Last updated August 1, 2026
Draft — not yet reviewed by counsel. This document was prepared to describe how the service actually works, but it has not been reviewed by a lawyer and still contains unfilled placeholders. It should not be relied on until it has been. Edit app/_content/company.js to fill in the remaining details and clear this banner.
1. Who we are
Common Ground is operated by Road Command LLC ([ADD BUSINESS MAILING ADDRESS]). This policy explains what personal data the service handles, why, and what choices people have. Questions go to admin@roadcommand.co.
2. Two different relationships
It matters which one applies to you, because it determines who decides what happens to your data.
- If you are a customer — an organization that has bought the service — we are a processor acting on your instructions for the employee data in your account. You are the controller and decide what goes in and what comes out.
- If you are an employee of a customer, your employer decided to use this service and supplied your email address. We process your data on their behalf. If you want your data removed, ask your employer first — though you can always contact us directly and we will help.
- For our own website and enquiries, we are the controller of the limited data described below.
3. What we collect
From customer organizations
- Organization and department names and their URL slugs.
- Supervisor and department manager email addresses.
- Supervisor passcodes, stored only as bcrypt hashes and never recoverable in plain text.
- If single sign-on is enabled, the identity provider issuer, client ID, and client secret you give us.
From employees
- Email addresses, supplied by the employer so monthly invitations can be sent. Nothing else about a person is collected.
- Check-in responses, stored against an organization, a month, and a sequential anonymous code such as E-03. We do not store a name, and we do not store any link between an email address and a response.
From website visitors and enquiries
- If you submit the contact form: the name, email address, company, team size, and message you provide.
- Standard server and infrastructure logs generated by our hosting provider.
- We run no analytics, advertising, or third-party tracking and set no tracking cookies.
4. Cookies
The service sets only functional cookies. There are no advertising or analytics cookies.
- Supervisor session — a signed, HTTP-only cookie set after a supervisor signs in, scoped to one organization or department, expiring after 12 hours.
- Administrator session — the equivalent for our internal administration area.
- Single sign-on state — a short-lived cookie, valid for ten minutes, that ties a sign-in attempt to the browser that started it. Deleted as soon as sign-in completes.
Employees answering a check-in are not given any cookie, because they are never signed in.
5. How we use data
- To deliver the service: sending monthly invitations, collecting responses, and producing monthly briefs.
- To generate the monthly brief, pooled responses are sent to Anthropic's API and returned as a structured summary. Only anonymous codes accompany the text.
- To authenticate supervisors and administrators.
- To reply to enquiries you send us.
- To keep the service secure and operating correctly.
We do not sell personal data, we do not share it for advertising, and we do not use customer content to train machine learning models.
6. Legal bases (UK/EU customers)
- Contract — providing the service to a customer that has agreed to our terms.
- Legitimate interests — securing the service, and responding to enquiries you initiate.
- Employer's legal basis — where we act as processor, the customer is responsible for establishing a lawful basis for including employees, and for telling them about it.
7. Sub-processors
We use these providers to deliver the service. Each is bound by its own data protection obligations.
| Provider | Purpose | Data involved |
|---|
| Vercel | Application hosting and content delivery | Requests to the service |
| Neon (via Vercel Postgres) | Database hosting | All stored service data |
| Anthropic | Generating the monthly brief from pooled responses | Pooled, code-labelled check-in responses |
| Resend | Sending check-in invitations and monthly briefs | Recipient email addresses and message content |
These providers may process data in the United States and other countries. Where required, transfers rely on standard contractual clauses or an equivalent mechanism offered by the provider.
8. Retention and deletion
- Account and response data is retained while the organization is active.
- On request, or when an organization is closed, we delete the organization and everything attached to it: departments, roster, responses, and briefs.
- Removing an email address from a roster stops future invitations. It does not delete past responses, because no record connects the two.
- Contact form enquiries are kept in our email for as long as needed to deal with them and for ordinary business records.
- Backups held by our infrastructure providers expire on their own schedules after deletion.
9. Your rights
Depending on where you live you may have rights to access, correct, delete, or export your personal data, to object to or restrict processing, and to complain to a data protection authority.
If you are an employee of a customer, direct requests to your employer first — they control the data and can act faster. We will help them respond, and you can contact us directly at admin@roadcommand.co if you prefer.
One honest limitation: because responses carry no identifier, we cannot locate the specific responses written by a named individual. That is what makes the service anonymous, and it also means we cannot single out one person's answers for retrieval or deletion. We can delete an entire organization's responses on the customer's instruction.
10. Security
Data is encrypted in transit and at rest, passcodes are stored as bcrypt hashes, sessions use signed HTTP-only cookies, and API keys are held server-side only. Further detail is on the security page. No system is perfectly secure, and we do not claim otherwise.
11. Children
The service is a workplace tool sold to organizations and is not directed at children under 16.
12. Changes
If we make a material change we will update the date at the top of this page and, where the change significantly affects customers, notify them directly.
13. Contact
Road Command LLC, [ADD BUSINESS MAILING ADDRESS] — admin@roadcommand.co.