Privacy policy.
Radtak Field Ops ("the Service"), operated by Radtak Solutions LLC ("Radtak," "we"), is a field operations platform for trade contractors. This policy covers the Service at radtak.app and its per-customer subdomains. It's separate from the privacy policy for radtak.com, our marketing site.
Our customer is the contracting company that subscribes to the Service. The people who use it day to day are that company's employees and office staff. Where this policy says "you," it usually means the company; where it says "your people," it means the employees whose records the company keeps in the Service. If you're an employee with a question about your own data, your employer controls it — ask them first, and we'll help them answer you.
Our role
For most of the data in the Service, the customer is the controller and Radtak is the processor. The contracting company decides what goes in, who sees it, and how long it stays. We hold and process it to run the Service on their behalf. We do not sell data, share it with advertisers or data brokers, use one customer's data to benefit another customer, or use customer data to train machine learning models.
What we collect
- People and employment records. Names, work email addresses, phone numbers, job titles and roles, employment status, and pay classification where the customer chooses to store it. Kiosk PINs are stored only as salted hashes — we cannot read them back.
- Time and attendance. Clock-in and clock-out times, hours by job and task category, overtime, corrections, time-off requests, and the notes people attach to their own timecards. Time records are append-only: corrections are added alongside the original with the reason and the name of the person who made them, and the original is never altered or deleted.
- Location. When a customer enables location features, the Service records where a clock-in or clock-out happened, so hours can be tied to a job site and geofences can work. Location is captured at punch events, not continuously, and never when the app is closed. Location points are automatically deleted after 30 days.
- Photos and job media. Photographs taken in the field and attached to jobs or punches, subject to the customer's configured retention period. Photos are always optional.
- Jobs, bids and documents. Job records, addresses, bid opportunities, and links to documents stored in the customer's own systems.
- Account and access records. Sign-in identifiers, roles and permissions, and audit records of significant actions taken in the Service.
Connected services
The Service connects to systems the customer already owns. Every connection is authorized by a customer administrator, uses OAuth 2.0 so we never see or store the customer's passwords, and can be revoked at any time from the connected service.
QuickBooks Online (Intuit)
When a customer connects QuickBooks Online, the Service reads company information and the customer's lists of employees, service items, vendors, and accounts, so people and work categories can be matched to the corresponding QuickBooks records. It writes approved time activities (hours by employee, day, and service item) and vendor bills — nothing is written without the customer's configuration and approval of the underlying records. We store QuickBooks ID numbers so we know which record to update on the next sync, plus a history of what we posted, so the customer can reconcile. We do not copy the customer's QuickBooks financial records into our systems — no bank accounts, customer lists, invoices, payments, or payroll amounts. On disconnection we delete the stored access and refresh tokens; posting history is retained for reconciliation unless the customer asks us to delete it.
Microsoft 365
When a customer connects Microsoft 365, the Service can read a designated mailbox to identify incoming bid invitations, and create and update folders and files in a designated SharePoint site so job documents live in the customer's own tenant rather than ours. Access is restricted to that specific mailbox and site — we don't have access to other mailboxes or sites in the customer's tenant.
Artificial intelligence features
Where the Service offers AI-assisted features, they operate on the customer's own data within that customer's isolated environment, and a person reviews the output before it's used. AI features have no write access to QuickBooks — everything sent to QuickBooks is produced by ordinary application code after human approval. Any commercial AI provider we use is bound by API terms that prohibit training on submitted data; customer data is never used to train any model, ours or anyone else's.
Who processes data on our behalf
We use a small number of established providers, each processing data only to provide its service to us:
- Supabase — managed PostgreSQL database and application services, hosted on Amazon Web Services in the United States. This is where application data lives.
- Vercel — hosts the web application.
- Amazon Web Services — underlying infrastructure for the above.
- Google Maps Platform — converts job addresses into map coordinates.
We may add or change providers as our systems evolve. When we do, we update this list.
Where data lives
Application data is stored in the United States.
Security
Each customer's data is separated at the database level by row-level security, so one customer's records can't be read by another's. All traffic uses TLS, and data is encrypted at rest by our infrastructure providers. Access and refresh tokens for connected services are held in encrypted secret storage, separate from application data. Kiosk PINs are stored as salted hashes. Permissions within the Service are role-based, and access by Radtak staff to customer data is limited to the people who need it to operate and support the Service; support sessions that view the app as a specific user are read-only and enforced at the database level.
No system is perfectly secure, and we won't claim otherwise. If we become aware of a breach affecting personal information, we'll notify affected customers promptly and as required by law.
How long we keep it
- Location points — deleted automatically after 30 days.
- Job photos and media — retained for the period the customer configures.
- Time, job, and bid records — retained for the life of the customer relationship, because they're the customer's operating and payroll records.
- Connected-service tokens — deleted when the connection is removed.
- After termination — we delete or return customer data on request, and in any case within the period set out in our Master Services Agreement.
Your rights and requests
If you're an employee whose records are in the Service, your employer controls that data — direct requests to them, and we'll support them in responding. If you're a customer and need data exported, corrected, or deleted — your own or on behalf of one of your people — email privacy@radtak.com. We verify that the request comes from someone authorized to make it, and respond within 45 days. If we decline, we'll explain why and how to appeal.
Texas residents have rights under the Texas Data Privacy and Security Act, and residents of other states and countries may have comparable rights. We don't sell personal data or use it for targeted advertising, and we apply the same process to everyone rather than sorting requests by geography.
Children
The Service is workplace software and isn't directed at children. We don't knowingly collect information from anyone under 18. Customers are responsible for ensuring that anyone they enroll is lawfully employed.
Changes to this policy
We update this policy when our practices change. The date at the top reflects the most recent revision, and material changes are highlighted on this page rather than made silently.
Contact
Radtak Solutions LLC · 7600 Chevy Chase Dr, Suite 300, Austin, TX 78752
privacy@radtak.com · (737) 727-0020