Yard2Road icon

Yard2Road - Commercial

MOMD Digital

Privacy Policy

Version: commercial-privacy-2026-07-28-v1
Effective: 28 July 2026
Supplier: David Foster, under the MOMD Digital brand · ABN 86 975 807 584

1. Who this policy covers

This policy explains how MOMD Digital handles personal information in Yard2Road - Commercial, its public support and account-deletion pages, and its company administration portal. Contact us through the support page.

The subscribing company or organization decides which employees may join its workspace and what operational records its authorized users enter. The customer must use Yard2Road lawfully, limit access to people who need it, and provide any notices or permissions required when its users record information about other people.

2. Information handled

CategoryExamples
Account and membershipFirebase user ID, name, email, optional phone, email-verification state, Company ID, role, depot, permissions, membership state and account timestamps.
Company onboarding and authorityLegal entity and optional trading name, business address, state, postcode, representative and billing contact, optional purchase-order reference, ABN, ABN Lookup results, authority-review status, evidence-class labels, reviewer and external case reference. Raw authority documents are not stored in the application database.
Billing and accessApple or Google billing provider, product, purchase mapping, transaction/order reference, one-way Google purchase-token hash, price, currency, subscription status, renewal state, paid or grace end, refund/revocation information and billing audit events. Card details are handled by Apple or Google, not MOMD Digital.
Fleet and checksVehicle and unit identifiers, registration, description, odometer and service information, driver details, checklist answers, notes, timestamps, results and issues.
Incidents and accidentsType, status, time, details, location text, user-selected GPS coordinates, photographs, notified contacts and reports. Accident records may include other drivers, witnesses, occupants, insurers or police contact details supplied by a user.
Files and exportsIssue photos, generated PDF/spreadsheet/text reports, management-report files, export metadata and download activity.
Security and administrationAuthentication and App Check state, access and permission events, rate-limit counters, provider reconciliation, policy acceptance, deletion jobs and minimal deletion/fraud tombstones.
Device and request dataApp-private preferences and files, camera or selected-library images, user-invoked location, IP address and technical request information processed by the device, hosting provider and Google/Firebase services.

The current release does not declare an advertising SDK, cross-app advertising tracking SDK, product analytics SDK or crash-reporting SDK. We do not sell or rent personal information.

3. How information is collected

Information is collected from the user, a customer administrator, Apple or Google authentication and billing services, Firebase, ABN Lookup, and device features the user chooses to invoke. A user controls whether to grant camera, selected-photo and when-in-use location permission. OpenStreetMap tile requests necessarily send the requested tile coordinates and normal network request data, including an IP address, to the tile service.

4. Why information is used

5. Automated access decisions and human review

The service automatically permits or refuses access using authentication status, verified email, company membership, role and permissions, current policy acceptance, App Check, account state and verified subscription state. Purchase verification also checks fixed provider, company, product, price, currency and lifecycle rules. These decisions can affect access to a paid company workspace. Organizational authority approval remains a human decision. A person may request human review of an access, purchase-mapping or authority outcome through support.

6. Who may receive information

We do not disclose the Company ID, subscription state, dates or billing provider to an unproven person who asks about an ABN. That person is told only that the ABN may already be connected to an account.

7. Storage locations and overseas handling

The production Firestore database, Cloud Storage bucket and Cloud Functions are configured for Sydney, Australia (australia-southeast1). Firebase Authentication and services without a customer-selectable location may process information in the United States or other countries where Google and its service providers operate. Apple, Google, Crazy Domains and OpenStreetMap infrastructure may also process network or account information outside Australia under their own service arrangements. Data-protection laws in those places may differ from Australian law.

8. Security

Controls in the current design include individual authentication, verified email, tenant and role checks, server-authoritative subscription state, App Check for protected backend calls, restricted Firestore rules, server-only commercial registries, server-authorized file transport, rate limits, one-way purchase-token hashes, versioned policy acceptance and attributable privileged actions. Data is encrypted in transit by HTTPS and managed Google services encrypt stored service data. No system can guarantee absolute security.

Please report a suspected security or privacy incident promptly through support. MOMD Digital will contain and assess the incident, preserve required evidence, and make notifications required by applicable law.

9. Retention

DataRetention outcome
Store transaction, refund and chargeback recordsFive years after the later of the transaction or final related action, then delete or de-identify unless a scoped legal hold applies.
Policy/contract acceptance evidenceFive years after the later of acceptance or the end of the related company contract; direct user identifiers are removed when they are no longer required.
Active operational records, incidents, photos and committed reportsWhile the workspace is active. After normal cancellation/expiry or the end of provider grace for a previously verified paid entitlement, exactly 90 days of read-only report/export access is available, then a durable scheduled job deletes operational database records and stored files. Company identity, user accounts, billing evidence and policy evidence follow their separate schedules. A provider revocation or refunded-and-revoked purchase does not receive this automatic 90-day product-access window. A company-deletion request uses the faster process stated below.
Rejected or expired join requestsA pending request expires after 30 days. Its Yard2Road profile and membership claims are automatically removed 30 days later. A rejected request may be removed sooner and is removed no later than 30 days after rejection. The Firebase sign-in account remains available for a later request after cleanup.
Raw authority evidenceAvoid application storage. If temporarily required in a restricted support case, delete within 30 days after the final decision.
Authority decision metadata12 months after the decision, then delete or de-identify.
Security, access and privileged-administration logs12 months after the event, then delete or de-identify unless required for an active investigation or legal hold.
Temporary report exports24 hours after creation.
Unattested issue-photo uploads24 hours after reservation.
Minimal deletion/fraud tombstonesKeyed hash, reason, date and expiry only; delete after 12 months. Raw ABNs, names and email addresses are not retained in these tombstones.
Deleted data in backupsPut beyond normal use and expire within 30 days. A restoration must replay deletion records before restored data becomes available.

Post-expiry cleanup is bound to the exact verified access-end generation, retries durably after a technical failure, rechecks provider state and legal holds before destructive phases, and temporarily blocks activation while deletion is running. A new verified subscription after completed cleanup starts with an empty operational workspace. Legal/privacy access requests and rights that cannot lawfully be excluded remain available through support.

10. Legal holds

A legal hold is created only for a written legal, court, regulator, insurer or active-dispute reference. Its authority remains limited to the identified records, it grants no additional access, it is reviewed at least every 90 days, and it is released when the written basis ends. Because linked company evidence can share references and storage objects, automated deletion of linked shared company evidence is paused while any company legal hold is active so held evidence is not destroyed accidentally. Unheld personal authentication and profile data may still be deleted when it can be separated safely. Cleanup resumes after the last active hold is released. Create, review and release actions are audited.

11. Access, correction and deletion

A user can update some profile and operational information in the service. Any person may request access to, correction of, or a copy of their personal information through the support request form. We may ask for information needed to verify identity and authority and will explain any lawful refusal.

The app and authenticated web application include a Delete Account path. The public account-deletion page also explains how to request deletion without reinstalling the app. Employee deletion removes the person’s account and personal data but does not cancel the company subscription or erase shared records the customer or MOMD Digital must retain. Account deletion does not cancel Apple or Google billing.

For a sole owner, immediate personal-account deletion freezes the workspace. A separately proven organizational authority has 14 days to request recovery/export and nominate an existing active administrator. If no successor is approved, live operational company data is purged by day 30, except scoped commerce, security, deletion-tombstone or legal-hold information.

12. Complaints

Use the support page and put “Yard2Road Commercial privacy” at the start of the request. We aim to acknowledge a privacy complaint within five business days and provide an outcome or progress update within 30 calendar days. If the matter cannot be resolved, you may seek external advice or contact the Office of the Australian Information Commissioner where its jurisdiction applies.

13. Changes

Material changes to purposes, disclosures, retention, deletion, included accounts or subscription handling receive a new immutable policy version and require renewed in-service acknowledgment or acceptance before operational access. Previous versions remain available for five years. Urgent changes required to address law or security may take effect sooner, with notice as soon as reasonably practicable.