What we collect, and why.
A safety record is only worth keeping if you can say what is in it. This is the plain list: what Tailboard holds about your company, your crew and the people on your roster, why each piece is there, what we never collect, and how it is kept. The privacy policy is the full text; nothing here contradicts it.
Three kinds of people, three amounts of data
Account holders
The Owner and the safety team: the people who sign in. We hold your name, your email address and a password we cannot read, plus what you build in the product: meetings, job safety analyses, inspections, the written safety program, the equipment list, the mileage log, the documents you upload, and your logo if you add one. Everything you make is yours, kept as long as the account exists.
Crew who sign
Nobody on your crew needs an account. When they sign a talk or a JSA we record the name they typed or tapped, the signature they drew, and the date and time. Their approximate location is recorded only if you have switched that on; it is off by default, the page says so before anyone signs, and declining still lets them sign.
People on your roster
Everything about an employee is entered by you, and all of it is optional except a name: job role, crew, an internal reference, an email for their own certification reminders, their certifications, and driver's licence details limited to state, class, endorsements, expiry and the last four characters of the number. The field will not accept a full number.
Why each piece is there
Records, because someone will ask
A meeting, a JSA or an inspection is sealed when it is filed, and kept for as long as the account exists. That is the product: a record you can hand a general contractor or an inspector two years later and stand behind. Because it is sealed, we will not quietly rewrite one. If something in a sealed record is wrong we can say so and we can delete it, but we will not re-seal it as though it had always said something else.
Certifications, because they lapse
Expiry dates are held so the reminder can fire before a card runs out, and so the matrix can show a gap before a gate does. An email on a roster row is used for that person's own reminders and nothing else; it never creates an account.
Vehicle logs, because the DOT audits them
Per truck per day: both meters at each end, who took it out and brought it back, their signatures, and which state it worked in. Interstate operators account for miles by jurisdiction, and this is that account. It is not tracking: there is no live position, no route and no geofence anywhere in Tailboard.
A linked calendar, because the day starts there
On Fleet you can paste a calendar's private address so jobs appear on the day. We read it every fifteen minutes and keep only the events from yesterday to two weeks ahead. We never write to it and never sign in to it, and unlinking it deletes the address and every event we held.
Payments, held by Stripe
Card details never reach our servers. We keep a Stripe customer reference, your tier, your subscription status and the renewal date. When the billing page shows your card's brand and last four, it is reading them live from Stripe.
What we never collect
Full licence or ID numbers
The last four characters, and the field refuses more. We do not ask for Social Security numbers, medical cards or drug-test results, and we do not want them.
Card numbers
Stripe holds them. We never see a full card number.
Advertising profiles or analytics
No page on this site, public or signed in, loads an analytics script or any other third-party script. The cookies we set keep you signed in and do nothing else. If you arrive from a flyer's QR code we add one to that flyer's count for the day, and keep nothing about you with it.
Where a truck is
A mileage log is meters and a date. Nothing reports a vehicle's position.
Who sent an anonymous report
We do not log the sender's address against it, and there is no account behind it. We cannot be asked for something we do not have.
Children's data
Tailboard is a workplace tool. It is not directed at anyone under 13 and we do not knowingly collect their information.
How it is kept
Encrypted, twice over
Every connection is encrypted, and the database and file store are encrypted at rest by Cloudflare, where your data lives in the United States. On top of that, every file you upload and the most personal fields on a roster row, a phone number, the last four of a licence, the reason someone is exempt, are sealed by the application itself with a key that lives only in the running service. A copy of the store without that key reads as noise.
Passwords and PINs we cannot read
Account passwords and crew PINs are stored only as salted hashes. Nobody at your company and nobody at Tailboard can read one back; they can only be reset. Two-step sign-in is available to every account and required on our own operations console.
Sessions that end
A signed-in session ends after 30 minutes without activity. Changing your password or email signs out every other device.
Suppliers, and only the ones the job needs
Cloudflare for hosting and the database, Stripe for payments, Resend for email. Nothing is sold and there is no advertising business. Cloudflare keeps its own request logs under its own policy.
Getting it out
Your copy, any time
Records print to PDF, the mileage log downloads as a spreadsheet, and the prequal packet gathers what a GC asks for. After you cancel you keep read access for 90 days to export what you need.
Correct it, or delete it
Email support@tailboardsafety.com to ask for a copy of your data, a correction, or deletion, and we answer within 30 days. A crew member whose name or signature is in a record should ask their employer first: the record is the employer's, and they control it. If they cannot help, write to us and we will do what we can.
Questions about anything on this page: support@tailboardsafety.com. It reaches a person, and the answer will be as plain as this page.