pavemt
Privacy notice · Client organizations

How your organization's data is handled

This notice is for business customers (stations / operators) evaluating or using pavemt. The privacy notice for individual users of the pavemt mobile app (drivers and staff) is published separately.

Last updated August 1, 2026 Applies to pavemt hosted services

01Who we are and roles

pavemt provides a multi-tenant operations platform for delivery-station workforce, fleet, safety, and related workflows.

RoleWhoResponsibility
ControllerYour organization (the Client)Decides why and how workforce and operational personal data are processed for your business
Processorpavemt (platform operator)Processes that data on your behalf to host and run the Services
SubprocessorsAuth0 · Neon · Render · Cloudflare · MailgunIndependent providers supporting authentication, database, hosting, DNS/edge, and email

Your administrators configure who in your organization can access which modules through roles and page permissions. Data is isolated by tenant — users never see another client's workspace.

Our baseline promise

We do not sell personal information, and we do not use your workforce data for unrelated advertising.

02What the Services are for

We process data to provide features such as: user accounts and secure sign-in (web and mobile); employee, roster, scheduling, and onboarding workflows; fleet, garage, and related operational records; incident, coaching, and safety-related records; reports, imports, and administrative configuration; optional messaging configuration your administrators supply; and support, security, and service reliability.

03Categories of data processed

Account & access

Work email or username, name, role, permissions; authentication credentials or tokens (passwords stored as one-way hashes for credential-based login; web sign-in uses Auth0); session tokens and access-related security logs.

Workforce & HR-adjacent operations

Employee identifiers and contact details as you enter them; employment and operational fields your admins configure; sensitive fields some clients store for operational compliance (dates of birth, background or drug-screening results as entered by your staff) — treated at the highest sensitivity tier.

Safety & operations

Incident and related operational reports (locations, vehicle identifiers such as VIN, claim or report numbers, third-party contacts as entered); coaching, violations, and similar records; documents and images you choose to upload.

Fleet & assets

Unit identifiers, VIN, maintenance and task data, garage and audit records.

Technical & service data

IP address, device or app type, timestamps, and similar logs needed to operate and secure the Services; email delivery metadata for invites and notices sent on your behalf.

Configuration secrets

Integration secrets you enter (for example messaging API keys) — stored with encryption at rest and never exposed back to browsers in clear text.

04How we use data

05Sharing and subprocessors

We share data only as needed to run the Services:

SubprocessorPurpose
Auth0 (Okta)Web identity / secure sign-in
NeonHosted PostgreSQL database (AWS regions)
RenderApplication hosting
CloudflareDNS and related edge services (e.g. the custom sign-in hostname)
MailgunTransactional email (or your configured SMTP)

We may also disclose data if required by law, to protect rights and safety, or in connection with a corporate transaction (with appropriate protections). Your own vendors are not our subprocessors unless we integrate and transfer data to them under your instruction.

06Security measures (summary)

Layered controls appropriate to a B2B operations platform, including: encryption in transit (HTTPS/TLS) with certificate-verified database connections; Auth0 Universal Login for web plus one-way password hashing for credential login; tenant-scoped session tokens with role- and page-based authorization; security headers and rate limiting on sensitive auth endpoints; encryption at rest for high-value secrets; separated staging and production environments; and backup with point-in-time recovery capability via our database provider.

No online service is perfectly secure. Clients remain responsible for administrator hygiene: strong unique credentials, least-privilege roles, approved devices and networks, and lawful notices to their workers.

07Retention

We retain Client data for as long as your account is active and as needed to provide the Services, unless your agreement or applicable law sets a different period. Upon termination we follow the data return and deletion terms in your contract — or, if silent, delete or de-identify tenant data within a commercially reasonable period after written request, except copies retained in encrypted backups for a limited roll-off window or as required by law.

Ask your account contact to document specific retention periods if your compliance program requires fixed TTLs.

08Your responsibilities as Client

09Individual rights, children & changes

Individual rights. Employees and drivers using pavemt under your organization should contact your administrator or HR team for access, correction, deletion, or other rights regarding workplace data. If we receive a request that clearly relates to your tenant, we will redirect the individual to you or assist you as processor.

Children. The Services are for workplace use by adults and are not directed to children under 16 (or the applicable age of digital consent).

Changes. We may update this notice as the product or subprocessor list changes. Material updates are communicated to client administrators by email, in-product notice, or an updated "Last updated" date on this page.

10Contact

Product / support: the pavemt support page, or your designated account email.

Privacy or security inquiries: contact your pavemt account representative or the support channel and mark the subject "Privacy".