Privacy Policy
Effective September 8, 2026
1. Scope
This Privacy Policy explains how ForgeOne CRM LLC collects, uses, discloses, and protects information when you visit PDR One, create or join a company account, use storm-chase or dealer-contract workflows, sign a document, communicate with support, or interact with customer-facing links generated through the platform.
2. Information we collect and access
Account and company information
We collect names, email addresses, password hashes, phone numbers, company names, roles, permissions, account preferences, legal acceptances, subscription status, and billing identifiers.
Customer, dealer, vehicle, crew, and operational data
Users may submit customer and dealership contacts, addresses, storm events, canvass outcomes, vehicle identification numbers, license plates, mileage, damage observations, claims, insurers, estimates, repair orders, contracts, invoices, payments, commission records, technician information, photos, files, signatures, and related notes. Crew compliance documents uploaded by a company, such as W-9 or insurance documents, may contain taxpayer, insurance, or other sensitive business or personal information chosen by that company.
Location and mapped property data
When a user chooses My location during canvassing, PDR One requests foreground device location to show the user’s current position on the map. PDR One does not request background location. A user may deny location permission and continue by entering or selecting an address manually. Property addresses may separately be converted to map coordinates through address lookup or a user-selected map pin; those property coordinates are stored with the company’s canvass record.
Camera, photos, and files
PDR One accesses the camera or photo library only when a user chooses to capture or select an image or file for a company record, such as vehicle damage, receipts, contracts, or other job documentation. Selected content is uploaded only as part of the user-requested record workflow.
Notifications
If a user enables notifications, the device platform and push-notification services may generate an application or device push token used to route notifications. Notification permission is optional and is not used for advertising.
Usage and technical information
We may collect login activity, feature usage, audit events, support requests, IP addresses, browser and device information, session identifiers, page activity, error logs, and performance data.
Payment information
Payment-card details are processed by our payment provider and are not intended to be stored directly in PDR One. We may receive customer, subscription, invoice, payment-status, and transaction identifiers from that provider.
3. How we use information
- Provide, operate, secure, maintain, and improve PDR One.
- Authenticate users, enforce company roles, and keep each company’s records separated.
- Generate estimates, documents, signatures, reports, emails, financial records, and workflows requested by users.
- Process subscriptions and administer pilot or complimentary access.
- Provide support, investigate errors, and respond to feedback.
- Prevent fraud, abuse, unauthorized access, and security threats.
- Comply with legal obligations and enforce applicable agreements.
4. Company control and data separation
PDR One keeps each company’s records separate from other companies. Authorized owners and managers may access, manage, export, or delete company information according to their roles and permissions.
If your account is provided by an employer, dealership partner, contractor, or other organization, that organization may control your access and the records you create. Questions about its internal privacy practices should be directed to that organization.
5. Electronic signatures and audit information
When a person reviews, approves, declines, or signs a document, we may record the signer’s name, email, signature image, timestamp, IP address, user agent, document version, review-link activity, and related audit events. This information is used to create and preserve the requested electronic transaction record.
6. How information may be shared
We use service providers only as needed to operate PDR One. These may include Floot for application hosting, storage, and platform services; Stripe for company subscription billing; Google Maps and Places services for maps and address lookup; email and push-notification infrastructure; and vehicle, weather, or public-data sources used in user-requested workflows. We require service providers that process PDR One personal information for us to protect it consistently with our agreements, this Policy, and applicable law and to use it only for the services they provide to us.
Information may also be shared at a user’s direction, including through document review links, signatures, customer or dealer communications, invitations, exports, emails, integrations, or records made visible to business partners.
We may disclose information when required by law or valid legal process; to protect rights, safety, and security; or as part of a merger, financing, acquisition, or sale of assets subject to appropriate safeguards. PDR One does not display third-party advertising, and we do not sell personal information or use it for cross-app behavioral advertising.
7. Data retention and deletion
We retain information only for as long as reasonably necessary to provide PDR One, maintain company business and audit records, comply with law, resolve disputes, enforce agreements, prevent fraud or abuse, and protect the service. Retention varies by data type, account status, legal requirement, dispute, and the company that controls the business record.
When a user deletes a PDR One login account, PDR One removes the user’s authentication credentials, active sessions, company memberships, and personal login identity and de-identifies the remaining user reference. Company-owned operational, financial, contract, signature, and audit records may remain where the company or ForgeOne CRM LLC has a legitimate business, security, fraud-prevention, dispute, or legal-recordkeeping reason to retain them. Those retained records are no longer associated with an active personal login identity.
Deleted information may remain temporarily in backups, security logs, or disaster-recovery systems until the applicable backup or security-retention cycle expires, after which it is deleted or overwritten in the ordinary course.
8. Security
We use administrative, technical, and organizational safeguards designed to protect information, including authentication, password hashing, role-based access, company-specific data controls, secure transmission, and service-provider controls. No system can guarantee absolute security, and users are responsible for protecting credentials and managing account access.
9. Cookies, local storage, and device technologies
PDR One uses session cookies, local device storage, and similar technologies necessary to keep users signed in, protect accounts, remember preferences, support offline field workflows, install the web app, and operate application features. Blocking essential storage may prevent parts of the service from working. These technologies are not used to build advertising profiles across unrelated apps or websites.
10. Your choices, consent, and rights
You may withdraw optional device permissions such as location, camera, photo access, or notifications through your device or browser settings. PDR One provides manual address entry when location access is not granted, and users can choose whether to capture or select photos and files. Disabling an optional permission may disable only the feature that depends on it.
Users may update certain account and company information in PDR One. Company owners and authorized managers may manage members and company records. A user can permanently delete their PDR One login account from the in-app Delete account screen or from the public web account-deletion page. The public page uses secure sign-in and current-password re-authentication and does not require the installed mobile app. PDR One blocks deletion when that user is the last active Owner of a company so the company is not left without an accountable owner; another active Owner must be assigned first.
Account deletion removes the user’s sign-in credentials, active sessions, and company memberships and de-identifies the personal login identity. Company-owned operational, financial, contract, signature, and audit records may be retained where needed for the company’s business records, security, fraud prevention, disputes, or legal obligations. Depending on applicable law, individuals may also have rights to request access, correction, restriction, or a copy of personal information.
Privacy questions or requests that cannot be completed in-app may be sent to admin@forgeonecrm.com. We may need to verify identity and coordinate with the company that controls the account.
11. Children and account eligibility
PDR One is a business service intended for adults acting for a company or organization. PDR One accounts are intended for users age 18 or older and are not directed to children. We do not knowingly provide personal PDR One accounts to children.
12. Changes and contact
We may update this Privacy Policy as PDR One, legal requirements, or data practices change. Material changes may be presented in the application for renewed acknowledgment. Privacy questions may be sent to admin@forgeonecrm.com.
