Privacy Notice
Updated July 30, 2026
This Privacy Notice explains how Modern Mindset Development, LLC (“Provider,” “we,” “us,” or “our”) collects, uses, discloses, and retains personal information in connection with Lift Office, related websites, mobile or installable components, support, communications, and services (collectively, the “Service”). It also explains the choices and rights that may be available to you. This Service is intended for business use by crane and rigging companies and their authorized personnel, not for personal or consumer use.
- Scope and Roles
- Personal Information We Collect
- Sources of Personal Information
- How We Use Personal Information
- Artificial Intelligence and Gemini Processing
- How We Disclose Personal Information
- Sale, Sharing, Targeted Advertising, and Deidentified Data
- Data Security and Shared Responsibilities
- Retention, Export, and Deletion
- Your Choices and Privacy Rights
- International and Cross Border Processing
- Children and Age Restrictions
- Third-party Services and Links
- Changes to This Privacy Notice
- Contact Us
- Appendix A - Third-Party Terms Referenced
Scope and Roles
1.1 Information We Process for Clients
A Client may submit, create, manage, or direct us to process information about its employees, contractors, customers, vendors, projects, equipment, and operations (“Client Data”). For Client Data, Provider generally acts as a service provider or processor on behalf of the Client. The Client is responsible for providing privacy notices, obtaining legally required consent or authorizations, deciding what information to collect, assigning user access, and responding to individual requests, subject to applicable law and the Client Agreement.
1.2 Information We Use for Our Own Purposes
Provider may act as a controller or business for information used to create and secure accounts, manage the Client relationship, provide support, administer billing contacts, operate and improve the Service, prevent abuse, comply with laws, and communicate about the Service.
1.3 Client Privacy Notices
Your employer or other Client may have its own employee, applicant, customer, vendor, or workforce privacy notice. That notice may apply in addition to this Privacy Notice. Questions about why Client Data is collected or how Client uses it should ordinarily be directed to the Client.
Personal Information We Collect
2.1 Account, Identity, and Administration Information
Name, work email address, work phone number, username, Client organization, department, job title, role, permissions, manager or reporting relationships, and account status;
Password hashes, authentication records, multi-factor authentication information, recovery information, session identifiers, and security events;
Client administrator instructions concerning user enrollment, access changes, suspension, and termination; and
Billing-contact and subscription-administration information for Client representatives.
2.2 Employee, Workforce, and Sensitive Information in Client Data
Depending on Client configuration and use, Client Data may include sensitive personal information. Examples include:
- employee and contractor names, home addresses, personal or work contact details, employee identifiers, dates of birth, emergency-contact information, and employment records;
- Social Security numbers, tax identifiers, driver’s-license or other government-identification information;
- compensation, timekeeping, payroll, deductions, benefits-related fields, bank-account or direct-deposit information, payment-related information, and other financial details;
- work schedules, site assignments, attendance, time on site, work performed, coworkers scheduled together, approvals, notes, disciplinary or performance-related entries if a Client chooses to enter them; and
- other information that may be considered sensitive under applicable privacy law.
Clients and users should collect and enter only information necessary for legitimate business purposes. Payment card information should not be stored in the Service unless an expressly designated feature and an approved payment processor are used, and prohibited card authentication data must never be stored.
2.3 Operational, Project, Equipment, and Commercial Information
- project names, locations, tasks, schedules, work orders, reach sheets, field records, job notes, photographs or attachments, time on site, work completed, and assigned personnel;
- cranes, rigging, vehicles, tools, equipment identifiers, maintenance or inspection-related records entered by Client, capacities, availability, and resource assignments;
- customer and vendor names, contacts, addresses, project and contract information, purchase orders, quotes, invoices, billing details, rates, costs, and revenue-related information;
- Client-configured rules for time, pay, scheduling, billing, approvals, reports, and notifications; and
- reports, exports, dashboards, purchase orders, messages, and other records generated from Client Data.
2.4 Device, Usage, Log, and Technical Information
IP address, device and browser type, operating system, application version, device identifiers, language, time zone, and approximate location derived from IP address;
login times, session activity, pages and features used, queries, clicks, actions taken, role and permission events, exports, and audit logs;
performance, diagnostic, error, crash, latency, availability, security, fraud, and abuse-prevention information; and
cookies, local storage, tokens, and similar technologies used for authentication, session management, security, preferences, and, if implemented and disclosed, limited analytics.
2.5 Mobile and Field Information
If Client enables a mobile or field feature and you grant device permissions, the Service may process device information, camera or photo content, push notification tokens, timestamps, and approximate or precise location information used for the enabled feature. The Service will request device permission where required. You may change device permissions, although some features may stop working.
2.6 Support and Communications
support tickets, emails, chat messages, call notes, screen-sharing or troubleshooting information, attachments, and feedback;
contact details and preferences for email, text, push, or in-app notifications; and
message content, delivery status, recipient information, and opt-out events for communications sent through the Service.
2.7 AI Inputs, Outputs, and Feedback
Some limited AI-enabled Features may process prompts, instructions, selected Client Data, generated reports or responses, ratings, corrections, and comments. Some AI-enabled Features are designed to provide general guidance without using Client Data; others may use Client Data that a user selects or authorizes for a report or another requested function. Users should not submit sensitive information to an AI-enabled Feature unless the feature expressly requires it and the Client has authorized the processing.
Sources of Personal Information
We may collect personal information from:
- you, including through account setup, data entry, uploads, mobile features, AI prompts, feedback, support, and communications;
- the Client, Client administrators, managers, payroll or operations personnel, and other Authorized Users;
- Client’s customers, vendors, contractors, integration partners, and other people whose information Client directs us to process;
- devices, browsers, logs, cookies, and Service interactions;
- Third-Party Services, integrations, authentication providers, communications providers, and security tools; and
- public or commercially available sources where lawful and relevant to account administration, fraud prevention, or business contacts.
How We Use Personal Information
- Provide and administer the Service, create Accounts, authenticate users, maintain Client tenants, enforce licenses, and apply role-based permissions.
- Store, organize, calculate, display, transmit, export, and otherwise process Client Data according to Client instructions.
- Support project management, resource scheduling, field data capture, timekeeping, operational and financial reporting, purchase-order generation, and Client-configured workflows.
- Apply Client-configured rules and generate reports, notifications, schedules, and other outputs for Client review.
- Provide ticket support, troubleshoot issues, assist users in completing functions, respond to requests, and communicate about incidents or changes.
- Send Client-directed or user-enabled email, text, push, in-app, recurring, and transactional notifications.
- Secure the Service, prevent unauthorized access and abuse, maintain audit logs, detect fraud, investigate incidents, and enforce agreements.
- Monitor performance, diagnose errors, maintain availability, plan capacity, test changes, and develop or improve features.
- Create and use aggregated or deidentified statistics and usage information for lawful business, analytics, security, and improvement purposes.
- Comply with law, legal process, records obligations, and lawful government requests; establish or defend legal claims; and protect rights, safety, and property.
- Manage corporate transactions, insurance, audits, financing, and other legitimate business operations.
Artificial Intelligence and Gemini Processing
5.1 How AI-Enabled Features Work
Provider uses Google Gemini as a third-party provider for limited AI-enabled Features. When an AI-enabled Feature is used, the AI Input and relevant context may be transmitted to Google, and Google returns AI Output to the Service. Provider may also process AI Input and AI Output to display results, maintain conversation context or report history, provide support, and comply with Client instructions.
5.2 Paid Gemini Configuration Assumption
Provider configures production AI-enabled Features through a paid Gemini API or other enterprise configuration associated with active Cloud billing. Under Google’s current Gemini API terms for paid services, Google states that it does not use prompts or responses to improve its products, although it may log them for a limited time for abuse prevention and legal or regulatory purposes. Google’s terms, configurations, and practices may change, and Google processes other technical, account, usage, feedback, and security information under its applicable terms and privacy policies.
5.3 Do Not Use Unpaid AI for Client Data
Authorized Users must not route Client Data, confidential information, Social Security numbers, payroll records, financial information, or other sensitive data through unpaid or consumer Gemini services. Google’s current terms state that content submitted to unpaid Gemini services and generated responses may be used to improve Google products and may be reviewed by humans.
5.4 AI Feedback
If an AI Feature asks whether a response was helpful, you may voluntarily submit a rating, correction, or comment. Provider may use the feedback and limited associated context, in deidentified form or as otherwise authorized by Client, to evaluate, test, and improve AI-enabled Features and the Service. Do not include sensitive or confidential information in feedback. Provider will not use identifiable Client Data to train a third-party foundation model without Client’s prior written authorization, except as expressly permitted by the Client Agreement or required by law.
5.5 AI Limitations
AI Output may be inaccurate, incomplete, non-unique, biased, or inappropriate. Provider and Client require human review before AI Output is used for payroll, employment, legal, tax, financial, engineering, safety, customer, or other material decisions. AI-enabled Features are not intended to make solely automated high-impact decisions about individuals.
How We Disclose Personal Information
We may disclose personal information as follows:
- To the Client and Authorized Users. Information is visible to Client administrators and users according to roles, permissions, assignments, and Client instructions. Client administrators may access account and activity information and may change or terminate access.
- To Supabase. Supabase is the primary hosting and infrastructure platform for the Service and may process Client Data, account information, authentication information, logs, storage content, and related technical data to provide database, hosting, authentication, storage, backup, and infrastructure services.
- To Google Gemini. Google and its subprocessors may process AI Input, AI Output, prompts, context, logs, and technical information when AI Features are used.
- To other service providers. We may use providers for email, SMS, push notifications, support, monitoring, security, error reporting, analytics, billing administration, professional services, and other functions. They receive information reasonably necessary to perform services for us or Client.
- To Client-designated recipients. At Client direction, the Service may send reports, purchase orders, schedules, notifications, or other information to employees, customers, vendors, or other recipients selected by Client.
- For legal and safety reasons. We may disclose information to comply with law or legal process; respond to lawful requests; protect rights, safety, and property; investigate fraud or security incidents; and enforce agreements.
- In a corporate transaction. Information may be disclosed in connection with a financing, merger, acquisition, reorganization, sale of assets, bankruptcy, due diligence, or similar transaction, subject to appropriate safeguards.
- With consent or direction. We may disclose information when you or Client directs or authorizes us to do so.
Sale, Sharing, Targeted Advertising, and Deidentified Data
Provider does not sell personal information for money, does not share personal information for cross-context behavioral advertising, and does not use Client Data for targeted advertising. Provider may use or disclose aggregated or deidentified information that cannot reasonably be linked to an individual or Client. Where required by law, we will maintain deidentified information in deidentified form and will not attempt to reidentify it except to test deidentification or as otherwise permitted by law.
Data Security and Shared Responsibilities
8.1 Measures Used
Provider uses measures designed to protect personal information, including logical tenant separation, role-based access controls, database row-level security, authentication controls, logging, encryption capabilities provided by hosting providers, vulnerability management, vendor review, access restrictions, and incident-response procedures. Provider relies substantially on Supabase and other service providers for hosting, infrastructure security, availability, backups, and recovery.
8.2 No Absolute Security
No method of storage, transmission, encryption, access control, or backup is completely secure or error-free. We cannot guarantee that unauthorized access, disclosure, alteration, destruction, loss, ransomware, malicious code, insider misuse, credential compromise, or other incidents will never occur. Clients and users are responsible for credential security, endpoint and network security, least-privilege permissions, prompt deprovisioning, data minimization, secure exports, and independent business-continuity practices.
8.3 Security Incidents
We investigate confirmed security incidents and provide notices as required by applicable law and the Client Agreement. If you suspect an incident, contact Client and support@mmdsoftware.com promptly. Do not include unnecessary sensitive information in an initial report.
Retention, Export, and Deletion
9.1 During the Subscription
We retain Client Data in accordance with Client instructions, the Client Agreement, Service configuration, legal requirements, and operational needs. Account, support, security, audit, billing contact, and Usage Data may be retained for the duration of the relationship and for a reasonable period afterward for security, dispute resolution, legal compliance, fraud prevention, and legitimate business records.
9.2 End-of-Subscription Export
When the subscription ends, Provider will offer an authorized Client representative a bulk export of Client Data in Provider’s then-standard, commercially reasonable format. The Client is responsible for requesting, downloading, validating, securing, and retaining the export within the period stated in the Client Agreement or, if none, thirty (30) business days after termination.
9.3 Deletion and Backups
After the retrieval period, Provider may delete or deidentify Client Data from active systems, subject to legal holds, security logs, fraud prevention, dispute records, and other lawful needs. Copies may remain in backups or disaster-recovery systems until overwritten or deleted through ordinary cycles. Deletion from backups may not occur immediately, and restoration of particular data is not guaranteed.
9.4 Client-Directed Retention
The Client may configure or request retention periods and is responsible for determining how long employment, payroll, tax, safety, project, financial, and customer records must be retained. Provider does not provide legal advice about record-retention requirements.
Your Choices and Privacy Rights
10.1 Account and Client Data
You may be able to review or update certain account information in the Service. For corrections to Client Data, access permissions, or employment records, contact the Client administrator. Provider may refer requests regarding Client Data to Client, as Client generally controls and is responsible for that information.
10.2 Notifications and Device Permissions
You may manage available notification preferences in the Service or through Client. You may opt out of text messages using the method provided in the message, where available, but doing so may affect receipt of work-related notifications. You may manage mobile permissions through device settings. Essential administrative, security, legal, and transactional communications may not be optional.
10.3 U.S. State Privacy Rights
Depending on where you live and how the law applies, you may have rights to request access to, correction of, deletion of, or a copy of personal information; to opt out of sale, sharing, targeted advertising, or certain profiling; to limit certain uses of sensitive personal information; and to appeal a decision. These rights may be limited or unavailable for information processed in an employment context, business-to-business context, on behalf of a Client, or under another legal exception.
To exercise a right concerning Provider-controlled information, contact privacy@mmdsoftware.com. To exercise a right concerning Client Data, contact the Client first. We may verify identity and authority and may ask the Client to respond. Authorized agents must provide legally sufficient proof of authority. We will not discriminate against you for exercising applicable rights.
10.4 No Sale or Targeted Advertising Requests
Provider does not currently sell personal information or use Client Data for targeted advertising, so there may be no applicable opt-out to process. If practices change, this Notice and any required preference mechanisms will be updated.
International and Cross-Border Processing
Provider and its service providers may process information in the United States and other countries where they operate. Those countries may have different data-protection laws. Where required, Provider will use contractual or other lawful transfer mechanisms. Client is responsible for selecting available hosting regions and ensuring its instructions and use comply with applicable transfer restrictions, subject to the Client Agreement.
Children and Age Restrictions
The Service is intended for business and Authorized Users aged 18 or older and is not directed to children. We do not knowingly permit individuals under 18 to use AI-enabled Features. If you believe a minor has provided personal information through the Service without authorization, contact privacy@mmdsoftware.com.
Third-party Services and Links
The Service depends on and may link to Third-Party Services, including Supabase and Google Gemini. Their processing is governed by their own terms and privacy notices. Provider does not control third-party websites or independent practices. Current reference links are included in Appendix A. A third party may change its terms, services, security measures, or processing practices.
Changes to This Privacy Notice
We may update this Privacy Notice to reflect changes in the Service, law, vendors, or practices. We will revise the “Last Updated” date and provide additional notice of material changes when required, such as through the Service, by email, or through renewed acknowledgment. The version in effect when the information is processed will apply, subject to applicable law.
Contact Us
Modern Mindset Development, LLC
Attn: Privacy
5801 W Dillon Wash Rd., Prescott, AZ 86305
privacy@mmdsoftware.com
928-224-5915
Appendix A - Third-Party Terms Referenced
Any links to third-party documents or resources are provided solely for convenience and informational transparency. Such documents and resources are maintained and controlled by the applicable third parties and may be modified, replaced, or discontinued at any time without notice. Provider has no obligation to monitor, verify, update, or ensure the continued availability, accuracy, or completeness of any linked material.
These links are provided for transparency and should be reviewed periodically. Third-party terms and policies may change independently of this Privacy Notice.
Supabase Privacy Policy - https://supabase.com/privacy
Supabase Terms of Service - https://supabase.com/terms
Supabase Data Processing Addendum - https://supabase.com/legal/dpa
Supabase Security Information - https://supabase.com/security
Supabase Service Level Agreements - https://supabase.com/sla
Gemini API Additional Terms of Service - https://ai.google.dev/gemini-api/terms
Google APIs Terms of Service - https://developers.google.com/terms
Google Generative AI Prohibited Use Policy - https://policies.google.com/terms/generative-ai/use-policy
Google Privacy Policy - https://policies.google.com/privacy
Google Data Processing Addendum for Products Where Google Is a Data Processor - https://business.safety.google/processorterms/

