Privacy Policy
This Privacy Policy ("Policy") describes how ENDEVR, LLC ("ENDEVR", "we", "us", "our") collects, uses, and shares personal information when you use the ENDEVR platform, including the RrAD Engine and Map Tool (the "Service"), or visit our website. Please read it together with our Terms of Service (the "Terms"). Capitalized terms not defined here have the meanings given in the Terms. This Policy covers personal information — information about identifiable individuals, such as our users.
1. Information We Collect
Account and identity information. When your organization signs up or you sign in through your organization's identity provider (Microsoft or Google, via Auth0), we receive your name, email address, and a unique account identifier. We also store your role within your organization's ENDEVR account (for example, administrator or member) and the organization you belong to. We do not receive or store your password — authentication happens with your identity provider.
Billing information. Subscription payments are processed by Stripe. We store your organization's billing status, subscription details, and seat count. We do not store credit card numbers — those are collected and held by Stripe.
Usage information. We collect information about how the Service is used, such as pages visited, features used, processing jobs started and completed, and general activity events. We use PostHog for product analytics, including session replay. Session replays mask all text and all input fields — we can see how the interface is used, but not what you type, or the content displayed from your files.
Log and device information. Our servers automatically record operational logs: timestamps, IP addresses, file names, and processing status. Application logs never include the contents of your uploaded data files.
Communications. If you contact us for support or we email you, we retain those communications.
Customer Data. The data and content your organization uploads or generates ("Customer Data") using our Service is governed by the provisions of the Terms, not by this Policy.
2. How We Use Personal Information
We use personal information to: (a) provide, operate, and secure the Service, including authentication and access control; (b) process subscriptions and billing; (c) understand how the Service is used so we can fix problems and improve it; (d) provide support you request; (e) send service communications such as invitations, security notices, and updates required under the Terms; and (f) comply with law. We do not sell personal information, and we do not use it for third-party advertising.
3. How We Share Personal Information
We share personal information only with service providers that help us run the Service as described below:
| Provider | Purpose | What they process |
|---|---|---|
| Amazon Web Services (AWS) | Cloud hosting and storage | All Service data, encrypted in transit and at rest |
| Auth0 (Okta) | Authentication | Name, email, organization, identity-provider ID |
| Microsoft / Google | Sign-in (your org's identity provider) | Your organization's login credentials (never visible to us) |
| Stripe | Payment processing | Billing contact and payment details |
| PostHog | Product analytics and masked session replay | Usage events, account identifier, name, email, organization |
| SendGrid | Transactional email | Recipient name and email |
| Mapbox, Esri/ArcGIS, OpenStreetMap | Map tiles, imagery, and geocoding | IP address and map/search requests made from your browser |
| Cal.com | Demo scheduling | Name, email, and booking details you submit |
We may also disclose personal information if required by law, or as part of a merger, acquisition, or sale of assets (in which case this Policy continues to apply until updated). We do not share personal information with any third party for their own marketing. We may add or replace providers performing equivalent functions, and will keep this table current.
4. Cookies
We use a small number of cookies: a session cookie that keeps you signed in (essential), and analytics cookies set by PostHog to distinguish visitors and measure usage. We do not use advertising cookies. Most browsers let you block or delete cookies; blocking the session cookie will prevent sign-in from working.
5. Data Retention
We retain account and billing information for as long as your organization has an account, and thereafter as needed for legal, accounting, and security purposes. Usage analytics are retained for one year, and session replays are automatically deleted after 30 days. Server and security logs are retained for up to 30 days. Customer Data retention and deletion is governed by the Terms.
6. Security
We protect the Service and your information using multiple layers of security: encryption in transit (HTTPS/TLS 1.2+) and at rest (AES-256), network firewalls and DDoS protection (AWS WAF and Shield), continuous automated threat monitoring (AWS GuardDuty), single sign-on through your organization's identity provider, whose protections include brute-force detection and account lockout, and organization-level data isolation with per-project access controls. No system is perfectly secure, and we cannot guarantee absolute security — but we take reasonable and industry-standard measures to protect your information. We will notify affected organizations of any data breach as required by applicable law.
7. Your Choices and Rights
Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your personal information. Because you use the Service through your organization, some requests (such as deleting your account) may need to go through your organization's administrator. To exercise any privacy right, contact us at the address below and we will respond as required by applicable law.
8. Where Data Is Processed
The Service is hosted in the United States, and our service providers process data in the United States. If you access the Service from outside the U.S., you understand your information will be transferred to and processed in the U.S.
9. Changes to This Policy
We may update this Policy from time to time. We will post the current version on our website and, for material changes, provide notice as described in the Terms. The "Effective" date above shows when this Policy was last revised.
10. Contact
Questions or privacy requests: contact@endevrsolutions.com.