Legal

Privacy
Policy

We built Yardwise for the bay floor, not the boardroom. That means keeping your fleet's data exactly where it belongs, in your yard, not ours.

Effective date May 10, 2026 Version 1.0 Questions [email protected]

01

Who we are

Yardwise Inc. ("YardWise," "we," "us," or "our") operates the YardWise platform, a voice-first AI copilot for fleet maintenance yards. Our registered address is 2727 Walsh Avenue, Santa Clara, CA 95051. For privacy questions, contact us at [email protected].

If you are a California resident, Section 10 describes your specific rights.

02

What this covers

This Privacy Policy describes how we collect, use, store, share, and protect personal data when you visit our website, create an account, or use the YardWise Service. It also describes your rights regarding your personal data.

Scope

This policy covers personal data about individual users and administrators. It does not govern Customer Data, which refers to the files, manuals, and documents your organization uploads to the Service. That data is governed by your agreement with us (the Terms of Service and any applicable Data Processing Agreement). We process Customer Data on behalf of your organization, not for our own purposes.

We are committed to building GDPR compliance ahead of our European market launch. Prospective EU clients are welcome to contact us at [email protected] to discuss our compliance roadmap.

03

Data we collect and why

3.1 Account and identity data

When you or your organization creates an account, we collect:

  • Name and email address
  • Organization name and role within the organization
  • Your password, stored as an encrypted hash. We never have access to your actual password.
  • Profile information you choose to provide

Purpose: to authenticate you, manage access, and operate the Service.

3.2 Usage data

We collect data about how you use the Service, including:

  • Log data: IP address, browser type, device identifiers, pages visited, timestamps
  • Feature usage: which screens you visit, queries you submit, documents you upload
  • Error and performance logs used to diagnose problems

Purpose: to operate, improve, and secure the Service; to diagnose problems; and to enforce our Terms of Service.

3.3 Communication data

If you contact us by email or through the Service, we retain the content of those communications and your contact details. Purpose: to respond to your requests and improve support.

3.4 Payment data

We use Stripe, a third-party payment processor, to handle billing. We do not store full credit card numbers. We retain transaction records (amount, date, plan) for accounting and legal compliance.

3.5 Voice data

If you use voice features, audio is transmitted to our speech-to-text provider for transcription and then discarded. We retain the resulting text transcript as part of your conversation history, subject to your retention settings. We do not retain raw audio recordings beyond the transcription process unless you explicitly save a voice note as a knowledge entry, in which case the audio file is stored in your organization's isolated storage container.

3.6 Mobile application data

The Service is available on iOS and Android. When you use the mobile application, we request the following device permissions:

  • Microphone access, required for push-to-talk voice queries. Audio is captured only while you actively hold the push-to-talk button. We do not record in the background.
  • Camera access (optional), used to photograph binder pages or physical documents for ingestion into the knowledge base. Photos are processed for OCR and then discarded unless you save them as a knowledge entry.

You can revoke these permissions at any time through your device settings. Revoking microphone access will disable voice features. We do not collect precise device location.

3.7 Data we do not collect

Commitment

We do not collect sensitive personal data such as health information, financial account details, government ID numbers, biometric data, or data about children. We do not use the Service to infer sensitive characteristics about individuals.

04

Customer data and tenant isolation

Your organization controls the content of files, manuals, knowledge entries, and other Customer Data uploaded to the Service. We process that data as a data processor acting on your behalf.

  • Customer Data belonging to your organization is never accessible to, shared with, or used by any other organization on the platform.
  • We do not use Customer Data to train or fine-tune AI models used by other customers or by us generally.
  • Employees with access to Customer Data are bound by confidentiality obligations. Access is restricted to what is necessary to operate and support the Service.
  • A full description of technical isolation controls is in our Terms of Service.

05

How we use personal data

  • Create and manage your account and authenticate you
  • Provide, operate, and improve the Service
  • Process payments and manage billing
  • Send transactional communications (account confirmation, password reset, usage alerts)
  • Send product updates and announcements. You can opt out at any time.
  • Detect, investigate, and prevent security incidents, fraud, and abuse
  • Comply with legal obligations, enforce our Terms of Service, and resolve disputes

Commitment

We do not use personal data for automated decision-making that produces legal or similarly significant effects about you.

06

How we share personal data

Commitment

We do not sell personal data. Full stop.

6.1 Subprocessors

We use third-party service providers to operate the Service. Each is bound by data processing agreements and may only use your data to provide their services to us.

Microsoft Azure Cloud infrastructure, storage, AI services, and authentication
OpenAI / Azure OpenAI AI language model and embedding services
Azure Cognitive Services Speech-to-text and text-to-speech
Cloudflare Content delivery network, DDoS protection, and bot management. Cloudflare processes visitor IP addresses and request metadata for all traffic to the Service. See Cloudflare's privacy policy.
Google Fonts Web font delivery. Loading the Service causes your browser to make a request to Google's font servers, which processes your IP address. See Google's privacy policy. We are evaluating self-hosting our fonts to eliminate this transfer.
Stripe Billing and payment processing
Google Workspace Transactional email delivery (account confirmations, password resets, usage alerts)

A current list of subprocessors is available at yardwise.ai/subprocessors. We will notify you of material subprocessor changes with at least 30 days' notice.

6.2 Legal requirements

We may disclose personal data if required by law, court order, or lawful government request. We will notify you of such requests to the extent permitted by law.

6.3 Business transfers

If we are acquired, merge with another company, or transfer substantially all of our assets, personal data may be transferred as part of that transaction. We will notify you before your personal data is transferred and becomes subject to a different privacy policy.

6.4 With your consent

We may share personal data for other purposes with your explicit prior consent.

07

Data retention

Account data Retained for the duration of your subscription plus 30 days, then deleted or anonymized
Conversation and query history Retained for the duration of your subscription. Your administrator can delete earlier.
Audit logs 2 years, for security and compliance purposes
Billing records 7 years, to comply with financial regulations
Voice transcripts Retained as part of conversation history. Raw audio discarded immediately after transcription.

When you delete your account or your subscription ends, we delete or anonymize personal data within 30 days from active systems. Backup copies are purged on their normal rotation schedule, typically within 90 days.

08

Security

Encryption at rest AES-256
Encryption in transit TLS 1.3
Access controls Role-based, limiting employee access to data
Audit logging Structured logging of all data access and mutations
Testing Regular security testing and vulnerability assessments
Incidents Defined incident response procedures for security breaches

No method of transmission or storage is 100% secure. If we become aware of a security breach affecting your personal data, we will notify you without undue delay as required by applicable law. See our Security page for the full technical picture.

09

Your rights

You may have the following rights regarding your personal data. To exercise any of them, contact us at [email protected]. We will respond within 30 days.

9.1 Rights for all users

  • Access: request a copy of the personal data we hold about you
  • Correction: request correction of inaccurate or incomplete data
  • Deletion: request deletion of your personal data, subject to legal retention obligations
  • Objection to marketing: opt out of marketing communications at any time using the unsubscribe link in any email or by contacting us

9.2 Rights for California residents (CCPA / CPRA)

See Section 10 below.

10

California residents (CCPA / CPRA)

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):

  • Know: the categories of personal information we collect and the purposes for which we use it
  • Delete: request deletion of personal information we hold about you, subject to exceptions
  • Correct: request correction of inaccurate personal information
  • Opt out of sale or sharing: we do not sell or share personal information for cross-context behavioral advertising
  • Limit use of sensitive personal information: we do not collect sensitive personal information as defined by CPRA
  • Non-discrimination: we will not discriminate against you for exercising your rights

To submit a verifiable request, contact us at [email protected]. We will verify your identity before processing your request. You may designate an authorized agent to make requests on your behalf.

Categories of personal information collected in the last 12 months: identifiers (name, email, IP address), commercial information (subscription plan, payment records), internet or network activity (usage logs), and audio data (voice recordings, if used). We collect this information for the business purposes described in Section 5.

11

Cookies and tracking

Strictly necessary Required for authentication, session management, and security. Cannot be disabled while using the Service.
Functional Remember your preferences such as display theme and density settings. Stored in your browser's local storage and not transmitted to our servers.
Analytics We do not currently use third-party analytics cookies. If we introduce an analytics tool in the future, we will update this policy before doing so and seek consent where required by applicable law.

We do not use advertising or tracking cookies for third-party ad targeting. You can control cookies through your browser settings. Blocking strictly necessary cookies will prevent you from using the Service.

12

Children's privacy

The Service is not directed to individuals under the age of 16. We do not knowingly collect personal data from children under 16. If we become aware that we have collected such data, we will delete it promptly. If you believe a child has provided us with personal data, contact us at [email protected].

13

Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email and by displaying a prominent notice within the Service at least 30 days before the changes take effect. The updated policy will indicate the new effective date. Your continued use of the Service after that date constitutes acceptance of the updated policy.

14

Contact us

Post Yardwise Inc., 2727 Walsh Avenue, Santa Clara, CA 95051
Response time We aim to respond within 30 days. Complex requests may take up to 90 days with notice.