OnRotationsWORKSPACE
YOUR INFORMATION

Privacy policy

Effective September 20, 2026 · Last updated September 23, 2026

OnRotations is a dealership team management service based in Los Angeles, California. This policy describes how the OnRotations team handles information through our website and browser application. Our service is intended for United States dealerships and their authorized personnel.

The essentials

We do not sell personal information or share it for cross context behavioral advertising. We use information to operate your account, organize your store, support your team, and protect the service. Your dealership can review workplace activity recorded in its store.

1. Information we collect

We receive information from you, your dealership, authorized coworkers, and your use of the service.

  • Account and profile information: email address, account identifier, authentication information, name, displayed last name initial, optional phone number, profile photo, store membership, role, and an employee ID if your dealership uses one. Authentication is handled through Supabase.
  • Workplace activity: schedules, schedule confirmations, leave dates, appointments, check ins, assigned points, rotation history, availability, time on point, restroom and other break status and duration, grace allowances, deal activity, vehicle stock numbers, and task completion.
  • Content and communications: messages, notes, announcements, bonuses, reports, invitations, and information you send when requesting help. Enterprise inquiries include your account email, contact name, dealership, expected store and team size, purchase timeline, and operational priority.
  • Service and technical information: store settings, plan and account limits, session information, and request or security logs that may contain IP addresses, browser and device information, requested pages, errors, and timestamps. Hosting and authentication providers process technical information when delivering the service.

Online checkout is not currently connected. We do not currently collect payment card details through this website. We do not currently request precise device location or use GPS tracking.

Do not enter or share customer information of any kind, including customer names, contact details, Social Security numbers, driver’s license documents, customer financial records, passwords in messages, medical details, or other sensitive customer records. Use only the information needed to coordinate your team. A restroom or leave status does not require a medical explanation.

2. How we use information

We use information to authenticate users, assign access, operate rotations and schedules, deliver messages and store updates, produce activity reports, manage accounts, respond to support requests, investigate errors or misuse, and meet legal obligations. Managers may use reports for coaching and reviewing store operations.

Your dealership decides how it uses OnRotations for workplace management. It is responsible for appropriate employee notices, lawful instructions, and the information it asks staff to submit. This policy does not replace your employer’s workplace privacy notice or authorize undisclosed monitoring.

3. Who can see information

  • Your store: authorized team members can see shared rotation activity, availability, schedules, team messages, team notes, bulletins, and bonuses. Store managers can review their store’s employee data, activity reports, and task completion. Employee IDs are restricted to the employee concerned and authorized management, rather than the whole sales team.
  • Messages and personal notes: direct conversations are addressed to their participants. They are not end to end encrypted. Authorized platform administrators may access service records when administering accounts, providing support, investigating misuse, or complying with law. Daily private notes are stored in the database and available only to their author through the application. Managers and the owner dashboard cannot read another real user’s private notes. They are not end to end encrypted. Earlier browser-only notes and preferences may remain on the original device; anyone with access to that browser or device may be able to access those local records.
  • Service providers: Supabase provides authentication and database services; Vercel hosts the website. Email providers process account emails and correspondence. Our current contact mailbox uses Gmail. These providers process information needed for their services. See the Supabase privacy notice, Vercel privacy notice, and Google privacy policy for their own practices. Those notices do not replace this policy.
  • Legal and business circumstances: we may disclose necessary information to comply with legal process, protect people and the service, investigate fraud, or obtain professional advice. If the business is transferred, information may be transferred subject to applicable law and appropriate notice.

We do not disclose personal information to third parties for their direct marketing. We do not install advertising trackers or optional analytics tools in the current application. Following an external link takes you to a service with its own privacy practices.

4. Cookies and browser storage

We use cookies to authenticate accounts, protect sign-in, and connect employees through invitations. Browser storage also supports preferences, drafts, some notes, read status, and application state. These technologies operate on the browser and website address where you use the service.

  • Account session cookies: Supabase session cookies keep you authenticated and renew your session. They may be split into multiple cookies with names beginning with “sb-”. The current authentication library sets a browser lifetime of up to 400 days and may renew it when updating a session. Session validity is separately controlled by the authentication service. These cookies are removed on successful sign-out. A cookie can remain in the browser longer than a valid session; our server still checks your account and permissions.
  • Sign-in verification cookies: temporary verification data supports confirmation and authentication redirects. The current library may give these cookies a browser lifetime of up to 400 days, though the sign-in flow itself can expire much earlier. Verification data is removed when the associated flow is consumed or cleared.
  • Invitation cookies: “onrotation-invite” and “onrotation-team-link” retain your invitation while you sign in or register. They expire after seven days or are cleared when you accept or cancel the invitation.
  • Optional remembered verification: selecting “Remember this device for 30 days” after successful 2FA sets the “onrotations-trusted-device” cookie. It holds a random secret, not your password, and is protected with HttpOnly and HTTPS on the live site. A matching hashed database record associates the choice with your account. Normal sign-out preserves it until its original expiry, up to 30 days after verification. Returning or signing in does not extend that period. You still need your email and password after sign-out. Password or verified authenticator changes invalidate remembered access. Some sensitive owner actions still require fresh 2FA.
  • Cookie choice: the first party “onrotations-cookie-choice” cookie saves your Accept Cookies or Deny Optional Cookies selection, notice version and timestamp for up to 366 days in this browser. It contains no account identifier. Both choices retain essential service cookies. No optional analytics or advertising providers are currently enabled. Acceptance is limited to this disclosed inventory and does not approve future tracking. Use Cookie Settings at the bottom of any page to change your choice. If your browser blocks saving the choice, it applies only for the current visit and the banner may appear again.
  • Local and session storage: display preferences and some drafts, notes, and read markers may stay until you remove them or clear browser storage. Session storage lasts for that browser tab’s session. Clearing this storage may permanently remove information saved only on that device.

To remove remembered verification, choose “Sign out and forget this device” from the Sign out menu while signed in. You can also delete this website’s cookies in your browser settings, including when signed out. Deleting cookies removes the browser’s saved copy; it does not delete your account or historical store records. A server record may remain until expiry or cleanup, but cannot be used without its matching secret. Private browsing, a different browser, clearing cookies, or using a different website address may require verification again.

Use remembered verification only on a private device. On shared computers, sign out and forget the device, and clear locally saved notes or drafts before leaving. Blocking authentication cookies may prevent sign-in. We do not currently set optional advertising or analytics cookies, and this notice does not request consent to advertising.

We do not sell personal information or share it for cross context behavioral advertising. A browser Do Not Track signal does not change essential service processing. We recognize the browser Global Privacy Control signal and display its status in Cookie Settings. There is currently no sale or advertising sharing for it to opt you out of; neither banner choice overrides that protection. We will reassess applicable choices and update these disclosures before adding optional tracking.

5. Retention and deletion

We retain information while needed to provide the service, maintain relevant store records, resolve disputes, protect accounts, and satisfy legal obligations. Retention depends on the record, its purpose, and any applicable legal requirement.

Explicit platform archives of stores or accounts are scheduled for deletion after 30 days. Removing a person from a store is different from deleting their platform login. Historical posts or activity may remain where associated records are retained; archive deletion is not a promise to erase every reference or backup immediately. Records subject to a legal obligation may also need to be retained.

Copies exported by your dealership are controlled by that dealership. Browser copies must be removed from the relevant device. Contact us about deletion requests and the scope of remaining records.

6. Access, corrections, and privacy requests

You can edit available profile fields and schedule information in your account. Contact your store manager about workplace records or store membership. You may also email us to request access, correction, or deletion, or ask how your information is used. We may verify your identity and coordinate with your dealership where we process records on its behalf. Do not send identity documents or passwords unless a secure verification method has been agreed.

California residents may have rights under applicable law to know about, access, correct, or delete personal information, and to exercise applicable sale, sharing, or sensitive information choices without unlawful discrimination. The availability of these rights depends on the law’s coverage and exceptions. An authorized agent may contact us with evidence of authorization. We respond within the periods required by applicable law and explain any lawful limitations.

We do not use sensitive personal information to infer personal characteristics for advertising. You may ask us to stop promotional emails by replying to them or contacting us. Essential account and security messages may still be necessary.

7. Security and processing locations

We use authentication, access controls, and encrypted connections to help protect information. No system can guarantee complete security. Use a unique password, protect your device, and do not share authentication codes.

Our service is intended for United States use. Providers may process information in the United States and other locations where they operate. We do not promise that all information remains exclusively in California or the United States.

8. Children

OnRotations is a workplace service and is not directed to children under 13. We do not knowingly collect personal information from children under 13. Contact us if you believe a child has supplied information so we can investigate and take appropriate action.

9. Policy updates

We will post changes here and update the date above. For material changes, we will provide an appropriate notice through the service or account email before the change takes effect, and obtain consent where required. New payment, location, mobile, or analytics features will need disclosures that reflect how they actually work.

10. Contact OnRotations

Privacy contact: Emmanuel Babakhanlou, OnRotations
Los Angeles, California, United States

Emmanprofitpathway@gmail.com

Include “Privacy request” in the subject and describe what you need. This is our current contact address while our company domain and mailbox are being established.