Some companies have a workhorse. We're building you a War Horse.
Privacy policy
DestrierOS is built for companies that need sensitive operational data to stay controlled, scoped, and traceable.
This Privacy Policy explains how Schardt Industries collects, uses, stores, and protects information when organizations use DestrierOS. Last updated August 2, 2026.
Mobile location and tracking
When an organization enables mobile GPS, DestrierOS may collect precise location while the app is open, backgrounded, suspended, or relaunched by supported operating-system location events. iOS force-quit, Android Force Stop, permission revocation, and other operating-system restrictions can stop collection until the app is reopened.
Each app install receives a random application install identifier. It is not an advertising ID, hardware serial number, phone number, or employee identifier. The server assigns the install to a company-owned always-on, user-owned always-on, or user-owned clocked-in-only policy.
User-owned tracking requires affirmative in-app consent and operating-system location permission. Users can revoke consent, and operating-system permission can be changed in device settings. Company administrators control the assigned tier but cannot override an operating-system denial.
For user-owned clocked-in-only installs, clocked-out samples are hidden from ordinary maps, history, trips, events, and exports. They become eligible for deletion after seven days and the server expiry job runs hourly. An authorized manager may release only the exact reviewed window needed for a missed-clock correction, with a stated reason, employee notice, and employee-visible audit record.
Who we are
DestrierOS is operated by Schardt Industries.
Privacy and support requests can be sent by email.
Privacy and support contact: matthewschardt@schardtindustries.com.
Business-only service
DestrierOS is designed for companies, operators, and invited business users rather than consumer use.
Owner accounts can be created through public self-signup, and additional users are managed by invitation from the company workspace.
Each company workspace is intended to control its own users, permissions, and operational records.
Information we collect
account and profile information for invited and self-serve owner users
company and workspace configuration data
customer, CRM, and relationship records
employee, HR, payroll-adjacent, and compliance records
GPS, fleet, device, and location-history data
uploaded documents, forms, fleet inspection responses, safety notes, and attachments
communications records, message metadata, and inbox connection details
billing, subscription, and transaction data when commercial billing goes live
application logs, usage data, and security telemetry
How we use data
We use information to operate DestrierOS, provide company workspaces, secure the service, support customers, and improve platform functionality.
We also use data to deliver workflow features such as scheduling, fleet visibility, HR records, forms routing, communications, reporting, and audit history.
We may use service and security logs to detect abuse, troubleshoot incidents, and maintain performance.
Sensitive data
Customers may store sensitive company, employee, document, location, and compliance data in DestrierOS.
Schardt Industries uses encryption and controlled access patterns for sensitive records, including encrypted snapshots for SSNs, HR address and compensation fields, sensitive form values, and fleet form notes and responses.
Customers are responsible for deciding what data they place in the service and for configuring access consistent with their legal obligations.
Sharing and subprocessors
We do not sell customer data. We may share data with infrastructure and integration providers only as needed to operate the service.
Supabase for database, authentication support, storage, and application infrastructure
Google for workspace and inbox integrations where connected by a customer
Microsoft 365 for work and school inbox integrations where connected by a customer
Mapbox for maps, geocoding, and location visualization where fleet or location features are enabled
OpenAI for AI-assisted workflow features when enabled by a customer workspace
Stripe for billing and payments once commercial billing is enabled
Retention and deletion
Customer workspace data is generally retained while the workspace remains active.
Precise GPS history, trip history, telematics event history, and driver identity history are retained for up to 2 years unless a customer contract requires a shorter period.
Detailed Teltonika device readings are retained for up to 1 year, and raw Teltonika ingest logs are retained for up to 180 days for troubleshooting and security review.
After cancellation or termination, we expect to retain workspace data for up to 90 days before deletion, subject to backups, legal obligations, and security needs.
Customers may request export, deletion, or legal/security-reviewed audit actor anonymization. Audit events may be retained for security and SOC 2 evidence even when actor identity snapshots are anonymized.
Backup systems may retain copies for a limited period before normal expiration.
Cookies and analytics
The public site and product may use cookies, local storage, and similar technologies for login state, security, product functionality, and analytics.
These tools help us understand service usage, keep sessions secure, and improve product performance.
Your choices
Company administrators can manage invited users, permissions, and workspace access.
Customers may contact us to request account assistance, data export, correction, or deletion review.
Questions about this policy can be sent to matthewschardt@schardtindustries.com.