Common Ground
monthly team check-ins
Legal

Privacy policy

Last updated August 1, 2026
Draft — not yet reviewed by counsel. This document was prepared to describe how the service actually works, but it has not been reviewed by a lawyer and still contains unfilled placeholders. It should not be relied on until it has been. Edit app/_content/company.js to fill in the remaining details and clear this banner.

1. Who we are

Common Ground is operated by Road Command LLC ([ADD BUSINESS MAILING ADDRESS]). This policy explains what personal data the service handles, why, and what choices people have. Questions go to admin@roadcommand.co.

2. Two different relationships

It matters which one applies to you, because it determines who decides what happens to your data.

3. What we collect

From customer organizations

From employees

From website visitors and enquiries

4. Cookies

The service sets only functional cookies. There are no advertising or analytics cookies.

Employees answering a check-in are not given any cookie, because they are never signed in.

5. How we use data

We do not sell personal data, we do not share it for advertising, and we do not use customer content to train machine learning models.

6. Legal bases (UK/EU customers)

7. Sub-processors

We use these providers to deliver the service. Each is bound by its own data protection obligations.

ProviderPurposeData involved
VercelApplication hosting and content deliveryRequests to the service
Neon (via Vercel Postgres)Database hostingAll stored service data
AnthropicGenerating the monthly brief from pooled responsesPooled, code-labelled check-in responses
ResendSending check-in invitations and monthly briefsRecipient email addresses and message content

These providers may process data in the United States and other countries. Where required, transfers rely on standard contractual clauses or an equivalent mechanism offered by the provider.

8. Retention and deletion

9. Your rights

Depending on where you live you may have rights to access, correct, delete, or export your personal data, to object to or restrict processing, and to complain to a data protection authority.

If you are an employee of a customer, direct requests to your employer first — they control the data and can act faster. We will help them respond, and you can contact us directly at admin@roadcommand.co if you prefer.

One honest limitation: because responses carry no identifier, we cannot locate the specific responses written by a named individual. That is what makes the service anonymous, and it also means we cannot single out one person's answers for retrieval or deletion. We can delete an entire organization's responses on the customer's instruction.

10. Security

Data is encrypted in transit and at rest, passcodes are stored as bcrypt hashes, sessions use signed HTTP-only cookies, and API keys are held server-side only. Further detail is on the security page. No system is perfectly secure, and we do not claim otherwise.

11. Children

The service is a workplace tool sold to organizations and is not directed at children under 16.

12. Changes

If we make a material change we will update the date at the top of this page and, where the change significantly affects customers, notify them directly.

13. Contact

Road Command LLC, [ADD BUSINESS MAILING ADDRESS] — admin@roadcommand.co.