ROADCASE / LEGAL / PRIVACY
Privacy policy.
What personal data RoadCase holds, why, where it lives, and what you can ask us to do with it.
Who is responsible for your data
RoadCase is a logistics platform for touring and live events. Crew members scan cases on and off trucks, and the system keeps a permanent record of those scans.
RoadCase is used by companies (production companies, vendors) that enroll their own crews. For crew data, your company decides who is enrolled and controls your profile. We process that data on the company’s behalf and on its instructions. For director and administrator accounts that we provision directly, we are responsible for the account data ourselves.
The operator is Technically Creative LLC, a Michigan LLC (“we”, “us”). If you are a crew member with a question about your data, start with your production manager. You can also write to support@roadcase.tools.
We describe our actual practices here. We do not claim certifications or compliance badges we cannot demonstrate.
What we hold
Account and sign-in data
- Email address and last sign-in time.
- Sign-in is passwordless. You sign in with a passkey or with a six-digit code we email to you. For a passkey we hold the public credential. The private key, and any fingerprint or face data used to unlock it, stay on your device.
- We do not hold passwords.
People profiles
- Full name, role, job title, department, phone number, and an active flag.
- If you enable notifications, a web-push subscription for your browser or device.
Labour contact records
- Contact details that a customer company records for hired labour and local crew, such as a name and a phone number. The company controls these records.
Scan records
- Every scan is recorded with who scanned, which case, which truck, which device, and when. These records are append-only and cryptographically chained so they cannot be silently altered. They are the system’s chain-of-custody ledger.
Audit records
- System and administrative actions are written to an append-only audit log.
Photos
- Users can photograph packed trucks and cases. Photos are of equipment, but people can appear in them incidentally.
Correspondence
- Email you send to support@roadcase.tools, which is held in our operator mailbox.
We do not run advertising trackers or third-party analytics. We do not sell personal data, and we do not share it with anyone for marketing.
Why we hold it
- To run the service: signing you in, recording scans, reaching crew for a production, and showing your company its own logistics data. This is performance of our contract with your company and, for crew data, processing on that company’s instructions.
- To keep the record trustworthy: the scan and audit ledgers exist so a company can prove what happened to its equipment. Keeping that ledger intact is a legitimate interest of ours and of the companies using the service.
- To protect the service: sign-in abuse limits and security logging.
We do not use personal data for profiling, automated decision-making with legal effect, or advertising.
Where data lives
Data is stored in the United States. Our database, authentication, and file storage provider is Supabase (AWS us-east-2, Ohio). The application is hosted on Vercel. Sign-in code email is sent through Mailgun (US region). Our operator email runs on Google Workspace. The scanner fetches a runtime file from the jsDelivr content delivery network. Error reporting through Sentry is planned and not yet receiving data. The current list, with the data each provider handles, is on the subprocessors page.
If you use notifications, your browser vendor’s push service carries them. That service is chosen by your browser and is not one of our subprocessors.
Because data is stored in the United States, data about people in Australia is transferred there. We do not enroll crew located in the European Union or the United Kingdom until a signed data processing agreement with standard contractual clauses is in place with the customer company.
How long we keep it
Scan and audit records are kept indefinitely by design. They are the integrity ledger of the system. When a person’s identity should be removed, we pseudonymize the profile instead of deleting history (see section 06).
| Data | Retention | Why |
|---|---|---|
| Scan records | Indefinite, by design | The integrity ledger. Append-only and hash-chained. Deleting or editing entries would break the chain. |
| Audit log | Indefinite, by design | Append-only record of system and administrative actions, including erasure actions themselves. |
| People profiles (crew and administrators) | Kept while the ledger references them. Pseudonymized on request or departure. | Scan records reference the profile permanently, so the row is not hard-deleted. Identity is removed instead. |
| Phone numbers and other profile contact details | Kept with the profile. Scrubbed when the profile is pseudonymized. | Used to reach crew for the production. |
| Web-push subscriptions | Until notifications are turned off, the device is unsubscribed, or the profile is pseudonymized. | Needed to deliver notifications to a device. |
| Labour contact records | Life of the customer relationship, or until the customer removes them. Identifying details are scrubbed on a verified request. | Customer content used to reach hired labour. |
| Sign-in codes and sign-in attempt records | Held by our authentication provider under its own settings. | Running passwordless sign-in and limiting abuse. |
| Photos and other uploaded files | Until deleted by the customer, or at exit per the terms. | Customer content. |
| Logistics data (cases, items, trucks, manifests) | Life of the customer relationship, plus the export window at exit. | Customer content. Deleting a case archives it, and its history stays on its internal identifier. |
| Database backups | Daily, on a rolling seven-day window. | Disaster recovery. Data removed from the live database can remain in a backup until the seven-day window passes it. |
| Backups of uploaded files | Weekly and encrypted. Being put in place. The retention window will be stated here once the backup is active. | Disaster recovery for uploaded files. |
| Support and privacy correspondence | Kept in our operator mailbox only as long as needed to handle the request. | Answering your request and keeping a record that we did. |
Backups are limited to what is listed above. Point-in-time recovery is not enabled at this stage, so we cannot restore the database to an arbitrary moment inside the backup window.
Your rights and erasure requests
Depending on where you live, you may have rights under privacy law, including the Australian Privacy Act. These generally include access to your data, correction of inaccurate data, and deletion.
What we will do on request:
- Access: give you a copy of the personal data we hold about you.
- Correction: fix inaccurate profile data, or route the request to your company, which controls your profile.
- Deletion: because scan records are an append-only ledger, we do not delete history. Instead we pseudonymize. Your name, job title, phone number, and other identifying contact details are scrubbed, your sign-in credentials and web-push subscriptions are removed, and your profile is deactivated. The remaining records no longer identify you. If you also have an administrator account, we delete it. We believe this balances erasure rights against the ledger’s integrity purpose. The pseudonymization is itself written to the audit log.
- Objection or restriction: tell us what you object to and we will respond.
Photos in which you appear can be deleted by the customer company, or by us on the company’s instruction.
Send requests to support@roadcase.tools. We respond within 30 days. If you are enrolled by a customer company, we may route the request through that company, since it controls your enrollment. If we refuse or delay part of a request, for example because an active show still needs your name on a manifest, we will tell you what and why. If you are unsatisfied, you can complain to your local data protection authority (in Australia, the OAIC).
Security
- Sign-in uses passkeys or emailed one-time codes. There are no stored passwords to leak.
- The browser does not talk to the database directly. Access goes through server routes that enforce per-company isolation, and the database enforces row-level security per company.
- Sessions are held in an httpOnly cookie and expire after 12 hours.
- Scan and audit records are append-only and hash-chained, so tampering is detectable.
- Backups are described in section 05. Weekly backups of uploaded files are not yet active.
No system is perfectly secure. If we learn of a breach affecting your personal data, we will notify affected customers, and regulators where the law requires it.
Children and changes
RoadCase is a workplace tool for touring crews. It is not directed at children, and we do not knowingly collect children’s data.
We will post changes to this policy here and update the effective date. For material changes we will notify customer companies by email.