Legal
Privacy Policy
Effective date to be set · Draft
Effective date: [Effective date]
This policy explains what personal data SmartCrop (“we”, “us”) collects, why we collect it, who we share it with and what choices you have. It covers:
- the public website at smartcrop.com;
- the SmartCrop web application at app.smartcrop.com; and
- the SmartCrop Field, SmartCrop QC and SmartCrop Asset Tracker mobile apps for iOS and Android (together, the “Apps”).
We refer to the web application and the Apps together as the “Service”. If you have a question this policy does not answer, write to [email protected].
Who is responsible for your data
Website visitors and demo requests. When you browse smartcrop.com or use the contact form, SmartCrop decides how that information is used. We are the data controller.
People whose records are in the Service. SmartCrop is operations software for growing and packing operations. The operation that licenses SmartCrop (the “Customer”) enters and manages records about its own employees, crews, ranches, fruit and equipment. For that data the Customer is the employer and the data controller. SmartCrop processes it on the Customer’s behalf and on the Customer’s instructions, as a data processor.
If you are an employee, crew boss, inspector or contractor of a Customer and want to see, correct or delete a record about you, your first point of contact is your employer. Their account administrators control the records. We help them fulfil your request, and we will also point you to the right person if you contact us directly.
What we collect
On smartcrop.com
The website is a static site. It does not use accounts, and it does not set analytics or advertising cookies. If we add analytics later, we will update this policy first.
The contact form asks for your name, email, a topic and a message, plus your operation, role and approximate size if you choose to give them. We use them to reply to you and, if you asked for one, to schedule a demonstration. If you write to us about a job, we keep your message while we consider it. Nothing else on the site collects personal data.
In the Service
The categories below describe the data the Service holds. Most of it is entered by the Customer and its staff, not collected by us directly.
- Account data. Name, email address, password (stored hashed), timezone, profile photo, role and permissions, and the companies you belong to. Users who sign in to SmartCrop Field on shared devices may also set a five-digit Badge PIN (stored hashed).
- Employee HR and payroll records entered by the Customer. Employee number, position, home ranch, photo, phone, address, date of birth and similar personal details, Social Security number, insurance details, federal withholding fields, hire and access history, uploaded documents and completed onboarding forms. Onboarding forms are built from fillable PDFs the Customer uploads and are sent to employees as signed email links that do not require an account.
- Time and piece records. Clock-in and clock-out punches, pieces recorded per badge scan, breaks and non-productive time, sick-hour requests, travel stipends, task assignments and the resulting payroll runs and exports. Each punch and piece records who entered it.
- Inspection data and fruit photos. Defect counts, starch and sugar readings, firmness readings, verdicts, lot numbers, and photos of fruit taken during Defect Analysis, Receiving and Room Sample inspections. Fruit photos show apples and cross-sections, not people.
- Storage and harvest logs. Grower, variety, room number, bin counts, treatment flags and room quality grades.
- Asset records. Equipment details, serial numbers, photos, custody assignments to employees, maintenance, warranty and insurance records, and the per-asset activity log.
- Messages. SMS, email and push messages the Customer sends to its crews through the Message Center, with per-recipient delivery status.
- Device and push tokens. When you sign in to an App, it registers a push notification token together with device details (model, manufacturer, operating system and version, device name) so notifications reach the right device. The token is removed when you log out.
- Phone numbers. Employee phone numbers entered by the Customer are used to deliver SMS messages and alerts the Customer chooses to send.
- Technical logs. Standard server logs such as IP address, request time and user agent, used for security and troubleshooting.
App permissions
The Apps request only the permissions their features need, and only when you use those features:
- Camera. To scan QR employee badges and asset labels, to run Kiosk Mode, and to photograph tasks, assets and fruit samples.
- Photo library. To attach existing photos to tasks, assets and inspections.
- Bluetooth (SmartCrop QC only). To read firmness values from an FTA pressure tester over a Bluetooth serial adapter. Bluetooth is used only to find and connect to that adapter.
- Notifications. To deliver push notifications about tasks, crews, inspections and equipment in the Apps.
No location tracking. SmartCrop does not track where employees, devices or equipment are. On Android 11, SmartCrop QC may ask for location permission because Android requires it to scan for Bluetooth devices; it is used only to find the pressure-tester adapter, and no location is collected or stored. SmartCrop Field and SmartCrop Asset Tracker do not request location permissions. Ranch and block boundaries are drawn by administrators on the web; they are not derived from anyone’s position.
How we use data
We use data to:
- provide the Service: record work, run payroll, log inspections, track equipment and deliver messages, as directed by the Customer;
- authenticate users and enforce each Customer’s roles and permissions;
- send notifications the Customer or the system generates (for example, a task starting today or an asset assigned to you);
- respond to messages sent through the contact form and to support requests;
- keep the Service secure, investigate abuse and diagnose faults; and
- meet legal obligations.
We do not sell personal data. We do not use Customer data to build advertising profiles or to train machine-learning models.
Who we share data with
We share data only with service providers that help us run the Service, and only the data each one needs:
- Twilio. Sends SMS messages. Receives the recipient phone number and message text.
- Firebase Cloud Messaging (Google). Delivers push notifications to the Apps. Receives the device push token and the notification content.
- OpenAI. Powers Starch Scan, the starch-grading feature in QC. When an inspector uses it, photos of iodine-stained apple cross-sections are sent for analysis and a starch index is returned. Only fruit photos are sent. No employee, grower or company records leave the Service through this feature. The Customer can choose not to use it.
- Transactional email provider. Delivers account emails, onboarding form links, notifications and Message Center emails.
- Hosting provider. Runs the servers and storage on which the Service operates.
Each provider is bound by contract to use the data only to provide its service to us. We may also disclose data when the law requires it, to protect the rights and safety of users or the public, or as part of a merger or sale of SmartCrop, in which case this policy continues to apply to the transferred data.
Within the Service, data is visible to the Customer’s own users according to the roles and permissions the Customer sets. Records belong to one company and are not shared between Customers. One exception: scanning an asset’s QR label opens a public asset page, without login, showing that asset’s summary, custody history, maintenance and photos. Customers decide which assets to label.
Retention
We keep Customer data for as long as the Customer’s agreement with us is active, because payroll, inspection and custody history is the point of the Service. When a Customer’s agreement ends, we delete or return its data within a reasonable period after the Customer’s written request, except for copies in routine backups, which expire on their own schedule, and records we must keep to meet legal obligations.
Contact form submissions are kept for as long as we are in conversation with you and deleted when no longer needed. Server logs are kept for a limited period for security purposes and then discarded.
Within the Service, deleting a record is under the Customer’s control. Some records, such as tasks included on a payroll, are locked to preserve the payroll history.
Security
We take practical steps to protect data:
- All traffic between your browser or App and the Service is encrypted in transit.
- Access inside the Service is role-based. Administrators grant each user only the permissions their job needs, and the web and Apps hide actions a user is not allowed to take.
- Passwords and Badge PINs are stored hashed, never in plain text.
- Mobile sessions use access tokens kept in the device’s secure store (iOS Keychain or Android encrypted storage). Administrators can revoke a user’s access at any time, which ends every mobile session for that user. Badge-scan kiosk tokens expire after ten minutes and can only clock that employee in or out.
- Push tokens are cleared on logout so a shared tablet does not carry one worker’s notifications to the next.
No system is perfectly secure. If we learn of a breach affecting your data, we will notify the affected Customer without undue delay so they can inform their staff, and we will notify regulators where the law requires.
Children
The Service is a workplace tool. It is not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child’s data has been entered into the Service, contact [email protected] and we will work with the Customer to remove it.
Your rights and choices
Depending on where you live, you may have the right to access the personal data we hold about you, correct it, delete it, receive a copy, or object to or restrict certain processing. To exercise these rights:
- Website visitors and people who contact us: email [email protected]. We will confirm your identity and respond within the time the law allows.
- Users and employees of a Customer: ask your employer’s SmartCrop administrator, who controls your records. If you contact us instead, we will forward your request to the Customer and assist them.
You can turn off push notifications in your device settings, and your employer’s SmartCrop administrator can set per-category email preferences on your employee record. Some operational notifications, such as those your employer sends about your work, are part of the Service and are controlled by your employer.
We will never treat you differently for exercising a privacy right.
Where data is processed
SmartCrop is based in Washington State, USA, and the Service is hosted in the United States. If you use the Service from outside the United States, your data will be transferred to and processed there.
Changes to this policy
When we change this policy we will post the new version at smartcrop.com/privacy with a new effective date. For material changes we will also notify Customer administrators by email before the change takes effect. Continued use of the Service after that date means you accept the updated policy.
Contact
SmartCrop [email protected]