Privacy policy
Who we are
CallRunner is a hosted office and field product for small service businesses. We operate the public site at callrunner.app, the office web app at office.callrunner.app, the API at api.callrunner.app, and the Android field app named CallRunner.
This Privacy Policy explains how we collect, use, share, and retain personal information when you use those services.
“You” means the business that opens an office account, the people who sign in as office users, and the technicians who sign in on the field app. “We” means CallRunner, the operator of the service.
Information we collect
We collect the information you and your organization enter, plus the session data needed to keep you signed in.
Office accounts and technicians
When someone creates or uses an office account, we collect the company name, org code, optional trade tag, office user’s name, email address, and password.
Technicians are created in the office. The field app does not create accounts. A technician signs in by opening an invite from the office, then entering a PIN set by the office.
We store a hash of each password and PIN. We do not store them in plaintext, and we cannot display a PIN later.
Service-call records
The office stores the jobs your shop enters, including:
- job description, category, priority, status, schedule, and access notes
- job-site address (street, unit, city, state, and postal code)
- caller name, phone number, and email, if entered
- assigned technician
- expenses (type, description, amount, vendor, and date)
- job photos and optional captions
- a history of status changes
- when the office closes a job: invoice number, check number, paid status, and paid date
- when the office cancels a job: a cancellation reason
On the field app, a signed-in technician can update status on assigned jobs (other than close or cancel), add expenses, and upload job photos. The field app does not collect payment-card numbers and cannot close a job or record payment.
Photos
If a technician attaches a photo from the camera or the device library, we store that image and any caption with the job. Camera and photo-library access is used only to attach a job photo. Photos are private to the shop. They are not published at public URLs. Only a signed-in office user for that organization, or the assigned technician, can retrieve them.
Sessions and device storage
After a successful sign-in we issue a session token.
- Office sessions last about seven days, or until you sign out.
- Field sessions last about thirty days, or until the technician signs out.
The office stores the session token in the browser’s local storage. The field app stores the session and the API host in on-device storage so the technician can stay signed in.
Information we do not collect
CallRunner does not include advertising, analytics, or crash-reporting software. We do not collect device GPS or other device location. The field app does not access contacts, text messages, the microphone, or a list of other apps on the device. We do not process card payments in CallRunner.
Browsing the public website, including this page, does not create an account. As with any website, our host may see ordinary connection data (such as an IP address) while serving the request. We do not write that data into the shop’s records or use it to determine your location.
How we use it
We use personal information to:
- provide the office and field product — creating, assigning, updating, and closing jobs
- authenticate office users and technicians, maintain sessions, and limit repeated failed sign-in attempts
- show a technician only the jobs assigned to them
- store expenses and job photos on the shop’s record
- respond to support and privacy requests
- operate, maintain, and secure the service
- comply with law
We do not use this information to show advertisements, to build advertising profiles, or to sell your job or customer lists.
How we share it
We do not sell personal information.
Your organization. Office users in your shop can see that shop’s jobs, technicians, expenses, and photos. A technician can see the jobs assigned to them. They cannot see another shop’s data, and they cannot see another technician’s assigned jobs.
Service providers. We host CallRunner on Cloudflare. Cloudflare processes information on our behalf as a service provider so we can run the site, API, database, and file storage. That hosting is not a sale, and we do not treat it as sharing with an unrelated third party.
Legal and organizational changes. We may disclose information if we are required to by law, a valid legal process, or to protect the service and its users. If the operator of CallRunner changes, we will update this page.
We do not share personal information with advertising networks, analytics companies, or data brokers.
Retention
We keep an organization’s records for as long as that organization uses CallRunner. Closing or cancelling a job does not delete the job record. Deactivating a technician stops their field sign-in; it does not remove jobs they already worked.
Office sessions expire after about seven days. Field sessions expire after about thirty days. Signing out revokes the current session.
There is no in-product control that permanently deletes an entire organization, its job history, and all photos. If you need that removed, contact us and we will handle the request manually. We may retain limited information when we must — for example to finish a deletion request, prevent abuse, or meet a legal obligation.
Security
We transmit information between your browser or the field app and our servers over HTTPS. Passwords and PINs are stored as hashes. Job photos are served only through authenticated requests; they are not public files.
Each organization’s data is scoped to that organization. Another shop cannot open your records.
We use reasonable technical and organizational measures to protect personal information. No method of transmission or storage is completely secure.
Your choices
You can:
- sign out of the office or the field app
- change the company name and trade tag in office Settings (the org code does not change after signup)
- deactivate a technician or clear their PIN so they cannot sign in on the field app
- cancel a job (the cancelled record remains)
- ask us to correct or delete personal information we hold
Technicians do not create their own CallRunner accounts. A technician who wants their name taken off the shop should ask the shop owner. The owner can deactivate the technician and, if needed, contact us.
To request deletion of a technician’s data, a shop’s job history, or the organization itself, use the office or email [email protected]. We do not offer a self-serve deletion portal. Please do not include PINs or an export of job records in that message.
Signing out of the field app clears the session stored on the device.
Children
CallRunner is for adult shop staff. The field app is intended for people 18 years of age and older. We do not knowingly collect personal information from children. If you believe a child has used the service, contact us and we will delete the information.
Contact
For privacy questions and deletion requests, email [email protected].
You can also reach us through the signed-in office at office.callrunner.app.
Changes
If we collect additional information or use it in a new way, we will update this page and the effective date.