Privacy Policy
This policy explains what personal information Depot collects, why we collect it, who we share it with, and the choices you have. It covers this marketing website and the Depot application — the web app at app.thedepot.io and the Depot mobile apps for iOS and Android. Where your employer has an agreement with Depot, that agreement additionally governs your organization's data in the application.
Who we are
Depot is operated by Depot Holdings Group, Inc. ("Depot", "we", "us"), 14306 Seventh St #100, Dade City, FL 33523. Depot serves customers in the United States and Canada. Depot has designated an individual accountable for its compliance with this policy and with privacy law; that person can be reached at [email protected] and will be identified by name on request. For any privacy question, or to exercise any right described below, email [email protected]. For the marketing website we are the data controller. For the Depot application, your organization controls the business records it keeps in Depot; we process that data to provide the service under our agreement with your organization.
What we collect on this website
We collect only what you type into the "Claim a workspace" form and the minimum technical data needed to serve and protect the site.
- Information you give us. When you submit the form we receive your name, work email address, company name, equipment or fleet size, and industry. All five fields are supplied by you.
- Anti-spam data. Our bot check (Cloudflare Turnstile) processes your IP address and basic browser signals to confirm you are not an automated script. We do not see or store the IP address ourselves; it is processed by Cloudflare.
- Server logs. Our host (Cloudflare) records standard request data — IP address, timestamp, user agent, requested URL — for security, abuse prevention, and reliability.
We do not ask for, and you should not send us, payment card numbers, government identifiers, health information, or any other sensitive category of personal data through this website.
The interactive preview
The clickable Depot preview on our homepage is a static simulation. It runs entirely in your browser, is populated with fictional sample equipment and people, and is connected to no database. Nothing you type or click inside the preview is transmitted to us, recorded, or stored anywhere.
Why we use it
- To respond to your enquiry and set up a demonstration or workspace, at your request.
- To protect the site from spam and automated abuse.
- To comply with law where we are required to retain or disclose information.
We collect and use personal information only for these purposes, and only where a reasonable person would consider the use appropriate in the circumstances. Where the law requires your consent, we obtain it. You may withdraw consent at any time, subject to legal or contractual restrictions and reasonable notice, and we will explain what withdrawal would mean for any service you receive.
We do not sell your personal information, we do not share it for cross-context behavioural advertising, and we do not use it to build advertising profiles.
Who we share website enquiries with
We share personal information only with the service providers that make this website work, and only so they can perform that service for us:
- Cloudflare, Inc. — website hosting, content delivery, server logs, and the Turnstile bot check.
- Supabase, Inc. — database hosting for Depot's internal sales and support system, where your enquiry is stored.
- Google LLC (Google Workspace) — email and document services we use to correspond with you about your enquiry.
- Stripe, Inc. — payment processing, if you start a subscription. Stripe receives your name, email, and payment details; we never receive or store your full card number.
- X.AI LLC — artificial-intelligence assistants inside our internal sales and support system. They read enquiries, prospect records, support conversations, and the directory of customer organizations and users, to draft replies and summaries for a member of our staff. Every read is logged, and an assistant can never send anything or approve anything on its own — a person does that. Content we send is not used to train their models.
We may also disclose information if compelled by law, or in connection with a merger, acquisition, or sale of assets, in which case we will give notice before your information becomes subject to a different privacy policy.
Telephone calls
If you call us, the call is recorded and transcribed. You hear a notice saying so before anyone at Depot picks up, and the recording does not start until after that notice. If you would rather not be recorded, hang up at the notice and email us instead — we are happy to handle anything by email. Calls we place to you are not recorded at all.
Florida, where Depot is based, requires every party to a call to consent to its recording, which is why the notice is built into the call itself rather than left to whoever answers.
What we collect from a call: your telephone number, the number you dialled, the menu option you chose, the time and length of the call, the audio, and a written transcript of it. We use these to answer your question, to train and review our own staff, and to keep an accurate record of what was said.
Two providers handle this for us: Telnyx LLC (telephone numbers, routing, and recording) and Deepgram, Inc. (speech-to-text transcription). Both are in the United States and both appear on our sub-processor list.
We delete recordings and transcripts no later than 24 months after the call, automatically. Voicemail is treated the same way. You can ask us to delete a specific call sooner by emailing [email protected].
Where your information is processed
Your core records are stored in Canada. The application database, the files you upload, and your sign-in records are held in a Montreal region. Content delivery, telephone call recordings and backups are handled across North America and may be located in the United States. Several of our providers — email delivery, payments, telephony, transcription, support email, maps and diagnostics — operate in the United States, and one, Capgo, operates from Switzerland; each is named with its location on our sub-processor list. If you are in Canada, this means that while the records your organization keeps in Depot stay in Canada, some personal information is processed outside Canada, including in the United States, where it is subject to the laws of those jurisdictions and may be accessible to their courts and law enforcement under those laws. Depot remains accountable for personal information it transfers to a provider and requires each provider, by contract, to protect it to a comparable standard.
How long we keep it
Enquiry details are retained for as long as needed to respond and, if you become a customer, for the life of the relationship plus any period required for legal or accounting purposes. If you do not become a customer, we delete or anonymize the enquiry within 24 months. Call recordings and transcripts are deleted within 24 months of the call. Server logs are retained on our host's standard schedule.
Cookies and how we track where leads come from
When you first visit, a banner asks whether you accept our tracking. Your answer is stored in a single first-party cookie (depot_consent, kept for 180 days) so we do not ask again. That cookie is strictly necessary and holds nothing but the word "accepted" or "declined".
If you accept, we record how you found us: the campaign tags on the link you arrived from (utm_source, utm_medium, utm_campaign, utm_term, utm_content), an ad click identifier if one is present (gclid or fbclid), the referring site's hostname, the page you landed on, and the time. This is stored in your browser (local storage), only the first visit's values are kept, and it is sent to us only when you submit a form, start a checkout, or open the live demo, attached to that enquiry so we know which channels bring real customers. It is not shared with advertisers and we run no third-party trackers.
If you decline, nothing is stored beyond the consent cookie itself. If you then send us an enquiry, any campaign tags on the page you submit it from still arrive with that enquiry, the same way the form's contents do.
Unfinished forms. If you start filling in one of our forms and leave before sending it, we may save what you entered, including your email address, so we can follow up, exactly as if you had submitted it. It is stored and shared the same way as a submitted enquiry, and you can ask us to delete it at any time.
Functional storage. If you unlock the live demo we keep the name, email, and company you entered in your browser's local storage so later forms can be pre-filled, and we note per browsing session that the demo invitation has already been shown. Neither is used for tracking.
Analytics. We currently run no analytics or advertising scripts. If we enable one later, it will load only after you have accepted the banner, and this policy will name it first.
Cloudflare Turnstile may set a short-lived, strictly necessary token in your browser solely to confirm the bot check passed; it is not used to track you across sites.
The Depot application
Depot is an application for equipment operations. You can sign up on this website (checkout is handled by Stripe), or your organization's administrator can add you to an existing workspace. Signing in uses a 6-digit email code; Depot accounts have no passwords.
What the application collects
- Account information. Your name, work email address, role, and the organization and branch you belong to, provided when your administrator invites you.
- Content you and your organization create. Equipment records, inspections, work orders, maintenance schedules, and documents — including photos you attach as inspection evidence, and video clips (up to 10 seconds, with sound) and voice memos you choose to record on a failed inspection item. A video clip can capture the faces and voices of people nearby. If you allow location access when you attach a photo, we store the device's precise location (latitude, longitude, and accuracy) and the capture time with that photo. This content belongs to your organization and is visible only within it.
- Diagnostics. We use Sentry to collect crash reports and basic device information (such as device model and operating-system version), associated with your user ID, so we can find and fix defects.
Device permissions
- Camera — used when you scan an equipment tag, attach an inspection photo, or record a video clip on a failed inspection item. Clips are compressed on your device before upload. On Android, tags are read on the device by Google ML Kit; the camera image is not sent to Google.
- Microphone — used only when you choose to record a voice memo or a video clip on a failed inspection item. If you choose to turn a voice memo into text, that happens on your device.
- Notifications — used for assigned-work and operational alerts.
- Location — precise, when you attach an evidence photo, and a general region from the network. When you attach an evidence photo, the application asks for your device's precise location and, if you allow it, stores that location with the photo so the evidence records where it was captured. This is foreground location only, requested while you are attaching the photo. If you decline, or if the device cannot determine a location, the photo still saves and we record that location was not available. The application does not collect location in the background. Separately, our content-delivery and security provider derives a country or general region from the network address of each request, and the live-update service used by the mobile apps receives the same when checking for updates. Our app-store disclosures therefore declare both precise location, for evidence photos, and approximate location, for that network region. Equipment locations shown on maps come from coordinates stored in your organization's records, rendered by Mapbox as a map image on an asset and as an interactive map of your fleet.
The application remains usable if you decline an optional permission, except for the specific feature that needs it.
Application service providers
The application shares personal information only with the providers that operate it, and only so they can perform that service. The current, canonical list — including the providers behind this website — is published at thedepot.io/subprocessors, so that adding or replacing a vendor does not require amending this policy:
- Supabase, Inc. — application hosting, database, file storage, and authentication.
- Resend, Inc. — transactional email: sign-in codes, invitations, and operational notifications.
- Functional Software, Inc. (Sentry) — crash and error diagnostics as described above.
- Capgo (Digital Solutions AG) — delivery of application updates; processes basic device and app-version information needed to serve the correct update.
- Cloudflare, Inc. — content delivery and security for the web application.
- Google LLC — Firebase Cloud Messaging, used to deliver push notifications to mobile devices.
- Mapbox, Inc. — maps of equipment locations: a map image on an asset and an interactive fleet map. Mapbox receives the coordinates stored in your organization's records for the equipment in view, the map area being viewed, and standard request information such as IP address and device or browser type, and records map loads for usage metering.
- Google LLC (ML Kit) — on-device barcode scanning in the Android application. The camera image stays on the device; ML Kit sends Google device information, app information, and performance and diagnostic metrics about the scanning feature.
- Anthropic PBC and OpenAI, L.L.C. — artificial-intelligence models that interpret text, images and audio submitted to the application, as described below. Both are engaged on commercial terms under which content we send is not used to train their models. We have not yet enabled these features, and no customer content has been sent to either provider.
We do not sell personal information from the application, and we do not use it for advertising or cross-context behavioral advertising.
Artificial-intelligence features
On-device features (in use today)
On supported iPhones, the Depot app offers features that use the artificial intelligence built into your device: recognizing a new piece of equipment from a photo or description and suggesting its details, reading serial numbers and license plates from a photo, turning a voice memo on a failed inspection item into text, and reviewing a submitted inspection's notes for items that may need a recheck or a work order. These run entirely on your device. The photos, text and audio they read are not sent to Depot's servers for this purpose, to Apple, or to any model provider, and nothing is used to train a model. The device's model may fall back to Apple's cloud processing for some apps; Depot does not use that option.
What these features produce is a suggestion. Nothing is saved until a person approves it, the app says on screen that AI can make mistakes, and Depot records which saved values came from a suggestion so that it can keep showing that later. What a person approves and saves becomes part of your organization's records like anything else they enter.
Model-provider features (not enabled)
These features are not enabled today. Nothing you submit is sent to a model provider, and no evaluation set exists. This section describes what will happen if and when we turn them on, and we will update the date on this page and tell customers before that happens.
Where the application uses artificial intelligence to interpret text, images or audio you submit — for example to suggest a component, failure type or severity from a technician's note, photograph or voice memo — that content is sent to the model providers listed above in order to produce the suggestion. Those providers do not use it to train their models, and we never use one organization's content, or any excerpt of it, to produce output for another.
We keep a bounded evaluation set — at most 50,000 records, held for up to five years from selection — of selected submissions together with the suggestion produced and any correction made to it. Before an image is selected we screen it for faces and vehicle registration plates, and we do not knowingly keep any image in the set that shows a face, a plate, or anything else identifying a person or someone else's property; if we find one, we delete it. We use it to measure whether these features are accurate and to improve them: that includes fine-tuning or otherwise adapting the models we use, and deriving shared reference data such as component and failure-mode vocabularies or the shape of an effective instruction to a model. Anything derived that way contains none of your content and nothing identifying your organization, its people, its sites or its assets, which is what makes it usable across customers. For this evaluation set we act as a controller of that information rather than as a processor on your organization's behalf, and we use it only for the purposes described here.
Your organization can opt out of the evaluation set in writing. That stops future selection and, on request, removes what has already been selected. It cannot reverse an adaptation already made: a model that has been fine-tuned on content cannot be made to un-learn it, and we would rather say so than have you discover it. Shared reference data is unaffected by opting out, because there is nothing of yours left in it to remove. The corresponding contract terms are in our Data Processing Addendum (Sections 2.5 to 2.8 and 8.3(c)).
Retention and account deletion
Application data is retained for as long as your organization remains a Depot customer, plus any period required for legal or accounting purposes; business records within the application are managed by your organization. When an organization's account closes we keep its data for twelve months so it can still be retrieved — for the organization's own records, or to move to another provider — and we will export it on request during that period, after which we delete it. An organization can tell us not to wait, at any point before or after closing, and we will delete within 30 days instead. If we are asked to certify that deletion, the certificate says what remains — including whether any content is still in the evaluation set described above and when it will be deleted — rather than claiming everything is gone while some of it is not. Inspection video clips are deleted sooner: 30 days after the related work order is completed or cancelled, or 30 days after the inspection if no work order is opened, and are not kept in backups. The record that a clip existed (who recorded it, when, and on which inspection) stays with the inspection; the photo remains the lasting evidence. You can request deletion of your own account inside the app (Settings → Delete account): the request signs you out, starts a 30-day recovery period, and is then finalized unless you sign back in and restore the account. The steps are also published at app.thedepot.io/account-deletion, and you can always email [email protected] from your account email address.
Application security
Application data is encrypted in transit, and encrypted at rest by our infrastructure providers — that covers the database, uploaded photographs, video clips, documents and voice memos, and backups. Every organization's data is isolated: access rules enforced in the database limit each user to their own organization (and, for branch-scoped roles, their own branch). Access by Depot staff is limited to what operating and supporting the service requires.
Your rights
Depending on where you live, you may have the right to access the personal information we hold about you, to correct it, to delete it, to restrict or object to how we use it, to receive it in a portable format, and to withdraw consent where we rely on it. Residents of California may request disclosure of the categories of information collected and request deletion, and may not be discriminated against for exercising those rights. In Canada, you may request access to the personal information we hold about you and ask us to correct it if it is inaccurate or incomplete.
To exercise any of these, email [email protected]. We will verify your identity and respond within the time the applicable law allows. If you are not satisfied with our response, you may complain to the privacy regulator where you live. In Canada that is the Office of the Privacy Commissioner of Canada, or the provincial commissioner where your province has its own privacy regulator.
Security
The site is served over HTTPS. Form submissions are transmitted over an encrypted connection and verified server-side before delivery. Access to enquiries is limited to the people at Depot who need it. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.
If something goes wrong. If we discover a breach affecting your personal information, we will notify you and the relevant regulator where the law requires it, and within the time that law allows. Where you are a user of the Depot application, we notify your organization’s administrators under our Data Processing Addendum, which commits us to doing so within 72 hours of confirming the incident.
Children
This website is directed at businesses. We do not knowingly collect personal information from anyone under 16. If you believe a child has given us information, email us and we will delete it.
Changes
If we change this policy we will update the date at the top of this page. Material changes affecting how we use information you have already given us will be communicated directly where we have a means of contacting you.
Contact
Depot Holdings Group, Inc.
14306 Seventh St #100, Dade City, FL 33523
[email protected]