Scope & Roles
This policy covers Vendor Callout — the website at vendorcallout.com, the application
your team signs into, the tokenised pages your compression vendors open, and the emails we send on your
behalf. It is written by the company that builds and operates the software.
Two different relationships run through this product, and they carry different obligations:
- Your operational records belong to you. Callouts, units, vendors, routes, locations,
down-hours, costs, credits, photographs and notes are your company's data. You decide what goes in, who
may see it, and how long it stays. We hold and process it to run the service for you, on your
instructions — we do not treat it as ours, and we do not use it to build products for anyone else.
- Account and billing data is ours to administer. Names, email addresses, phone numbers,
sign-in activity, invoices and payment references exist so the service can function and be billed. We
decide how that is handled, within this policy.
In data-protection terms: for your operational records we act as a
processor and your company is the
controller. For account, billing and website data we act
as a controller. If your compliance team needs this written into an agreement, ask us — see
Contact.
The Short Version
Everything below is the detail. This is the substance:
- We collect what the product needs to work, and little else.
- There is no analytics, no advertising, and no third-party tracking anywhere in this
product — not on the marketing site, not in the application, not in our emails.
- One cookie, and it exists only to keep you signed in.
- We never sell or rent data, and never share it for advertising.
- We never see or store a card number.
- Your vendors see one callout at a time, through an expiring link, with no costs and no credits.
- Ask us and we will send you everything your account holds as a spreadsheet — including every
callout, credit and audit entry. Your first export is free.
Information We Collect
Account information
When your company is set up, and whenever a user is added: company name, the person's name, email
address, telephone number, role (administrator or field user), and optionally a profile picture.
Email addresses must be unique across the platform, which is why only we can change one.
Operational records you enter
The substance of the product, entered by your people or by us during onboarding:
- Compressor units — number, make and model, horsepower, monthly rental rate and its
effective dates, production figures, GPS coordinates, status.
- Vendors — company name, contact name, telephone, email addresses including up to five
dispatch addresses that receive callout notifications.
- Routes and locations — names and, for locations, latitude and longitude.
- Callouts — the unit, the reason, what your operator found, the timestamps for called
out, vendor arrived and back online, the calculated down-hours, rental cost and lost production, and who
submitted it.
- Photographs — up to two images per callout, taken in the field. These are stored as
files on our server and are visible to your team and to the vendor handling that callout.
- Vendor work notes — what the vendor's dispatch recorded, with their email address and
a timestamp. These are append-only.
- Vendor credits — the amount agreed for a unit in a month, its status, and any note.
Billing information
Invoices, the units and user seats they were calculated from, discounts, professional services, payment
status, and the reference or trace number you give us when you pay by ACH or wire.
Communications
Messages sent through the contact form on our website, including the name, email address, company and
message body, and our replies. Presentation bookings, including the name, email and chosen time.
Technical information
Sign-in records. Each time someone signs in we record the network address they
connected from, the browser they used, and the time, and we flag when an account is used from an
address it has not been used from before. That is a security measure — it is how an account taken
over with a stolen link gets noticed. It is an address, not a location: we do not
look it up against any geolocation service, we plot nothing on a map, and no third party is
involved.
Ordinary web server logs — IP address, browser user agent, requested page, timestamp — kept for security
and troubleshooting. An audit log within the application records consequential actions:
who created, edited, closed or deleted a callout, who changed a credit, who moved a unit between routes,
who added or removed a user, and when. That log is deliberately durable, because the value of the product
rests on the record being trustworthy.
What We Don't Collect
Stated plainly, because these are the questions security reviewers ask:
- No analytics or tracking. There is no Google Analytics, no tag manager, no advertising
pixel, no session recording, no heat mapping, and no third-party tracking script anywhere in this
product.
- No card numbers. We do not collect, process or store payment card details. Invoices are
settled by ACH or wire, and we record only the reference number you provide.
- No tracking pixels in our emails. We do not embed open-tracking or click-tracking
beacons in the notifications we send you or your vendors.
- No location tracking of people. The coordinates in the product describe compressor
units and leases. We do not track the position of any person or device.
- No data sales. We do not sell, rent, or licence data to anyone, and we do not share it
with advertisers or data brokers. There is no circumstance in which we would.
- No training of AI models on your data. Your operational records are not used to train
machine-learning models, ours or anyone else's.
Cookies
The product sets one cookie: a session identifier that keeps you signed in as you move
between pages. It is marked HttpOnly and Secure, holds no personal information
itself, and is cleared when you sign out.
Small preferences — whether your sidebar is collapsed, which map view you last chose, which table columns
you hid — are kept in your browser's own local storage. They never reach our server.
We use no advertising cookies and no cross-site cookies, which is why the site shows you no cookie
banner: there is nothing to consent to.
How We Use Information
- To run the service — record callouts, calculate down-hours, costs, lost production and
contract credits, produce reports, and notify the right people.
- To notify — send callout notifications to your nominated addresses and your vendors'
dispatch contacts, and send sign-in links, password resets and invoices.
- To bill — count units and active user seats, issue invoices, and record payment.
- To support you — investigate problems you report, which may require us to look at the
records involved.
- To keep the service secure — detect abuse, investigate incidents, and maintain the
audit trail.
- To comply with law where we are required to.
We do not use your operational records for marketing, and we do not use one customer's data to serve
another. Each company's data is separated by a tenant identifier enforced on every query.
Who Sees It Inside Your Company
Access inside your account is determined by role, and it is enforced on the server, not merely hidden in
the interface:
- Field users log callouts and see operational information — units, hours, status,
barrels at risk. They do not see rental rates, downtime cost, lost production value,
vendor credits, or billing.
- Company administrators see everything in their own account, including money, and
manage their own team.
- We can access your account to support you, to fix a fault, and to maintain master data
such as units and rental rates, which we administer on your behalf. Those actions are audit-logged.
What Your Vendors Receive
Your compression vendors are notified when a callout is submitted, and they may record what they did. They
never hold an account with us, and what reaches them is deliberately narrow:
- The notification email contains the unit, model, location, route, reason, the timestamp, what your
operator found, any photographs, the production at risk in volume, a map link, and the name and contact
details of the person who reported it.
- It contains no rental rates, no downtime cost, no dollar value of lost production, and no
credits.
- The link they open is tokenised and expires, and it shows them one
callout — never a list, never another unit, never anything financial.
- What they write is attributed to their email address, timestamped, and cannot be edited afterwards by
them or by you.
You control which vendor addresses are on file. Removing an address stops future
notifications to it; it does not withdraw emails already delivered.
Service Providers
We keep the list of companies involved in delivering this product deliberately short. Each is used for a
specific purpose and receives only what that purpose requires.
| Provider | Purpose | What it receives |
| DigitalOcean | Server hosting and backups |
All application data, at rest on their infrastructure |
| Brevo | Outbound email delivery |
Recipient address, subject and message body of the emails we send |
| Cloudflare | DNS and network protection |
Request metadata in transit, including IP address |
Google Drive Workspace |
Off-site storage of encrypted system backups |
A complete encrypted copy of the database and uploaded photographs, hourly. Google cannot
read it: archives are encrypted with AES-256 before they leave our server, and the key
never leaves it. |
| Google Calendar | Calendar entries for presentations you book — only if enabled |
Booking name, email, and the appointment time |
| healthchecks.io | External monitoring — alerts us if the service stops responding |
A periodic signal, and when something is wrong, the technical reason (for example "disk 91% full").
No customer data. |
| jsDelivr, unpkg | Serving common code libraries to your browser |
Your IP address and browser, as with any file a web page loads |
| Google Fonts | Typeface used across the product |
Your IP address and browser |
| OpenStreetMap, Esri | Map and satellite imagery tiles |
Your IP address and the map area being viewed |
Map tiles are requested only on pages that show a map, and only for the area you
are looking at. Neither provider is told which company or unit you are viewing.
Other Disclosure
Beyond the providers above, we disclose information only:
- On your instruction — including the notifications you configure and the vendors you
nominate.
- When the law requires it — a valid subpoena, court order or equivalent. Where we are
permitted to tell you, we will, so you have the opportunity to respond.
- To protect people or the service — to investigate fraud, abuse, or a threat to
someone's safety.
- In a business transfer — if the company is acquired or merges, data may transfer as
part of that business, subject to this policy. We would notify you.
Security
What is actually in place:
- Encryption in transit. The entire site and application are served over HTTPS,
and the connection between our edge network and our server is authenticated as well as encrypted.
- Encrypted, tested backups. The system is archived hourly. Every archive is
signed, and each one is verified by actually restoring it into a scratch database and comparing
record counts — an unverified backup is a hope, not a backup. Copies held off-site are encrypted
with AES-256 before they leave our server.
- Passwordless sign-in. We recommend and default to emailed sign-in links, which work
once and expire in fifteen minutes. There is no standing password to steal or reuse. Where passwords are
used, they are stored only as salted hashes.
- Sessions expire. Ten minutes of inactivity raises a warning; two minutes later
you are signed out.
- Separation between companies. Every query is scoped to a tenant; one customer cannot
reach another's records.
- Role enforcement on the server. Money and administrative functions are refused for
users who lack the role, not merely hidden from view.
- Expiring vendor links. Vendor access is tokenised, single-callout and time-limited.
- An audit trail covering consequential actions, which outlives the records it
describes.
No system is perfectly secure, and we will not claim otherwise. If we become aware of a breach affecting
your data, we will notify you without undue delay, describe what happened and what we are doing about it.
Retention & Deletion
- Operational records are kept for as long as your account is active, because their value
is historical: a callout from two years ago is the evidence behind a credit you claimed.
- Deleting a person does not delete their work. If a user is removed, the callouts they
logged remain, still under their name. Suspending an account ends access while keeping everything.
- Photographs stay with their callout. Only an administrator can remove one, and the
removal is recorded in the audit log with the file name and who uploaded it.
- Audit entries are durable and outlive the records they describe. That is deliberate.
- Contact-form messages and presentation bookings are kept while they are useful to the
conversation, and removed when they are not.
- On termination, you may export first, free of charge and regardless of how many
exports you have had before. After that, we delete your account data from live systems within ninety
days, except where we must keep records for legal or accounting reasons — invoices being the usual
case.
- Backups are a separate clock, and worth being precise about. The whole system is
archived hourly. Those archives are kept on a rolling schedule — every hour for a day, one a day for
a month, one a month for a year — so data you have deleted can persist in an encrypted backup for up
to twelve months before the last copy ages out. We do not restore a backup to
resurrect deleted records, and we will tell you the date the final copy expires if you ask.
Your Rights
Depending on where you live, you may have rights to access, correct, export, restrict or delete personal
information about you. We honour these requests regardless of whether a particular law compels us to.
- Access and export — ask us and we will produce your whole account as a
spreadsheet: company details, users, vendors and their contacts, routes, locations, units, every
callout, vendor credits, rental-rate history, vendor work notes and the audit log.
Your first export is free. Each export after that is
$500.00, which covers the work of producing it and the server time it consumes —
except the export you take when you leave, which is always free.
We handle this ourselves rather than putting a one-click download in the application, because that
single file contains your complete commercial record with your vendors and the audit trail behind
it. Photographs are listed by filename; ask and we will package the image files themselves.
- Correction — names, telephone numbers and profile pictures are editable in the product.
Ask us to change an email address, as those must stay unique.
- Deletion — ask, and we will explain precisely what will and will not disappear, since
some records exist to keep the audit trail honest.
- Complaint — if you believe we have handled data badly, tell us first; we would rather
fix it. You retain the right to complain to a supervisory authority.
If you are an employee of one of our customers, please raise requests with your own administrator first —
it is their data, and they may act faster than we can. We will help them.
Where Data Lives
Our servers are located in the United States, and the service is designed and sold for
oil and gas operators in the United States. If you use it from elsewhere, understand that your
information is processed in the United States, under United States law.
One qualification, for accuracy: encrypted backup archives are stored in Google Workspace, and Google
may hold them in data centres outside the United States depending on how that storage is configured.
The archives are encrypted before they leave our server and Google cannot read them, but the ciphertext
may not remain within United States borders.
Children
This is industrial software sold to companies. It is not directed at children, and we do not knowingly
collect information from anyone under 18. If you believe we have, tell us and we will remove it.
Changes to This Policy
If we change this policy we will update the date at the top. For changes that materially affect how we
handle your information, we will notify account administrators by email before the change takes effect
rather than relying on you to notice.