itself refuses cross-company reads rather than relying on the application to filter them.
- Integration secrets are stored in a table that is unreachable by any client role, and reversible secrets such as mailbox credentials are encrypted with AES-256-GCM using a key held outside the database.
- Access to features and records is governed by role and by company membership. Significant actions are written to an audit trail.
- Database privileges are audited on a schedule against a recorded baseline, and drift is reported.
No system is perfectly secure, and we do not claim otherwise. If we become aware of a breach affecting personal information, we will notify affected account owners and any regulator entitled to notice, within the time the applicable law requires.
8. How long we keep information
We keep records for as long as the account is active and afterwards for as long as needed to meet legal, tax, safety, and recordkeeping obligations — which for some categories, such as driver qualification and injury records, is set by regulation rather than by us. We do not currently run an automated deletion schedule; deletion is performed on request as described in Section 9. Backups may retain a copy for a limited period after deletion from the live system. Accounting and audit records are cancelled or reversed rather than erased, so that a financial history cannot be silently rewritten.
9. Your choices and rights
Depending on where you live, you may have the right to know what personal information we hold about you, to get a copy, to correct it, to delete it, and to not be discriminated against for asking. Residents of California and other states with comprehensive privacy laws have these rights by statute. We do not sell personal information or share it for cross-context behavioral advertising, so there is nothing to opt out of on that front.
If you are a worker, customer, or vendor of a business that uses BDO, that business controls the records about you and decides what happens to them. Send your request to that business first; if you send it to us, we will route it to them and support them in answering it. To make a request, contact us using the address at the foot of this page. We may need to verify your identity before we act.
10. Where information is processed
The platform and its database are hosted in the United States. If you access it from outside the United States, you are sending information to be processed there, under United States law.
11. Changes to this policy
We will update this page when our practices change, and we will change the effective date at the top. If a change materially reduces the protection of information already collected, we will give account owners notice before it takes effect.
Bad Daddy Operations LLC · Duncan, South Carolina, United States
Questions about this document: craigs@baddaddyoperations.com