Privacy policy.
Effective July 1, 2026 · Last updated July 2026
Hardtack is the customer-facing brand of Hardtack AI LLC (“Hardtack,” “we,” “us”), a company based in West Jordan, Utah, USA. Hardtack is an AI-native operations platform for waste haulers and portable sanitation operators. This policy explains what personal information we handle, why, how long we keep it, and the choices you have. It covers our website, the operator dashboard, the customer and municipal portals, the driver app, and the AI voice agent. It also serves as our California notice at collection.
Controller vs. processor
We handle two different kinds of data in two different roles:
- Operator account data — the information an operator gives us to open and run their account (name, work email, phone, company, billing details). For this, Hardtack is the controller.
- Operator customer data — the information an operator loads into or generates on the platform about their customers, jobs, routes, invoices, and calls. For this, Hardtack acts as a processor on the operator’s behalf; the operator is the controller and decides how that data is used, under our agreement and Data Processing Addendum with them. As our Security page puts it: your customers’ data stays yours.
If you are an operator’s customer, direct privacy requests to that operator first; we will support their response.
Information we collect, and where it comes from
We collect the following categories of personal information — some directly from you (when you request a demo, sign in, or use the platform), some from the operator you work with, and some automatically from your device as you use the service:
- Identifiers & contact details — name, email, phone, company, and role.
- Commercial & billing information — plan, invoices, and payment details. Payments are processed by Stripe; we do not store full card numbers on our servers.
- Audio & electronic information — when the AI voice agent answers a call, the call may be recorded and transcribed to book jobs, quote prices, and keep an accurate record (see “Voice calls” below).
- Geolocation — for routing and the driver app, we process service-address and, for drivers on shift, device location.
- Internet / network activity — IP address, browser/device type, and product interactions, used to operate and secure the service.
- Operator-provided customer data — customers, jobs, containers, invoices, and related records an operator enters or imports (handled in our processor role above).
- Inferences — operational insights we generate to run the platform (for example, route and scheduling suggestions).
How we use information
We use personal information to:
- provide, maintain, and secure the platform;
- answer and process calls, book jobs, generate quotes and invoices, and route work;
- take payments and send transactional messages;
- provide support and respond to your requests;
- improve our own product — without using your data to train third-party AI models (see below); and
- meet legal, tax, and regulatory obligations.
Voice calls & recording
Where recording applies, the voice agent is built to disclose that the call is being recorded at the start of the call, before any substantive conversation — which is what all-party-consent states require. Operators configure the recording notice and remain responsible for any additional consent their jurisdiction requires. Where call recordings are retained, we keep the audio for up to90 days and then delete it; call transcript text is kept for30 days and short call summaries for up to 90 days, after which they are automatically purged.
AI & automated decisions
The platform uses AI models from third-party providers to power the voice agent and other features. We configure those providers to not train on your data and to enable available logging opt-outs, and we redact personal information before it reaches a model where feasible.
Our AI does not make legal or similarly significant decisions about individuals on its own. It proposes actions and surfaces information; a human operator reviews and approves anything irreversible or high-value. We do not use your personal information for automated decision-making or profiling that produces legal or similarly significant effects without human review.
How we share information & sub-processors
We do not sell your personal information, and we do not “share” it for cross-context behavioral advertising, as those terms are defined under California law. Because we do not sell or share, we do not offer a “Do Not Sell or Share My Personal Information” link. We disclose information only to vendors (sub-processors) who help us run the service — categories include cloud hosting and databases, payment processing, communications (telephony and email), AI/LLM providers, mapping, and error/uptime monitoring — each bound to handle it only on our instructions. We maintain a current list of sub-processors and their data-handling terms,available on request. We may also disclose information to comply with law or to protect rights and safety.
How long we keep it
We keep each category of personal information only as long as needed for the purpose it was collected and to meet legal, tax, and security obligations, then delete or anonymize it. Specific windows:
- Call recordings (where retained) — up to 90 days, then deleted.
- Call transcripts — 30 days; call summaries up to 90 days.
- Driver location data — 30 days (rolling).
- Support-ticket transcripts — 90 days.
- Account & billing records — for the life of the account; financial records may be retained up to 7 years to meet tax obligations, after which they are deleted or anonymized.
- Backups — purged on a rolling schedule (daily copies within about 30 days).
- Sign-in sessions — access tokens expire in 24 hours, refresh tokens in 30 days, sign-in links in 30 minutes.
Your choices & rights
Depending on where you live, you may have the right to know what personal information we hold, to access or export it, to correct or delete it, to opt out of sale or sharing (which we do not do), and to limit the use of sensitive personal information. We honor these California (CCPA/CPRA) rights, and — to the extent laws such as the GDPR or UK GDPR apply to you — the equivalent rights of access, rectification, erasure, restriction, portability, and objection.
If you use a customer portal, you can exercise two of these rights yourself, without contacting anyone. From your portal account you can:
- Download your data — we build a file containing your own records: your profile, your jobs, your invoices and line items, your payments, your calls, and your messages.
- Request deletion of your account and data — you confirm the request, and it is then held for 30 days before anything is permanently removed, so you can cancel during that window if you change your mind. You can check its status at any time.
To exercise a right, write to support@hardtack.ai. We will verify your request and respond within 45 days (extendable by another 45 where the law allows), you may appeal a denial, and we will not discriminate against you for exercising a right. If you are an operator’s customer, contact that operator (the controller) first; we will support their response. A Data Processing Addendum is available to operators on request.
Security & data residency
Hardtack is a US company serving US-based operators on US-hosted infrastructure; our services are not directed to individuals in the EEA or UK. We protect data with encryption in transit and at rest for sensitive fields, database-level tenant isolation, least-privilege access, passwordless sign-in with two-factor for admins, and daily encrypted backups. If a security incident affects your data, we will notify affected operators within 72 hours of confirming that the incident plausibly affected their data — we will not wait for a complete picture before telling you, and a first notice may say what we do not yet know. Where we act as a processor, we notify the operator, who decides how to inform their own customers. Full detail is on our Security page.
Cookies
We use only the cookies needed to run the site and keep you signed in (for example, secure, HttpOnly session cookies) and a bot-defense check on our forms. We do not use advertising or cross-site tracking cookies.
Children
Hardtack is a business tool and is not directed to children. We do not knowingly collect personal information from anyone under 16, or from children under 13 as defined by COPPA.
Changes & contact
We review this policy at least annually and will post any updates here with a new “last updated” date; we’ll flag material changes. Questions about privacy or this policy go to support@hardtack.ai, or by mail to Hardtack AI LLC, West Jordan, Utah, USA. Security concerns go to security@hardtack.ai.