Legal & Privacy Center

Privacy Policy

How Pinstripe Fleet collects, uses, discloses, and safeguards personal information.

Effective
July 29, 2026
Last updated
July 29, 2026
Version
2026-07-29.v1

Pinstripe Business Services LLC operates Pinstripe Fleet. This Privacy Policy explains what information we collect, how we use and share it, how long we keep it, the choices you have, and how to contact us.

01.Our Role

Our role differs depending on the situation:

  • As a business — for account information, billing records, support communications, and public-website activity, we act as the entity that collects and uses the information.
  • As a service provider or processor — for the customer, employee, job, media, and other business data an Organization enters or generates in the platform, we act on the Organization's behalf.
  • Website operator — for visitors to our marketing website.

Organizations may have their own privacy notices to their employees and customers. Those notices are the Organization's responsibility.

02.Information We Collect

Account and authentication: name, email, phone (optional), job title (optional), avatar, time zone, hashed authentication credentials (managed by our identity provider — we do not view your password), authenticator identifiers when you use Google sign-in, and multi-factor authentication factors when you enroll them.

Organization: business name, business type, contact details, branding, operating configuration, and tax identifier when you provide it.

Workforce (when your Organization uses these features): user role, schedule, job assignments, work status, time entries, and notes. Optional location or device details are collected only when the Organization enables that feature and its workers use it.

Customer and job records: names, email addresses, phone numbers, service locations, access instructions, job details, estimates, invoices, payment metadata, communications, signatures, uploaded documents, photos, and videos.

Payment information: our payment processor (Stripe) handles card and bank-account information directly; we receive limited metadata such as a Stripe customer identifier, connected-account identifier, subscription status, transaction amount, last four digits of the card when provided by Stripe, card brand, invoice identifier, and receipt information. We do not store full payment-card numbers.

Device and usage: IP address, browser, operating system, device type, application version, log data, session information, error records, security events, feature usage, referral URL, and cookie identifiers.

Support: emails, form submissions, and troubleshooting information you share with us.

We do not currently collect precise device GPS unless the Organization enables an optional location-collection feature.

03.Sources

Information comes from you, your Organization, other authorized users, customer-portal visitors, integrated providers such as Stripe and calendar providers, device permissions you grant, cookies, usage logs, and support interactions.

04.How We Use Information

  • Providing, operating, and maintaining the service (authentication, organization administration, scheduling, job management, media hosting, customer portals).
  • Processing platform subscription payments and, through Stripe Connect, enabling your Organization to accept payments from its own customers.
  • Sending operational notifications and support communications.
  • Providing calendar-feed synchronization and integrations you enable.
  • Detecting, preventing, and investigating fraud, abuse, and security incidents.
  • Analyzing usage in aggregate to improve the product.
  • Complying with legal obligations, enforcing our agreements, and defending our rights.
  • Communicating service changes.
  • Marketing only where permitted and with your consent when required.

05.How We Share Information

We share information with:

  • Your Organization and its authorized users.
  • Customer-portal visitors when your Organization grants access to a job.
  • Service providers acting on our behalf — see our Subprocessor List.
  • Payment, hosting, storage, email, analytics, and monitoring providers as reasonably necessary to deliver the service.
  • Professional advisers such as auditors and counsel.
  • Government or legal authorities where required, with notice where permitted.
  • Parties involved in a merger, acquisition, financing, or similar business transaction, subject to appropriate protections.

We do not sell your personal information, and we do not share it for cross-context behavioral advertising.

06.Information Controlled by Your Organization

Much of the information handled through the platform is controlled by the Organization that uses it. If you are an employee, customer, or portal visitor of an Organization, questions about how the Organization uses your information should be directed to that Organization.

07.How Long We Keep Information

We keep information for as long as your account or your Organization's account remains active and as needed to provide the service. After closure, we keep limited records where necessary for billing, fraud prevention, audit history, security, statutory recordkeeping, or dispute resolution. Media is retained until job deletion plus 30 days. Audit logs are retained for 24 months. Billing records are retained for the applicable tax-record window.

08.Security

We use reasonable administrative, technical, and organizational safeguards appropriate to the service, including transport-layer encryption, role-based access, tenant isolation through database Row Level Security, short-lived signed URLs for media, webhook signature verification, and audit logging of sensitive actions. Details are on our Security Overview.

No system is completely secure. If you believe your account has been compromised, contact us immediately at [email protected].

09.Your Privacy Rights

Depending on where you live, you may have rights to access, correct, delete, export, restrict, or object to certain uses of your personal information, or to appeal a denied request. You can submit a request at Privacy Choices.

10.State-Specific Rights (United States)

Residents of California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and other states with comprehensive privacy laws may have additional rights, including the right to know, access, correct, delete, and where applicable opt out of certain sharing or targeted advertising. We do not currently sell personal information or share it for cross-context behavioral advertising, so no “Do Not Sell or Share” link is displayed.

If you are an authorized agent submitting a request on someone else's behalf, we may require verification of your authority.

11.Children

Pinstripe Fleet is a business platform and is not directed to children under 13. Organization-account users must be at least 18. We do not knowingly collect personal information from children.

12.International Processing

The platform is currently operated from the United States. Information may be processed in the United States and by service providers in the regions listed in our Subprocessor List. We have not entered international transfer commitments such as Standard Contractual Clauses at this time.

13.Changes to This Policy

We may update this Policy. When we make a material change, we will update the “Last updated” date, post the new version, and where appropriate ask you to acknowledge the change.

14.Privacy Contact

For privacy questions or to submit a privacy request, email [email protected] or use the Privacy Choices form.

Contact

Pinstripe Business Services LLC

New York, United States

Email: [email protected]

For legal or privacy inquiries, please contact us electronically at the address above.