Privacy Notice
Effective date: August 16, 2026 · Version 2026-08-16.2
A subscribing company controls the customer and employee information its users enter. Companies must give their own customers and workers any notices and choices required by law. TradeCommand does not sell Company Data.
1. Scope and roles
Trade Command LLC, a Kansas limited liability company, operates the TradeCommand website and application. In this Privacy Notice, “TradeCommand,” “we,” “us,” and “our” mean Trade Command LLC. This notice explains how TradeCommand handles information through its website, application, support, and subscription flows. For Company Data entered by a subscribing business, the Company generally decides why and how the information is used and TradeCommand processes it to provide the service. Contact the Company Owner first about a customer, employee, or job record in that workspace.
2. Information collected
- Account, company, and carrier-registration data: names, legal or DBA business name, entity type, trade, timezone, physical address, website, business and authorized-representative email, title and phone, optional professional photos, company logos, contractor-license details, requested area code, the last four digits of an EIN when applicable, registration attestations, provider status and correction information, roles, permissions, security events, and login records. When an Owner submits an EIN for carrier registration, TradeCommand sends the complete EIN directly to the carrier during that request but retains only its last four digits. TradeCommand does not retain the full EIN.
- Subscription and payment data: plan, add-ons, customer Service Plan price and cadence, recurring-authorization disclosure version and timestamp, discounts, provider customer, subscription, connected-account, Checkout Session, PaymentIntent, charge, invoice, refund, receipt, renewal date, cancellation state, billing-status, and card brand and last four digits. For Automatic Instant Payouts, we also retain the setting status and version; selected destination's provider identifier, type, label, and last four digits; saved Stripe payout schedule; enable, disable, and consent actors, versions, and timestamps; source payment, charge, and balance-transaction identifiers; provider-net funds, fee, and deposit amounts; provider payout, application-fee, balance, and failure identifiers; payout status and timing; and limited failure or reconciliation messages. Stripe collects complete card, bank, identity, payout-destination, balance, and payout details on its hosted or embedded interfaces; TradeCommand does not store full card numbers, security codes, connected-account bank credentials, or the short-lived Stripe payout-session secret.
- Accounting-integration data: the connected QuickBooks company name, Intuit realm identifier, encrypted OAuth credentials, selected chart-of-accounts mappings, employee and Service Item mappings, TimeActivity identifiers, reviewed-set tokens, provider sync tokens, export status, and reconciliation errors. TradeCommand does not collect or store a Company Owner’s Intuit password.
- Operations data: customers, public booking requests, contact details, requested service times and addresses, Google Maps place identifiers and address-match dates when a user chooses a suggestion, properties, equipment, appointments, jobs, notes, photos, checklists, pricebook, inventory, estimates, signatures, invoices, recorded payments, service plans, and communications.
- Data-import records: when an Owner or Office Admin chooses to move records from another service, we process the uploaded customer, property, and compatible service-plan rows; source-system identifiers; filenames and row numbers; match decisions; validation issues; and local record links. TradeCommand does not request or store the source-service password or stored customer payment card. Staged row contents are cleared after completion or cancellation, while limited result and source-link records are retained to prevent duplicate imports and support an audit trail.
- Voice and Call Tracking data: the shared Business Texting number used as the main business caller ID, separately assigned tracking numbers, marketing source code and campaign label, forwarding destination, whisper setting, eligible workers' saved physical-phone destinations, customer phone numbers, carrier subaccount, phone-number and parent/child call identifiers, call direction, timestamps, duration, status, routing, handler, linked customer or job, disposition, notes, billable minutes, webhook state, and usage-reporting identifiers. Recording is off by default. If the Company Owner enables it, TradeCommand also processes the call audio, carrier recording identifier, duration, channel count, private-storage key, selected expiration date, processing and deletion status, recording-policy acceptance, and authorized playback audit records. TradeCommand does not provide voicemail or transcription.
- Customer Messaging data: the Company and customer phone numbers, customer and job links, one-to-one SMS bodies, employee sender identity, timestamps, unread state, delivery status, isolated provider account, Customer Profile, Brand, Campaign, Messaging Service, phone-number and message identifiers, registration-event authentication hash, error codes, segment counts, usage and cost data, and conversation status. We also retain versioned customer-consent evidence, including the disclosure text, source, time, person who recorded it, limited browser evidence, and STOP, START, HELP, suppression, and compliance events. The text-only beta does not store MMS attachments; if a customer sends media, the app records a placeholder and the carrier and Twilio may process the attachment before TradeCommand receives the webhook.
- Workforce data: employee profile, professional photo and title, role, clock-in/out events, approved or disputed time, review notes, audit events, worker classification, QuickBooks mapping status, and historical legacy-payroll records.
- Team Chat data: direct and group conversation names, participants, message bodies, sender and timestamp, unread and membership state, first-use notice acceptance, and permission or monitoring-audit events.
- Location data: when a user is clocked in and grants device permission, latitude, longitude, accuracy, heading, speed, capture time, and the related shift. If the Company enables customer arrival tracking, we also process an expiring link-session identifier, a hashed link token, job and assigned-worker references, expiration and end reason, and first and latest link-open times. Location collection stops when no active shift exists, although browsers and devices may interrupt tracking sooner.
- Technical and support data: IP-derived security signals, browser and device information, request logs, error data, cookies, session identifiers, support messages, and feedback.
3. How information is used
We use information to authenticate users; enforce company boundaries, roles, and subscription limits; provide requested workflows; display time and team location information to authorized Company users; optionally show an assigned worker's latest available location to the customer through an expiring On My Way link; generate reports; connect approved providers; route one-to-one service and account texts; correlate delivery callbacks; enforce consent, STOP suppression, access, rate, and segment limits; route Voice calls between the shared business number, authorized staff physical phones, and saved customer numbers; preview, validate, deduplicate, and complete user-requested data imports; process subscriptions; secure and troubleshoot the service; prevent fraud and abuse; communicate about the account; comply with law; and improve reliability and usability.
We may create aggregate or deidentified statistics that do not identify a Company, customer, or worker. We do not use Company Data to train a general artificial-intelligence model without separate, express permission.
4. GPS and employee monitoring
Precise location is sensitive. TradeCommand accepts location only from the user’s own authenticated account during an active clocked-in shift and makes current team-location information available to the Company Owner and to an Office Admin or Dispatcher only when the Owner grants that separate permission. A free-text manager title or ordinary office access does not grant location access. The Company—not TradeCommand—decides whether to use tracking and is responsible for employee notice, consent, lawful purpose, and workplace monitoring requirements. Device permission may be changed in the phone or browser settings.
The optional customer arrival-tracking feature defaults off. When enabled and the assigned worker has a recent clocked-in location, an On My Way email or prepared text may contain an expiring link showing that worker's professional name, latest available latitude and longitude, accuracy and capture time, and optional professional photo as the marker. The customer view does not disclose the worker's personal phone number, shift history, speed, heading, or other customer records. If the worker has no current professional photo, the view uses initials instead.
The customer link does not require an account login. Anyone who obtains or is forwarded the link may be able to open it while it remains active, so the Company and customer should treat it as sensitive. The application database stores a one-way hash rather than the link token itself. The view fails closed if the worker clocks out, the job is no longer On My Way, the worker is no longer assigned, the link is revoked, or the link expires, and it omits a location reading that is no longer recent. Link access never extends collection beyond an active clocked-in shift.
Browser location is foreground-dependent and is not guaranteed. A closed or backgrounded browser, operating-system restrictions, revoked permission, weak satellite reception, or lost connectivity may pause updates or make a reading delayed or inaccurate. TradeCommand is not an emergency or safety-monitoring service. The Company must tell affected workers when supervisor and customer views are enabled, explain any professional-photo sharing, and obtain all required worker and customer permissions.
Team Chat is company-managed workplace communication. Every Company Owner can review all direct and group conversations in that Company workspace. An Owner may separately grant read-only oversight to an Office Admin or Dispatcher; ordinary team access, Platform Admin status, or a free-text job title does not provide that permission. Oversight views and permission changes are audited, and the app presents the monitoring notice before a user first enters Team Chat. The Company is responsible for lawful purpose, worker notice, consent where required, and appropriate internal access.
Customer Messaging is also a Company-managed business record, not a private employee channel. Owners, Office Admins, and Dispatchers may view the shared Company inbox. A Technician can view and send only for a current assigned customer and only when the Owner grants the specific permission. Access is checked against the user's current role and job assignment. Messages use the configured Company number, so the customer does not receive and TradeCommand does not disclose an employee's personal mobile number as the SMS sender. The Customer Messaging request sent to Twilio does not include the employee's profile phone number. The Company is responsible for telling workers how this shared record is accessed and for revoking permissions promptly.
5. Accounting, payment, and financial providers
When an authorized user searches for or selects a customer service address, TradeCommand sends only the typed address text or selected Google place identifier to Google Maps Platform. Google returns address suggestions and standardized address components. When an authorized user opens a property or schedule map, Google may receive the service address or place identifier, browser and network information needed to render live Maps, satellite, or Street View content. TradeCommand does not send Google the customer's name, phone, email, access notes, or internal notes for these map requests; does not copy Google imagery into its own storage; and retains the selected place identifier and user-confirmed address rather than raw provider responses. Google's Privacy Policy and applicable Maps Platform terms apply.
TradeCommand does not collect Social Security numbers, tax-withholding elections, full bank-account details, or direct-deposit instructions for the QuickBooks approved-time beta. Do not enter those values in ordinary notes or mapping fields. Historical Check Payroll references may be retained only for cancellation, reconciliation, security, disputes, or legal recordkeeping; new Check onboarding and payroll processing are retired.
When a Company enables customer payments, TradeCommand sends server-derived invoice amount, Company, invoice, job, and payment-request references, and return addresses to Stripe. Stripe hosts connected-account onboarding and card checkout, processes direct charges and refunds, and returns status, receipt, payout-readiness, and reconciliation data. Stripe’s privacy notice and the Company’s own customer privacy obligations apply to that processing.
When an eligible Company Owner enables Automatic Instant Payouts, TradeCommand creates an immutable authorization record containing the exact disclosure, selected eligible destination's limited display details, saved Stripe payout schedule, current legal versions, fee rule, acceptance time, and authorizing Owner. For each future eligible TradeCommand invoice card payment, TradeCommand verifies its provider balance transaction and calculates and caps a request from that payment's provider-net amount. Stripe debits a fungible connected-account card balance and cannot bind the payout to that specific Charge. TradeCommand does not request an aggregate or full-balance sweep. Stripe receives the payout request and controls eligibility, limits, authentication, and delivery.
When the Owner separately opens Stripe's payout center, TradeCommand asks Stripe to create a short-lived connected-account session and sends the browser only the public Stripe key and ephemeral session secret needed to load the embedded component. Stripe authenticates the connected-account user and processes balance, destination, fee, and manual-payout information. TradeCommand does not store the session secret or receive full bank-account or debit-card credentials.
If the Company enables native Tap to Pay for field collection, TradeCommand also sends the service-location street address and an internal location reference to Stripe so Stripe Terminal can create or select the required reader location. Stripe receives contactless card-present transaction data directly from the supported phone or tablet; TradeCommand does not receive the full card number. The Company is responsible for telling customers that Stripe processes the payment and for using Tap to Pay only at authorized service locations.
When the Company Owner connects QuickBooks Online, TradeCommand sends the accounting records and mappings the Owner enables—including customer, item, approved-estimate, issued-invoice, successful-payment, successful-refund, and eligible approved-time data—to Intuit. For approved time, this can include the worker's name and local account reference, mapped QuickBooks employee and Service Item, work date, duration, description, local entry reference, and export/reconciliation state. OAuth credentials are encrypted at rest and are used only server-side. The Company’s Intuit agreement and privacy notice apply separately.
6. When information is shared
Information may be shared with infrastructure, storage, authentication, email, payment, telephone and SMS carrier, accounting, mapping, security, analytics, and support providers only as reasonably needed to deliver their services; with an integration the Company chooses to enable; during a merger, financing, reorganization, or sale subject to appropriate protection; to protect rights, safety, or service security; or when required by valid legal process. We do not sell Company Data or precise employee location, and we do not share it for cross-context behavioral advertising.
When a Company enables customer status or document email, TradeCommand may send the Company name, customer destination, job or document details, company logo, and—only for an arrival notice—the assigned worker’s professional name, title, and photo to the configured transactional-email provider. The visible sender uses TradeCommand’s verified domain and the Company’s active team mailbox is used for replies. Until compliant provider texting is configured, a text choice only prepares a message in the signed-in user’s device composer and does not silently send from the business number saved in TradeCommand.
If the Company enables live arrival tracking, the On My Way recipient may use the expiring link to request the assigned worker's latest available location, professional name, and optional professional photo from TradeCommand. To render the live map, TradeCommand may send the current coordinates and browser and network information to Google Maps Platform. The customer link may be forwarded by its recipient; TradeCommand cannot control access by someone who obtains the link before it ends. Google's privacy notice and Maps Platform terms apply to its processing.
When the Company registers and activates the separate Customer Messaging beta, TradeCommand creates and manages an isolated provider subaccount for that Company. TradeCommand sends Twilio the business and authorized-representative registration details described above, including the complete EIN transiently when applicable, and creates the Customer Profile, Brand, Campaign, Messaging Service, event subscription, and local number on the Company's behalf. For messages, TradeCommand sends Twilio the configured Company number, the customer's mobile number, message body, status-callback address, and routing and compliance fields needed to transmit the SMS. Twilio and downstream mobile carriers return identifiers, segment counts, delivery states, error codes, opt-out signals, and inbound messages. Outbound requests instruct Twilio to discard message content after provider processing where supported, but TradeCommand retains the conversation body in the Company workspace and providers and carriers may retain metadata or other information under their own terms and legal obligations. The beta is one-to-one and text-only; it does not send MMS or customer group messages.
When a Company activates Voice, TradeCommand sends Twilio the Company's existing Business Texting number, eligible staff members' saved telephone numbers, the selected customer telephone number, call-routing instructions, and signed callback addresses. Twilio and downstream telephone carriers process the call and return call identifiers, status, timing, duration, and error data. The customer sees the shared business number as caller ID rather than the employee's saved personal number. TradeCommand does not ask the contractor to create a separate Twilio account, token, or TwiML App for this workflow.
If the Company Owner enables call recording, Twilio temporarily creates the recording after the mandatory announcement. TradeCommand copies the completed audio into Company-scoped private object storage and requests deletion of the carrier copy. Only authorized Company Owners, Office Admins, and Dispatchers may request playback; each playback request is checked against the current Company and role and is logged. Technicians cannot access recordings. The Company must not use a recorded call to collect sensitive payment, banking, credential, health, or government-identifier data.
7. Retention and deletion
Active-shift GPS pings are retained for up to 30 days and then scrubbed through the service retention process. A customer arrival link is limited to a short period of no more than eight hours and can end sooner when the shift, assignment, or job state changes or the Company revokes it. Link-session metadata—including its one-way token hash, expiration, open times, and end reason—may be retained with the related notification and security records; it does not duplicate the worker's location history. Other Company Data is generally retained while the subscription is active and afterward as reasonably needed for account recovery, provider reconciliation, security, backups, disputes, legal holds, and legal obligations. Time and payroll records may need longer retention under employment or tax law; the Company is responsible for exporting and retaining legally required copies. Deleted user accounts may remain in audit, time, invoice, or payroll history when needed for record integrity.
Voice and Call Tracking metadata, source attribution, webhook evidence, and billing-usage records may be retained after telephony cancellation for provider reconciliation, account recovery, disputes, fraud prevention, and legal obligations. Canceling Voice does not release the shared Business Texting number or stop its existing SMS configuration. Separately assigned Call Tracking numbers are carrier resources and may be retained temporarily for recovery before release under the Cancellation & Refund Policy.
Call audio is retained for the Company Owner's selected 30, 90, 180, or 365-day period and then scheduled for deletion from private object storage. Changing the setting applies to newly completed recordings; turning recording off prevents future calls from being recorded but does not shorten an existing recording's selected expiration. Provider copies are requested for deletion after the private copy is verified. A deletion may be delayed where preservation is required by law or a valid legal hold.
Company logos and professional photos are stored in private object storage. Replaced media may be retained while an unexpired customer document or notification still references that version, and afterward for bounded recovery, security, or legal needs. Customer-notification attempts retain destination, status, provider references, and a frozen message snapshot for delivery audit and duplicate-send prevention.
Customer Messaging bodies are generally retained with other Company Data while the subscription is active and afterward as reasonably needed under this section. Consent disclosures and evidence, opt-in and opt-out events, recipient suppressions, message and segment ledgers, provider references, delivery state, webhook audit records, and security evidence may be retained longer when needed to prove consent or suppression, prevent duplicate sends, reconcile carrier charges, investigate abuse, resolve disputes, satisfy legal holds, or comply with law. Closing a conversation, pausing messaging, deactivating a worker, or replying STOP does not automatically erase those records.
8. Security
TradeCommand uses salted password hashing, opaque server sessions, company-scoped authorization, private object storage, role-based access, signed billing and messaging webhooks, provider-hosted sensitive onboarding, and audit records for selected actions. No system can guarantee absolute security. Companies must use unique accounts, appropriate roles, strong passwords, and prompt offboarding, and must report suspected unauthorized access promptly.
9. Choices and requests
Company Owners and authorized users can correct many records within the app. Customers and workers should contact the relevant Company first because that Company controls its workspace records. Account-level access, correction, deletion, or privacy requests may be sent to the contact below. We may need to verify identity and authority and may retain information where law, security, provider reconciliation, or another person’s rights require it.
Deactivating a worker prevents future Team Chat access but does not automatically remove that worker’s attributed messages, membership history, or monitoring audit records. The Company should contact TradeCommand for a verified export, legal-hold, retention, or deletion request; requests may be limited where preservation is required for security, another participant, or applicable law.
A customer can reply STOP to suppress further Company texts to that number, START to opt in again through the supported process, or HELP for the configured help path. STOP is applied across the Company's TradeCommand SMS activity; it does not erase prior messages or consent and delivery evidence. The Company must not use another TradeCommand text workflow to evade a suppression. Customers may also contact the Company to correct the number or make a privacy request, subject to verification and records that must be preserved.
10. Children, territory, and changes
TradeCommand is business software for adults and is not directed to children under 13. The service is operated for United States businesses. We may update this notice as the service, providers, or law changes. Material changes will be posted with a new version and may also be communicated in the app or by email.