This policy describes how BAW International Inc. ("BAW," "we") handles personal information in connection with the Helix Field platform, apps, and the helixfielddispatch.com website. It has two parts, because we play two different roles.
What we collect. When a business signs up for Helix Field we collect: account details (name, business name, email, phone, password), business profile (trade/industry, headquarters location), billing details (processed by Stripe, which handles subscription billing for us; we do not store full card numbers), payment processor connection details (the identifier of the Stripe or Square account you connect for collecting your own customers' payments and, for Square, the authorization tokens that let the Service act on that account, which we store encrypted; we never receive your processor password), plan and usage information (features used, seats, log data, device and browser information), support communications, and information you submit through forms on our websites.
How we use it. To provide, secure, support, bill, and improve the Service; to communicate about your account (transactional email and push notifications); to send marketing you can opt out of at any time; to aggregate statistics about the platform (see "Aggregated and deidentified data"); and to comply with law. We use this data because it is necessary to provide the service you asked for, or for our legitimate business operations described here.
We do not sell personal information, and we do not share it for cross context behavioral advertising. This includes both the data we control and the Service Data we process.
Helix Field customers (field service businesses) use the platform to manage their customers and personnel. That data (homeowner names, addresses, phone numbers, email addresses, job and service history, property photos, signatures, invoices, and technician clock, route, and location records) ("Service Data") belongs to and is controlled by the Helix Field customer you do business with, not by BAW. We process it only to operate the platform on that customer's behalf, under our Terms of Service and Data Processing Addendum.
If you are a homeowner or end customer of a business that uses Helix Field: that business decides what is collected and how it is used. Please direct questions, corrections, and deletion requests to them; we support our customers in honoring those requests.
If you pay an invoice from a business that uses Helix Field: you pay on the hosted payment page of the payment processor that business has connected, Stripe or Square. Your card details are entered on that processor's page and never reach BAW systems. Helix Field sends the processor the invoice number, the amount, and the name and email the business has on file for you, and receives payment status back so the business can mark your invoice paid. The processor also handles your payment information for its own purposes, such as fraud prevention, legal compliance, and, in Square's case, digital receipts Square may send you on its own behalf, under its own privacy notice: Stripe's privacy policy or Square's privacy notice for buyers. Questions about a charge, a refund, or a receipt go to the business you paid.
If you are a technician or employee of a Helix Field customer: the app collects job, time clock, photo, signature, and location/route information in connection with your work, for your employer's dispatch, scheduling, and operations purposes. Location is collected in connection with work activity (such as shifts, routes, and jobs), not for BAW's own purposes. Questions about your employer's monitoring practices should go to your employer.
Where a Helix Field customer enables SMS, messages such as appointment reminders are sent by that business to its customers. Message frequency varies; message and data rates may apply; reply STOP to opt out at any time or HELP for help. Text messaging originator opt in data and consent are not shared with or sold to any third party or affiliate for marketing or promotional purposes.
We create aggregated or deidentified data (for example, counts of companies by trade and region, and feature usage statistics) for internal analytics and product improvement. Any statistics we publish are aggregate figures that do not identify any company or individual. We publicly commit to maintain deidentified data in deidentified form, not to attempt to reidentify it except as permitted by law solely to test whether our deidentification process works, and to contractually require the same of any recipient with whom we share it.
We use a small set of vendors to run the platform, each under contract terms limiting their use of data: Amazon Web Services (hosting, storage; United States regions), Stripe (subscription billing for Helix Field, and customer payment collection for businesses that use a Stripe account set up through the Service), Square (customer payment collection, only for businesses that connect their own Square account), Brevo (email delivery), Google Firebase (push notifications), Mapbox and Geocodio (maps and geocoding of service addresses), Intuit QuickBooks Online (accounting sync, only for customers who connect their own QuickBooks account), and, when SMS launches, our SMS delivery provider. Each payment processor handles card details on its own hosted payment page, so full card numbers never reach BAW systems, and each also acts as an independent controller for fraud prevention and its own legal obligations (and, for Square, the digital receipts it sends on its own behalf), as described in Stripe's privacy policy and Square's privacy notice. The current list is maintained at /legal/subprocessors; customers receive advance notice of new subprocessors through the DPA process.
We use encryption in transit (TLS) and at rest, role based access controls, company scoped data isolation, logging, and routine backups, and we limit access to personal information to personnel who need it. No system is perfectly secure, and we do not promise absolute security; we commit to the practices described here and to improving them as we grow.
Service Data export remains available at no charge while an account is suspended for nonpayment and for 30 days after termination.
If we become aware of a security breach affecting Service Data, we will investigate without undue delay and notify the affected customer without undue delay, on the timeline stated in our Data Processing Addendum, with the information they reasonably need to meet their own notification duties; legal notification to individuals belongs to the data's controller. For data we control, we will notify affected individuals and regulators as applicable law requires.
Helix Field is a business service and is not directed to children under 13. We do not knowingly collect personal information from children under 13; if you believe a child has provided us information, contact helixfielddispatch@gmail.com and we will delete it.
Our sites do not currently respond to Do Not Track or Global Privacy Control browser signals. Because we do not sell or share personal information, these signals would not change how we handle your data.
You can access and update account information in the app, opt out of marketing email via the unsubscribe link, and request a copy or deletion of the data we control about you by emailing helixfielddispatch@gmail.com. We honor requests as applicable law requires and will not discriminate against you for making one. Depending on where you live, you may have additional rights under state privacy laws; we respond to all reasonable requests regardless of threshold applicability.
We will post changes here with a new "Last updated" date, and for material changes we will notify account owners by email before the change takes effect.
Contact: helixfielddispatch@gmail.com · BAW International Inc., an Oklahoma corporation · Legal notices by mail: BAW International Inc., c/o Corporation Service Company, registered agent, 10300 Greenbriar Place, Oklahoma City, Oklahoma 73159