Privacy Policy

Effective date: May 3, 2026  ·  Last updated: June 22, 2026

240 Operations LLC (“1% Club Audit,” “we,” “our,” or “us”) operates an operations reporting platform that connects to field service management, CRM, and marketing software to generate and deliver operational briefings, dashboards, and AI-assisted analysis. This Privacy Policy explains what information we collect, why we collect it, how we use and share it, and your rights regarding that information.

The platform is operated under more than one name. “1% Club Audit” and “Worksite Daily” refer to the same platform and the same operator, 240 Operations LLC, whichever name or web address you reached it through. This Policy applies in all cases.

By creating an account or using our services, you agree to the practices described in this policy. If you don't agree, please don't use the Service.


1. Who This Policy Applies To

This policy applies to Customers (businesses and individuals who register for an account) and, to the extent described below, to End Users whose data appears within Customer Data.

We act as a data controller for information we collect about Customers directly: account registration data, billing data, and usage analytics. We decide how and why that information is processed.

We act as a data processor (or service provider) for Customer Data retrieved from Third-Party Platforms on Customer's instruction. In that capacity, we process data solely to provide the Service as directed by Customer. Customer is the controller for that data and is responsible for ensuring it has the legal basis to share it with us.

End Users (Customer's employees, technicians, and end-customers whose information appears in Customer Data) are data subjects whose information we process on Customer's instruction. We don't contact End Users directly, and Customer is responsible for End Users' privacy rights with respect to Customer Data.

2. Categories of Data Collected

Account Data

When you register, we collect your name, business email address, company name, and phone number. You may also provide a business address and billing contact details. We use this to create and manage your account, deliver the Service, and communicate with you about your subscription.

Payment Data

Payments are processed by Stripe, Inc. We never see or store your full payment card number. We retain only the tokenized references and subscription status information that Stripe returns after a successful transaction.

Third-Party Platform Data

When you connect an integration, we retrieve Customer Data from that system on your behalf. What we retrieve depends on the type of system you connect.

From field service management systems (such as FieldRoutes), this may include job records, appointment history, revenue figures, technician performance data, callback records, and fleet data.

From CRM and marketing systems (such as GoHighLevel, HubSpot, and Pipedrive), we retrieve only what a count, a grouping, or a total requires: the number of leads and when each was created, the marketing source or campaign recorded against a lead, the labels or tags applied to it, sales opportunities and their values and stages, appointment counts, and payment amounts and statuses.

We do not collect the personal details of your customers. We do not retrieve or store their names, email addresses, phone numbers, mailing addresses, or card numbers, and we do not read the contents of your messages or conversations. Every figure this platform produces is a count, a grouping, or a sum, and none of them require knowing who any individual is. Where a record is retrieved at all, it is identified only by the opaque identifier your CRM assigns it, used solely so records are not counted twice.

Payment card numbers are never available to us from any source. Your own subscription payments are handled by Stripe as described above, and the payment records we read from your CRM contain amounts and statuses only.

Usage and Log Data

When you use the platform, our servers automatically log your IP address, browser type and version, operating system, referring URLs, pages visited, features used, and request timestamps. We use this for security, debugging, and improving the Service.

AI Processing Data

Customer Data sent through our report-generation pipeline is processed by our AI sub-processors (see Section 4). Section 10 (AI-Generated Output) of our Terms of Service describes what happens during that processing.

Communications Metadata

When the Service sends email on Customer's behalf, we collect delivery metadata (sent timestamps, delivery status, bounce codes) via Resend. We use this to diagnose delivery issues and provide delivery reporting to Customer.

3. Purposes of Processing

We process personal data for the following purposes:

  • Running the Service, including generating and delivering briefings to the recipients you configure.
  • Account management: creating accounts, authenticating users, and providing support.
  • Billing: processing payments, managing subscriptions, issuing invoices, and resolving billing disputes.
  • Improving the Service: analyzing aggregated, anonymized usage patterns to fix bugs and build new features.
  • Security: monitoring for unauthorized access, abuse, or threats to our systems.
  • Legal compliance: meeting our obligations under applicable law and responding to lawful government requests.

4. Sub-Processors

We share data with the following sub-processors to operate the Service. Each one processes data only as needed to do its job and is bound by data protection agreements.

Sub-ProcessorPurpose
VercelApplication hosting and edge delivery
SupabaseDatabase hosting and authentication
StripePayment processing and subscription management
ResendTransactional and report email delivery
Anthropic / OpenAIAI inference for automated briefing and report generation
PostHogProduct analytics (page views and feature usage, identified-only mode)

We keep this sub-processor list current. If we add a new sub-processor that materially changes how Customer Data is processed, we'll give you advance notice by email or through the application.

5. Customer Data vs End-User Data

Customer Data is the operational and business data belonging to the Customer (the field service business) that we retrieve from Third-Party Platforms or that Customer otherwise submits to the Service.

End-User Data is data about third parties that appears within Customer Data: Customer's technicians, employees, and the end-customers whose records exist in Customer's field service management system (names, contact information, service histories, and similar records).

We process End-User Data only as a processor acting on Customer's instructions. Customer is responsible for getting any consents required from End Users under applicable law before directing us to process their data. We do not contact End Users directly. Briefings and notifications go only to the recipients that Customer configures in the Service.

If an End User contacts us directly with a privacy request, we'll refer that request to the relevant Customer, who is the data controller for that individual's data.

6. Data Retention

Retention periods vary by data type.

  • Account and billing data: retained for the duration of the active subscription plus 7 years, to meet tax, audit, and legal obligations.
  • Customer Data retrieved from Third-Party Platforms: deleted from our active systems within 30 days of account termination or Credential revocation, whichever is earlier.
  • AI-generated Output: retained for the duration of the active subscription, then deleted upon account termination.
  • Credentials (API keys, OAuth tokens): deleted within 30 days of account termination or disconnection of the relevant integration.
  • Aggregated and anonymized data: retained indefinitely; this data cannot reasonably be used to identify Customer or any End User.

We may keep specific data longer if required by law, court order, or to resolve a pending legal dispute.

7. California Rights (CCPA / CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), gives you specific rights over your personal information.

You have the right to: (a) know what categories of personal information we collect about you and how it is used; (b) access the specific personal information we hold about you; (c) correct inaccurate personal information; (d) request deletion of your personal information, subject to certain exceptions; and (e) not be discriminated against for exercising any of these rights.

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. Because we do not sell or share personal information as those terms are defined under the CCPA, no opt-out mechanism for sales is required or offered.

To submit a request to know, access, correct, or delete your information, contact us at james@240operations.com. We'll respond within 45 days of a verifiable request, with one extension of up to 45 additional days where reasonably necessary.

8. GDPR Rights

If you are located in the European Economic Area, United Kingdom, or Switzerland, the GDPR or equivalent local legislation may apply to how we handle your personal data.

Our legal bases for processing are: contract performance (Article 6(1)(b)) for account and billing data, legitimate interests (Article 6(1)(f)) for analytics and security monitoring, and consent for any optional marketing communications.

You have the right to access, correct, delete, restrict processing of, and port your personal data, and to object to certain types of processing. Where we transfer personal data outside the EEA, we use Standard Contractual Clauses or other lawful transfer mechanisms.

To exercise any of these rights, contact us at james@240operations.com. Our customer base is currently US-based, and we will expand this section as needed when we serve EU customers.

9. Cookies and Tracking

We use a small number of cookies and similar technologies to operate the Service.

  • Session cookies: keep your authenticated session alive. The application will not work without them.
  • Authentication cookies: store your login state so you do not have to sign in again on every page load.
  • Analytics: PostHog collects page view data and product usage events so we can understand how the Service is used. PostHog does not fingerprint users or set advertising cookies. Analytics data is tied to authenticated accounts only (identified-only mode) and is never shared with advertisers.

We do not use behavioral advertising cookies or cross-site tracking. You can set your browser to refuse cookies, but doing so will prevent you from using the authenticated parts of the platform.

10. Security Practices

We take reasonable technical and organizational steps to protect your information from unauthorized access, disclosure, alteration, and destruction.

  • All data in transit is encrypted using TLS 1.2 or higher.
  • Data at rest is encrypted using AES-256.
  • Credentials and OAuth tokens are stored in encrypted form and accessed only by the processes that require them to retrieve Customer Data.
  • Access to production systems and Customer Data is restricted to authorized personnel on a least-privilege basis.
  • Database-level row security isolates each organization's data so no account can access another's information.

No method of transmission or storage is perfectly secure. We do our best to protect your information, but we cannot guarantee absolute security. If you believe your account has been compromised, contact us right away at james@240operations.com.

11. Breach Notification

If we confirm a security breach affecting personal data we control, we will notify affected Customers within 72 hours of discovering the breach. Our notice will describe what happened, the categories and approximate volume of data involved, what we are doing about it, and how to reach us with questions.

If the breach involves Customer Data we process on Customer's behalf (data pulled from Third-Party Platforms), we will notify the affected Customer within 72 hours so Customer can meet its own notification obligations to End Users and regulators. Customer, as the data controller, is responsible for any downstream notifications.

12. Children

The Service is for business use only and is not directed at anyone under 13 (or under 16 in the European Economic Area). We do not knowingly collect personal information from minors. If we learn that we have collected personal information from a minor, we will delete it promptly. If you believe we may have information about a minor, please contact us at james@240operations.com.

13. Changes to This Policy

We may update this Privacy Policy. When we make material changes (what data we collect, how we use it, or who we share it with), we will notify you by email and by posting a notice in the application at least 30 days before the change takes effect.

Non-material changes (typographical corrections, clarifications that don't affect your rights) take effect immediately upon posting. The “Last updated” date at the top of this page reflects when the policy was most recently revised.

If you continue using the Service after an update takes effect, you are accepting the revised policy.

240 Operations LLC

Email: james@240operations.com

Website: https://hpauditing.com


© 2026 240 Operations LLC. All rights reserved.