Privacy Policy
1. Who this policy covers
This policy explains how MOMD Digital handles personal information in Yard2Road - Commercial, its public support and account-deletion pages, and its company administration portal. Contact us through the support page.
The subscribing company or organization decides which employees may join its workspace and what operational records its authorized users enter. The customer must use Yard2Road lawfully, limit access to people who need it, and provide any notices or permissions required when its users record information about other people.
2. Information handled
| Category | Examples |
|---|---|
| Account and membership | Firebase user ID, name, email, optional phone, email-verification state, Company ID, role, depot, permissions, membership state and account timestamps. |
| Company onboarding and authority | Legal entity and optional trading name, business address, state, postcode, representative and billing contact, optional purchase-order reference, ABN, ABN Lookup results, authority-review status, evidence-class labels, reviewer and external case reference. Raw authority documents are not stored in the application database. |
| Billing and access | Apple or Google billing provider, product, purchase mapping, transaction/order reference, one-way Google purchase-token hash, price, currency, subscription status, renewal state, paid or grace end, refund/revocation information and billing audit events. Card details are handled by Apple or Google, not MOMD Digital. |
| Fleet and checks | Vehicle and unit identifiers, registration, description, odometer and service information, driver details, checklist answers, notes, timestamps, results and issues. |
| Incidents and accidents | Type, status, time, details, location text, user-selected GPS coordinates, photographs, notified contacts and reports. Accident records may include other drivers, witnesses, occupants, insurers or police contact details supplied by a user. |
| Files and exports | Issue photos, generated PDF/spreadsheet/text reports, management-report files, export metadata and download activity. |
| Security and administration | Authentication and App Check state, access and permission events, rate-limit counters, provider reconciliation, policy acceptance, deletion jobs and minimal deletion/fraud tombstones. |
| Device and request data | App-private preferences and files, camera or selected-library images, user-invoked location, IP address and technical request information processed by the device, hosting provider and Google/Firebase services. |
The current release does not declare an advertising SDK, cross-app advertising tracking SDK, product analytics SDK or crash-reporting SDK. We do not sell or rent personal information.
3. How information is collected
Information is collected from the user, a customer administrator, Apple or Google authentication and billing services, Firebase, ABN Lookup, and device features the user chooses to invoke. A user controls whether to grant camera, selected-photo and when-in-use location permission. OpenStreetMap tile requests necessarily send the requested tile coordinates and normal network request data, including an IP address, to the tile service.
4. Why information is used
- authenticate individual users and keep company workspaces separate;
- verify an ABN, review organizational authority and prevent duplicate company accounts;
- verify, restore and reconcile Apple or Google subscription access;
- issue a Company ID and company certificate after authority and payment are verified;
- approve users and enforce roles, permissions and the 25-active-account allowance;
- create, synchronize, display, correct, export and delete authorized operational records;
- provide support, account access, correction and deletion processes;
- protect the service, investigate errors or misuse, meet legal obligations and establish or defend legal claims; and
- record the exact policy versions a user accepted.
5. Automated access decisions and human review
The service automatically permits or refuses access using authentication status, verified email, company membership, role and permissions, current policy acceptance, App Check, account state and verified subscription state. Purchase verification also checks fixed provider, company, product, price, currency and lifecycle rules. These decisions can affect access to a paid company workspace. Organizational authority approval remains a human decision. A person may request human review of an access, purchase-mapping or authority outcome through support.
6. Who may receive information
- authorized users of the same customer workspace, according to their role and permissions;
- Google/Firebase and Google Cloud for authentication, App Check, database, file storage and server processing;
- Apple or Google for the sign-in or store-billing service selected by the user;
- ABN Lookup when an ABN is verified;
- OpenStreetMap tile infrastructure when a user opens the accident map;
- Crazy Domains for public website delivery and, when deployed there, web application delivery;
- MOMD Digital personnel who need access to resolve a documented support, authority, security or legal matter; and
- courts, regulators, law enforcement, insurers or professional advisers when disclosure is required or permitted by law or reasonably necessary for an active claim.
We do not disclose the Company ID, subscription state, dates or billing provider to an unproven person who asks about an ABN. That person is told only that the ABN may already be connected to an account.
7. Storage locations and overseas handling
The production Firestore database, Cloud Storage bucket and Cloud Functions are configured for Sydney, Australia (australia-southeast1). Firebase Authentication and services without a customer-selectable location may process information in the United States or other countries where Google and its service providers operate. Apple, Google, Crazy Domains and OpenStreetMap infrastructure may also process network or account information outside Australia under their own service arrangements. Data-protection laws in those places may differ from Australian law.
8. Security
Controls in the current design include individual authentication, verified email, tenant and role checks, server-authoritative subscription state, App Check for protected backend calls, restricted Firestore rules, server-only commercial registries, server-authorized file transport, rate limits, one-way purchase-token hashes, versioned policy acceptance and attributable privileged actions. Data is encrypted in transit by HTTPS and managed Google services encrypt stored service data. No system can guarantee absolute security.
Please report a suspected security or privacy incident promptly through support. MOMD Digital will contain and assess the incident, preserve required evidence, and make notifications required by applicable law.
9. Retention
| Data | Retention outcome |
|---|---|
| Store transaction, refund and chargeback records | Five years after the later of the transaction or final related action, then delete or de-identify unless a scoped legal hold applies. |
| Policy/contract acceptance evidence | Five years after the later of acceptance or the end of the related company contract; direct user identifiers are removed when they are no longer required. |
| Active operational records, incidents, photos and committed reports | While the workspace is active. After normal cancellation/expiry or the end of provider grace for a previously verified paid entitlement, exactly 90 days of read-only report/export access is available, then a durable scheduled job deletes operational database records and stored files. Company identity, user accounts, billing evidence and policy evidence follow their separate schedules. A provider revocation or refunded-and-revoked purchase does not receive this automatic 90-day product-access window. A company-deletion request uses the faster process stated below. |
| Rejected or expired join requests | A pending request expires after 30 days. Its Yard2Road profile and membership claims are automatically removed 30 days later. A rejected request may be removed sooner and is removed no later than 30 days after rejection. The Firebase sign-in account remains available for a later request after cleanup. |
| Raw authority evidence | Avoid application storage. If temporarily required in a restricted support case, delete within 30 days after the final decision. |
| Authority decision metadata | 12 months after the decision, then delete or de-identify. |
| Security, access and privileged-administration logs | 12 months after the event, then delete or de-identify unless required for an active investigation or legal hold. |
| Temporary report exports | 24 hours after creation. |
| Unattested issue-photo uploads | 24 hours after reservation. |
| Minimal deletion/fraud tombstones | Keyed hash, reason, date and expiry only; delete after 12 months. Raw ABNs, names and email addresses are not retained in these tombstones. |
| Deleted data in backups | Put beyond normal use and expire within 30 days. A restoration must replay deletion records before restored data becomes available. |
Post-expiry cleanup is bound to the exact verified access-end generation, retries durably after a technical failure, rechecks provider state and legal holds before destructive phases, and temporarily blocks activation while deletion is running. A new verified subscription after completed cleanup starts with an empty operational workspace. Legal/privacy access requests and rights that cannot lawfully be excluded remain available through support.
10. Legal holds
A legal hold is created only for a written legal, court, regulator, insurer or active-dispute reference. Its authority remains limited to the identified records, it grants no additional access, it is reviewed at least every 90 days, and it is released when the written basis ends. Because linked company evidence can share references and storage objects, automated deletion of linked shared company evidence is paused while any company legal hold is active so held evidence is not destroyed accidentally. Unheld personal authentication and profile data may still be deleted when it can be separated safely. Cleanup resumes after the last active hold is released. Create, review and release actions are audited.
11. Access, correction and deletion
A user can update some profile and operational information in the service. Any person may request access to, correction of, or a copy of their personal information through the support request form. We may ask for information needed to verify identity and authority and will explain any lawful refusal.
The app and authenticated web application include a Delete Account path. The public account-deletion page also explains how to request deletion without reinstalling the app. Employee deletion removes the person’s account and personal data but does not cancel the company subscription or erase shared records the customer or MOMD Digital must retain. Account deletion does not cancel Apple or Google billing.
For a sole owner, immediate personal-account deletion freezes the workspace. A separately proven organizational authority has 14 days to request recovery/export and nominate an existing active administrator. If no successor is approved, live operational company data is purged by day 30, except scoped commerce, security, deletion-tombstone or legal-hold information.
12. Complaints
Use the support page and put “Yard2Road Commercial privacy” at the start of the request. We aim to acknowledge a privacy complaint within five business days and provide an outcome or progress update within 30 calendar days. If the matter cannot be resolved, you may seek external advice or contact the Office of the Australian Information Commissioner where its jurisdiction applies.
13. Changes
Material changes to purposes, disclosures, retention, deletion, included accounts or subscription handling receive a new immutable policy version and require renewed in-service acknowledgment or acceptance before operational access. Previous versions remain available for five years. Urgent changes required to address law or security may take effect sooner, with notice as soon as reasonably practicable.