Privacy policy

Effective August 14, 2026 · Blacktop Labs LLC

What lotbiddr is

lotbiddr is business software for paving and pavement-maintenance companies: estimating, scheduling, timecards, and a mobile field app for crews. Your company — the organization that invited you — runs its own lotbiddr account, and you use lotbiddr as a member of that organization. This policy explains what data lotbiddr handles and how.

Account data

When your organization invites you, lotbiddr stores your name, email address, and a password (stored only as a salted hash) — or, if you sign in with Microsoft, the name and email your Microsoft account provides. Optional profile photos and two-factor settings are stored if you add them. We use this data to run your account: signing you in, showing who did what, and sending the notifications you or your organization configure.

Your organization's data

Companies, contacts, sites, projects, estimates, proposals, schedules, timecards, and similar records belong to the organization that created them. lotbiddr (operated by Blacktop Labs LLC) stores and processes that data solely to provide the service to that organization. Organizations are isolated from each other at the database level (row-level security); no organization can see another's data. Before enabling workforce features like location tiers, each organization is responsible for satisfying any employee-notice obligations that apply where its crews work.

Location (the field app)

This is the part that matters most to field crews, so here it is plainly:

  • On the clock only. Location is recorded only between your own clock-in and clock-out, and only when your organization uses a location tier — each organization picks its tier, or turns location off entirely, in its field settings. The tracker stops at clock-out, every time. Never off the clock.
  • Two tiers, chosen by your organization. Punch points: your location is recorded at clock-in and clock-out only — never in between. On the clock: location is recorded in the background from clock-in to clock-out, even if the app is closed — never off the clock — so hours and site visits match the right jobs. The app shows a persistent indicator while this runs.
  • What is recorded: GPS coordinates, accuracy, a timestamp, and — when you cross a jobsite boundary — an entered/left marker tied to the jobsite and your open punch. The app also reads your phone's motion state on the device to pause GPS while your phone is still (battery saving); motion data never leaves your phone and is never stored by lotbiddr.
  • Consent, and the decline path. Before your first location-enabled punch, the app shows you a consent screen. If you choose "Punch without location," you can still clock in and out of every job — you're just responsible for clocking in and out of each job yourself. Declining never blocks your pay or your punches.
  • The trail is kept 90 days. The on-the-clock location trail — the recorded points and the jobsite entered/left markers — is deleted after 90 days. The single location stamps captured at clock-in and clock-out are part of the timecard itself: they stay with that business record, and are removed when you delete your account.
  • Who sees it: the office staff and crew leads of your own organization, on its timecard and crew surfaces. Location is never sold, never used for advertising, and never shared with other organizations or third parties.

Cookies and sessions

lotbiddr uses cookies only to run the app: a session cookie that keeps you signed in, a security (CSRF) token, and small preference cookies (such as your theme and screen hints). No advertising cookies, no cross-site tracking.

Service providers

lotbiddr runs on service providers that process data on our instructions:

  • Fly.io — application hosting and managed Postgres databases.
  • Resend — transactional email (invites, sign-in codes, notifications).
  • Tigris — object storage for uploaded files: profile and project photos, organization logos, and generated documents.
  • Google Maps Platform — maps, address autocomplete, and drive-time estimates on office and estimating surfaces: jobsite addresses and coordinates are sent to Google to render maps and compute distances. The on-the-clock location trail is never sent to Google.
  • BoldSign — e-signature delivery when your organization sends a proposal for signature: the recipient's name, email address, and the document being signed.
  • Sentry — error and crash reporting, so we can fix problems. Session replay never runs on field-crew surfaces or in the mobile app.
  • Anthropic — only if your organization enables optional AI features with its own Anthropic API key; the relevant content is then sent to Anthropic under your organization's key. Off by default.

Security

All traffic is encrypted in transit (HTTPS). Passwords are stored as salted hashes. Certain sensitive fields are additionally encrypted at rest. Organizations are isolated by database row-level security.

Data deletion and your choices

  • You can delete your own account data yourself, at any time — the account-deletion page walks through it, including what stays with your employer's organization as its business records and why.
  • Organization data is deleted at the organization's direction; when an organization leaves lotbiddr, its data is removed on request.
  • The on-the-clock location trail is deleted after 90 days (see Location above).
  • For any deletion or access request, email support@lotbiddr.com from the address on your account and we will respond within a reasonable time.

Children

lotbiddr is workplace software and is not directed at children under 16.

Changes to this policy

We'll post changes here with a new effective date. For material changes affecting field workers — like the location sections above — we'll notify organizations so they can inform their crews.

Contact

Blacktop Labs LLC · support@lotbiddr.com