Scope and who this policy covers
This Privacy Policy applies to Runnit’s websites, applications, field-service tools, account onboarding, support, communications, and related services that link to this policy (collectively, the “Services”). In this policy, “Runnit,” “we,” “us,” and “our” refer to Automotive Resource Co., an Oklahoma company based in Oklahoma, United States.
The policy covers people who visit a Runnit website, create or use a Runnit account, receive communications from Runnit, interact with a business using Runnit, or otherwise have information processed through the Services. It does not apply to third-party products, websites, or services that have their own privacy notices.
Our role and your business’s role
Privacy responsibilities depend on why information is in Runnit and who decides how it is used.
Information Runnit controls
Runnit acts as the business responsible for information used to create accounts, administer subscriptions, operate our websites, provide support, protect the Services, and communicate about the Services. We decide how and why this information is processed, subject to this policy and applicable law.
Information a customer controls
When a business uses Runnit to manage its customers, contacts, employees, contractors, jobs, invoices, files, or other business records, that business generally decides why the information is collected and how it is used. Runnit processes that information to provide the Services on the business’s instructions.
If you are an employee, technician, customer, property contact, or other individual whose information was entered by a Runnit business customer, direct requests about that information to the business first. We will support the business in responding where required.
Customer responsibilities
Businesses using Runnit are responsible for having an appropriate legal basis to collect and use personal information, providing any required notices, honoring individual rights, configuring access appropriately, and avoiding information that is unnecessary for field-service operations.
Information we collect
The information we collect depends on how you interact with Runnit and how your organization configures the Services.
Account and identity information
- Name, work email address, password credentials handled by our authentication provider, verification status, account identifiers, role, permissions, and invitation status.
- Company name, business address, phone number, contact email, time zone, logo, trade type, team structure, and account configuration.
- Signup answers, onboarding progress, subscription status, and communications preferences.
Customer and contact records
- Customer and company names, contact names, job titles, email addresses, phone numbers, notes, tags, and communication history.
- Service, billing, and mailing addresses; property or site details; access instructions; and map coordinates derived from an address.
- Records imported from spreadsheets or a connected accounting platform at the direction of a business customer.
Field-service and commercial records
- Jobs, visits, schedules, dispatch assignments, routes, service categories, work descriptions, checklists, time entries, completion details, and internal notes.
- Equipment details, materials, receipts and receipt images, invoices, purchase order references, tax settings, payment status, and document templates.
- Photos, logos, attachments, files, messages, and any other content a user chooses to upload or enter.
Billing and transaction information
- Subscription plan, seats, trial dates, billing status, transaction references, discounts, and limited payment metadata.
- Payment card and bank details are collected and processed by our payment provider. Runnit does not receive full payment card numbers.
Connected-service information
- Connection status, authorization tokens, external account or company identifiers, synchronization settings, mappings, import selections, and sync history.
- Data requested from or sent to a connected service, such as customers, contacts, products and services, accounts, tax references, and invoices in QuickBooks Online.
Device, usage, and support information
- IP address, browser and device type, operating system, timestamps, referring pages, requested URLs, session activity, error data, and security events.
- Support requests, feedback, survey responses, call or meeting details you choose to share, and related correspondence.
- Local browser storage used for interface preferences, onboarding progress, walkthrough status, and drafts. Session storage may preserve signup progress within a browser session.
Where information comes from
- Directly from you when you register, configure an account, enter records, upload files, connect another service, or contact us.
- From your employer, organization, account owner, administrator, or another authorized Runnit user.
- From your customers, vendors, or other people whose details are entered into business records.
- From connected services when an authorized user requests an import, synchronization, or other integration action.
- Automatically from browsers, devices, servers, cookies, local storage, logs, and similar operational technologies.
- From public or licensed sources used for functions such as address completion or geocoding.
How we use information
Provide and operate Runnit
- Create and authenticate accounts, maintain sessions, apply roles and permissions, and administer subscriptions.
- Store and organize business records; support customer, job, dispatch, field-work, invoice, reporting, and integration workflows.
- Generate documents, deliver authorized emails and notifications, map service addresses, and synchronize connected services.
Secure and maintain the Services
- Prevent fraud, abuse, unauthorized access, and other harmful activity.
- Monitor availability, investigate errors, maintain audit history, back up data, and enforce our agreements.
- Verify integration callbacks and webhooks and protect credentials used to connect third-party services.
Support, communicate, and improve
- Respond to questions, troubleshoot issues, provide account and service notices, and send requested or transactional communications.
- Understand feature use, evaluate performance, develop new capabilities, and improve workflows and usability.
- Create aggregated or de-identified information that does not reasonably identify an individual, and use it for lawful business purposes.
Comply with law and protect rights
- Meet tax, accounting, legal, regulatory, and recordkeeping obligations.
- Establish, exercise, or defend legal claims and protect Runnit, our customers, users, and the public.
Legal bases for processing
Where a law requires a legal basis, we process information as necessary to perform a contract with you or your organization; to pursue legitimate interests such as operating, securing, supporting, and improving the Services; to comply with legal obligations; or with consent when consent is the appropriate basis.
If we rely on consent, you may withdraw it at any time. Withdrawal does not affect processing that already occurred and may prevent us from providing a feature that depends on the information.
How we disclose information
We disclose information only as needed for the purposes described in this policy or at a customer’s direction.
Within an organization
Information is available to account owners, administrators, office users, field workers, and other authorized users according to the organization’s settings, roles, assignments, and workflow. An organization controls which people it invites and what access they receive.
Service providers
We use vendors to provide infrastructure, hosting, authentication, file storage, database operations, security, email delivery, payment processing, maps and geocoding, support, and similar services. They may process information only to perform services for us under appropriate contractual restrictions.
Connected services and recipients you choose
We disclose information when an authorized user connects a third-party service, sends an invoice or dispatch notice, shares a document, or otherwise directs Runnit to transmit information. The recipient’s own terms and privacy practices apply after the information is received.
Legal, safety, and corporate events
We may disclose information to comply with law or legal process; respond to lawful requests; investigate fraud, security, or policy violations; protect rights, property, or safety; obtain professional advice; or support a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets. Where appropriate, we will seek confidentiality protections and provide notice.
Service providers and international processing
Depending on configuration and availability, Runnit may use providers such as Google Firebase for authentication or storage, Stripe for subscription billing, Mailgun for email delivery, Vercel or cloud infrastructure providers for application hosting, OpenStreetMap-based services for maps or geocoding, and Intuit for QuickBooks Online connections.
Providers may process information in the United States and other countries where they or their subprocessors operate. Those countries may have different data-protection laws. Where required, we use contractual or other lawful transfer mechanisms intended to protect information transferred across borders.
Provider names and functions may change as the Services evolve. A business customer may contact us for current information relevant to its account.
QuickBooks Online data
This section applies when an authorized account owner or administrator connects Runnit to QuickBooks Online.
What Runnit accesses
Based on the actions you request and the permissions granted through Intuit, Runnit may access QuickBooks company details, customers, products and services, accounts, tax references, invoices, identifiers, and related metadata. Runnit also receives connection credentials, realm or company identifiers, webhook events, and synchronization results.
Why Runnit accesses it
Runnit uses QuickBooks data to help you review and import accounting references, map Runnit records, prepare or synchronize accounting copies of invoices, reconcile totals and tax treatment, detect changes, display connection status, and troubleshoot integration activity. Runnit does not access QuickBooks data for unrelated advertising.
Storage, security, and disconnect
Runnit stores connection credentials in encrypted form and limits integration actions to authorized users and account-scoped workflows. When you disconnect QuickBooks, Runnit removes active credentials from its systems and requests revocation where supported.
Disconnecting does not automatically delete business records previously imported into Runnit or accounting records previously sent to QuickBooks. Those records remain subject to the retention rules and controls of the system where they reside. Intuit independently controls information held in QuickBooks.
Retention and deletion
We retain information for as long as reasonably necessary to provide the Services, maintain the account, complete requested transactions, satisfy legal and accounting requirements, resolve disputes, enforce agreements, protect the Services, and preserve legitimate business records.
Retention varies by category. Account and business records generally remain while an account is active. Security logs, audit records, invoices, payment references, support history, and records needed for legal obligations may be retained longer. Browser-stored preferences and drafts remain until cleared by the user, the application, or the browser.
Deletion from the active application may not immediately remove information from encrypted backups, logs, fraud-prevention systems, or records retained for legal reasons. Residual copies are isolated from ordinary use and removed or overwritten according to applicable retention cycles.
Account owners may request account closure and deletion. Before closing an account, export information the business must retain. We may verify authority, preserve required records, and provide information about material limitations before completing the request.
Security
Runnit uses administrative, technical, and physical safeguards designed to protect information, including access controls, tenant-scoped authorization, encrypted network connections, protected session cookies, credential protection, audit mechanisms, and security testing appropriate to the nature of the Services.
No method of storage or transmission is completely secure. Customers should use unique credentials, limit administrative access, promptly remove former users, review connected services, protect devices, and notify us of suspected unauthorized access.
Your choices and privacy rights
Account controls
- Review and update profile, company, customer, team, and integration information through available account settings.
- Disconnect supported integrations, change user access, manage certain notifications, or close the account through the account owner or by contacting Runnit.
- Control browser cookies and local storage through browser settings. Blocking essential storage may prevent authentication or saved preferences from working.
Communications
You may opt out of non-essential marketing emails by using the unsubscribe method provided. We may still send account, security, billing, support, or other transactional messages necessary to provide the Services.
Legal rights
Depending on where you live, you may have rights to request access, correction, deletion, portability, or restriction of personal information; to object to certain processing; to withdraw consent; or to appeal a denied request. You may also have the right not to receive discriminatory treatment for exercising a privacy right.
We may verify your identity, authority, and jurisdiction before acting. Authorized agents may be required to provide signed permission. Some information may be exempt, and a request may be limited where retention is required by law or needed to protect rights and security.
United States state disclosures
For residents of states with comprehensive privacy laws, the categories of personal information we may collect are described in “Information we collect.” We collect them from the sources in “Where information comes from,” use them for the purposes in “How we use information,” and disclose them to the recipients in “How we disclose information.”
Runnit does not sell personal information and does not share it for cross-context behavioral advertising. We do not knowingly use sensitive personal information to infer characteristics or for purposes other than providing and protecting the Services. Because we do not engage in these practices, Runnit does not currently offer a “Do Not Sell or Share” link.
We may disclose identifiers, commercial information, internet or device activity, professional information, approximate location derived from business addresses, and customer-provided content to service providers and connected services for the business purposes described above. We retain each category under the principles in “Retention and deletion.”
Children
The Services are for business use and are not directed to children under 16. We do not knowingly collect personal information directly from children for their own use of Runnit. If you believe a child submitted information directly to us without appropriate authorization, contact us so we can review and, where appropriate, delete it.
Business customers should not place information about minors in Runnit unless it is necessary for a lawful business purpose and the customer has provided any required notice or obtained any required permission.
Changes to this policy
We may update this Privacy Policy to reflect changes in the Services, law, or our practices. We will post the revised policy with a new “Last updated” date. If a change materially reduces privacy protections, we will provide additional notice when required, such as an account notice or email to the account owner.
The version in effect when information is processed governs that processing, unless applicable law requires otherwise.
Contact and requests
For privacy questions or requests, email Runnit at info@autoresourceco.com. You may also use the in-product support channel or the contact information listed in your order form or subscription record. Include the email address associated with your account, the business you are connected to, your jurisdiction, and the nature of your request. Do not include passwords or other credentials.
If your information was entered by a business using Runnit, contact that business first. If you contact us directly, we may refer the request to the business and assist it in responding.
We aim to acknowledge verified privacy requests promptly and respond within the period required by applicable law. If we deny a request, we will explain the basis when required and provide appeal instructions where available.
info@autoresourceco.com