Legal
Privacy Policy
Effective · Version 1.0
1. Who we are and our role
GroundTender is field-service operations software for outdoor-service businesses — lawn care, landscaping, hydroseeding, snow removal. It is operated by Abacus Tech Design LLC (“we”, “us”), and it is available as a web app at app.groundtender.com and as a mobile field app for iOS and Android. This policy covers this website, the web app, and the mobile app.
We act in two different roles, depending on the data:
- Account data — the owner's login e-mail, the organization profile, and the subscription. For this data, Abacus Tech Design LLC is the controller: we decide how and why it is processed.
- Business content — the customer, property, contact, scheduling, photo, and invoicing data a business enters into GroundTender. For this data, the business is the controller and GroundTender processes it on the business's behalf and under its instructions.
If you are a customer of a business that uses GroundTender — for example, you received an estimate or invoice from them — that business is responsible for how your information is used. Contact them directly; we will support them in answering you.
2. Data we collect
Account data
- Your sign-in e-mail address and password (stored only as a hash).
- Your role in each organization you belong to, and the invitations you send or accept.
- The organization's name, business profile (contact details, reply-to address, payment instructions shown on invoices), and operational settings.
- Your subscription status, plan, and billing history. Payment card numbers are collected and held by Stripe; we never see or store them.
- Sign-in sessions and the devices they were started from, so you can review and revoke them.
Business content
The records a business creates while running its operation, including:
- Customers and their contacts (names, e-mail addresses, phone numbers, notes).
- Properties and their addresses, including coordinates from address validation or a pin the business places manually.
- Service catalog, pricing, and service agreements.
- Schedules, crew assignments, and the history of every change to a job.
- Crew member profiles, availability, and time recorded on jobs.
- Job notes and photos taken in the field.
- Estimates, invoices, receipts, payments (including check and cash payments recorded by hand), and payment reminders.
- The e-mails sent to the business's customers on its behalf.
Device and usage data
- Service logs and telemetry — request timing, error codes, and opaque identifiers we use to run, secure, and troubleshoot the service. Telemetry is designed to exclude names, addresses, and other sensitive fields.
- Audit log — a record of consequential actions (who did what, when, and from which network address), kept for security and accountability.
- Crash reports from the web and mobile apps: app version, device model, operating system version, and the error's stack trace. We do not capture screenshots or session replays.
- Mobile app — data the app keeps on your device is stored encrypted. The camera and photo library (for job photos) and notifications are optional permissions you can decline or revoke at any time. Push notifications carry only a generic message and an opaque reference — never customer names, addresses, or job details. The app does not collect your device's location.
Cookies
This website sets no cookies. The web app uses only the cookies strictly necessary to keep you signed in and to protect against cross-site request forgery. We use no advertising cookies, no cross-site tracking, and no third-party analytics.
3. How we use data
- To provide the service: run schedules, sync the field app, produce estimates, invoices, and receipts, record payments, and generate reports.
- To send transactional e-mail: account messages to you (verification, password reset, invitations, billing notices), and — on a business's behalf — estimates, invoices, receipts, and payment reminders to that business's customers. Those messages carry signed links so the recipient can view the document without creating an account. Recipients can be unsubscribed or suppressed by the business at any time.
- To bill the subscription through Stripe.
- To secure and operate the service: detect abuse, apply rate limits, investigate incidents, keep the audit trail, and maintain backups.
- To support you when you write to us.
- To comply with the law, including tax and accounting obligations.
We do not sell personal data. We do not use business content for advertising, and we do not use it to train machine-learning models.
4. Sub-processors
We rely on the following providers to run GroundTender. Each processes data only to provide its service to us, under a contract that binds it to confidentiality and security obligations.
| Provider | What it does for us | Data it handles | Location |
|---|---|---|---|
| Stripe | Subscription billing for GroundTender; payment processing for businesses that connect their own Stripe account (Stripe Connect). | Billing contact and e-mail, payment card details (entered directly with Stripe — never stored by us), invoice amounts and references. | United States (global provider) |
| Microsoft Azure | Hosting, database, and file storage (US Central region); Azure Communication Services for transactional e-mail; Azure Maps for address validation; Application Insights for service telemetry. | All service data at rest (encrypted); e-mail addresses and message content; addresses submitted for validation; telemetry without names or addresses. | United States (Central) |
| Cloudflare | Edge network and DNS for groundtender.com and the app. | Network traffic metadata: IP addresses, request headers, timing. | Global edge network |
| Expo | Mobile app updates and push-notification delivery. | Device push tokens; generic notification payloads (no customer detail); app update manifests. | United States |
| Sentry | Crash reporting for the web and mobile apps. | App version, device model and OS version, error stack traces. No screenshots, no session replays. | United States |
We store and process data in the United States. If you use GroundTender from elsewhere, your data is transferred to and processed in the United States. We will update this table before adding a sub-processor that handles personal data.
5. Retention and deletion
- While your organization is open, we keep its data so the business can operate and meet its own record-keeping duties.
- Export: an owner can request an export of the organization's data at any time. Write to [email protected] from the owner's sign-in address; we confirm the request by e-mail before preparing it, and the export is delivered as a private, time-limited download.
- Closure: an owner can request closure (deletion) of the organization the same way — by e-mail to [email protected], confirmed through a link we send to the owner's address. Nothing is removed until the request is confirmed. Closure removes personal data after a short hold, while financial records required for tax and accounting (invoices, payments, receipts) are minimized rather than deleted: personal details are stripped and the financial record is kept.
- Your own login: any account holder can request deletion of their login by e-mail. If you are the only owner of an open organization, name another owner or close the organization first.
- Suppression: when a recipient asks not to be e-mailed, we keep the minimum record (the address) needed to honour that request.
- Backups and logs: encrypted backups and audit records age out on a fixed schedule after deletion; they are used only for recovery and security.
6. Security
- Sensitive fields — names, addresses, contacts, notes, photos, and financial details — are encrypted at rest with application-managed keys, in addition to storage-level encryption. Keys are rotated.
- All traffic between your browser or device and our servers uses TLS.
- Access is scoped to the business's own organization: every request and every background job is checked against the organization it belongs to, and roles limit what each user can see and do.
- Consequential actions are recorded in an append-only audit log.
- The mobile app keeps its working data in an encrypted database keyed from the device's secure store, and wipes it on sign-out or when access is revoked.
- Passwords are stored as hashes; sign-in sessions can be reviewed and revoked; password resets sign out every other session.
No system is perfectly secure. If we learn of a breach that affects your data, we will notify the affected organizations by e-mail without undue delay and tell you what we know and what we are doing about it.
7. Your choices
- Access and correction: sign in and update your records in the app.
- Export and deletion: see section 5, or our Support page.
- Notifications: push notifications are optional. Turn them off in the app or in your device settings.
- E-mails from a business that uses GroundTender: ask that business — they can stop messages to your address. If you cannot reach them, write to us and we will help.
- Your legal rights: depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal data, or to object to some processing. E-mail us and we will respond within the time the law requires. Where a business is the controller, we will refer your request to it and support its response.
We do not track you across other websites, so there is no cross-site tracking to opt out of.
8. Children
GroundTender is for business use only, and users must be at least 18 years old. We do not knowingly collect personal data from anyone under 18; if we learn that we have, we delete it.
9. Changes to this policy
We may update this policy. The version and effective date at the top change when we do, and we notify organization owners by e-mail before a material change takes effect.
10. Contact
Abacus Tech Design LLC
[email protected]
We answer within one business day.