A LoadOut customer generally controls the operational personal information entered into its workspace. LoadOut processes that data for the customer. LoadOut separately determines how account, billing, security, website, and support data is used to operate the service.
Scope
This Privacy Policy applies to the public LoadOut website, the LoadOut application, billing and support interactions, and related services that link to this policy. It does not govern a customer’s practices outside LoadOut, a third-party website or service, or information processed solely under another agreement that expressly supersedes this policy.
“Personal information” means information that identifies, relates to, describes, or can reasonably be linked with a person or household, subject to the definitions and exceptions in applicable law.
Our role and the customer’s role
For account administration, billing, website operation, security, fraud prevention, support, and our own service administration, LoadOut acts as a controller or business. We decide why and how that information is processed.
For personal information that a customer or its Users submit to a workspace for event-rental operations, the customer ordinarily acts as controller or business and LoadOut acts as processor or service provider. The customer decides what to collect, why to collect it, who may access it, and how long it should be retained. Individuals should direct requests about this workspace data to the organization that collected it. We will assist customers with verified requests as required by applicable law and our agreements.
Information we collect
Account and workspace administration
We process names, business email addresses, workspace and company names, job or operational roles, invitations, membership, permissions, authentication assertions, whether optional two-factor authentication is enabled, and information needed to verify an authentication code.
Operational Customer Data
Depending on how a customer uses LoadOut, a workspace may contain customer and contact names, email addresses, telephone numbers, delivery or event locations, event schedules, notes, inventory and vehicle records, assigned personnel, dispatch and return records, cleaning or repair work orders, timestamps, audit history, and photographs or other evidence uploaded by Users. Customers should not submit sensitive personal information unless it is necessary, lawful, and appropriate for the service.
Billing and transaction information
We process plan selection, subscription status, billing contact, Stripe customer and subscription identifiers, payment outcomes, invoice and receipt references, and tax-related details. Stripe collects payment-card or bank details through its hosted interfaces; LoadOut does not ordinarily receive complete payment-card numbers or card security codes.
Device, network, and usage information
When someone accesses the website or application, we and our infrastructure providers may process IP address, browser and device information, requested pages or API operations, timestamps, authentication events, error details, security signals, and similar logs needed to deliver, diagnose, and protect the service.
Communications
We collect the contents of support requests, feedback, security reports, and other communications, along with related contact details and attachments.
Sources of information
We collect personal information:
- directly from Users, workspace administrators, billing contacts, and people who communicate with us;
- from a customer or its authorized Users when they enter operational data about personnel, customers, vendors, or event contacts;
- automatically from browsers, devices, network requests, and use of the service;
- from Cloudflare when it authenticates a User or provides security, network, and application infrastructure; and
- from Stripe when it processes checkout, subscriptions, invoices, refunds, or payment events.
How we use information
We use personal information to:
- authenticate Users, create and administer workspaces, and enforce roles and plan limits;
- provide event, inventory, warehouse, dispatch, return, evidence, cleaning, repair, customer, and reporting workflows;
- process subscriptions, verify payment status, provide invoices and receipts, and prevent unauthorized plan changes;
- secure the service, detect abuse or fraud, troubleshoot errors, preserve audit history, and respond to incidents;
- respond to support, privacy, and security requests and communicate material service or policy changes;
- analyze reliability and feature use, maintain the service, and improve functionality; and
- comply with law, enforce agreements, establish or defend legal claims, and protect Users, customers, LoadOut, and others.
Depending on the context and applicable law, these activities rely on performance of a contract, legitimate interests in operating and securing a business service, compliance with legal obligations, consent, or the customer’s documented instructions.
Cookies and similar storage
LoadOut and Cloudflare use cookies or similar browser storage that is necessary to authenticate Users, maintain sessions, remember security or interface state, route requests, and protect against abuse. Blocking required cookies may prevent sign-in or application features from working.
LoadOut does not currently use third-party advertising cookies or disclose personal information for cross-context behavioral advertising. If our practices materially change, we will update this policy and provide any controls required by law.
How information is disclosed
We disclose personal information only as reasonably necessary:
- Within a customer workspace. Information is available to Users according to the roles and permissions configured for that workspace.
- To service providers. Cloudflare provides hosting, application delivery, security, identity controls, and data infrastructure. Stripe provides checkout, subscription, invoice, customer-portal, and payment services. These providers process information to perform services for LoadOut under their applicable terms and safeguards.
- For legal and safety reasons. We may disclose information when we reasonably believe it is required by law or necessary to protect rights, safety, and the integrity of the service; investigate fraud or abuse; or respond to lawful process.
- In a business transaction. Information may be disclosed under appropriate safeguards in connection with a financing, merger, acquisition, reorganization, or sale of all or part of the service or its assets.
- At the customer’s direction. We may disclose information to a recipient or integration a customer authorizes.
LoadOut does not sell personal information and does not share it for cross-context behavioral advertising as those concepts are defined by applicable U.S. state privacy laws.
Where information is stored
Core application records are stored using Cloudflare D1. Uploaded evidence and files are stored using private Cloudflare R2 object storage and are delivered through authenticated application controls. Stripe stores and processes payment information within its systems.
LoadOut and its providers may process information in the United States and other countries where they operate. Those countries may have different data-protection laws. Where required, we use contractual or other legally recognized safeguards for cross-border transfers.
Retention
We retain account, workspace, operational, and billing information for as long as reasonably necessary to provide the service, maintain accurate subscription and audit records, fulfill customer instructions, comply with law, resolve disputes, and protect the service. The period depends on the data type, workspace status, sensitivity, contractual requirements, and legal or security needs.
Customers control many records within their workspaces and may request assistance with export or deletion. Following account closure or a verified deletion instruction, information may remain for a limited period in restricted logs, continuity copies, or records we must retain for legal, billing, fraud-prevention, or security purposes. We delete or de-identify information when continued retention is no longer reasonably necessary.
Security
We use safeguards designed for the sensitivity of the service, including identity verification through Cloudflare Access, optional authenticator-based two-factor authentication, server-side authorization and workspace scoping, private object storage, encrypted network transport, audit records for sensitive operations, and server-verified billing events. More detail is available on our Security page.
No security measure can eliminate all risk. Customers should assign the minimum appropriate permissions, enable available account protections, remove former personnel promptly, and avoid uploading information that is not needed for operations.
Privacy choices and rights
Depending on where a person lives, they may have rights to request access, correction, deletion, portability, or restriction of personal information; to object to certain processing; to withdraw consent; or to appeal a decision. These rights may be subject to verification, exceptions, and limits under applicable law.
For information in a customer workspace, contact the customer that collected the information first. That customer is best positioned to verify the request and determine the appropriate response. For LoadOut-controlled information, send a request to support@loadoutoperations.com. Include enough detail for us to identify the relevant account and request, but do not send passwords, authentication codes, or full payment-card details.
We may verify identity and authority before acting. An authorized agent may submit a request where permitted by law, but we may require proof of authorization and direct verification. We will not discriminate against a person for exercising a privacy right. Individuals may also complain to their local privacy or data-protection authority.
Children
LoadOut is a business service and is not directed to children under 13 or the minimum age at which a person may consent to data processing in their location. Children may not create accounts. If we learn that personal information was collected directly from a child contrary to this policy, we will take appropriate steps to delete it. A customer must not upload children’s information unless it has a lawful business need and all required authority and notices.
Changes to this policy
We may update this policy as the service, providers, or legal requirements change. The effective date at the top identifies the current version. We will provide additional notice through the service or account email when a change is material and applicable law requires notice.
Contact
For privacy questions or requests, email support@loadoutoperations.com. Identify the relevant workspace, describe the request, and state whether the information was submitted by a LoadOut customer. We will route processor requests to the appropriate customer when necessary.
