Privacy Policy
The short version
- RunSheets is dispatch software sold to field service businesses. Most of the personal information in it is not ours — it belongs to the business using RunSheets, and it is about their customers and technicians.
- We set no cookies and run no advertising or analytics trackers on this site or in the app.
- We never sell personal information, and we never share it for cross-context behavioral advertising.
- Job photos are tagged with the location of the device that took them. Live location sharing is off until a user turns it on.
- Business records are stored in infrastructure that Nagoh Creative provisions and administers on your behalf. Read Section 8 — it explains exactly who can reach your data.
This policy explains what personal information RunSheets collects, why we collect it, who we share it with, how long we keep it, and what you can ask us to do about it. It covers the RunSheets website at runsheets.us, the RunSheets web and installable app, and the RunSheets chat widget that our customers embed on their own websites (together, the Service).
1. Who we are
RunSheets is a product of Nagoh Creative, LLC (“RunSheets”, “we”, “us”), a company organized in the State of Georgia, United States.
- Location: United States
- Privacy contact: support@nagoh.us
2. Two kinds of data, two different roles
This distinction runs through the whole policy, so it comes first.
a. Data we control
When a field service business signs up for RunSheets, we handle the information needed to create and run that account: the company name, the names and contact details of the people who log in, billing arrangements, and support correspondence. For this information we are the controller (a business, in the language of the California privacy laws). This policy is our disclosure to you about it.
b. Data we only process on a customer's behalf
Everything a customer's team puts into RunSheets — their own customer records, service addresses, tickets, job photos, invoices, technician details, chat conversations, location pings — belongs to that business. They decide what to collect and why. We hold and process it strictly to provide the Service to them. For that information they are the controller and we are the processor (a service provider under the California laws).
If you are an end customer of a business that uses RunSheets — a homeowner whose air conditioner was serviced, say — and you want to see, correct, or delete your information, please contact that business directly. They control the record. If you contact us instead, we will pass your request on to them and help them act on it, but we will not unilaterally change or delete a customer's records.
Our handling of this second category is governed by our agreement with the customer, including its data processing terms, which take precedence over this policy where the two differ.
3. What we collect
Account and login information
To create a session we process the company identifier, user name, and password entered at the login screen, together with the assigned role (Admin, Staff, or Technician). A session token is issued on successful login and stored in your browser; see Section 7.
Business records entered by our customers
The core of the Service. Depending on how a customer configures it, this includes:
- Their customers: name, email address, phone number, service and billing addresses, service locations, equipment and assets on site, subscriptions, agreed pricing, and free-text notes.
- Tickets and jobs: descriptions, categories, priority, status history, assigned technician, due dates, arrival times, warranty returns, and expenses.
- Technicians and staff: names, email addresses, phone numbers, on-call and after-hours schedules, and assignment history.
- Billing: invoices and line items generated inside the Service.
- Sign-offs: a typed technician name recorded against a completed ticket. These are typed text, not a captured handwritten signature or any biometric.
- Audit log: a record of actions taken in the account — who changed what and when — across tickets, customers, invoices, technicians, users, settings, chat sessions, on-call schedules, reports, push subscriptions, warranty returns, SMS, and AI assistant use. This exists so account administrators can investigate mistakes and misuse; it is a security feature and we do not delete individual entries on request.
Photos
Technicians can attach photos to tickets and customer records, taken with the device camera or chosen from its library. Photos are resized in the browser and uploaded to the customer's own data store.
Photos are geotagged. When a photo is uploaded, the app asks the device for its current coordinates and stores the latitude and longitude alongside the image. This happens on every photo upload, and it is separate from the Live Location Sharing setting described below — turning that setting off does not turn off photo geotagging. If the device refuses or cannot supply a location within five seconds, the photo is uploaded without coordinates. Photos may also be sent as MMS messages, which means the image is transmitted through our SMS provider.
Location information
The Service uses device location in three distinct ways. Your browser or phone will always ask for permission before any of them can read a position, and denying that permission disables all three.
- Live location sharing (opt-in). Off by default. A user turns it on under Settings, and only then does the app begin reporting position, at most once per minute, so the team can be shown on the account's map. Switching it back off stops reporting immediately and removes the user from the map. The last known position row is marked inactive rather than deleted, so that re-enabling the setting later resumes without reconfiguration.
- Automatic arrival detection. When the assigned technician opens their own ticket, the app may take a single position reading and compare it to the job's address to move the ticket's status to arrived. It runs only for that technician, only on a ticket not yet in progress, and an account administrator can switch the feature off for the whole account.
- Photo geotagging. Described above.
To place jobs on a map we send service addresses to the Google Maps Platform for geocoding. Results are cached in the browser to avoid repeat lookups.
Chat widget conversations
Our customers can embed a RunSheets chat widget on their own websites. A visitor who opens it is asked for a name and an email address or phone number so the business can reply, and then for the content of their messages. The widget checks for new replies every few seconds while it is open. This information is delivered to the business that embedded the widget and is stored in their account; we process it on their behalf. The widget keeps the conversation identifier and the details the visitor supplied in that browser's local storage, so a returning visitor is not asked twice.
Text messages and notifications
Where a customer enables it, the Service sends SMS and MMS messages — dispatch notifications, after-hours alerts — to phone numbers held in their account, through our SMS provider. It also sends email notifications, and browser or device push notifications to users who grant permission; granting it registers a push subscription endpoint for that device, which is deleted when notifications are turned off.
The RunSheets AI assistant
Accounts with the “Ask RunSheets” assistant and Copilot enabled let Admin and Staff users type questions in plain language and receive answers drawn from that account's own records. The question and the account data needed to answer it are processed by an external AI provider. Questions and answers are recorded in the account's audit log. Technicians do not have access to this feature.
Technical information
Like any service reachable over the internet, our infrastructure processes the IP address, browser user agent, and request metadata of connections to it, for security, abuse prevention, rate limiting, and diagnostics. Our hosting providers keep their own operational logs of this traffic.
What we do not do. We do not set advertising cookies, embed social media pixels, or run third-party analytics on this website or in the app. We do not build profiles of individuals for marketing. We do not use personal information from customer accounts to train AI models of our own.
4. Why we use this information
| Purpose | What it involves |
|---|---|
| Providing the Service | Authenticating logins, storing and displaying records, dispatching jobs, generating invoices, delivering chat messages and notifications. |
| Location features | Showing a team map, detecting arrival at a job site, and recording where a job photo was taken. |
| Support | Responding to questions, investigating faults, and restoring accounts. |
| Security and integrity | Preventing unauthorized access, rate limiting, and maintaining the audit log. |
| Billing and administration | Managing subscriptions and keeping business records. |
| Legal compliance | Meeting tax, accounting, and other legal obligations, and responding to lawful requests. |
| Improving the product | Understanding which features are used and where they fail, using aggregate and support information rather than mining customer records. |
We do not use personal information for a materially different purpose than the one it was collected for without telling you first.
5. Who we share it with
We do not sell personal information, and we do not share it for cross-context behavioral advertising. We disclose it only in these situations:
- To the customer whose account holds it. Records belong to the business that entered them, subject to the roles configured in their account.
- To service providers who run parts of the Service under contract, listed below.
- When the law requires it — a valid subpoena, court order, or similar legal process — or to protect our rights, safety, or property, or those of our customers or the public.
- In a business transfer. If the business is sold, merged, or reorganized, account data may transfer to the acquirer under the same commitments made here; we will notify affected customers.
Service providers and subprocessors
| Provider | What it does | What it can see |
|---|---|---|
| Stores account records and runs the per-account backend; geocodes addresses and renders maps; serves the site's web font. | All stored business records. Service addresses sent for geocoding. Connection metadata, including IP address, for font and map requests. | |
| Cloudflare | Secures and routes traffic to the Service. | Data in transit to the Service, and connection metadata. |
| Twilio | Delivers SMS and MMS messages. | Recipient phone numbers, message contents, and any photo sent as MMS. |
| GitHub (Pages) | Hosts the public website. | Connection metadata for visits to runsheets.us. |
| jsDelivr | Serves open-source libraries used for charts and for Excel and PDF export. | Connection metadata when the application loads. |
| DeepSeek | Answers questions asked through the RunSheets AI assistant. | The question asked and the account records needed to answer it. |
We will keep this list current. Customers who need advance notice of changes to it should say so in their agreement with us.
6. Cookies and browser storage
RunSheets does not use cookies. Instead the Service stores a small amount of information in your browser's local storage, all of it either necessary to keep you logged in or a convenience setting. None of it is used for advertising or tracking, and none of it is sent to any third party.
| Category | Purpose |
|---|---|
| Session | Keeps you signed in. Removed automatically after a period of inactivity, and when you log out. |
| Location sharing preferences | Whether you turned Live Location Sharing on for this device, and whether you want other people shown on your map view. |
| Display preferences | Light or dark mode, color palette, and layout/view settings. |
| Map cache | Cached coordinates for addresses already looked up, to avoid repeat requests to Google. |
| Chat widget | Set by the chat widget on a business's own website: the conversation identifier and the name and contact detail the visitor gave, so they are not asked again. |
You can clear this at any time through your browser's settings for the site. Clearing it logs you out and resets your preferences.
7. How long we keep it
- Account and business records: kept for as long as the customer's account is active. After an account closes, we delete or return the records within 30 days, except where we must keep something longer by law.
- Job photos: kept with the ticket or customer record they belong to, and deleted when that record is deleted or when a user deletes the photo.
- Location pings: the current and last known position of each user who has enabled sharing, retained for 30 days.
- Chat conversations: retained in the customer's account for 90 days, and deletable by the business at any time.
- Audit log: retained for 24 months, because it is what makes account misuse investigable.
- Infrastructure logs held by our providers follow their own retention schedules.
Backups are overwritten on their own cycle, so deleted information may persist in a backup for a short period after it disappears from the live Service.
8. Where your data lives, and who can reach it
We want to be direct about this, because it matters more than anything else in this document.
Each RunSheets account's records are stored separately from every other account's, in a backend tied only to that account and reachable only through our access-controlled service. One account's users cannot reach another account's data through the Service.
RunSheets provisions and manages that storage on your behalf so customers do not need their own Google Workspace subscription (see the FAQ). The practical consequence is that RunSheets, as the vendor administering that storage, retains the ability to access account records. We restrict that ability to the people who need it to run the Service, and use it only to operate, support, secure, and repair the Service, or where the law requires it — never to browse a customer's data out of interest, and never to disclose it to another customer.
A customer who requires sole custody of their own data should raise it with us before signing up, so we can discuss whether a different arrangement is possible.
Data is stored and processed in the United States. Google and Cloudflare operate globally, so information may transit their networks outside the United States. Questions sent to the RunSheets AI assistant, and the account records needed to answer them, are processed by DeepSeek, whose servers are located outside the United States; this only happens for accounts with that feature enabled.
If we stop operating the Service, we will give customers advance notice and a reasonable window — at least 60 days — to export their records, and we will delete what remains afterwards. Records can be exported as CSV, Excel, or PDF from within the Service at any time.
9. How we protect it
We take these measures, and we describe them plainly rather than in superlatives:
- All traffic between your browser and the Service runs over encrypted HTTPS connections.
- Every request is authenticated before it can reach your account's data, and sessions expire automatically after a period of inactivity.
- Access permissions are enforced on our servers, not in your browser, so they can't be bypassed by tampering with the page.
- Each account's records are isolated from every other account's, and are reachable only through credentials we hold securely on our servers.
- Roles limit what each user can see and do, and an audit log records significant actions.
- Administrative access to the systems behind the Service is limited to personnel who need it.
No service can promise perfect security, and we do not. If you believe you have found a vulnerability in RunSheets, please write to support@nagoh.us and give us a reasonable opportunity to fix it before disclosing it publicly. We will not pursue legal action against researchers who report issues in good faith and do not access or alter other people's data.
10. If there is a breach
If we determine that a security incident has compromised personal information, we will investigate, take steps to contain it, and notify affected customers without undue delay and within the time limits the applicable state or federal law sets. Our notice will describe what happened, what information was involved, what we have done, and what we recommend you do.
When we act as a processor for a customer's data, we will notify that customer promptly so they can meet their own notification obligations to the individuals concerned; we will not notify their end customers directly unless they ask us to or the law requires it.
11. Your privacy rights
Residents of California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy laws have rights over personal information. Depending on where you live, these include the right to:
- know what personal information we hold about you and how we use it;
- obtain a copy of it, in a portable format;
- correct information that is inaccurate;
- delete it, subject to the exceptions the law allows;
- opt out of sale, sharing for targeted advertising, or profiling with legal effects — none of which we do; and
- not be discriminated against for exercising any of these rights. We will not deny service, charge a different price, or reduce quality because you made a request.
To make a request, email support@nagoh.us with enough detail for us to identify your records. We will verify your identity before acting, usually by confirming you control the email address or phone number in the record. We respond within 45 days and may extend once by another 45 days where the request is complex, telling you why. Requests are free unless they are manifestly unfounded or excessive.
You may use an authorized agent, who must provide written permission signed by you. If we deny a request, we will tell you why, and where state law provides one you may appeal by replying to our decision; if we deny the appeal you may complain to your state Attorney General.
Requests about a business's records go to that business. Where we hold information as a processor, the business using RunSheets decides. We will forward your request to them and assist them in answering it. See Section 2.
We do not collect sensitive personal information for the purpose of inferring characteristics about anyone. Precise geolocation is sensitive information under California law; we use it only for the operational purposes described in Section 3.
12. International users
RunSheets is built for, sold to, and operated for businesses in the United States, and all data is stored there. We do not target the Service at the European Economic Area or the United Kingdom.
If you are in the EEA or the UK and believe we hold information about you, contact us at support@nagoh.us and we will address your request.
13. Children
RunSheets is a business tool. It is not directed at children, and we do not knowingly collect personal information from anyone under 16. If you believe a child's information has reached us — for instance through a chat widget on a customer's website — write to support@nagoh.us and we will delete it, and tell the relevant business to do the same.
14. Changes to this policy
We may update this policy as the Service changes. The effective date at the top always shows the current version. If a change materially affects how we handle personal information, we will notify account administrators by email or in the app before it takes effect. Continuing to use the Service after that date means the updated policy applies.
15. Contact us
Questions, requests, and complaints about privacy all go to the same place, and a person reads them.
- Email: support@nagoh.us
If you use RunSheets as a customer and need a data processing addendum for your own compliance obligations, it is Exhibit A to our Customer Agreement.