Privacy Policy
Effective September 18, 2026 · Last updated September 18, 2026
This Privacy Policy explains how Command Post, operated by Hinkle Productions ("we," "us," or "our"), collects, uses, shares, and protects information. It applies to the Command Post web application, the third-party services you choose to connect to it, and the communications we send in connection with it. Some features described below are optional or not yet available; those are marked with wording such as "where enabled" or "if you connect."
1. Scope
Command Post is a multi-tenant operations-management platform for service businesses. Each company that uses it (a "tenant") controls the business, employee, and customer data it puts into its own workspace. This policy covers information we handle in providing the service. By using Command Post you agree to our Terms of Service.
2. Information We Collect
Account and profile data
- name, email address, and phone number;
- address, if you choose to provide one;
- sign-in and account metadata, such as your role within a company and when you joined.
Company and tenant data
- company information, locations, and business hours;
- users, roles, and permissions;
- schedules, availability, tasks, and projects;
- operational data your organization imports or enters, which may include job, order, or customer information such as customer names and service addresses.
Customer and lead management features may be added later and, when they are, will handle the customer and lead data your organization enters.
Financial and accounting data
If your organization connects QuickBooks Online, we receive company metadata (such as the QuickBooks company name, country, and fiscal-year start) and financial reports you request, such as a Profit & Loss. Your organization may also upload or import accounting files. We do not necessarily store every piece of source-system data: some data is displayed on request without being saved, while imported files and their derived figures are stored in your organization's workspace.
Google Workspace data
If your organization connects Google Workspace, we receive the connected account's identity (its email address) and Google Calendar information needed for the enabled feature. Today that feature is limited to Google Calendar: we list the calendars you can use, let an administrator choose one, and create, update, and remove events on it for published schedule assignments. Those events can contain an employee's name, the shift date and time, the location, and any note on the shift. We do not currently read your existing calendar events into Command Post.
If and when you enable a feature that requires Gmail, Google Drive, Contacts, Sheets, or other Google Workspace data, we will describe the specific data requested and its purpose when we ask for your permission (see Section 5).
Microsoft data
Command Post does not currently connect to Microsoft services. If Microsoft 365 integrations are enabled in the future, we would receive Outlook, calendar, OneDrive, SharePoint, or Microsoft 365 profile data only as permitted by the access you grant for the feature you enable.
Advertising and marketing platform data
Command Post does not currently connect to advertising platforms. If a tenant later connects one, such as Google Ads, we may process account, campaign, performance, and conversion or attribution data, and the identifiers needed to provide that integration.
Communications data
- email address and phone number;
- communication and notification preferences;
- opt-in and opt-out records;
- delivery and status information for messages we send.
Device and technical data
- IP address, browser, and device type;
- server logs and security or audit records;
- session and authentication cookies (see Section 11).
3. How We Use Information
- provide the features you use, including planning, scheduling, staffing, and reporting;
- authenticate users and manage tenants, roles, and permissions;
- synchronize connected calendars and display connected accounting data;
- send notifications and messages you or your organization have requested;
- provide support and troubleshoot problems;
- prevent fraud and abuse and maintain the security of the service;
- comply with legal obligations;
- improve the reliability and usability of the service.
4. Google API Services User Data
The use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In particular, Command Post does not:
- sell Google user data;
- use Google Workspace user data for advertising, or transfer it to advertising platforms, data brokers, or other information resellers;
- use Google user data to determine creditworthiness or for lending purposes;
- use Google user data to develop, improve, or train generalized artificial intelligence or machine-learning models.
We use Google user data only to provide and improve the user-facing features you enabled. People at Hinkle Productions do not read Google user data unless you give us permission for support, it is needed for security purposes such as investigating abuse, it is needed to comply with applicable law, or it is otherwise permitted by Google's policies.
We request only the Google access needed for the features enabled. You can disconnect Google Workspace in Command Post at any time (an administrator can do this in Settings), and you can also remove access from your Google Account. You may ask us to delete data associated with the integration (see Section 16).
5. Gmail, Drive, and Other Google Workspace Features
Command Post does not currently read Gmail or Google Drive data. If you choose to enable a future Command Post feature that requires Gmail, Drive, or other Google Workspace data, Command Post will disclose the specific data requested and its purpose at the time permission is requested.
6. QuickBooks Online / Intuit
- Connecting QuickBooks Online is optional. Your organization authorizes access through Intuit's own sign-in and authorization (OAuth) screen.
- We store the resulting authentication tokens securely on the server. They are never shown in the browser.
- The current integration is read-only. It reads accounting data such as company information and financial reports (for example a Profit & Loss). It does not create, change, or delete transactions or other records in QuickBooks.
- Only administrators authorized by your organization can connect, test, or disconnect the integration and view the QuickBooks data check.
- When you disconnect, we delete the stored access credentials and ask Intuit to revoke them, subject to legal and operational requirements. Data already imported into Command Post may remain unless it is deleted under applicable retention or account rules.
Use of QuickBooks is also subject to Intuit's own terms and privacy statement.
7. Microsoft 365 and Outlook
This section describes possible future functionality; Command Post does not currently connect to Microsoft. If Microsoft 365 integrations for Outlook, calendar, OneDrive, SharePoint, or related services are offered, access would occur only after your organization or you authorize it, would be limited to the scopes needed for the enabled feature, would be used only to provide that feature, and could be revoked or disconnected.
8. Google Ads and Advertising Data
Command Post does not currently connect to advertising accounts. If a tenant later connects an advertising account, we may access the campaign, performance, and conversion data needed to provide reporting or management features, and we will process personal information consistently with the authorization given and the provider's policies. Google Workspace data is never repurposed for advertising or ad targeting.
9. Text Messaging and Mobile Information
Command Post does not currently send text messages. Where texting is enabled in the future, we may collect phone numbers and text-message consent records.
- Mobile information and text-message opt-in consent are not sold or shared with third parties for their own marketing or promotional purposes.
- Service providers may receive limited information solely to deliver the messages.
- You can opt out of optional texts by replying STOP where supported.
- We may keep consent and opt-out records to document compliance.
- Standard message and data rates may apply.
10. Notifications
Depending on the features enabled, notifications may be delivered in the app, by email, by push notification if later enabled, and by text message where enabled and consented to. Operational alerts follow the preferences and settings available to you or your organization. Security and account-critical notices may not always be optional.
12. Service Providers
We use service providers to operate Command Post, for example for hosting, authentication, database and secure storage, communications, security, and the integrations you connect. They may process information on our behalf for those purposes only. We do not publish an exhaustive provider list here and may add a page describing providers in the future.
14. Data Retention
We keep information for as long as needed to provide the service. Some audit, security, and legal records may be kept longer. When you disconnect an integration, we remove stored access credentials and revoke them where the provider supports it, but some operational or imported records may remain in your workspace. Deletion requests are handled subject to legal obligations and our backup cycles; we do not promise immediate deletion from every backup.
15. Security
We use reasonable safeguards, including access controls, authentication, encryption in transit, secure storage of integration credentials, separation of each tenant's data, and logging and security controls. No system is completely secure, so we cannot promise absolute security.
16. Your Choices and Rights
Depending on where you live, you may have certain rights regarding your personal information, such as access, correction, and deletion. You can update your own profile in the app, disconnect integrations where supported, and manage communication preferences where available. Because a tenant controls the data in its workspace, requests about workspace data may be directed to that tenant's administrator. You can also contact us at info.hinkleproductions@gmail.com, and we will respond as required by applicable law.
17. Children
Command Post is a business application and is not intended for children under 13. We do not knowingly collect personal information from children under 13.
18. Where Information Is Processed
Information may be processed in the United States and in other locations used by our service providers, subject to applicable law.
19. Changes to This Policy
We may update this policy. We will post the updated version with a new "Last updated" date, and where a change is material we will provide additional notice where appropriate, such as in the app or by email.
20. Contact
Privacy questions and requests can be sent to info.hinkleproductions@gmail.com. Command Post is operated by Hinkle Productions.