Important: BaseOps acts as a service provider / processor for each tenant. Your municipality or organization is the primary controller of the records stored inside your workspace.
1. Who we are
BaseOps is a software platform (“the Service”) used by municipalities and other organizations to manage forms, approvals, logbooks, meetings, minutes, reporting, and related workflows. Throughout this Policy, “we”, “our”, or “BaseOps” refers to the platform operator.
2. Information we collect
2.1 Account information
To create and manage user accounts, we may collect:
- Name and contact information (such as email address)
- Role, department, and tenant affiliation
- Authentication and security metadata (login timestamps, password reset tokens, etc.)
2.2 Operational data & records
BaseOps stores data created and managed by tenants inside the platform, including but not limited to:
- Public-facing form submissions (applications, complaints, requests, etc.)
- Internal-only forms and staff submissions
- Logbook entries and daily operational records
- Meeting agendas, packets, and minutes
- Attachments such as PDFs, documents, and images
- Chat messages and notes (if the chat module is enabled for your tenant)
In some cases, this may include sensitive information such as Social Security Numbers or driver’s license details when tenants configure forms to collect it.
2.3 Usage and technical information
When you use BaseOps, we collect limited technical information to operate and secure the Service:
- IP address and general location at time of access
- Browser and device information
- Pages or modules accessed and timestamps
- Error logs and performance metrics
2.4 Program registration and family information
When tenants use BaseOps Programs, we may process information related to participants, guardians, family relationships, emergency contacts, attendance records, authorized pickup contacts, and registration history.
- • Participant names and dates of birth
- • Guardian and household contact information
- • Emergency contacts
- • Authorized pickup information
- • Attendance and participation history
- • Medical or accommodation information voluntarily provided by the participant or guardian
2.5 Payment information
When payments are collected through BaseOps, payment processing is performed by Stripe.
BaseOps does not store full credit card numbers or payment credentials.
We may store limited payment-related information including:
- • Payment status
- • Amount paid
- • Currency
- • Transaction references
- • Refund information
- • Billing contact information
3. How we use information
We use data for the following purposes:
- To provide, maintain, and improve the BaseOps platform
- To authenticate users and enforce permissions
- To power workflows configured by each tenant (forms, approvals, logbooks, etc.)
- To generate PDFs, exports, and public records packets
- To provide customer support and diagnose technical issues
- To monitor security, detect abuse, and protect the integrity of the Service
We do not sell your data, and we do not use your data for advertising or marketing unrelated to BaseOps.
4. Data ownership and sharing
Tenants (for example, a municipality or department) are the primary custodians of the data they store in BaseOps. We operate the platform on their behalf.
We may share information in the following limited circumstances:
- Within a tenant: Data is visible to authorized users and departments according to the roles and permissions configured by that tenant.
- Service providers: We may use trusted infrastructure or email providers to host the Service or send notifications, under appropriate security and confidentiality obligations.
- Legal requirements: We may disclose information when required by applicable law, court order, or valid legal process.
-
Payment Providers: When a tenant enables online payments, payment information is processed by Stripe and subject to Stripe's privacy practices.
BaseOps receives only the information necessary to facilitate payments, refunds, receipts, reporting, and reconciliation.
BaseOps does not directly respond to public records requests. Those requests are handled by the tenant, who may use BaseOps to generate or export appropriate records.
5. Security
BaseOps is designed with security and auditability in mind, including:
- Encryption in transit via HTTPS/TLS
- Encryption at rest for stored data where supported by infrastructure
- Role-based access control (RBAC) and tenant scoping
- Audit logs of key actions (views, edits, approvals, exports, and sensitive field access)
- Secure password hashing and session management
- Regular backups and restricted server access
No system is completely risk-free, but we apply industry-standard practices and continue to refine our security posture over time.
6. Sensitive data & SSN handling
Some tenants may collect Social Security Numbers, driver’s license numbers, or other sensitive identifiers as part of their operational workflows. BaseOps provides:
- Dedicated field types for SSN-like data
- Segregated and encrypted storage for those fields
- Redaction by default in PDFs and standard detail views
- Additional permissions and audit logging for full views of sensitive fields
Tenants are responsible for configuring which forms collect sensitive data and for ensuring compliance with local, state, and federal regulations.
7. Data retention
Retention of records is managed primarily by each tenant, based on their internal policies and legal obligations. BaseOps retains data for as long as a tenant account remains active, unless:
- The tenant deletes a specific record, user, or form template
- The tenant requests removal or anonymization of certain data
- We are required by law to retain or remove certain information
Backups may temporarily retain deleted information for disaster recovery purposes, typically for a limited and rotating period of time.
8. Cookies & local storage
BaseOps uses a small number of cookies and similar technologies to operate the Service:
- Session cookies for authentication and security
- Preference storage (e.g., theme selection, interface options)
We do not use tracking pixels or third-party advertising cookies inside the BaseOps application.
Certain public-facing experiences, including family portals, registration workflows, and saved draft forms, may use browser storage technologies to temporarily retain information between visits.
This information is used solely to improve the user experience and is not used for advertising or tracking purposes.
9. Your rights
Depending on your jurisdiction and your organization’s policies, you may have rights regarding your personal data, such as:
- Accessing data about you stored in BaseOps
- Requesting corrections or updates
- Requesting deletion, where compatible with public records obligations
- Requesting a copy or export of your data in a machine-readable format
Most of these requests are handled by your tenant administrator (such as a municipal records officer). We may assist the tenant with tools to fulfill those requests.
10. Children’s data
BaseOps is not marketed directly to children. However, some tenants may use BaseOps to manage programs that involve minors (for example, recreation registrations or youth services).
When that happens, the tenant is responsible for ensuring proper consent, notice, and handling of those records.
11. Changes to this Policy
We may update this Privacy Policy from time to time to reflect changes to the Service, legal requirements, or best practices. When we do, we will update the “Last updated” date at the top of this page.
Significant changes may be communicated to tenant administrators via email or in-app notices.
12. Contact
If you have questions about this Privacy Policy or how BaseOps handles data, you can contact us at:
- Email: privacy@baseops.app
For questions about specific records, disclosures, or retention policies, please contact your organization or municipal administrator directly.