Privacy policy
What OpsBrio does with the records a delivery company keeps in it, and with the little we hold for ourselves. This is the product's policy; the Chrome extension has its own.
Last updated 14 September 2026
This is a draft awaiting legal review. The marked gaps are facts only the company can fill. A lawyer should check it against the state privacy laws that apply to your customers before it is relied on.
01Two different roles
Almost everything personal in OpsBrio is somebody else’s employment record. A delivery company decides what to keep about its own drivers and office staff, and OpsBrio is the filing cabinet it keeps them in. In data-protection language that company is the controller and we are its processor: we act on its instructions, not on our own account.
For a small amount of data we are the controller ourselves — the account of the person who signs up, our billing records, and anyone who fills in the form on this website. That is section 5.
[A data processing addendum should be offered to customers who ask. Counsel to draft; link it here].
02What we hold for a company
Running a delivery station means keeping records about the people who work there. In a portal that can include:
- Who they are: name, the name they prefer to go by, staff identifiers, work email, phone number, home station.
- Their work: schedule, shifts, routes, vans, the day’s board, absences and time off.
- Their hours and pay basis: hours clocked and paid, breaks, and the limits their hours are measured against.
- How the job went: delivery performance scores, rescues, coaching notes, write-ups.
- Vehicles: inspections and their photographs, damage reports, tickets.
- Safety: workplace incident and injury records, which a company is required by federal law to keep. These can include information about a person’s health.
- Employment paperwork: driver’s licence details, signed policies and write-ups, offer letters, and — for the I-9 only — a Social Security number.
- Messages: what people write to each other in the portal’s chat, including pictures, video and documents they attach.
- Applicants: for companies using the hiring tools, the details somebody gives when they apply for a job.
A driver’s Social Security number is the one field treated differently everywhere: it is encrypted before it is stored, with a key kept outside the database, and only an HR role can reveal it.
03Where it comes from
- The company’s own office staff, typing it in.
- Its drivers, from the phone app — a check-in, a photograph, a message, a signature.
- Amazon’s DSP portal, copied across by the Chrome extension running inside a dispatcher’s own signed-in browser session.
- People who apply for a job through one of the company’s own apply pages.
04What we never do
- We never ask for, store or transmit an Amazon password. The extension cannot sign in to Amazon.
- We never sell personal data, and we never share it with another customer.
- We never use it for advertising, and we run no advertising on this site or in the product.
- We never use a customer’s records to train a machine-learning model, ours or anybody else’s.
- We run no analytics, no tracking pixels and no third-party scripts on this website or in the product.
05What we hold for ourselves
- If you ask for a portal: your company name, your name, your email, your phone if you give it, your DSP code and stations, and anything you type in the box. We use it to answer you and to set the portal up. If you do not become a customer we delete it after [12] months.
- If you become a customer: the account details of the people we deal with, and our billing records. Billing records are kept for as long as tax law requires.
- Our server logs: the ordinary record of a web request — the address asked for, the time, an IP address, the browser’s description of itself. They exist to keep the service up and to investigate faults and abuse, and they are kept for [30] days.
07Where it lives
Every company’s portal runs on its own database, in the United States (Northern Virginia). Files — inspection photographs, documents, signed letters — sit in that same company’s own storage. We do not operate outside the United States and we do not move customer records abroad.
08Who can see it
Inside a company: whatever its own roles allow. A dispatcher sees the board. HR sees the file. A driver sees only their own records — that is enforced by the database itself, not by the screen, so it holds even when a screen has a bug.
From OpsBrio: an OpsBrio support login exists inside a company’s portal only if that company turns it on, and the company can remove it without asking us. Beyond that, the small number of our staff who run the platform can reach the systems a portal runs on, because that is what applying an update, restoring a backup or fixing a fault requires. They do that to keep the service running or to answer a request from the company, and not to read records for any other reason.
Nobody else, unless the company tells us to, or unless we are required by law — in which case we will tell the company first, unless we are forbidden to.
09The companies we rely on
We use a short list of American suppliers to run the service. Each holds data only to do its job for us.
| Who | What they do | Where |
|---|---|---|
| Supabase | Each company’s database, file storage and sign-in | United States |
| Vercel | Runs the application and serves the pages | United States |
| Resend | Sends hiring and sign-in email | United States |
| Twilio | Sends and receives hiring text messages, for companies that switch texting on | United States |
Amazon is not on this list. Amazon is where some of the data comes from, not somewhere we send it.
We will tell customers by email at least [30] days before adding a supplier that handles personal data, so there is time to object.
10How it is protected
- One database per company. Not one shared database with a column saying which company a row belongs to. There is no query another customer could write that would reach your records.
- The access rules live in the database. Who may read which row is enforced underneath the application, so a mistake in a screen cannot show somebody a record they are not entitled to.
- Encrypted in transit and at rest. Social Security numbers are encrypted a second time, with a key held outside the database entirely.
- No Amazon credentials anywhere. There is nothing of Amazon’s to steal from us.
- Photographs expire on a schedule the company sets, and the files are deleted, not merely hidden.
- Sign-in is by password or an emailed link, and an emailed link is good for 24 hours and one use.
No system is perfect. If personal data is exposed we will tell the affected company without undue delay and, in any case, within [72] hours of establishing what happened, with what we know and what we are doing about it.
11How long it is kept
- Operational records are kept for as long as the company needs them. It is their decision; we do not delete a customer’s records on our own initiative.
- Inspection photographs follow the retention the company sets in its own settings.
- Chat messages follow the retention the company sets, by kind of conversation.
- I-9 files are deleted automatically 30 days after the hire is entered into payroll.
- When a company leaves, its database is kept for [30] days so it can take a copy, then the whole project is deleted, backups included, within a further [30] days.
12If you are a driver or an employee
If you drive for or work at a company that uses OpsBrio and you want to know what is held about you, to correct it, or to have it deleted, ask your employer. The records are theirs, the decision is theirs, and they can see and change everything from inside their own portal.
You can write to us at privacy@opsbrio.com and we will pass it on to them and help them answer it, but we will not change or hand over an employer’s records on the strength of a request from us to them being forwarded.
Some states give you rights directly, including the right to know, to correct, to delete and not to be discriminated against for asking. Where those apply, they apply to your employer as the controller. [Counsel to confirm which state laws apply to your customer base and add the specific notices they require].
13Changes, and how to reach us
If this policy changes in a way that matters, we will email the companies using OpsBrio at least [30] days beforehand, and the date at the top of this page will change with it.
Privacy questions, and requests from a customer about their own records: privacy@opsbrio.com, or by post to [registered address].
The Chrome extension has its own policy, written for the same facts from the extension’s side: the Cortex sync privacy policy. Our terms of service sit alongside this one.