Privacy Policy
Last updated 25 July 2026
Draft — pending legal review
This document is starter boilerplate prepared for a B2B SaaS field-operations platform. It has not been reviewed by counsel and does not constitute legal advice. Have a qualified attorney review and adapt it before relying on it in production or in any marketing or contractual context.
1. Who we are
DynamoSuite provides a field-operations platform used by construction and field-services businesses to manage jobs, scheduling, crews, safety records, and job costing. This policy explains what information we handle and why.
Most information in DynamoSuite is entered by a customer organization about its own business and employees. In that arrangement the customer is the controller of that information and DynamoSuite acts as a processor on its instructions. If you are an employee of a customer and want your records corrected or removed, contact your employer first — they control the account.
2. Information we collect
Account and identity information. Name, work email, phone number, employee ID, job title, department, branch, and role assignments.
Operational data you enter. Jobs, schedules, daily logs, time and hours, photos and files, safety and incident records, certifications, equipment and materials, customer and vendor records, quotes, and job-costing figures.
Human-resources data, where a customer chooses to store it: personal and emergency contacts, family details, compensation, performance and review records. Access to this category is restricted within the product to the account's administrators, HR administrators, and a person's reporting chain.
Location data, where a customer enables it: job-site coordinates and geofence checks used to confirm clock-in and clock-out events.
Technical data. IP address, browser and device type, pages visited, timestamps, and diagnostic information captured when an error occurs.
3. How we use information
- To provide, operate, and secure the platform and its features.
- To authenticate users and enforce role- and organization-based access controls.
- To diagnose faults, monitor reliability, and investigate security incidents.
- To provide support to the customer organization that holds the account.
- To meet legal, tax, safety, and recordkeeping obligations, including workplace-safety reporting where a customer uses those features.
We do not sell personal information, and we do not use customer operational data to build or train models for other customers.
4. Cookies and similar technologies
We use strictly necessary cookies and local browser storage to keep you signed in, remember interface preferences, and protect against request forgery. Session cookies are set by our authentication provider. Because these are required for the product to function, they cannot be disabled while using the service; blocking them in your browser will prevent sign-in.
5. Service providers
We rely on a small number of subprocessors to run the platform. Each receives only what its function requires.
- Supabase — database, authentication, and file storage. Holds account and operational data at rest.
- Vercel — application hosting and content delivery. Processes request metadata such as IP address.
- Sentry — error monitoring. Receives diagnostic event data. User context is limited to an internal user identifier and organization identifier, except where you voluntarily submit your name and email through the in-product feedback form.
- Upstash — rate limiting. Processes IP addresses and request counters to protect public endpoints from abuse.
- Acumatica — where a customer enables the ERP integration, job, project, and financial records are exchanged with that customer's own Acumatica instance under their control.
6. Data retention
We retain operational data for as long as the customer organization maintains an active account, and afterwards only as needed to comply with legal obligations, resolve disputes, and enforce agreements. Diagnostic and error data is retained on a shorter cycle. On written request from the account administrator we will delete or return customer data, subject to any retention period the law requires — safety and payroll-adjacent records in particular are frequently subject to statutory minimums.
7. Security
Access is controlled per organization and per role, and enforced in the database as well as in the application. Data is encrypted in transit and at rest. Administrative access is limited to personnel who need it. No system is perfectly secure; we do not guarantee that unauthorized access can never occur.
8. Your rights
Depending on where you live, you may have the right to access, correct, delete, or export personal information about you, to object to or restrict certain processing, and to withdraw consent where processing relies on it. Because most data is held on behalf of a customer organization, direct your request to that organization; if you send it to us, we will refer it to them and support their response. You will not be discriminated against for exercising these rights.
9. International transfers
The platform is operated from the United States, and information is processed there. If you access it from another country, you are transferring information to the United States, where data-protection law may differ from your own.
10. Children
The platform is a workplace tool intended for business use. It is not directed to children, and we do not knowingly collect information from anyone under 16.
11. Changes to this policy
We may update this policy as the product changes. Material changes will be reflected in the “Last updated” date above, and we will notify account administrators where the law requires it.
12. Contact
Questions about this policy or a privacy request:
DynamoSuite2166 E University Dr, Tempe, AZ 85288
hello@dynamosuite.com