MS Rollout (the Android app, the web portal at app.msrollout.com and this website, msrollout.com) is provided by Marc Robitaille, doing business as MS Rollout ("we," "us"). This page says what we collect, why, who sees it, how long we keep it, and what you can ask us to do with it.
The short version
- We keep what your company puts in MS Rollout so it is on every phone and in the portal of your company, and we use it only to run the service.
- While signed in, a phone shares its latest position with its company at each sync, also from the check every 15 minutes with the app closed, and, while a dispatch is open, every 3 minutes or 50 m, screen off too (every 10 minutes or 100 m once it has not moved for about 10 minutes). The server keeps only each person's latest position. Positions are also saved with visits, photos and clock-ins, as proof.
- Chat messages, photos and voice messages are deleted after 14 days.
- Payments are handled by Paddle; card details never reach our servers.
- When a company takes payments of its invoices online, its customers pay through Stripe, into the company's own Stripe account; card and bank details never reach our servers.
- We do not sell your data or share it for advertising, and this website has no cookies or trackers. News and offers by email only if you tick the box, and you can stop them with one click.
- You can ask to see, correct, export or delete your data.
Who is responsible
For the accounts of companies and their people, billing, this website and its contact form, we decide how personal data is used: we are the "controller" (or "business").
The records a contractor keeps in MS Rollout about its own customers and workers (customer names and addresses, quotes, visits, photos, hours, positions, messages) belong to that contractor. For those, the contractor is the controller, and we handle them on its behalf, only to provide the service and as it instructs (we are its "processor" or "service provider"). If you are a customer or a worker of a company that uses MS Rollout, the best first contact about your data is that company; we will help it answer you.
What we collect
Accounts and sign-in
For each company: its name, a company number and its settings. For each person: name, email address (a manager may create a person without one), role (worker, crew chief, estimator, manager or support crew), a job title if a manager gives one (Mechanic, Office...), a person number (U01, U02...), and a password, stored only as a salted hash, never as written. We also keep when the account was made and last used. For each phone or browser signed in: a sign-in token, when it signed in and was last used, the IP address it last came from, and a short description of the device taken from what the app or browser says about itself (for example "Chrome on Windows" or "MS Rollout app (Android)"). For each device or browser a person has signed in with, a one-way fingerprint of its random code, so we can tell when a new one signs in. After "Forgot password", a temporary password (as a salted hash) for one hour; after asking to change an email address, the new address until its confirmation link is opened (48 hours). Invitation codes made by a manager work for 7 days. A manager may make API keys (to let other tools read the company's records): we keep each key's name, a one-way fingerprint of it (the key itself is shown once and never stored), and when it was made, last used and removed.
Company records
What your company enters or records: company details and settings (logo, prices, taxes, privileges, quote terms), customers and their contact details, sites and addresses, drawings and measurements, estimates and quotes, price changes, job sheets, dispatches, visits with their start and end, delays and notes, punch clock hours with the history of each change (who changed what, and when), pay information if the company uses Pay (pay rates, pay period, overtime rules, fixed hours, time off, bonuses, reimbursements and deductions, payroll numbers, approved pay runs and payslips), and the messages sent to customers. The app also adds to each change a random code it makes for the phone, so the server does not send a phone its own changes back. It also includes the company's equipment (costs per hour, services done, equipment used on visits), and the budgets and extra costs of jobs for job costing.
Labor costs
For job costing, a manager may enter a cost per hour for the company and for each person (when the company uses Pay, the person's hourly pay rate is used instead), and a percentage for employer costs. They are kept on our server, shown only to the company's managers, and never sent to the phones.
Invoices, payments and contracts
The invoices, credit notes and service contracts a company makes: their numbers, customer name, email and billing address, lines, taxes, amounts, dates, notes and terms; the payments recorded on them (amount, how it was paid, reference, date); when each was sent, opened by the customer (with the IP address it came from), reminded, paid or voided, and who did it. When a customer signs a contract online we keep the name they typed, their signature (a picture), the time and the IP address, as the record of the signature.
Online payments of invoices (Stripe)
A company may connect its own Stripe account to take card and bank payments of its invoices. Stripe then collects the payment details under its own privacy policy, and the money goes to the company's account; card numbers and bank account numbers never reach our servers. We send Stripe the invoice's number, amount and currency, the customer's email address and a reference to the company and the customer; when the company connects, its name, country and the manager's email address. We receive from Stripe what we need to show the payment: its identifiers, amount, status, refunds, the payment method's kind, brand and last 4 digits and expiry (for a card kept on file for automatic payments), and whether the company's Stripe account can take payments.
QuickBooks Online
A company may connect its QuickBooks Online company. We then send it the company's customers (name, email, phone, address), its invoices, credit notes and payments, and read back the payments entered in QuickBooks on those invoices and the customers' email, phone and address. We keep the link between each record and its QuickBooks copy, a log of what was sent and read, and the connection's access keys, encrypted.
Customer page and website form
A company's customers can open a customer page with a sign-in link sent to the email address the company has for them (no password). We keep the link (30 minutes, used once) and the sign-in (30 days), with the email address and when it was last used. There they see only their own quotes, invoices, visits with their photos and times, and contracts; they can ask for work and change their phone, contact name and address, which updates the company's records. A company can also put a request form on its own website: what the person types (name, email, phone, address, the work wanted, dates) goes to the company as a quote request; the form uses a small sum and limits per IP address against robots.
Positions (GPS)
- During a dispatch, screen off too. When a dispatch is open, the person is signed in and has allowed location "all the time," the app runs a position service, shown by the notification Android requires. It takes a position after about 50 m of movement and at least every 3 minutes. When the phone has not moved for about 10 minutes, it slows to one every 10 minutes or 100 m, and goes back to the normal pace as soon as the phone moves. It uses medium accuracy (a phone network or Wi-Fi fix when good enough, to save battery; readings vaguer than 300 m are ignored) and sends each position to our server. It stops when the last open dispatch is closed, or when the person signs out or taps Exit on the map.
- At each sync, always while signed in. Each sync with the server includes the phone's current position, with or without a dispatch: about every 2 minutes and soon after changes while the app is open, and from the background check about every 15 minutes while the app is closed. Signing out, or Exit on the map, stops it.
- After the phone restarts (Android). If the position service was running (a dispatch open), it starts again by itself, and so does the check every 15 minutes; the service stops by itself if no dispatch is open any more. A switch in the app's Settings, "Start on boot", turns this off; it is on unless the person turns it off. When it is off, nothing runs until the app is opened.
- What the server keeps. Only the latest position of each person, with its time and crew name: each new one replaces the one before, so the server keeps no trail. The people of the company allowed to see the map, in the app and in the portal, see it. While a company's plan has ended, positions are not saved. A manager may hide their own position from everyone or from chosen people (Settings in the app, Account in the portal); MS Rollout staff still see it, for support.
- Positions saved with records. Clocking in and out saves the position and its accuracy with the shift; visits save where they started and ended, with accuracy; photos taken in the app save where and when they were taken. These are part of the company's records, as proof of service and of hours. A crew chief clocking in or out someone of their crew saves no position.
- Positions that stay on the phone. The clock reminders ("Forgot to clock out?", "Still working?", "Not clocked in") look at the phone's position on the phone only; it is not sent for them. The same for the automatic job clock's suggestions, when a company turns them on ("You are at a site: clock in?", "You left a site: end this job?"): the phone compares the positions of the dispatch's position service with the dispatch's sites on the phone; nothing more is sent, and nothing changes unless the person taps yes. On iPhones, the phone also asks iOS to watch the next stops of the dispatch (region monitoring, on the phone only), so it can ask with the phone at rest.
Location is used only with the permission given in Android, which can be changed or removed at any time in the phone's settings; without it, the map, dispatch and proof of service work only in part.
Photos and signatures
Photos taken before and after the work at a visit, with the time and position where they were taken; photos added to estimates; the company logo. When a customer accepts a quote on a phone, the name they type and their signature (a picture) are saved with the quote; a signed paper quote can also be scanned with the phone's camera.
Profile photo
A person may add a photo of themselves in the app or the web portal, and a manager may add or remove anyone's in the portal or the app. It is shown, with their first name, on the company's maps, in chat and in lists of people, only to the people of the same company. It is deleted when it is replaced or removed, when the person is removed, and with the company.
Chat
Text, photos and voice messages between people of the same company, messages to everyone in the company, and conversations between a company's managers and MS Rollout support.
Emails
- To people with an account: the sign-up confirmation link, a notice when someone tries to sign up with an address that already has an account, free trial and free access reminders (14 and 3 days before the end), plan cancelled or ended, deletion warnings, seats ended, and quote acceptances; and, for the security of the account, a notice when it is signed in on a new device (with the time, device and IP address), a temporary password when asked for with "Forgot password", a notice when the password is changed, and, for an email change, a confirmation link to the new address and a notice to the old one; to managers, payments received or failed, contracts signed, declined or ending, and new quote requests from the customer page or the website form.
- To your customers, on your company's behalf: "on my way" and "job done" messages (with the after photos chosen), quote links, and the confirmation of an accepted quote with its PDF; invoices and credit notes with their PDF and link, payment reminders on the days your company chooses, payment receipts, contracts to sign and their signed copy, follow-ups of quotes not answered (when your company turns them on), and sign-in links to the customer page. They are sent from our mail server under your company's name, and replies go to your company's email address. A quote can also be sent from the email app on your phone, which then sends it, not us. Your company may also send requests for a review, with the review link it set. The day of a scheduled job (with a link to cancel it) and the confirmation of a cancellation are sent too. Replies go to the address your company chose for each kind of email, and your company may receive its own copy of them.
- News and offers from MS Rollout: only to people who ticked "Send me news and offers from MS Rollout by email" (at sign-up in the app, or in the portal's Settings). Each one has a link to stop them at once. To count how many are read, each holds a small picture with a code unique to that email; when the picture is loaded, we note the time it was first opened. Turning off pictures in your email app stops this.
- Service messages from MS Rollout about your account or the service (for example a planned maintenance), to the managers of the companies concerned.
A copy of each email we send (address, subject, text, and whether it went out) is kept 90 days, to check delivery and send it again if needed; an email that could not be sent is deleted 90 days after it was written. A temporary password is removed from the copy as soon as the email has gone out. Offers and other promotional emails go only to people who agreed to receive them, never as a service email.
Notices and messages from MS Rollout
We may show a notice in the app and the portal, or send a chat message from "MS Rollout", to all companies or to some of them (by plan, role or person). We note for each person whether a notice was shown and closed, so it is not shown again.
Problem reports, feature requests and support
With "Report a problem" in the app or portal, you send us your text, a screenshot if you add one, the page or screen you were on, the app version and device, and the last error messages the app or portal noted. Feature requests from managers keep their text, pictures and our replies. When a support message is in another language, and only if we turn on our translator, its text is sent to a translation service (LibreTranslate, or Anthropic's Claude) to be translated; the translation is kept 180 days.
Online quote approvals
When a customer opens a quote link, we note when it was opened and the IP address it came from. When they accept or decline, we keep their answer, the name they typed, their signature, any note, the time and the IP address, as the record of the approval.
Job cancellations
Emails about an accepted quote or a scheduled job can carry a link to cancel the job. When a customer cancels on that page, we keep when they opened it and cancelled, the IP address it came from, the name and the reason they typed, and the cancellation fee if one applied, as the record of the cancellation. The company sees it with the job, and it is kept with the company's records.
Unpaid invoices and collection agencies
A company may hand an unpaid invoice to a collection agency it chooses. We then keep the agency's name, email and phone, its reference, the date and the amount. If the company asks us to, we email the agency a collections package: the invoice, a statement of the customer's account (invoices, payments and reminders sent), the customer's contact details and the quote they signed. The company decides this, as the one responsible for its customers' data, and confirms it with its password; the agency then handles that data under its own terms. Settlements agreed with a customer and invoices written off are kept with the invoices.
Free trial
To give each email address one free trial, when a company is deleted we keep a one-way fingerprint (a keyed hash) of its managers' email addresses. The address cannot be read back from it; it is used only to check whether a new sign-up with the same address has had a free trial.
Payments
Subscriptions are sold through Paddle.com, our reseller and Merchant of Record. Paddle collects the payment details, billing name and address and tax details under its own privacy policy; card numbers never reach our servers. We send Paddle the manager's email address (to fill in the checkout), the plan and number of seats, and a reference to the company. We receive from Paddle what we need to run the subscription: its identifiers, plan, seats, prices, status and billing period, and its payments, refunds and chargebacks. Invoices and the card on file are on Paddle's customer page, not with us.
This website and its contact form
This website uses no cookies, no analytics or advertising tools, and loads nothing from other sites. To count visits, our server reads its own web log: pages seen, the site a visitor came from, the kind of device, and the visitor's country. The country is worked out from the IP address on our own server when the visit is counted, with a free country database we keep there (from DB-IP.com), so no outside service is asked; only the country is kept, not the IP address. A visitor is counted once a day through a one-way fingerprint of the IP address and browser, made with a key that changes every day and is deleted after 2 days; no IP address is kept in these counts. The contact form sends us your name, email address, company (if given), trade and message; we keep it, with the IP address it came from (to spot abuse), and it also reaches our support mailbox. You receive a short receipt by email. A small sum to solve, a hidden box that robots fill in, and limits per address and per email keep robots out; no outside service is used for this.
Technical data
- Activity log. Sign-ins (including wrong passwords), password changes, resets and temporary passwords, people added, renamed, removed or restored, role changes, email changes and sign-outs, each with its time, the person, who did it, the IP address and the device. Kept 12 months and shown to the company's managers, to keep accounts secure. API keys made or removed are logged too.
- Logs. Our web servers log each request (IP address, time, page or file asked for, browser or app details). The MS Rollout server also logs events such as sign-ups, refused sign-ins, people added or removed, syncs, emails sent and errors, with the email address or name and, for sign-ups and contact messages, the IP address. Logs are used to keep the service running and secure, and are kept 30 days.
- Limits against abuse. Counts of sign-ups, wrong passwords, password resets, invitation codes, contact messages, customer page sign-in links, website form requests and payment page openings per IP address, per email address or per account are kept in our database for up to 24 hours, then deleted.
- Devices. With each request, the app sends its version, build, the Android version, the phone model and a random code made for the installation. We keep, for each phone, these details, when it was first and last seen, and how many requests it made, to help when something goes wrong.
- App health. About once an hour, the app sends counts: syncs that worked or failed, changes waiting to be sent, positions found or not found, minutes the app was open, map pictures loaded, how many positions the position service took and how many minutes it ran, and the last error message. No positions or records are in it. Kept 30 days.
- Request log per person. For each person, the server keeps a list of their last 300 requests (time, what was asked, the answer's code, size and time taken, the app or browser) for at most 14 days, to find problems. Only when we look into a problem for a person, and for at most one hour, it also keeps what was sent and answered, with passwords, codes and keys blanked out.
- Updates. On Android, the app reads a small file on msrollout.com to see if a newer version is out: when it starts, when it comes back on the screen (at most once an hour), every 4 hours while it stays open, and when you tap "Check for updates". It downloads a newer version from msrollout.com when you choose to install it. No app store is involved.
On the phone and in the browser
- The app keeps the company's records, photos and the map pictures already seen on the phone, so it works without signal. Signing out clears the chat and the people's photos from the phone; the records stay on it until the app is uninstalled or its data is cleared, and are removed from the phone before anyone signs in there to another company (the app asks first). Its notifications (new dispatch, new message, clock reminders, update, the position service) are made on the phone; no push service is used.
- The web portal uses no cookies. It keeps in the browser's local storage the sign-in token and who is signed in (both removed when you sign out), changes not yet sent to the server, and your choices (light or dark, chat sound, list views, messages already seen). Its device code for syncing is new at each page load and is not stored; a separate random code for the browser is kept so the server can tell a browser it has seen before at sign-in.
Why we use it
Only to provide and protect the service: sync each company's records between phones and the portal; show where crews are; produce quotes, job sheets, proof of service, hours and exports; send the emails described above; run subscriptions and free trials; keep accounts secure and prevent abuse; answer support and contact messages; and meet legal obligations (for example tax and accounting records).
Where the GDPR or similar laws apply, our legal bases are: the contract with the company and its people (running the service); our legitimate interests in keeping the service secure, preventing abuse and repeat free trials, and answering messages; legal obligations; and consent where the law requires it (location and notification permissions on the phone, which can be withdrawn at any time).
Who sees it
- Your company. The people of a company see its records according to their role and the privileges set by its managers; managers see the most, including positions, hours and people, the devices each person is signed in on (device, IP address, last used) and the activity log. Pay is kept apart from the records the phones share: only managers and people a manager gives the Pay privilege see it, and each person sees only their own pay and payslips in the app.
- Your customers see the quotes, invoices, contracts, messages and photos your company sends them, and on the customer page their own visits with their photos and times; never another customer's records.
- MS Rollout staff see, in our operations console, the list of companies and their people (names, email addresses, roles, when last active), people's latest positions, plans and billing, the server log, the devices, app health and request logs described above, problem reports, feature requests, and support conversations. To help a company, staff can open its portal read-only as its manager, for 30 minutes at most, with a banner showing it. Every action staff take in the operations console is written in a log kept 24 months. We look at company data only to give support, find and fix problems, keep the service secure, or when the law requires it.
- Service providers listed below, only for what they do for us.
- Authorities, only when the law requires it.
Service providers and outside services
- OVHcloud hosts our servers (the MS Rollout server with its data and photos, the web portal, this website and our mail server) in OVHcloud's data center in Montréal, Quebec, Canada.
- Our own mail server sends every email; the recipient's email provider then receives it.
- LibreTranslate or Anthropic (Claude): only if we turn on our support translator, the text of support messages and feature requests in another language, to translate it.
- Paddle.com: reseller and Merchant of Record for payments (see Payments). Its checkout code (cdn.paddle.com) and window (buy.paddle.com) load in the portal only on the Billing page.
- Stripe: online payments of the companies' invoices, only for companies that connect their own Stripe account (see Online payments of invoices). Customers pay on Stripe's pages.
- Intuit (QuickBooks Online): only for companies that connect their QuickBooks company (see QuickBooks Online).
To show maps and find places, the app and the portal call some public services directly. Like any website, they see the device's IP address, and each works under its own privacy policy:
- Esri (ArcGIS): satellite pictures and street maps, in the app and the portal; OpenStreetMap: street maps in the portal. They see which map area is shown.
- Photon (komoot), built on OpenStreetMap: address search, and the address of a point on the map. It sees the text searched for, or the point.
- OSRM (the public project-osrm.org service): driving routes and distances. It sees the points of the route. It also finds the shortest order of a run ("Optimize route").
- Google Maps: opens with the site as destination only when you tap to drive there; from then on Google's own terms apply.
- cdnjs (Cloudflare): the portal's map code (Leaflet), and its PDF and Excel code (jsPDF, SheetJS) when you make a PDF or Excel file.
What we never do
We do not sell or rent your data, or your customers' or workers' data, and we do not share it for advertising or use it to profile anyone. We do not show ads.
How long we keep it
| Data | Kept |
|---|---|
| Company records (customers, sites, estimates, quotes, visits, photos, signatures, hours, pay information and payslips, customer messages, quote approvals) | While the company account is open, and deleted with it (pay settings, pay rates and payroll numbers, time off, extras, approved pay runs and payslips included). Those allowed can delete records in the app or portal at any time; the photo and PDF files of deleted records are removed when the company is deleted. |
| Invoices, credit notes, payments and contracts | While the company account is open, and deleted with it; an invoice is never deleted on its own, only voided (accounting keeps every number). The company keeps its own copies as its tax laws require. |
| Customer page sign-in | The link: 30 minutes, once. The sign-in: 30 days, or until the customer signs out. |
| Stripe and QuickBooks connections, their logs, cards on file (brand and last 4 digits) | While connected and the company account is open; the card itself stays with Stripe until the customer or the company removes it there. |
| Payment notices from Stripe | With the company's records; deleted with the company. |
| Labor costs per hour; API keys (name, fingerprint, made, last used) | While the company account is open, and deleted with it. A removed API key stops working at once; its row is kept, marked removed, with the company's records. |
| Latest position of each person | Replaced by the next one; no trail is kept. |
| Chat (text, photos, voice messages) | 14 days, then deleted automatically (an open support request keeps its last message until it is closed). |
| People removed by a manager, or whose seat ended | They can no longer sign in, at once. Their name and what they recorded stay in the company's records, and are deleted with the company, or sooner on request. A removed person's profile photo and latest position are deleted at once; a person whose seat ended keeps them until they are removed or the company is deleted. |
| Sign-ups never confirmed | Deleted after 72 hours (the link works for 48 hours). |
| A company whose plan or free trial ended | New records are still saved for 60 days. If no plan is chosen, the company and all its data are deleted 60 days after the email saying the plan ended reached a manager; managers are warned by email again 7 days and 1 day before. A company is never deleted without that email delivered, nor while its Paddle subscription could still charge it. Time while billing is not yet switched on never counts against a free trial. |
| Free trial fingerprint | Kept to give each address one free trial; the address cannot be read back from it. |
| Payment notices from Paddle | As long as accounting and tax laws require, also after the company is deleted. |
| Contact form messages | 24 months in our database; in our support mailbox as long as needed to answer and follow up. |
| Devices (app version, Android version, model, installation code) | While the company account is open, and deleted with it. |
| App health counts | 30 days. |
| Request log per person | The last 300 requests, 14 days at most. |
| Problem reports and feature requests | While the company account is open, and deleted with it. |
| Copies of emails we sent | 90 days. |
| News emails: when each was first opened | 12 months. |
| Translations of support messages | 180 days. |
| Operations console log (what staff did, including billing changes and access codes used) | 24 months. |
| Website visit counts | Counts per day, with no personal data; the daily fingerprints 2 days. |
| Sign-ins (token, device, IP address, last used) | Until signed out: on that device, from the web portal's Your account (one device or everywhere), by changing the password (other devices), or when the person is removed or their seat ends. Sign-ins do not expire on their own. |
| Activity log; fingerprints of devices used to sign in | 12 months, then deleted (a removed person's device fingerprints at once; a deleted company's activity log and its people's device fingerprints with the company). |
| Server and web logs | 30 days, then deleted. |
| Limits against abuse (counts per IP address, email or account) | In our database, up to 24 hours. |
| On a phone or in a browser | Until the app is uninstalled or its data cleared; in the portal, the sign-in is removed at sign-out. |
Your rights
You can ask to see your personal data, to correct it, to have it deleted, and to receive a copy of it in a common format (managers can also export the company's records from the web portal). You can object to a use based on our legitimate interests, ask us to limit a use, and withdraw a consent at any time. We answer within 30 days, free of charge, and will not treat you differently for using these rights. We may first ask you to confirm who you are, and we keep what the law requires us to keep (for example billing records).
- Europe and the UK (GDPR): the rights above; you may also complain to your data protection authority.
- California (CCPA/CPRA): the rights to know, delete and correct, and to limit the use of sensitive data. Precise positions are used only to provide the service. We do not sell or share personal information, as those laws define it. An authorized agent may ask for you.
- Canada (PIPEDA) and Quebec (Law 25): the rights of access and correction, to withdraw consent, and in Quebec to have your data given to you or to another organization in a common format. The person in charge of the protection of personal information is Marc Robitaille, reachable at the address below. You may complain to the Office of the Privacy Commissioner of Canada or, in Quebec, to the Commission d'accès à l'information.
Customers and workers of a company that uses MS Rollout: write to the company first, since it decides about its records. You can also write to us; we will pass your request on and help it answer.
Security
- All data travels over encrypted connections (HTTPS) between the app, the portal and our servers.
- Passwords are stored only as salted hashes. Sign-in tokens are random, and end at sign-out (on the device, or from Your account for one device or everywhere), when the password is changed (other devices), when a person is removed, or when their seat ends. You are emailed when your account is signed in on a new device.
- Managers type their own password again before changing someone's password or role, or removing someone.
- Each company sees only its own records, and each person what their role allows.
- Limits on wrong passwords, sign-ups and messages, a sum to solve against robots (on every portal sign-in, and in the app after wrong passwords), strict browser security rules on the portal, and browsers told to use only encrypted connections to our sites.
- Our operations console is not on the public internet; only MS Rollout staff can reach it.
- Payment service keys (Paddle, Stripe) and QuickBooks access keys are stored encrypted, and Paddle's and Stripe's notices are checked by their signature.
- Invoice, contract and customer page links are long random codes; the customer page signs in only by a link sent to an address on file.
No system is perfectly secure. If a breach puts your personal data at risk, we will tell you and the authorities as the law requires.
International transfers
Our servers are hosted by OVHcloud in Montréal, Quebec, Canada, and Paddle, Stripe, Intuit and the map services above run in several countries, so your data may be stored or handled outside your own country or province. Where the law requires it, we rely on the safeguards it provides for (such as adequacy decisions or standard contractual clauses) and on our providers' own commitments.
Children
MS Rollout is a work tool for businesses. It is not meant for children, and we do not knowingly collect their data.
Changes
If we change this policy, we will update this page and its date, and tell company managers about important changes by email or in the app before they apply.
Contact
Questions about privacy, or requests about your data: Marc Robitaille, doing business as MS Rollout, through the contact form or at supports [at] msrollout.com.