Privacy Policy
Last updated September 24, 2026.
The short version, in plain words, is on What we collect, and why.
This policy explains what Tailboard collects, why, and what happens to it. It is written to be read, not to be impressive.
Three kinds of people
Tailboard holds information about three groups, and they are not in the same position.
Account holders are the people who sign in: owners, superintendents, office staff, safety officers, foremen. They chose to use Tailboard.
Signers are crew members who open a link and sign a safety meeting. They have no account and usually didn't choose Tailboard - their employer did.
Employees on a roster are people a company has added so it can track who attended what and which certifications are current. They may never open Tailboard at all, and may not know it exists.
For the second and third groups, the information belongs to their employer. We hold it on that employer's behalf and act on its instructions. If you are a crew member with a question about your own record, start with your employer.
What we collect
From account holders
- We record your name and email address.
- Your password is stored only as a salted PBKDF2 hash. We cannot read it.
- We keep the equipment list you enter: unit names, plates, VINs, the crew each one usually runs with, its annual inspection date, the pre-trips filed against it and the repairs noted and fixed.
- We keep the written safety program the wizard writes from your answers, every signed version of it, and the Owner's signature on each. It is shown to the crew behind your SOP code and on signing pages.
- We keep the logo you upload, if you upload one. It is shown on your signing pages, records and packet, at a public address that cannot be guessed, until you remove it.
- We record your company name, trade, business address if you give one, and the state whose safety-meeting rule you have asked us to count down to.
- We record which meetings you created, which you closed, and when you last signed in.
- Your signature is recorded if you close a meeting or file a JSA. Closing seals the record, and the signature is part of what gets sealed.
- We keep the job safety analyses you file: the job, the hazards and PPE checked, who from the roster was on it, the meeting place, and the crew's signatures.
- We keep the inspections you file: the checklist, the answer on each line, the notes, the photos added to a failed line, and the inspector's signature. Filing seals them, the same as a meeting.
- We keep the documents you upload to the document folder, and the note you attach. If the office marks a document as open to the crew, anyone holding a signing link for your company, or scanning the company's SOP sign, can open it; nobody else can.
- When a meeting is filed, whoever files it can add a note and up to three photos. They are stored with the record, hashed into its seal, and shown to anyone who can read your records. Photograph the site and the setup, not people, unless they know and agree.
- We keep the feedback you send us through Give feedback: the star rating, what you wrote, and whether the Owner checked the box allowing us to quote it. It is emailed to us the moment it is sent, labeled by role and company.
- If you turn on two-step sign-in, we hold the secret your authenticator app shares with us, stored only to check your codes. We never see the codes themselves and cannot recover the secret for you; we can only clear it.
From signers
- We record the name they type, or the name they tap from their employer's roster.
- We record the signature they draw, stored as an image.
- We record the date and time they signed.
- We record their approximate location, only if their employer has switched that on. It is off by default. When on, the signing page says so before anyone signs, and the phone asks permission. Declining still lets them sign.
From a linked job calendar
An employer on the Fleet tier can link the calendar their jobs live on, for the whole company or for one crew, by pasting that calendar's private subscribe address. We hold the address and read the calendar from it every fifteen minutes. We never write to the calendar and we never sign in to it.
- We keep only the events that fall from yesterday to two weeks ahead: the title, the date and time, the location, and the notes, up to a short length each. Events that pass or leave the calendar are dropped on the next read, unless a meeting or a job safety analysis was filed for them, in which case the event stays as part of that record's context.
- The employer can choose to read every event, or only events with a word in them, and can hand a job to an account holder. That person is emailed the job, its date and place. The employer can also switch on a morning email to the crew's foreman, or the Owner, listing that day's jobs with nothing filed yet.
- The calendar address is shown to nobody after it is saved, only the host it points to. Unlinking the calendar deletes the address and every event we held from it.
About employees on a roster
An employer can record the following about people who work for it. All of it is optional except a name, and all of it is entered by the employer, not by us.
- The employer can record the person's name, job role, and which crew they are on. A crew has a state, which decides the meeting deadline and the rule its records cite.
- The employer can record whether the roster entry is linked to an account that signs in, so the meetings a foreman runs count as attended.
- The employer can record an internal reference such as a payroll number.
- The employer can record an email address, used only to send that person reminders about their own certifications. It never creates an account.
- The employer can record certifications: the type, issue and expiration dates, and a free-text note such as a card number or awarding body.
- The employer can record driver's license details: issuing state, class, expiration date, endorsements, and the last four characters of the license number only. We do not store full license numbers, and the field will not accept one.
Employee IDs and PINs
An employer on the Fleet tier can give the people on its roster a way in of their own: a six-digit Employee ID and a four-digit PIN, used on that employer's crew page. The ID is generated by us or set by the employer. The PIN is chosen by the person themselves and stored the same way an account password is - put through a key-derivation function with a random salt, never in readable form. Nobody at the employer, and nobody at Tailboard, can read it back. It can only be reset, which sends that person a fresh link to choose a new one.
We record when a PIN was set, how many times a wrong one was tried, and whether that number is temporarily locked. Wrong tries lock the number for fifteen minutes after eight attempts.
What an ID and PIN open is limited on purpose: signing a talk or a job safety analysis, reading the employer's safety manual, logging miles and hours. Every one of those already has a link of its own that anyone holding it can open. No personnel record sits behind those four digits.
Vehicle logs, on the Fleet plan
Where an employer uses the mileage log, we hold, per truck per day: the odometer and power take-off hours at the start and end, who took the vehicle out and who brought it back, their signatures, whether the work was out of state and which state, the distance the employer has recorded from their yard to that state line, and any figure the employer has asked for such as fuel added.
This is a record of a vehicle and a working day, and it is kept because interstate operators are required to account for miles by jurisdiction and to answer a DOT audit. It is not location tracking: nothing reports where a vehicle is, and there is no live position, route or geofence anywhere in Tailboard.
Network addresses
We count failed sign-in attempts per network address so that somebody working through a list of email addresses is stopped. The address is not stored: it is hashed, and only the hash, a count and an expiry are kept. Rows are deleted within a day. Cloudflare, which serves this site, keeps its own request logs under its own policy.
Payment information
Card details are handled entirely by Stripe and never reach our servers. We store a Stripe customer reference, your subscription status, your plan, and the renewal date. When the billing page shows your card brand and last four digits, it is reading them live from Stripe; we do not keep them.
Analytics
We run none. No page on this site - the pages you can read without signing in, every page you see once you have signed in, the pages your crew signs on, the crew platform and the sign-in page - loads an analytics script or any other third-party script. Every page is served with a policy that permits no outside script origin at all, so even a script that somehow ran would have nowhere to fetch from and nowhere to report to.
One counter, and it is ours: a flyer's QR code lands on a page address of its own, and we add one to that flyer's count for the day before sending you on to pricing. Nothing about you is kept with it - not your address, not your device, not the time.
Until 13 September 2026 the marketing pages could load a visit counter (HeyCatch) if you accepted it on the cookie notice. That is gone, along with the choice, and the browser setting that remembered your answer is cleared the next time you open the site.
We do not want, and do not collect, behavioral data about people who never chose this service.
Cookies
Tailboard sets cookies that are strictly necessary for the service to work. None is used for advertising or profiling, and we set no advertising cookies. Because there is nothing optional, the notice at the foot of these pages asks nothing of you; "Got it" only stops it showing again on that browser.
| tb_crew | Keeps a crew member signed in to their employer's crew page after they enter their Employee ID and PIN. Scoped to the crew pages only, so it is not sent with anything else. Expires after 12 hours or when they sign out. |
| tb_session | Keeps you signed in. Expires after 30 days, after 30 minutes of inactivity, or when you sign out - whichever comes first. |
| tb_device | A random identifier used only for meetings locked to a single device, so the app can tell which phone claimed the meeting. It identifies a browser, not a person, and contains no personal data. Expires after 90 days. |
| tb_viewas | Set only when a Tailboard operator previews a lower permission level while supporting a customer. Expires after two hours. |
Your browser also keeps two small notes of its own, on this site only and never sent to us: that you have seen the cookie notice, and - if you asked for it on the rules-by-state page - which state's rules to show first.
Why we hold it
We hold it to run the service you asked for: showing safety talks, collecting signatures, producing an attendance record that can be verified, and telling you when a certification is about to lapse.
We use email addresses to send account emails - invitations, password resets, notice that a password or address changed - and, where an employer has entered one, to send an employee reminders about their own certifications and nothing else. When a meeting is filed, the sealed record is emailed to the account holders whose role lets them read records; the Owner can switch that off in Settings. We may also email account holders about changes to the service, and the Owner of a company about something we fixed for them. Every email we send comes from noreply@tailboardsafety.com, and a reply to any of them reaches a person at support@.
We do not sell personal information and we do not share it with advertisers. We have no advertising business.
Who we share it with
We share it only with the suppliers needed to operate the service:
- Cloudflare - hosting and database
- Stripe - payments and subscription management
- Resend - sending email
When an employer links a job calendar, our servers fetch it from the calendar's host (Google, Apple, Microsoft or Cozi, whichever it is). That host sees a request from Tailboard for the address the employer gave us, and nothing else.
People who work for Tailboard reach customer data only through our operations console, each with a named account, two-step sign-in, and only the permissions their work needs; every change they make there is logged with their name.
We will disclose information if legally required to do so, and will tell you unless we are prohibited from doing so.
How long we keep it
We keep different things for different reasons:
| Sealed meeting records | For as long as the account exists. An attendance record you cannot produce two years later is worthless, which is the whole point of the product. |
| Signature images and any location captured with them | For the life of the record they belong to. They are part of what the seal covers, so removing them would break the record. |
| Job safety analyses and inspections | As for meeting records: for as long as the account exists once they are sealed. A JSA that was never signed can be deleted by the employer at any time. |
| Feedback | Until you ask us to delete it. A quote we have published comes down when you ask. |
| Linked job calendar | The address, until the employer unlinks it. Events, from yesterday to two weeks ahead, replaced on every read; an event a record was filed for stays with that record. |
| Employee roster, certifications, license details | Until the employer deletes them or closes the account. An employer can archive someone who has left, which keeps their past attendance intact while removing them from current lists. |
| After you cancel | You keep read access to your records for 90 days so you can export them. After that we may delete the account and its data. Export what you need before you cancel. |
| Session records | Deleted when they expire, at sign-out, and whenever you change your password or email address. |
Employers: what is yours to do
When you put your crew's information into Tailboard, you remain responsible for it. Several things are worth stating in particular:
- Location. If you turn on location recording, you are collecting location data about your employees. Tell them before you switch it on. Depending on where you operate, you may have obligations around notice or consent.
- Employee email addresses. If you add one, that person will receive email from us about their certifications. Tell them to expect it. You can turn employee reminders off entirely in Settings.
- License and certification details. Collect only what you actually need. We deliberately do not accept full license numbers, and we would suggest you don't record more elsewhere either.
- Job calendars. The subscribe address is a secret: anyone who has it can read the calendar. Point Tailboard at a calendar that holds jobs, or use the tag word, so personal appointments never reach us. What we read is described above; tell whoever keeps the calendar.
- Roles. You choose what each account holder can see. Giving someone a role that reads every record, or that manages the roster, is your decision about your own employees' information.
- The prequalification packet. It gathers your employees' names, job roles and certification status into one document meant to be sent to a general contractor. We do not send it anywhere - you print it and you decide who receives it. Once you hand it over, what that contractor does with your crew's information is between you and them.
Your rights
You can ask for a copy of your data, ask us to correct it, or ask us to delete it. Email support@tailboardsafety.com and we will respond within 30 days.
If you are a crew member whose name, signature or certification is in Tailboard, contact your employer first - the record is theirs and they control it. If they cannot help, write to us and we will do what we can.
One limit is worth stating plainly: we will not quietly alter a sealed meeting record, because a record that can be edited on request proves nothing. If something in a sealed record is wrong, we can tell you it is wrong, and we can delete it, but we will not rewrite it and re-seal it as though it had always said something else.
Security
- Passwords are hashed with PBKDF2-SHA256 and never stored in readable form.
- Two-step sign-in (a code from an authenticator app) is available to every account and required on our own operations console.
- Session tokens are stored only as hashes.
- All traffic is encrypted in transit, and the database is encrypted at rest.
- Sessions end after 30 minutes of inactivity, and changing your password or email signs out every other device.
No system is perfectly secure. If we discover a breach involving personal data, we will tell affected users promptly.
Where your data is held
Your data is held on Cloudflare infrastructure in the United States. If you are outside the United States, using Tailboard means your information is processed there.
Children
Tailboard is a workplace tool and is not directed at children under 13. We do not knowingly collect their information.
Changes
If we change this policy materially, we will update the date above and email account holders. Continuing to use the service after a change means you accept it.
Contact
Tailboard
Kennewick, Washington, United States
support@tailboardsafety.com