Privacy policy

Effective date: 15 August 2026

Who we are

CallRunner is a hosted office and field product for small service businesses. We operate the public site at callrunner.app, the office web app at office.callrunner.app, the API at api.callrunner.app, and the Android field app named CallRunner.

This Privacy Policy explains how we collect, use, share, and retain personal information when you use those services.

“You” means the business that opens an office account, the people who sign in as office users, and the technicians who sign in on the field app. “We” means CallRunner, the operator of the service.

Information we collect

We collect the information you and your organization enter, plus the session data needed to keep you signed in.

Office accounts and technicians

When someone creates or uses an office account, we collect the company name, org code, optional trade tag, office user’s name, email address, and password.

Technicians are created in the office. The field app does not create accounts. A technician signs in by opening an invite from the office, then entering a PIN set by the office.

We store a hash of each password and PIN. We do not store them in plaintext, and we cannot display a PIN later.

Service-call records

The office stores the jobs your shop enters, including:

On the field app, a signed-in technician can update status on assigned jobs (other than close or cancel), add expenses, and upload job photos. The field app does not collect payment-card numbers and cannot close a job or record payment.

Photos

If a technician attaches a photo from the camera or the device library, we store that image and any caption with the job. Camera and photo-library access is used only to attach a job photo. Photos are private to the shop. They are not published at public URLs. Only a signed-in office user for that organization, or the assigned technician, can retrieve them.

Sessions and device storage

After a successful sign-in we issue a session token.

The office stores the session token in the browser’s local storage. The field app stores the session and the API host in on-device storage so the technician can stay signed in.

Information we do not collect

CallRunner does not include advertising, analytics, or crash-reporting software. We do not collect device GPS or other device location. The field app does not access contacts, text messages, the microphone, or a list of other apps on the device. We do not process card payments in CallRunner.

Browsing the public website, including this page, does not create an account. As with any website, our host may see ordinary connection data (such as an IP address) while serving the request. We do not write that data into the shop’s records or use it to determine your location.

How we use it

We use personal information to:

We do not use this information to show advertisements, to build advertising profiles, or to sell your job or customer lists.

How we share it

We do not sell personal information.

Your organization. Office users in your shop can see that shop’s jobs, technicians, expenses, and photos. A technician can see the jobs assigned to them. They cannot see another shop’s data, and they cannot see another technician’s assigned jobs.

Service providers. We host CallRunner on Cloudflare. Cloudflare processes information on our behalf as a service provider so we can run the site, API, database, and file storage. That hosting is not a sale, and we do not treat it as sharing with an unrelated third party.

Legal and organizational changes. We may disclose information if we are required to by law, a valid legal process, or to protect the service and its users. If the operator of CallRunner changes, we will update this page.

We do not share personal information with advertising networks, analytics companies, or data brokers.

Retention

We keep an organization’s records for as long as that organization uses CallRunner. Closing or cancelling a job does not delete the job record. Deactivating a technician stops their field sign-in; it does not remove jobs they already worked.

Office sessions expire after about seven days. Field sessions expire after about thirty days. Signing out revokes the current session.

There is no in-product control that permanently deletes an entire organization, its job history, and all photos. If you need that removed, contact us and we will handle the request manually. We may retain limited information when we must — for example to finish a deletion request, prevent abuse, or meet a legal obligation.

Security

We transmit information between your browser or the field app and our servers over HTTPS. Passwords and PINs are stored as hashes. Job photos are served only through authenticated requests; they are not public files.

Each organization’s data is scoped to that organization. Another shop cannot open your records.

We use reasonable technical and organizational measures to protect personal information. No method of transmission or storage is completely secure.

Your choices

You can:

Technicians do not create their own CallRunner accounts. A technician who wants their name taken off the shop should ask the shop owner. The owner can deactivate the technician and, if needed, contact us.

To request deletion of a technician’s data, a shop’s job history, or the organization itself, use the office or email [email protected]. We do not offer a self-serve deletion portal. Please do not include PINs or an export of job records in that message.

Signing out of the field app clears the session stored on the device.

Children

CallRunner is for adult shop staff. The field app is intended for people 18 years of age and older. We do not knowingly collect personal information from children. If you believe a child has used the service, contact us and we will delete the information.

Contact

For privacy questions and deletion requests, email [email protected].

You can also reach us through the signed-in office at office.callrunner.app.

Changes

If we collect additional information or use it in a new way, we will update this page and the effective date.