Who provides CMD Ops
CMD Ops is provided by Clear Frameworks ("Clear Frameworks," "CMD Ops," "we," or "us"). This policy covers the CMD Ops public website, application, support, and related paid or custom services.
Privacy Policy
This policy explains what CMD Ops processes, why it is needed, who may receive it, and how a company or individual may request access, correction, export, or deletion.
Effective and last updated: September 5, 2026
CMD Ops is provided by Clear Frameworks ("Clear Frameworks," "CMD Ops," "we," or "us"). This policy covers the CMD Ops public website, application, support, and related paid or custom services.
The business or organization that creates a CMD Ops company is generally responsible for deciding what workforce, customer, and job information belongs in its workspace and who may use it. Clear Frameworks processes that workspace information to provide CMD Ops and follow authorized instructions.
Employers and other company customers are responsible for giving notices, obtaining permissions, honoring worker and customer rights, and using data lawfully. If you use CMD Ops through your employer, requests about an employment record may need to be handled by that employer.
We process names, email addresses, phone numbers, profile images, account and authentication identifiers, company name, industry, team size, timezone, business contact details, role, membership, invitations, notification preferences, and account activity.
Authentication providers handle passwords and recovery credentials. Clear Frameworks does not receive a readable copy of your password.
Depending on how a company uses CMD Ops, workspace data may include customer and job names, contact details, addresses, scope, estimates, status, priority, assignments, schedules, notes, requests, change information, materials, receipts, reports, and related operational history.
The company chooses this content and is responsible for avoiding unnecessary personal or sensitive information.
CMD Ops may process employee names, contact details, positions, employee numbers, roles, assigned jobs, schedules, clock-in and clock-out times, breaks, work locations, time segments, timecard status, approvals, job history, and optional labor cost or rate information.
This information is used to operate the company workspace, show each user the appropriate work surface, prepare requested exports, maintain history, secure access, and support the account. CMD Ops does not determine whether a time entry, break, classification, pay practice, or employment decision complies with law.
Users may upload photos, PDFs, receipts, contracts, material lists, notes, and other job or company files. We process the file, filename, type, size, storage path, visibility setting, related job or employee, uploader, and timestamps to store and display it to authorized users.
Do not upload passwords, full payment-card numbers, medical records, government identification, or other restricted information unless a written order expressly approves that data type and its safeguards.
Job addresses may be used to display jobs on a map or open directions. Live workforce location is a separate paid capability. When a company has that capability, the supported CMD Ops client requests device location only after the employee enables in-app location consent and device permission and the client identifies an open shift. It is designed to pause collection during an open lunch break and stop requesting samples after clock-out or revocation. Paid activation waits for the same boundary to be verified on the server.
A location sample may include latitude, longitude, accuracy, capture time, employee, shift, job context, and account that submitted it. The planned default location-retention setting is 90 days, within an allowed account setting of 1 to 365 days; paid activation also waits for automated retention deletion to pass acceptance. Location is used for enabled dispatch functions—not advertising. Route, arrival-history, and travel-analysis features are not included in the current release. Companies remain responsible for lawful notice, consent, access, and workforce use.
If a company purchases a paid plan or custom service, we process plan, order, quantity, billing contact, invoice and payment status, transaction identifiers, renewal and cancellation dates, credits, refunds, tax information, and related support history. A payment processor may collect payment-card or bank details under its own privacy terms. Clear Frameworks does not store full payment-card numbers.
A billing policy or order does not mean that self-service checkout or a particular payment method is currently available.
We process IP address, browser and device details, user agent, timestamps, authentication and request records, application route and work surface, security events, audit history, error details, usage counts, support reports, and similar diagnostic information. The site and application also use local or session storage needed for sign-in, company choice, preferences, and application operation.
A support report may include the description you submit, severity, current application route, work surface, user agent, company, account, and time.
We use information to create and authenticate accounts; operate company workspaces; enforce company, role, and feature boundaries; save and return records; provide maps, files, exports, and enabled functions; measure plan limits; process paid orders; answer support; maintain security and reliability; investigate misuse; improve the service; and meet legal, tax, and accounting duties.
We do not use private Customer Data to train a shared AI model without written permission. If an optional AI feature later processes Customer Data, its availability, provider handling, and relevant controls must be disclosed before the feature is enabled.
We disclose only the information reasonably needed for an approved function to service providers that support hosting, content delivery, database, private storage, authentication, mapping, fonts, email, monitoring, support, and, when purchased, billing or an expressly enabled integration. Current technical dependencies include Vercel, Supabase, Google Fonts, jsDelivr, and OpenStreetMap services. Provider availability and details may change as the service changes.
We may also disclose information when required by law; to protect users, the service, or legal rights; with the company customer's direction; or in a business transfer subject to appropriate confidentiality and notice. We do not rent personal information.
Clear Frameworks does not sell personal information and does not share private CMD Ops workspace data for cross-context behavioral advertising. If public-site analytics or advertising practices materially change, we will update this policy and provide any choices required by law before using the new practice.
Company data is separated by company and application access is based on signed-in membership, role, work surface, feature entitlement, and the requested record. Company owners and authorized administrators control memberships and may be able to view, correct, export, or delete records for their company. Certain employee, compensation, restricted-file, and location information receives narrower access.
The Security page describes verified safeguards without claiming that any system is risk-free.
Active workspace records are generally kept while the account is active and as needed to provide the service. Companies may delete supported records, and location information follows the location-retention setting. Security, audit, billing, tax, support, and legal records may be kept longer when reasonably necessary.
After a company requests account deletion or service ends without continuing on the Free plan, we normally provide a 30-day recovery period, remove active workspace data within 60 days after that period, and allow backup copies to expire through normal cycles within up to 90 additional days. A legal hold, security investigation, dispute, unpaid accounting record, or legal requirement may require limited information to be retained longer. Canceling a paid plan alone does not delete the workspace.
A company owner may use available product controls or contact us to request a standard export, correction, restriction, or company deletion. We may verify identity, authority, and company ownership first. We target a substantive response within 14 days, although applicable law may provide a different period.
An individual may contact us about personal information. When the company customer controls the record, we may direct the request to that company and assist it as appropriate. We will not withhold a standard Customer Data export solely because a paid plan was canceled or an amount is disputed.
We use technical and organizational safeguards appropriate to the service, including encrypted connections, authentication, tenant and role checks, private storage, short-lived file links, audit records, and restrictive browser security headers. No system can guarantee absolute security.
Report suspected unauthorized access or a security issue promptly to hello@retehost.com with "CMD Ops Security" in the subject.
CMD Ops is a business service for adults and is not directed to children under 18. Customers should not create accounts for children or place children's personal information in CMD Ops unless a written service scope and applicable law expressly allow it.
CMD Ops is operated from the United States. If you access it elsewhere, you are responsible for determining whether the service and your data use are lawful in that location.
We may update this policy as the product, providers, or law changes. We will post the updated effective date and give account owners reasonable notice before a material change applies to active workspace data.
Privacy questions and requests may be sent to hello@retehost.com. Clear Frameworks is based in Roanoke County, Virginia.