Legal

Privacy Policy

How Hitt Field collects, uses, stores, and protects your data — and why all of it stays on American soil.

Last updated: July 19, 2026

All data is stored and processed in the United States. We do not sell personal data, and no customer data leaves the US.

Who we are

Hitt Field ("Hitt Field", "we", "us", or "our") is a field-service dispatch and job-management product operated by Extant 2000 LLC, the company behind the Hitt Hosting suite. This Privacy Policy explains what information we collect when you use Hitt Field, how we use it, where it is hosted, and the rights you have over it.

If you have any questions about this policy or your data, contact us at privacy@hitthosting.com.

Information we collect

We collect the following categories of information:

  • Account & contact details. The information you provide when you create an account and use the product, such as your name, email address, organization details, and the account you sign in with.
  • Billing information. Payments are processed by Stripe. We do not store full card numbers; Stripe handles card data on our behalf. We retain records of your subscription and billing status.
  • Usage & log data. Technical information generated as you use the product, such as log records, activity associated with your account, and diagnostic data used to keep the service running.
  • Content you put into the product. The jobs, customers, vehicles, photos, documents, and other records you and your team create and store in Hitt Field.
  • Technician location. When a technician uses the arrival or check-in feature on a job, the app requests their device's current location and records it on that job (for example, as a drive-leg start or end point). Location is captured only at the moment of that work action — Hitt Field does not track technicians continuously or in the background — and the recorded coordinates are visible to their organization. Precise geolocation is a category of sensitive personal data; the organization using Hitt Field is responsible for informing its workers about this collection and for obtaining any consent their jurisdiction requires.
  • Geofenced arrival positions. An organization may turn on geofenced arrival, which is off by default. When it is on, and only after the technician's own browser grants permission, the app sends a coarse position (rounded to roughly 100 metres) about every 90 seconds while a job assigned to that technician is en route or on site. Capture stops when the job is completed or cancelled and when the technician signs out. There is no background tracking, no capture on unassigned time, and no location history: we store only the technician's latest position, and we delete it automatically after 24 hours. What we keep beyond that is the derived arrival timestamp on the job — the fact that the technician arrived at a time, not a record of where they were. The purpose is to stamp a defensible arrival time and measure the drive leg for billing. The position is visible to the technician's own organization and is never shown to the customer on the job-tracking page. Hitt Field never changes a job's status automatically from a position; it only suggests the change to a person, who decides.

How we use it

We use the information we collect to:

  • Provide, operate, and maintain the Hitt Field service.
  • Process payments and manage your subscription.
  • Authenticate you and keep your account and organization's data secure.
  • Respond to your support requests and communicate with you about the service.
  • Monitor, diagnose, and fix errors and keep the service reliable.
  • Meet our legal, accounting, and compliance obligations.

We do not sell personal data.

Where your data is hosted

All data is stored and processed in the United States. No customer data is stored or processed outside the US.

  • Application, web, and mail servers are located in Warrenton, Virginia (OVH US).
  • The primary application database runs on managed PostgreSQL (Supabase) in a US region (AWS US West, Oregon).

How we secure it

We take practical, layered measures to protect your data:

  • Data is encrypted in transit using TLS.
  • The application database is encrypted at rest.
  • PostgreSQL row-level security enforces per-organization isolation, so one organization cannot read another's data.
  • Audit logging records access to and changes of sensitive data.
  • A web application firewall (ModSecurity) and intrusion detection (CrowdSec) sit in front of the service.
  • We run regular vulnerability scanning.
  • Administrative access is restricted.
  • Payments are handled by Stripe (PCI-DSS Level 1); full card numbers are never stored by us.
  • We keep regular backups and use production error monitoring.

We do not hold SOC 2, ISO 27001, HIPAA, ITAR, FedRAMP, or PCI certification. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

Service providers

We rely on a small set of trusted providers ("subprocessors") to operate the service. Our email is self-hosted, not run by a third-party provider. The subprocessors we use are:

ProviderPurposeLocation
StripePayment processingUnited States
SupabaseApplication database & authenticationUnited States
OVH USServer hostingWarrenton, Virginia, United States
CloudflareDNSUnited States
SentryProduction error monitoringUnited States
AnthropicAI-assisted featuresUnited States

We do not sell personal data.

Data retention

We keep your data for as long as your account is active and for as long as we are legally required to retain it. After that, we delete or anonymize it. You can request an export or deletion of your data at any time.

Geofenced arrival positions are an exception, and are kept far more briefly. A technician's raw position is deleted automatically 24 hours after it is recorded, whether or not the account stays active. The derived arrival timestamp on the job is retained with the rest of that job's record, because it is part of the service history and of what was billed. Both are included in a data export and removed by a deletion request.

Your rights

You have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate personal data.
  • Delete your personal data.
  • Export your data.

To exercise any of these rights, contact us at privacy@hitthosting.com.

Your US state privacy rights

If you live in California, Virginia, Colorado, Connecticut, Texas, Oregon, or another US state with a consumer-privacy law, you have the right to know what personal data we hold about you, to request its correction or deletion, and to receive a copy.

We do not sell your personal data, and we do not share it for cross-context behavioral advertising. Exercising these rights will not result in worse treatment.

To make a request, email privacy@hitthosting.com — we may need to verify your identity first.

Changes

We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top of this page. We encourage you to review this policy periodically.

Contact

If you have questions about this Privacy Policy or how we handle your data, reach us at privacy@hitthosting.com.

By mail: Extant 2000 LLC, 7051 Brookfield Plz, PO Box 41, Springfield, VA 22150, USA