Privacy Policy

Effective date: October 17, 2026  ·  Amended from the first version of September 9, 2026

This version takes effect on October 17, 2026. Until then the version of September 11, 2026 is the one that applies to you: we posted this change 30 days before it takes effect, as this policy promises, and nothing we read changes until that day.

The Worksite Daily is an operations reporting and auditing platform for field service businesses. It is operated by 240 Operations LLC, an Arizona limited liability company. In this policy, “we,” “our” and “us” mean 240 Operations LLC.

This policy says what we collect, what we deliberately do not collect, who we share it with, how long we keep it, and how to get it deleted. It is short because the product holds less than most people expect.

By creating an account or using the Service, you agree to what is described here. If you do not, please do not use the Service.


1. Who this applies to

It applies to you, the account holder, and to the business you run it for.

For the information we collect about you directly, meaning your account, your billing and how you use the app, we decide what happens to it. In data protection language we are the controller.

For the operating figures we read out of the systems you connect, we act on your instruction and nothing else. You are the controller of that data. In data protection language we are the processor.

2. What we collect from you

Your account

Your name, your business email address, your company name and, if you give it, a phone number and a billing contact. We use it to create the account, run the Service and contact you about your subscription.

Your staff

The Team page holds the names and email addresses of your own employees, because that is what it is for. Those are your people, not your customers.

Your billing details

Payments run through Stripe, Inc. We never see or store a full card number. What we keep is the reference Stripe gives us and the state of your subscription. A trial account has no payment details at all, because we do not ask for a card to start one.

Your mobile number, if you opt in to texts

If you opt in to our text messaging program we keep your mobile number and a record of when and how you opted in. We use it to send the messages described in Section 14 of our Terms of Service: account notifications, report and briefing alerts, onboarding and support follow-ups, reminders, and promotional offers. Message frequency varies. Message and data rates may apply. Reply STOP to any message to opt out, or HELP for assistance. No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Your mobile number goes only to the provider that delivers the texts, and only for that.

What you type and upload

The questions you ask the assistant, and any documents such as standard operating procedures you upload to it.

Logs

Our servers record IP address, browser, operating system, pages visited and timestamps. We use that for security, for debugging and to see what needs improving.

3. What we read from the systems you connect

Nothing until you connect a system, and then only that system, and only on your instruction. The One System plan reads one platform. Unlimited reads as many as you have. You can disconnect any of them whenever you like.

The field service and CRM systems anyone can connect today are AccuLynx, FieldRoutes and JobNimbus (field service) and GoHighLevel and HubSpot (CRM). This list is printed from the product itself, so it changes the day a system is added or removed. Some other systems are offered to individual companies as Beta while we prove them, as Section 19 of our Terms explains, and this policy covers them in the same way.

From field service software: jobs and appointments, revenue figures, technician and route performance, callbacks and cancellations, service history at the record level, and the customer's name on each job and callback. Section 4 explains what we do with that name.

From CRMs: how many leads there were and when each arrived, the source or campaign recorded against a lead, the tags on it, opportunities with their values and stages, appointment counts, payment amounts and statuses, and the time and direction of the calls, emails and messages your team logs against a lead. Never their contents.

From a phone or call tracking system: call logs, duration, direction, the tracking number and the source. Not recordings and not what was said.

From a payment processor: the amount, fee and date of each payment, refund and payout, so we can count and total them. Never who paid, never card details, and never a customer record.

From a Meta ad account, if you connect one: spend, impressions, reach, clicks, cost per lead, and campaign and placement performance. Section 8 covers this in full.

4. Your customers' details

We keep one piece of personal information about your customers: the name on a field service job or callback, as your own system records it. That is a person's first and last name, or a business name. It is there so you can see whose job a figure belongs to.

We do not keep your customers' email addresses, phone numbers, mailing addresses or card numbers, and we do not read the contents of your messages or conversations. Everything else we read about a person, such as a lead or contact in a CRM, a caller or a payer, is reduced the moment it enters our system to an opaque identifier, a source, a created date and any tags, with no name. Where a vendor lets us choose what to ask for, we ask only for what we keep; from HubSpot that means no personal field at all. Some systems send whole records that cannot be trimmed. When they do, we remove everything we do not keep the moment the record arrives, before anything is stored.

Names are shown only to the people in your account, on screen. They are not in emailed reports, PDFs or exports, and they never appear on wall displays or shared screens. We do not send your customers' names to the AI models described in Section 7, to Meta, to our analytics provider, or to anyone else.

For these names you are the controller and we are the processor, as Section 1 explains. If one of your customers asks us about their information, we pass the request to you and help you answer it.

Card numbers are never available to us from any source. Your own subscription payments go through Stripe, and the payment records we read carry amounts and statuses only.

5. Why we process it

  • Running the Service: producing the daily briefing, the weekly scorecard, the monthly summary, the team and individual reports and, on Unlimited, the AI Weekly Audit, and delivering them to the recipients you choose.
  • Answering what you ask the assistant.
  • Text messaging: sending the messages you opted in to, and honoring STOP and HELP.
  • Running your account: signing you in, supporting you, and letting you invite your team.
  • Billing: taking payment, managing the subscription and sorting out disputes.
  • Improving the Service: looking at aggregated usage to fix what is broken and build what is missing.
  • Security: watching for unauthorized access and abuse.
  • Legal: meeting our obligations and answering lawful requests.

6. Who else touches the data

These are the companies we rely on to run the Service. Each one gets only what its job needs, and each is under a data protection agreement. We do not sell your data to anyone. We do not hand your operating figures, your reports or anything about your customers to an advertising company, and the one narrow exception, our own conversion measurement, is set out below and in Section 12.

CompanyWhat it does for us
Vercel Inc.Hosts the application
Supabase Inc.Hosts the database and handles sign-in
Stripe, Inc.Takes payment and manages subscriptions
ResendDelivers report and account email
Anthropic, PBCWrites the audit narrative and the assistant answers
PostHogProduct analytics: page views and feature usage, signed-in accounts only

Meta sits on both sides. When you connect an ad account it is a source we read from, described in Section 8. Separately, when we are running ads of our own, we send Meta a record that a quote request, a trial or a subscription happened on this site, which can include a hashed version of your email address. That is advertising measurement for our own marketing, and Section 12 describes it in full. Nothing we read out of your connected systems is ever sent to Meta, and that includes your customers' names.

We keep this list current. If we add anyone that materially changes how your data is handled, we will tell you by email or in the app before it happens.

7. AI processing

The AI Weekly Audit on the Unlimited plan, the narrative in your reports and the assistant answers are written by AI models run by Anthropic, PBC.

What we send is the aggregate figures the report is built from, such as counts, totals and averages by week, by route or by technician, plus whatever you type into the assistant and any document you upload to it.

We do not send your customers' names, or anything else that identifies them. Output can be wrong, so read it before acting on it.

8. Advertising data

If you connect a Meta ad account we ask for one data permission, ads_read, which is read-only. It shows us spend, impressions, reach, clicks, cost per lead, and which campaigns and placements performed.

We do not request the management permission, so we cannot create, edit, pause or delete anything. We do not request the lead retrieval permission, so we never see what anyone typed into a lead form. We see that a lead was submitted, the campaign, and the cost.

You can revoke access at any time, from the Integrations page or from your Facebook settings under Business Integrations. Reporting stops the same day.

9. How long we keep things

  • How far back your plan can look: 120 days on the One System plan and 365 days on the Unlimited plan. The figures themselves are kept, so moving to a longer plan shows the older history straight away. A generated report and its stored PDF are purged automatically once they fall outside that window.
  • Operating figures read from a connected system: held for 90 days after the account closes, then deleted from live systems. A deletion you ask for yourself in Settings runs immediately instead.
  • The customer names on your jobs and callbacks: kept with those records and deleted with them. Disconnecting a system leaves them with that system's history, like the figures. They are held for 90 days after the account closes, then deleted from live systems. A deletion you ask for yourself in Settings runs immediately instead.
  • Credentials, meaning API keys and tokens: deleted immediately when you disconnect an integration, and at the end of the 90-day hold if the account closes.
  • Account and billing records: kept for the life of the account plus 7 years, to meet tax and audit obligations.
  • Encrypted backups: not edited record by record. Anything deleted from live systems is overwritten in backups within 90 days.
  • Aggregated figures that cannot be traced back to you or to any individual: kept indefinitely.

A trial that ends without a paid plan follows the same rules: nothing is charged, and the data is deleted on the schedule above once the account closes. You can ask us to delete your data at any time, whether or not you are closing the account. The instructions are at theworksitedaily.com/data-deletion. We may keep something longer where the law requires it or a dispute is live, and we will say so rather than leaving it quietly in place.

10. California rights

If you live in California, the CCPA as amended by the CPRA gives you the right to know what we collect and why, to see it, to correct it, to have it deleted subject to some exceptions, and not to be treated worse for asking.

We do not sell personal information and we do not share it for cross-context behavioral advertising, so there is no sale opt-out to offer.

To make a request, email support@theworksitedaily.com. We answer within 45 days of a verifiable request, with one extension of up to 45 more days if we genuinely need it.

11. GDPR rights

If you are in the European Economic Area, the United Kingdom or Switzerland, the GDPR or its local equivalent may apply.

Our legal bases are performance of the contract for account and billing data, legitimate interests for analytics and security, and consent for marketing messages.

You may access, correct, delete, restrict, port or object to the processing of your personal data. Where data moves outside the EEA we rely on Standard Contractual Clauses or another lawful mechanism.

Email support@theworksitedaily.com to exercise any of these. Our customers are in the United States today, and we will widen this section as that changes.

12. Cookies and analytics

  • Session and sign-in cookies: keep you logged in. The app does not work without them.
  • PostHog: records page views and product events so we can see what is used. It does not fingerprint visitors or set advertising cookies, and it is never sent your customers' names. Events are tied to signed-in accounts only.

Advertising measurement. When we are running ads, theworksitedaily.com loads the Meta Pixel and reports the same events to Meta a second time from our own server, through Meta’s Conversions API. We use it for one thing: to see whether an ad led to a quote request, a trial, or a subscription. For that we store a first-party cookie on your device for up to 90 days recording how you arrived, meaning any campaign tags on the link you followed, the site that referred you, and any advertising click id. The Meta Pixel sets its own first-party cookies here as well. When one of those events happens we may send Meta a one-way hashed version of your email address so it can match the conversion to the person who saw the ad. Meta does not receive the address itself. None of this loads at all while advertising is switched off.

This measurement covers visitors to this site and our own account holders. It never covers your customers. Their names stay inside your account and are never measured, reported or matched.

Apart from the advertising measurement described above, we do not use cross-site tracking, and we never sell or share any of this for anyone else’s advertising. You can block cookies in your browser, but you will not be able to sign in.

13. Security, in plain English

  • Everything travelling between you and us is encrypted in transit.
  • Everything stored is encrypted at rest.
  • The keys and tokens you give us for connected systems are encrypted separately, and only the jobs that need them can read them.
  • The database keeps each business's rows walled off from every other business at the database level, not just in the application.
  • Only the people who need production access have it.

No system is perfectly secure and we will not pretend otherwise. If you think your account has been reached by someone else, email support@theworksitedaily.com straight away.

14. If there is a breach

If we confirm a breach affecting personal data we hold, we will tell affected customers within 72 hours of finding it. We will say what happened, roughly what was involved, what we are doing, and how to reach us.

Where the data affected is what we process on your behalf, you are the controller, so any notice further down the line is yours to give. We will get you what you need to give it.

15. Children

The Service is for business use and is not for anyone under 13, or under 16 in the European Economic Area. We do not knowingly collect information about minors, and we delete it if we find it. Tell us at support@theworksitedaily.com if you think we have any.

16. What changed

On October 17, 2026. Announced on September 17, 2026, 30 days before it takes effect. Section 3 adds one line to what we read from a CRM: the time each call, email or message your team logs was made, and whether your team made it or received it. That is how the product works out how long a new lead waits before somebody reaches out. We do not read what was said or written, and we do not read who it was with beyond the lead record it is attached to. We do not read any of it before this date. Nothing else changed, and nothing about how you use the product changes.

On September 11, 2026. Section 4 used to say we collect no personal information about your customers. From this date we keep one piece of it: the customer's name on a field service job or callback, so you can see whose job a figure belongs to. We still do not keep their email addresses, phone numbers, mailing addresses or card numbers, and CRM, call and payment records still carry no name. Names are shown only on screen inside your account: never in emailed reports, PDFs or exports, never on wall displays, and never sent to the AI, Meta or our analytics provider. Sections 3, 6, 7, 9 and 12 changed to match. Section 3 now also describes what we read from a payment processor, which can be offered to your company as Beta: amounts, fees and dates, never who paid or card details.

On September 11, 2026. Section 3 named seventeen systems as ones we read from, and most of them could not be connected. It now names only the systems anyone can connect, printed from the product itself, and says that some others are offered to individual companies as Beta while we prove them. Fleet systems are no longer described, because none can be connected. Later the same day, Section 3 was corrected to name the kinds of system that list covers, field service and CRM. A Meta ad account is covered separately, in Section 8.

On September 10, 2026. Section 9 said the operating figures we read and your Credentials are deleted 30 days after an account closes. That was our practice until this date, when we changed it. We now hold them for 90 days after an account closes, so a business that stops paying for a season does not lose its history. A deletion you ask for yourself in Settings still runs immediately, and disconnecting a system deletes its Credentials straight away.

On September 9, 2026. This is the first Privacy Policy written for The Worksite Daily as its own product. Until now this address served a document written for a different site.

  • Section 3 lists every kind of system we can read from and what we take from each, and says how many each plan may connect.
  • Section 4 is new as a section of its own: what we never collect, and why the product does not need it.
  • Section 7 names Anthropic as the only AI provider and says what is sent to it.
  • Section 8 is new: read-only advertising access, and how to revoke it.
  • Section 9 gives report history by plan, printed from the same table the app enforces, and covers backups and trials.
  • Section 13 describes security in plain English rather than in standards jargon.

When we make a material change in future, meaning what we collect, how we use it or who we share it with, we will email you and post a notice in the app at least 30 days before it takes effect. Corrections that do not affect your rights take effect when posted.

17. Contact

240 Operations LLC

An Arizona limited liability company.

Email: support@theworksitedaily.com

Mail: 4539 N 22nd St, Ste N, Phoenix, AZ 85016

Website: https://www.theworksitedaily.com


© 2026 240 Operations LLC. All rights reserved.