Privacy Notice

Updated July 30, 2026

This Privacy Notice explains how Modern Mindset Development, LLC (“Provider,” “we,” “us,” or “our”) collects, uses, discloses, and retains personal information in connection with Lift Office, related websites, mobile or installable components, support, communications, and services (collectively, the “Service”). It also explains the choices and rights that may be available to you. This Service is intended for business use by crane and rigging companies and their authorized personnel, not for personal or consumer use.


  1. Scope and Roles 
  2. Personal Information We Collect
  3. Sources of Personal Information
  4. How We Use Personal Information
  5. Artificial Intelligence and Gemini Processing
  6. How We Disclose Personal Information
  7. Sale, Sharing, Targeted Advertising, and Deidentified Data
  8. Data Security and Shared Responsibilities
  9. Retention, Export, and Deletion
  10. Your Choices and Privacy Rights
  11. International and Cross Border Processing
  12. Children and Age Restrictions
  13. Third-party Services and Links
  14. Changes to This Privacy Notice
  15. Contact Us
  16. Appendix A - Third-Party Terms Referenced


Scope and Roles


1.1 Information We Process for Clients


A Client may submit, create, manage, or direct us to process information about its employees, contractors, customers, vendors, projects, equipment, and operations (“Client Data”). For Client Data, Provider generally acts as a service provider or processor on behalf of the Client. The Client is responsible for providing privacy notices, obtaining legally required consent or authorizations, deciding what information to collect, assigning user access, and responding to individual requests, subject to applicable law and the Client Agreement.


1.2 Information We Use for Our Own Purposes


Provider may act as a controller or business for information used to create and secure accounts, manage the Client relationship, provide support, administer billing contacts, operate and improve the Service, prevent abuse, comply with laws, and communicate about the Service.


1.3 Client Privacy Notices


Your employer or other Client may have its own employee, applicant, customer, vendor, or workforce privacy notice. That notice may apply in addition to this Privacy Notice. Questions about why Client Data is collected or how Client uses it should ordinarily be directed to the Client.


Personal Information We Collect


2.1 Account, Identity, and Administration Information


Name, work email address, work phone number, username, Client organization, department, job title, role, permissions, manager or reporting relationships, and account status;

Password hashes, authentication records, multi-factor authentication information, recovery information, session identifiers, and security events;

Client administrator instructions concerning user enrollment, access changes, suspension, and termination; and

Billing-contact and subscription-administration information for Client representatives.


2.2 Employee, Workforce, and Sensitive Information in Client Data


Depending on Client configuration and use, Client Data may include sensitive personal information. Examples include:

  • employee and contractor names, home addresses, personal or work contact details, employee identifiers, dates of birth, emergency-contact information, and employment records;
  • Social Security numbers, tax identifiers, driver’s-license or other government-identification information;
  • compensation, timekeeping, payroll, deductions, benefits-related fields, bank-account or direct-deposit information, payment-related information, and other financial details;
  • work schedules, site assignments, attendance, time on site, work performed, coworkers scheduled together, approvals, notes, disciplinary or performance-related entries if a Client chooses to enter them; and
  • other information that may be considered sensitive under applicable privacy law.


Clients and users should collect and enter only information necessary for legitimate business purposes. Payment card information should not be stored in the Service unless an expressly designated feature and an approved payment processor are used, and prohibited card authentication data must never be stored.


2.3 Operational, Project, Equipment, and Commercial Information


  • project names, locations, tasks, schedules, work orders, reach sheets, field records, job notes, photographs or attachments, time on site, work completed, and assigned personnel;
  • cranes, rigging, vehicles, tools, equipment identifiers, maintenance or inspection-related records entered by Client, capacities, availability, and resource assignments;
  • customer and vendor names, contacts, addresses, project and contract information, purchase orders, quotes, invoices, billing details, rates, costs, and revenue-related information;
  • Client-configured rules for time, pay, scheduling, billing, approvals, reports, and notifications; and
  • reports, exports, dashboards, purchase orders, messages, and other records generated from Client Data.


2.4 Device, Usage, Log, and Technical Information


IP address, device and browser type, operating system, application version, device identifiers, language, time zone, and approximate location derived from IP address;

login times, session activity, pages and features used, queries, clicks, actions taken, role and permission events, exports, and audit logs;

performance, diagnostic, error, crash, latency, availability, security, fraud, and abuse-prevention information; and

cookies, local storage, tokens, and similar technologies used for authentication, session management, security, preferences, and, if implemented and disclosed, limited analytics.


2.5 Mobile and Field Information


If Client enables a mobile or field feature and you grant device permissions, the Service may process device information, camera or photo content, push notification tokens, timestamps, and approximate or precise location information used for the enabled feature. The Service will request device permission where required. You may change device permissions, although some features may stop working.


2.6 Support and Communications


support tickets, emails, chat messages, call notes, screen-sharing or troubleshooting information, attachments, and feedback;

contact details and preferences for email, text, push, or in-app notifications; and

message content, delivery status, recipient information, and opt-out events for communications sent through the Service.


2.7 AI Inputs, Outputs, and Feedback


Some limited AI-enabled Features may process prompts, instructions, selected Client Data, generated reports or responses, ratings, corrections, and comments. Some AI-enabled Features are designed to provide general guidance without using Client Data; others may use Client Data that a user selects or authorizes for a report or another requested function. Users should not submit sensitive information to an AI-enabled Feature unless the feature expressly requires it and the Client has authorized the processing.


Sources of Personal Information


We may collect personal information from:


  • you, including through account setup, data entry, uploads, mobile features, AI prompts, feedback, support, and communications;
  • the Client, Client administrators, managers, payroll or operations personnel, and other Authorized Users;
  • Client’s customers, vendors, contractors, integration partners, and other people whose information Client directs us to process;
  • devices, browsers, logs, cookies, and Service interactions;
  • Third-Party Services, integrations, authentication providers, communications providers, and security tools; and
  • public or commercially available sources where lawful and relevant to account administration, fraud prevention, or business contacts.


How We Use Personal Information


  • Provide and administer the Service, create Accounts, authenticate users, maintain Client tenants, enforce licenses, and apply role-based permissions.
  • Store, organize, calculate, display, transmit, export, and otherwise process Client Data according to Client instructions.
  • Support project management, resource scheduling, field data capture, timekeeping, operational and financial reporting, purchase-order generation, and Client-configured workflows.
  • Apply Client-configured rules and generate reports, notifications, schedules, and other outputs for Client review.
  • Provide ticket support, troubleshoot issues, assist users in completing functions, respond to requests, and communicate about incidents or changes.
  • Send Client-directed or user-enabled email, text, push, in-app, recurring, and transactional notifications.
  • Secure the Service, prevent unauthorized access and abuse, maintain audit logs, detect fraud, investigate incidents, and enforce agreements.
  • Monitor performance, diagnose errors, maintain availability, plan capacity, test changes, and develop or improve features.
  • Create and use aggregated or deidentified statistics and usage information for lawful business, analytics, security, and improvement purposes.
  • Comply with law, legal process, records obligations, and lawful government requests; establish or defend legal claims; and protect rights, safety, and property.
  • Manage corporate transactions, insurance, audits, financing, and other legitimate business operations.


Artificial Intelligence and Gemini Processing


5.1 How AI-Enabled Features Work


Provider uses Google Gemini as a third-party provider for limited AI-enabled Features. When an AI-enabled Feature is used, the AI Input and relevant context may be transmitted to Google, and Google returns AI Output to the Service. Provider may also process AI Input and AI Output to display results, maintain conversation context or report history, provide support, and comply with Client instructions.


5.2 Paid Gemini Configuration Assumption


Provider configures production AI-enabled Features through a paid Gemini API or other enterprise configuration associated with active Cloud billing. Under Google’s current Gemini API terms for paid services, Google states that it does not use prompts or responses to improve its products, although it may log them for a limited time for abuse prevention and legal or regulatory purposes. Google’s terms, configurations, and practices may change, and Google processes other technical, account, usage, feedback, and security information under its applicable terms and privacy policies.


5.3 Do Not Use Unpaid AI for Client Data


Authorized Users must not route Client Data, confidential information, Social Security numbers, payroll records, financial information, or other sensitive data through unpaid or consumer Gemini services. Google’s current terms state that content submitted to unpaid Gemini services and generated responses may be used to improve Google products and may be reviewed by humans.


5.4 AI Feedback


If an AI Feature asks whether a response was helpful, you may voluntarily submit a rating, correction, or comment. Provider may use the feedback and limited associated context, in deidentified form or as otherwise authorized by Client, to evaluate, test, and improve AI-enabled Features and the Service. Do not include sensitive or confidential information in feedback. Provider will not use identifiable Client Data to train a third-party foundation model without Client’s prior written authorization, except as expressly permitted by the Client Agreement or required by law.


5.5 AI Limitations


AI Output may be inaccurate, incomplete, non-unique, biased, or inappropriate. Provider and Client require human review before AI Output is used for payroll, employment, legal, tax, financial, engineering, safety, customer, or other material decisions. AI-enabled Features are not intended to make solely automated high-impact decisions about individuals.


How We Disclose Personal Information


We may disclose personal information as follows:


  • To the Client and Authorized Users. Information is visible to Client administrators and users according to roles, permissions, assignments, and Client instructions. Client administrators may access account and activity information and may change or terminate access.
  • To Supabase. Supabase is the primary hosting and infrastructure platform for the Service and may process Client Data, account information, authentication information, logs, storage content, and related technical data to provide database, hosting, authentication, storage, backup, and infrastructure services.
  • To Google Gemini. Google and its subprocessors may process AI Input, AI Output, prompts, context, logs, and technical information when AI Features are used.
  • To other service providers. We may use providers for email, SMS, push notifications, support, monitoring, security, error reporting, analytics, billing administration, professional services, and other functions. They receive information reasonably necessary to perform services for us or Client.
  • To Client-designated recipients. At Client direction, the Service may send reports, purchase orders, schedules, notifications, or other information to employees, customers, vendors, or other recipients selected by Client.
  • For legal and safety reasons. We may disclose information to comply with law or legal process; respond to lawful requests; protect rights, safety, and property; investigate fraud or security incidents; and enforce agreements.
  • In a corporate transaction. Information may be disclosed in connection with a financing, merger, acquisition, reorganization, sale of assets, bankruptcy, due diligence, or similar transaction, subject to appropriate safeguards.
  • With consent or direction. We may disclose information when you or Client directs or authorizes us to do so.


Sale, Sharing, Targeted Advertising, and Deidentified Data


Provider does not sell personal information for money, does not share personal information for cross-context behavioral advertising, and does not use Client Data for targeted advertising. Provider may use or disclose aggregated or deidentified information that cannot reasonably be linked to an individual or Client. Where required by law, we will maintain deidentified information in deidentified form and will not attempt to reidentify it except to test deidentification or as otherwise permitted by law.


Data Security and Shared Responsibilities


8.1 Measures Used


Provider uses measures designed to protect personal information, including logical tenant separation, role-based access controls, database row-level security, authentication controls, logging, encryption capabilities provided by hosting providers, vulnerability management, vendor review, access restrictions, and incident-response procedures. Provider relies substantially on Supabase and other service providers for hosting, infrastructure security, availability, backups, and recovery.


8.2 No Absolute Security


No method of storage, transmission, encryption, access control, or backup is completely secure or error-free. We cannot guarantee that unauthorized access, disclosure, alteration, destruction, loss, ransomware, malicious code, insider misuse, credential compromise, or other incidents will never occur. Clients and users are responsible for credential security, endpoint and network security, least-privilege permissions, prompt deprovisioning, data minimization, secure exports, and independent business-continuity practices.


8.3 Security Incidents


We investigate confirmed security incidents and provide notices as required by applicable law and the Client Agreement. If you suspect an incident, contact Client and support@mmdsoftware.com promptly. Do not include unnecessary sensitive information in an initial report.


Retention, Export, and Deletion


9.1 During the Subscription


We retain Client Data in accordance with Client instructions, the Client Agreement, Service configuration, legal requirements, and operational needs. Account, support, security, audit, billing contact, and Usage Data may be retained for the duration of the relationship and for a reasonable period afterward for security, dispute resolution, legal compliance, fraud prevention, and legitimate business records.


9.2 End-of-Subscription Export


When the subscription ends, Provider will offer an authorized Client representative a bulk export of Client Data in Provider’s then-standard, commercially reasonable format. The Client is responsible for requesting, downloading, validating, securing, and retaining the export within the period stated in the Client Agreement or, if none, thirty (30) business days after termination.


9.3 Deletion and Backups


After the retrieval period, Provider may delete or deidentify Client Data from active systems, subject to legal holds, security logs, fraud prevention, dispute records, and other lawful needs. Copies may remain in backups or disaster-recovery systems until overwritten or deleted through ordinary cycles. Deletion from backups may not occur immediately, and restoration of particular data is not guaranteed.


9.4 Client-Directed Retention


The Client may configure or request retention periods and is responsible for determining how long employment, payroll, tax, safety, project, financial, and customer records must be retained. Provider does not provide legal advice about record-retention requirements.


Your Choices and Privacy Rights


10.1 Account and Client Data


You may be able to review or update certain account information in the Service. For corrections to Client Data, access permissions, or employment records, contact the Client administrator. Provider may refer requests regarding Client Data to Client, as Client generally controls and is responsible for that information.


10.2 Notifications and Device Permissions


You may manage available notification preferences in the Service or through Client. You may opt out of text messages using the method provided in the message, where available, but doing so may affect receipt of work-related notifications. You may manage mobile permissions through device settings. Essential administrative, security, legal, and transactional communications may not be optional.


10.3 U.S. State Privacy Rights


Depending on where you live and how the law applies, you may have rights to request access to, correction of, deletion of, or a copy of personal information; to opt out of sale, sharing, targeted advertising, or certain profiling; to limit certain uses of sensitive personal information; and to appeal a decision. These rights may be limited or unavailable for information processed in an employment context, business-to-business context, on behalf of a Client, or under another legal exception.

To exercise a right concerning Provider-controlled information, contact privacy@mmdsoftware.com. To exercise a right concerning Client Data, contact the Client first. We may verify identity and authority and may ask the Client to respond. Authorized agents must provide legally sufficient proof of authority. We will not discriminate against you for exercising applicable rights.


10.4 No Sale or Targeted Advertising Requests


Provider does not currently sell personal information or use Client Data for targeted advertising, so there may be no applicable opt-out to process. If practices change, this Notice and any required preference mechanisms will be updated.


International and Cross-Border Processing


Provider and its service providers may process information in the United States and other countries where they operate. Those countries may have different data-protection laws. Where required, Provider will use contractual or other lawful transfer mechanisms. Client is responsible for selecting available hosting regions and ensuring its instructions and use comply with applicable transfer restrictions, subject to the Client Agreement.


Children and Age Restrictions


The Service is intended for business and Authorized Users aged 18 or older and is not directed to children. We do not knowingly permit individuals under 18 to use AI-enabled Features. If you believe a minor has provided personal information through the Service without authorization, contact privacy@mmdsoftware.com. 


Third-party Services and Links


The Service depends on and may link to Third-Party Services, including Supabase and Google Gemini. Their processing is governed by their own terms and privacy notices. Provider does not control third-party websites or independent practices. Current reference links are included in Appendix A. A third party may change its terms, services, security measures, or processing practices.


Changes to This Privacy Notice


We may update this Privacy Notice to reflect changes in the Service, law, vendors, or practices. We will revise the “Last Updated” date and provide additional notice of material changes when required, such as through the Service, by email, or through renewed acknowledgment. The version in effect when the information is processed will apply, subject to applicable law.


Contact Us

Modern Mindset Development, LLC

Attn: Privacy
5801 W Dillon Wash Rd., Prescott, AZ 86305
privacy@mmdsoftware.com

928-224-5915


Appendix A - Third-Party Terms Referenced


Any links to third-party documents or resources are provided solely for convenience and informational transparency. Such documents and resources are maintained and controlled by the applicable third parties and may be modified, replaced, or discontinued at any time without notice. Provider has no obligation to monitor, verify, update, or ensure the continued availability, accuracy, or completeness of any linked material.


These links are provided for transparency and should be reviewed periodically. Third-party terms and policies may change independently of this Privacy Notice.


Supabase Privacy Policy - https://supabase.com/privacy

Supabase Terms of Service - https://supabase.com/terms

Supabase Data Processing Addendum - https://supabase.com/legal/dpa

Supabase Security Information - https://supabase.com/security

Supabase Service Level Agreements - https://supabase.com/sla

Gemini API Additional Terms of Service - https://ai.google.dev/gemini-api/terms

Google APIs Terms of Service - https://developers.google.com/terms

Google Generative AI Prohibited Use Policy - https://policies.google.com/terms/generative-ai/use-policy

Google Privacy Policy - https://policies.google.com/privacy

Google Data Processing Addendum for Products Where Google Is a Data Processor - https://business.safety.google/processorterms/