1. Overview
DLCWorker ("we", "us", "our") is a cloud-based software-as-a-service (SaaS) platform for workforce scheduling and management. This Privacy Policy explains how we collect, use, store, and protect your information when you use our Service. DLCWorker operates as a data processor on behalf of your organization (the data controller). Your organization's administrator determines what data is collected and how it is used within the platform.
2. Information We Collect
We collect information in the following categories:
Account Information
- Name, email address, password (hashed), phone number, profile photo
- Date of birth, home address, and emergency contacts, where you or your organization enter them
- Role, job title, and permissions within your organization
- Notification and timezone preferences, and your text-message and phone-call preferences
Organization Data
- Company name, industry, team size, custom branding assets (logo, colors)
- Subscription plan and billing information (processed by third-party payment providers)
Work Data
- Schedules, shifts, time punches, check-ins, time-off requests
- Tasks, checklists, performance metrics, scorecard data
- Chat messages, announcements, and notifications within the platform
- Pay type, pay rates, and pay-rate history
- Photos taken at clock-in or clock-out where your organization uses them, and signatures drawn to sign documents
- Documents your organization uploads to an employee file — for example identification documents, tax forms, direct-deposit forms, background-check results, medical notes, and workers' compensation records
- Benefits and COBRA enrollment information, including dependents your organization enters for benefits purposes (name, date of birth, last four digits of a Social Security number)
- Vehicle inspection and damage photos, odometer and fuel photos, and phone-call recordings and transcripts (see Section 5b)
Job Applicants
- When you apply through an organization's DLCWorker application page, we collect what you submit on the organization's behalf: your name, contact details, the role you applied for, your resume and cover note, and your answers to screening questions
- To help the hiring organization review applications, your cover note may be summarized and given a fit score by an AI model (see Section 5a). The organization, not DLCWorker or the AI, makes every hiring decision
Technical Data
- Browser type, operating system, IP address, device identifiers
- Usage patterns, feature interactions, and error logs
- Location data: For users actively on a scheduled shift, precise geolocation (GPS coordinates) is collected when your organization enables location-based features such as check-in geofencing, route tracking, vehicle-location verification, or driver-status monitoring. Collection occurs only during scheduled shift windows, and only on devices where the user has granted operating-system-level location permission. Location data is retained for 90 days for dispatch coordination and dispute resolution, then deleted. Your organization is responsible for posting any workplace-monitoring or location-tracking notices required by federal, state, or local law (e.g., New York Civil Rights Law §52-c, California Labor Code §435, Connecticut Gen. Stat. §31-48d) before enabling these features.
3. How We Use Your Information
- Provide, maintain, operate, and improve the Service
- Process schedules, time tracking, and workforce management operations
- Send notifications related to shifts, tasks, and team activity
- Generate analytics, reports, and AI-powered insights for your organization
- Provide customer support and respond to inquiries
- Communicate service updates, maintenance notices, and security alerts
- Detect, prevent, and address security issues, fraud, and abuse
- Comply with legal obligations and enforce our terms
- Generate anonymized, aggregated analytics to improve the Service (no individual identification)
4. Multi-Tenant Data Isolation
DLCWorker is a multi-tenant platform. Each organization's data is logically isolated using organization-level access controls and database-level tenant identifiers. This means: your organization's data is never accessible to other organizations; all API requests and database queries are scoped to your organization; role-based access controls further restrict data visibility within your organization. We regularly audit our isolation mechanisms to prevent cross-tenant data leakage.
5. Data Sharing and Sub-Processors
We do not sell your personal data. We share information only with trusted service providers ("sub-processors") necessary to operate the Service:
| Provider | Purpose | Data Processed |
|---|
| Vercel | Application hosting, CDN, and file storage (Vercel Blob) | Request data, logs, uploaded files and photos |
| Supabase | Database | All customer data |
| GitHub and Backblaze B2 | Database backups (backup job runs on GitHub; backup files stored on Backblaze B2) | A full copy of the database |
| Stripe | Payment processing | Billing info, plan details (no card data stored by us) |
| Resend | Email delivery | Email addresses, notification content |
| Google (Gmail API) | Email integration for data import | OAuth tokens (encrypted), email attachments (processed, not stored) |
| Pusher | Real-time messaging | Chat events, check-in status updates |
| Twilio | SMS messaging and voice/phone-call delivery | Mobile numbers, message content, and (for AI Phone Agent calls) call audio — see section 5b |
| Anthropic (Claude) | AI-powered features | Operational context for the specific AI feature, and job applications for AI review — see section 5a below |
| ElevenLabs | AI Phone Agent voice, speech recognition and conversation handling; text-to-speech for announcements | Call audio, transcripts, caller phone numbers, and text converted to speech — see section 5b |
| OpenAI (via ElevenLabs) | Language model behind AI Phone Agent conversations | Call transcripts as they happen, and the caller context the agent looks up (for example the caller's schedule, route and vehicle) |
| Upstash | Rate limiting and usage counters | User and organization identifiers, request counts |
| Apple, Google, and browser push services | Push notifications to phones and browsers | Device push tokens, notification content |
| Slack (optional) | Sending notifications to your organization's Slack workspace, if connected | Notification content your organization chooses to send |
| Giphy and Tenor (Google) | GIF search in chat | GIF search terms |
| Open-Meteo | Weather forecasts | Your station's coordinates only — never a driver's location |
We may also share information: (a) within your organization based on role permissions; (b) when required by law, court order, or governmental authority; (c) in connection with a merger, acquisition, or sale of assets (with prior notice to affected users).
5a. AI Features and Third-Party AI Processing
AI is part of the Service your organization subscribes to, and your organization decides which features its team uses. Most AI features are processed by Anthropic, PBC via their Claude API; the AI Phone Agent is processed by ElevenLabs and the OpenAI language model it runs on (see Section 5b).
Interactive assistant features ask each user to enable AI first, in the in-app "Enable AI Features" dialog: the Ask AI chat assistant, chat-message issue detection, write-up drafting, report and chat summaries, coaching briefs and who-to-coach summaries, HR onboarding, offboarding and checklist suggestions, benefits Q&A, document import mapping, and freight rate-confirmation reading. You can grant or revoke that consent at any time in Settings → Privacy & Security → AI Features. Other AI features run as part of the workflow they belong to — for example importing a scorecard, inspecting a van, or reviewing a job application — without a separate per-user prompt, whenever someone in your organization uses that workflow. Job applicants do not have DLCWorker accounts, so their applications are reviewed this way.
The specific data sent depends on which AI feature is used:
- AI chat assistant (managers): your typed message, the last 10 messages of that conversation, and operational context drawn from your organization: employee names and job titles, today's shift assignments, weekly shift counts, 7-day safety-violation summaries, vehicle status, open route issues, delivery-performance averages (DPMO, package counts), pending time-off counts, and messages from group/announcement chat rooms in the last 24 hours.
- Chat-message issue detection: when you send a chat message that contains keywords suggesting a vehicle or route issue, the message text is analyzed to extract the issue details.
- AI write-up drafting: incident type, category, employee name (if provided), and any additional context the manager enters.
- AI report summary: the JSON contents of the report being summarized (capped at 3,000 characters).
- AI onboarding suggestions: role, department, and job title only.
- AI benefits Q&A: the employee's typed question, employment type, and enrolled benefit plan names.
- PDF scorecard import: the contents of the PDF the user uploads.
- Job-application review: the role applied for and the applicant's cover note (up to 2,000 characters), plus, when they attach a PDF résumé, the résumé itself and their yes/no answers to the job requirements, to produce a fit score and a one-line summary for the hiring organization. We don't include the applicant's name in the request, though a résumé they attach may contain it.
- Imports: the file or image uploaded for a scorecard, delivery-report, pad, roster, receipt, or sales-report import, which can include driver names, employee IDs and performance metrics — and, for a pasted roster, email addresses, phone numbers and pay rates.
- Coaching and team summaries: a driver's name, scorecard metrics, attendance and incident notes, customer-feedback quotes, and their coaching replies, to draft coaching messages, automatic coaching after a scorecard import, a driver's self-coach, and team-member summaries.
- Explanations, quizzes and narration: the text of a write-up, coaching note or announcement and, for explanations, the driver's question.
- Recognition messages: a driver's first name, packages delivered or years of service, and your organization's name and mission, for check-out, dispatch and work-anniversary messages.
- Route-note answers: your route notes, which can include delivery addresses and access instructions, and the question asked.
- Tasks and supplies: task text, assignees' first names, and inventory levels.
- Van inspections: vehicle, damage and dashboard photos.
- Owner reports: names of people with expiring certifications or long inactivity, for the daily digest and health report. Staffing forecasts and the weekly operations review use aggregate counts only.
Passwords and payment card details are never sent to any AI provider, and drivers' GPS coordinates are never sent to Anthropic. Other personal information is sent only when a feature listed above needs it.
Anthropic processes this data under their own terms and privacy policy. DLCWorker does not permit Anthropic to use your data to train AI models. For more information on Anthropic's practices, see anthropic.com/legal/privacy.
Revoking consent stops the interactive assistant features listed above for your account; it does not stop the workflow features your organization uses. It does not delete AI-generated outputs that have already been saved to your organization's records (for example, a previously drafted write-up remains on the employee file unless the organization deletes it).
5b. Phone Calls and Call Recording
DLCWorker offers an optional AI Phone Agent feature that places and receives operational telephone calls on behalf of your organization (e.g., driver outreach, dispatch coordination, rescue requests). When this feature is enabled and used:
- Calls are placed and received through Twilio
- Call audio is recorded for transcription, AI processing, audit, and dispute-resolution purposes
- The phone agent's voice, speech recognition, and transcripts are provided by ElevenLabs, which runs the conversation on a language model from OpenAI; call summaries and follow-up actions may also use the AI providers listed in Section 5
- Call audio and transcripts are retained for 90 days then automatically deleted, except where retention is required by law
Recording disclosure and consent. Some U.S. jurisdictions require all parties on a call to be notified that the call is being recorded ("two-party" or "all-party" consent — including California, Connecticut, Delaware, Florida, Illinois, Maryland, Massachusetts, Montana, Nevada, New Hampshire, Pennsylvania, and Washington). Outbound calls placed by DLCWorker state near the start that the call may be recorded, and the AI Phone Agent is instructed to tell inbound callers the same. Your organization remains responsible for any additional notice or consent its jurisdictions require, including telling drivers in advance that dispatch calls may be automated and recorded. Your organization is solely responsible for compliance with all applicable call-recording, wiretap, TCPA, and telemarketing laws in the jurisdictions where your drivers and callers are located.
6. Data Storage and Security
We implement industry-standard security measures to protect your data:
- Encryption in transit: All data transmitted between your device and our servers is encrypted using TLS 1.2+
- Encryption at rest: Stored data is encrypted using AES-256
- Authentication: Passwords are hashed using bcrypt; sessions use signed JWT tokens
- Access controls: Role-based permissions limit data access within organizations
- Infrastructure: Hosted on SOC 2 compliant cloud infrastructure
- Abuse protection: Rate limiting on sign-in and API access, and audit logs of administrative changes
While we strive to protect your data, no method of transmission or storage is 100% secure. We encourage you to use strong passwords and enable available security features.
Hawaii residents: In the event of a security breach affecting unencrypted personal information of Hawaii residents, we will notify affected individuals as required by Hawaii Revised Statutes §487N-2, including notice without unreasonable delay and with the content elements required by statute. We will also notify the Hawaii Office of Consumer Protection and any consumer reporting agencies where required.
7. Data Retention
- Active accounts: Data is retained for as long as your account and subscription are active
- After cancellation: Your data is available for export for 30 days, then permanently deleted
- Account deletion: Personal data is deleted within 30 days of request
- Backups: Data may persist in backups for up to 90 days after deletion
- Legal holds: Data required for legal or compliance purposes may be retained longer as required by law
- Anonymized data: Aggregated, anonymized data that cannot identify individuals may be retained indefinitely for analytics and Service improvement
8. Your Rights
Depending on your jurisdiction, you may have the following rights:
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate or incomplete data
- Deletion: Request deletion of your personal data ("right to be forgotten")
- Portability: Receive your data in a structured, machine-readable format (JSON/CSV)
- Restriction: Request restriction of certain processing of your data
- Objection: Object to processing based on legitimate interests
- Withdraw consent: Where processing is based on consent, withdraw at any time
To exercise any of these rights, contact us at the email below. We will respond within 30 days. Note that some requests may need to be directed to your organization's administrator, as they are the data controller for your work data.
9. Data Processing Agreement
For organizations that require a formal Data Processing Agreement (DPA) — such as those subject to GDPR, CCPA, or other data protection regulations — we offer a DPA that covers our obligations as a data processor. Enterprise customers can request a DPA by contacting us. The DPA supplements this Privacy Policy and governs our processing of personal data on your behalf.
10. International Data Transfers
Our Service is hosted in the United States. If you are located outside the US, your data will be transferred to and processed in the US. We ensure appropriate safeguards are in place for international transfers, including standard contractual clauses where required. By using the Service, you consent to the transfer of your information to the United States.
11. Google API Data & Gmail Integration
DLCWorker offers an optional Gmail integration that allows organization owners to automatically import delivery scorecard and performance data from Amazon emails. This section describes how we handle Google user data in compliance with Google's API Services User Data Policy, including the Limited Use requirements.
What We Access
- We request read-only access to your Gmail account (gmail.readonly scope)
- We only read emails matching specific subject filters (e.g., "Scorecard", "DOR", "Daily Report") configured by the organization owner
- We extract CSV and Excel file attachments from matching emails for data import
- We do not read, store, or process the body text of your emails
How We Use Gmail Data
- Extracted scorecard data (delivery metrics, safety violations) is imported into your DLCWorker organization's dashboard
- We do not use Gmail data for advertising, market research, or any purpose unrelated to the DLCWorker Service
- We do not share Gmail data with third parties except as required to operate the Service (see Sub-Processors above)
Data Storage & Security
- Gmail OAuth tokens (access and refresh tokens) are encrypted at rest using AES-256-GCM
- Tokens are stored in our database and are never exposed to client-side code
- Email attachment data is processed in memory and only the extracted metrics are stored
- Raw email content and attachments are not permanently stored after processing
Revoking Access
- You can disconnect Gmail at any time from DLCWorker Settings, which deletes all stored OAuth tokens
- You can also revoke access from your Google Account at myaccount.google.com/permissions
- Previously imported scorecard data remains in your DLCWorker account after disconnection
Google API Services User Data Policy
DLCWorker's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We only use Google data to provide and improve the DLCWorker Service for the user who authorized access.
12. Cookies and Tracking
DLCWorker uses the following types of cookies and similar technologies:
- Essential cookies: Required for authentication, session management, and security. Cannot be disabled
- Functional cookies: Remember your preferences (theme, timezone, language)
- Analytics: We may use privacy-respecting analytics to understand usage patterns and improve the Service. No third-party advertising cookies are used
13. Children's Privacy
DLCWorker is a workplace tool. Accounts are intended only for adults of legal working age, and we do not knowingly allow anyone under 18 to create an account or apply through an application page. If you believe a person under 18 has done so, please contact us and we will take steps to delete their data promptly. Separately, your organization may enter information about employees' dependents, including children, to administer benefits; that information is processed only on your organization's behalf, is visible only to authorized users in your organization, and is not used for any other purpose.
14. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes at least 30 days in advance via email or through the Service. Your continued use after changes take effect constitutes acceptance. Previous versions of this policy will be archived and available upon request.
15. Contact Us
If you have questions about this Privacy Policy, want to exercise your data rights, or need to report a security concern, contact us at support@dlcworker.com.