Privacy Policy
Cooper is owned and operated by CRY Holdings LLC, doing business as Cooper (“Cooper,” “we,” “us”). This Privacy Policy explains what information the Cooper platform collects, how it is used, who it is shared with, and the choices available to you. It applies to the Cooper website, kiosk application, employee application, management portal, and voice features (together, the “Service”).
The short, honest version: Cooper exists to record who moved what material, when, and for which job — that's the product, and your employer (the company that signed up) controls that data. We collect what's needed to run the Service, we don't sell personal information, and we don't run third-party advertising or tracking.
1. Cooper and your employer: who controls what
Cooper is workplace software. The company that registers for Cooper (the “Customer” — typically your employer) decides who its users are, what roles they hold, and how the records the Service produces are used inside its business. For the workforce activity records at the core of the product — takes, returns, transfers, requests, acknowledgments — the Customer is the controller of that data, and Cooper processes it on the Customer's behalf to provide the Service.
If you are an employee using Cooper at work, your employer is responsible for telling you about its use of these records and for handling requests about them (Section 10). For data about direct visitors to our website or direct communications with us, Cooper is the controller.
2. What we collect
Account and identity
- Name, work email address (where provided), and assigned role.
- Sign-in credentials: PINs are stored only as cryptographic hashes; badge codes; company sign-in credentials; password-based logins are handled by our authentication provider.
Operational records (the product itself)
- The Customer's inventory catalog: items, quantities, categories, locations, costs, jobs, fleet vehicles.
- The transaction ledger: every recorded take, return, receive, transfer, and adjustment — including which user recorded it, timestamps, quantities, the job or destination it was tagged to, and the acknowledgment stamp given at finalization (Section 5.3 of the Terms).
- Requests and their lifecycle (submitted, approved, staged, picked up, and by whom).
- Learned usage patterns derived from the ledger (for example, an employee's usual take quantities) and notes users explicitly ask Cooper to remember.
Device and technical
- Kiosk device identifiers and device settings (for example, a kiosk's home location).
- Basic technical data needed to operate: browser type, app version, connection state, and error logs. We do not use third-party analytics or advertising trackers on the Service.
- Cookies and local storage are used only to keep you signed in, remember device settings, and hold the local offline copy of your company's data — not for advertising.
Communications
- Emails you send us, early-access inquiries, and support conversations.
- Transactional emails the Service sends (for example, request notifications), where enabled.
3. How we use information
- To provide the Service: recording and synchronizing material movements, deriving counts, routing requests, sending in-product notifications, and operating role-based access.
- To keep accurate, attributable records — attribution of actions to the signed-in user is a core, intended feature of the product, relied on by your employer.
- To secure the Service, prevent abuse, and debug problems.
- To improve the Service, using aggregated or de-identified information where practicable.
- To communicate with account contacts about the Service.
- Not to sell personal information, and not to serve third-party ads. We also do not use your company's private data to train generalized AI models.
4. Voice and AI features
Cooper's voice assistant is optional and works like this:
- Wake-word detection (“Hey Cooper”) runs on the device while the app or kiosk is open with microphone permission; audio is analyzed locally for the wake word.
- When a voice session is active, microphone audio is streamed to our AI provider (currently OpenAI) to transcribe and respond. Those interactions are processed under that provider's data-protection terms; we do not permit them to use this audio to train their generalized models.
- Voice-proposed actions become records only after an on-screen confirmation, and material-out actions additionally require the same acknowledgment as any other take.
5. When information is shared
- Within your company. Operational records are visible to the Customer's users according to their roles — that is the product. For example, managers can see who took what and each vehicle's stock.
- Service providers. We share data with the infrastructure providers below, only as needed to run the Service.
- Legal. We may disclose information if required by law, or to protect the rights, safety, and property of Cooper, our customers, or the public.
- Business transfers. If Cooper is involved in a merger, acquisition, or sale of assets, data may transfer with the business, subject to this policy.
- We do not sell or rent personal information, and we have not done so.
6. Service providers we use
| PROVIDER | WHAT IT DOES |
|---|---|
| Supabase | Database, authentication, and server functions (primary data store) |
| PowerSync | Synchronization between the server and each device's offline copy |
| Cloudflare | Website and application hosting, content delivery, and network security |
| OpenAI | Voice transcription and AI responses when Cooper AI is used |
| Resend | Transactional email delivery, where email notifications are enabled |
Providers may change as the Service evolves; this page will be kept current.
7. Retention
- The transaction ledger is append-only by design — it is your company's permanent record of material movements and is retained for as long as the Customer's account exists.
- Account data is retained while the account is active. When an employee is deactivated, their sign-in stops working but their name remains attached to historical records (the ledger stays truthful).
- After account termination, Customer data is available for export for 30 days and then deleted from production systems in the ordinary course, subject to routine backups and legal obligations.
- Voice audio is processed to provide the session and is not kept by Cooper as recordings.
8. Security
- Every row of company data is isolated per organization and enforced at the database layer (row-level security), not just in the app.
- PINs are stored only as salted cryptographic hashes; PIN vault reads and administrative actions run through server-verified functions.
- Data in transit is encrypted (TLS); data at rest is encrypted by our infrastructure providers.
- No system is perfectly secure; we will notify affected customers of a breach as required by law.
9. Local copies on devices
Because Cooper is offline-first, each signed-in device keeps a local copy of the company's operational data so work continues without connectivity. That copy lives on the device until the device is signed out or its site data is cleared. The Customer is responsible for the physical security of its kiosks and devices and for signing out or wiping devices it retires.
10. Your rights and choices
- Employees and workforce users: because your employer controls the workplace records the Service holds, requests to access, correct, or delete those records should go to your employer. We support Customers in fulfilling them. Note that the ledger's factual history of recorded movements is the Customer's business record and may be retained by the Customer.
- Website visitors and direct contacts: you may request access to or deletion of the information Cooper holds about you directly by emailing us (Section 13). We will respond as applicable law requires (including, for California residents, the CCPA/CPRA).
- Microphone access for voice features is controlled by your device's permissions and is optional.
11. Children
The Service is workplace software, is not directed to children, and may not be used by anyone under 16. We do not knowingly collect information from children.
12. Changes to this policy
When this policy changes, the version and effective date above will change, and material changes will be surfaced in the Service or by notice to account contacts. Continued use after an update means the updated policy applies.
13. Contact
Privacy questions or requests: [email protected].