Legal
Privacy Policy
Last updated: July 1, 2026
The short version: your business data belongs to you, location is tracked only on shift with permission, and we never sell anything to anyone. The full version, below, is written to be read by humans.
What we collect
Account data: your name, work email, company name and role when you create a LanternBRP workspace. Customer data you enter: names, addresses, contacts, service history, photos and job notes belonging to your customers. This data is yours, and we process it only to provide the service.
Location data: technician GPS positions are collected only while a tech is clocked in and the app is active or running in the background with explicit permission. Techs can see exactly when tracking is on, and can end it by clocking out.
How we use it
To run the service: dispatching, routing, ETA calculations, syncing photos and reports, and generating invoices. To improve the product: aggregated, de-identified usage patterns (for example, average jobs closed per day) help us tune performance and prioritize features.
We do not sell personal data. We do not run advertising. We do not share your customer lists with anyone.
Photos, signatures and documents
Photos and signatures captured in the field are uploaded over TLS 1.3, stored with AES-256 encryption, and attached to the work order they belong to. Access is limited to members of your workspace with the right role.
Third-party processors
We use a small number of subprocessors to operate LanternBRP: cloud hosting (AWS, SOC 2), mapping and routing (Apple Maps / Mapbox), crash reporting, and transactional email. Each is bound by data-processing agreements and may only process data to deliver their service to us.
Retention and deletion
Your data stays yours while your account is active. After cancellation, workspaces remain exportable for 90 days, after which they are permanently deleted from production systems within 30 days and from backups within 60. You can request earlier deletion at any time by writing to privacy@lanternbrp.com.
Security
LanternBRP runs on SOC 2-compliant infrastructure with encryption in transit and at rest, role-based access control, audit logging and annual third-party penetration testing. If we ever discover a breach affecting your data, we will notify affected workspaces within 72 hours.
Your rights
Depending on where you live (including under GDPR and CCPA), you may have the right to access, correct, export or delete personal data we hold about you, and to object to certain processing. Email privacy@lanternbrp.com and we will respond within 30 days, usually much faster.
Contact
LanternBRP Labs, Inc., 212 Harbor Street, Suite 400, Portland, ME 04101. Privacy questions: privacy@lanternbrp.com. General support: support@lanternbrp.com.