Employee Data & Privacy Policy
Discount Forklift — Employee Archive and the generator applications
Version 1.0 · Effective 2026-08-26 · Owner: Stephen Cunningham
Prepared and issued by Stephen Cunningham, 2026 · Paralegal review complete
Applies to staff in Colorado (Denver), Texas (DFW), Arizona (Phoenix), and Nevada (Vegas).
This is the canonical copy. The Employee Archive serves it at /privacy, and every generator app links here. If a copy elsewhere disagrees with this file, this file wins.
⚠️ AMENDMENT PENDING REVIEW — the statements below are accurate, but this text has not been reviewed.
Drafted 2026-09-03. Version 1.0 above is the issued, reviewed text. The amendment below is factually correct as of that date but has not been through review, and this document should not be treated as formally amended until it has.
What changed. The Employee Archive stopped storing personal mobile numbers on 2026-09-03. The number was never used for anything except inferring a branch from an area code, and that now happens while the roster is being read, without keeping the number. The field is gone from the schema, the roster parsers, the internal service payload and the profile editor.
The deletion has been carried out. Mobile numbers held under the previous version of this policy were deleted on 2026-09-03 by an administrator action that reports how many were removed. Until this amendment was made, a statement that we did not hold mobile numbers would not have been true; it is true now.
This removes a data category rather than adding one, which is the safe direction for a privacy notice.
1. What this covers
Discount Forklift runs a small set of internal tools that hold employee media and contact details:
| Application | What it does |
|---|---|
| Employee Archive | The single store. Holds every employee's photos and roster contact details. |
| Email Signature Generator | Reads a headshot, generates an email signature, files it back. |
| Sales Signature Creator | Reads a headshot, generates a sales signature, files it back. |
| Business Card Creator | Reads a headshot, generates a business card, files it back. |
| OSHA License Generator | Reads a headshot, generates a forklift operator card, files it back. |
The generators hold nothing of their own. They read from and write to the Archive, which is the only place employee data lives.
2. What we collect
Contact and role details, taken from the staff roster export that HR uploads:
- Name (and the roster's own spelling of it)
- Job title, department, branch location
- Work phone extension and direct office line
- Work email address
- Employment status (current or former), derived from whether you appear on the most recent roster
Images, uploaded by staff or generated by our own tools:
- Headshot photographs
- Email signatures, sales signatures, business cards
- OSHA forklift operator cards
OSHA certification records — for operators we certify: operator name, training date, evaluation date, the person who performed the training or evaluation, the issue date, and the resulting card. Kept because 29 CFR 1910.178(l)(6) requires the employer to maintain this record.
What we deliberately do not collect
We hold no Social Security numbers, dates of birth, home addresses, driver's licence numbers, financial account details, wage or payroll data, and no medical or health information. None of these appear anywhere in these systems, and none should ever be added to them without a review against this policy first.
About personal mobile numbers
We do not store your personal mobile number.
It may still appear in the staff roster export that HR uploads. When it does, it is read once while the roster is being processed — only ever to work out which branch a person belongs to from their area code, and only when the roster does not say — and it is not written to your record. It was never printed on a signature, a business card, or any other generated artwork; those carry your direct office line and the corporate switchboard.
Mobile numbers held under the previous version of this policy have been deleted.
3. Why we hold it
Solely to produce and keep track of company-issued materials: signatures, business cards, headshots, and OSHA certification cards. We do not use this data to evaluate performance, to monitor staff, or to make any decision about pay, promotion, discipline, hiring, or termination.
4. We do not use facial recognition
This is a firm commitment, not a description of current convenience.
Our tools use AI to classify what kind of image a file is, to read printed text off signatures and business cards, and to generate card artwork. Nothing in these systems generates a facial map, facial geometry, a facial template, or any face embedding, and nothing identifies or matches a person by their face. Photographs are linked to people by name, never by biometric comparison.
Under Colorado's biometric provisions (added to the Colorado Privacy Act by HB 24-1130, effective 1 July 2025) and the Texas Capture or Use of Biometric Identifier Act (Tex. Bus. & Com. Code § 503.001), a photograph is not a biometric identifier unless it is processed to extract identifying characteristics such as a facial map or facial geometry. Because we perform no such processing, we do not collect biometric identifiers or biometric data.
If that ever changes, this policy must change first. Adding face matching, face search, or any facial-template feature would require written employee consent, a written biometric retention policy, and defined destruction timelines before a single face is processed. No such feature may ship without that work being done.
5. Who can see it
Access requires signing in with your Discount Forklift Microsoft account. There is no public access and no anonymous access to any of it.
- Photographs are stored privately. They have no public URL and cannot be linked to or shared outside the system. They are streamed only to a signed-in user.
- Sign-in is handled by Microsoft Entra. We never see, hold, or store your password.
- The generator apps reach the Archive using a server-side service credential that never reaches your browser.
- In practice the Archive is used by a small number of administrative staff. The wider workforce never opens it; they receive the finished signature or card.
- Administrative functions — deleting an asset, clearing the registry — are restricted to named administrators.
6. Who else processes it
We use these vendors. Each is bound by its commercial terms.
| Vendor | What it handles | Note |
|---|---|---|
| Microsoft (Entra ID) | Sign-in | Existing company tenant. We hold no passwords. |
| Vercel | Hosting and private image storage | Images stored as private blobs with no public URL. |
| Google (Gemini API) | Card and signature image generation | Paid tier. Under Google's paid-service terms, prompts and responses are not used to train or improve Google products. |
| Anthropic (Claude API) | Classifying images, reading roster and signature text | Commercial API terms. |
We do not sell employee data, share it with advertisers, or disclose it to any third party for a commercial purpose.
7. How long we keep it
Current employees — for the duration of employment, plus the retention periods below.
Former employees — records are retained indefinitely. Your profile is marked former when you no longer appear on the current roster, but your photographs and generated materials are not automatically deleted. This is a deliberate business decision: these are company-issued materials with continuing historical and operational value, and the data held is contact and role information rather than sensitive personal information.
OSHA certification records — retained for a minimum of three years, matching the three-year re-evaluation cycle in 29 CFR 1910.178(l)(4)(iii), and in practice for the duration of employment plus three years, so that a certification can be evidenced after an incident.
However: see the next section. Indefinite retention is our default, not a refusal.
8. Your rights — access, correction, and deletion
We will honour any deletion request from a current or former employee. If you ask us to remove your photographs, your generated materials, or your contact record, we will do it. You do not need to give a reason, and you do not need to cite a statute.
The only exception is OSHA certification records, which we are legally obliged to maintain as employment safety records for the retention period above. If you ask for deletion, we will remove everything else and tell you plainly what we retained and why.
You may also:
- Ask what we hold about you. We will provide a complete list.
- Correct anything wrong — a misspelled name, a stale title, a wrong branch.
- Ask us to correct your direct office line if what we hold is wrong. (The right to have your personal mobile removed, listed here previously, no longer applies: we no longer hold one.)
- Ask us to replace or remove a photograph you are unhappy with.
How to ask: email Stephen Cunningham at stephen@discountforklift.us, or raise it with HR and it will be routed. We aim to complete requests within 30 days.
We will not retaliate against anyone for making a request under this policy.
Rights specific to your state
- Colorado — C.R.S. 8-2-129 gives you the right to inspect your personnel file once per calendar year, and once more after you leave. We treat a request covering data in these systems the same way.
- Nevada — NRS 613.075 gives you the right to inspect records used to determine your qualifications for employment, promotion, or disciplinary action. Nothing in these systems is used for those purposes, but the right applies and we will honour it.
- Texas and Arizona — no general statutory right of access to personnel records applies to private employers in these states. We extend the same access and deletion rights to Texas and Arizona staff as a matter of company policy.
Colorado's and Texas's consumer privacy statutes (the CPA and the TDPSA) exclude data held about people in an employment context, so their consumer-request machinery does not formally apply here. We are choosing to offer these rights anyway.
9. How it is protected
- Every route requires an authenticated company sign-in; unauthenticated requests are rejected before reaching any data.
- Images are stored in private storage with no public URL and are streamed only to signed-in users, cached in that user's browser only.
- Service credentials are held server-side and never sent to a browser. No credential or secret is committed to source control.
- All traffic is HTTPS. The Archive rejects any configuration that is not HTTPS.
- Materials can only be filed against a person who is on the current staff roster, which prevents records accumulating against people who do not exist.
- Administrative and destructive functions are restricted to named administrators.
These practices are maintained under C.R.S. 6-1-713.5 (Colorado), Tex. Bus. & Com. Code § 521.052 (Texas), and NRS 603A.210 (Nevada), each of which requires reasonable security procedures appropriate to the nature of the information and the size of the business.
10. If something goes wrong
We maintain a written breach response procedure covering all four states. If a security incident affects employee data, we will investigate promptly and notify affected staff. Our operating standard is notification within 30 days, which is the strictest of the four state deadlines that apply to us, and we apply it in every state rather than tracking four different clocks.
Internal procedure: Security Incident & Breach Response Procedure.
11. Questions and changes
Questions, requests, or concerns: stephen@discountforklift.us.
This policy is reviewed when the systems change materially and at least annually. The version and effective date are at the top. Material changes will be communicated to staff rather than made silently.