5th Bull
Equipment maintenance, inspections, and work order management
Not signed in

Privacy Policy

Effective Date: July 30, 2026

This Privacy Policy explains how MaplesBoneYard LLC ("5th Bull," "we," "us," or "our") collects, uses, and shares information in connection with the 5th Bull fleet maintenance software (the "Service"). It applies to the companies that use the Service ("Customers") and the individual users those Customers create accounts for (drivers, mechanics, managers, etc.). 5th Bull is a business-to-business tool - it's not directed at, and we don't knowingly collect information from, individual consumers acting outside a business context, or from anyone under 18.

1. Information We Collect

Account and profile information. Company name, and for each user your company creates: username, role, and optionally an email address and/or phone number (used for password recovery and, if you opt in, critical-alert notifications).

Fleet and operational data ("Customer Data"). Whatever your company enters into the Service: equipment/vehicle records, work orders, inspection results and checklists, parts inventory, preventive-maintenance schedules, general labor time entries, notes, and any photos or PDF attachments your team uploads.

Billing information. Subscription plan and billing status. Payment card details are collected and stored directly by our payment processor, Stripe - we never see or store your full card number.

Usage and device data. Standard web server logs (IP address, browser user-agent, request timestamps), used for security, rate limiting, and troubleshooting.

Support and communications. Anything you send us directly, like support requests or emails.

2. How We Use Information

  • To provide, maintain, and secure the Service, including enforcing that each company can only see its own data (multi-tenant isolation).
  • To process payments and manage subscriptions, via Stripe.
  • To send transactional email (password resets, critical equipment alerts you've opted into, billing notices), via our email provider, Resend.
  • To respond to support requests.
  • To detect, investigate, and prevent fraud, abuse, and security incidents.
  • To improve the Service.

We do not sell your information, and we do not currently use any third-party advertising or analytics trackers on the Service - if that changes, we'll update this policy.

3. Cookies

We use a single session cookie to keep you logged in (marked HttpOnly and SameSite, and Secure in production so it's only ever sent over HTTPS). We don't use third-party advertising or tracking cookies.

4. Who We Share Information With

We share information only as needed to run the Service:

  • Stripe (payment processing) - billing and subscription data.
  • Resend (transactional email delivery) - the email address and content needed to send you a specific email.
  • Render (application hosting and database infrastructure) - all data stored in the Service, as our hosting provider.
  • Third-party systems you connect - if you generate an API key or configure a webhook, data flows to the destination you configured, under your control.
  • Law enforcement or legal process - if required to comply with applicable law, or to protect our rights, users, or the public.
  • A successor - if we're involved in a merger, acquisition, or asset sale, in which case we'll provide notice before data is transferred.

We don't sell Customer Data or personal information to third parties.

5. Data Retention

We retain your data for as long as your account is active. If you cancel your subscription, your data is retained but access to the Service is suspended - we don't run an automatic deletion process. If you'd like your data permanently deleted (after cancellation or at any other time), contact us at the address below and we'll process that request within a reasonable time.

6. Data Security

Passwords are hashed, never stored in plain text. We support optional two-factor authentication (TOTP) for user accounts. Data is transmitted over HTTPS. Every domain table is scoped by company, so one company's data is never visible to another. No system is perfectly secure, and we can't guarantee absolute security, but we take reasonable measures to protect your information and to detect and respond to incidents.

7. Your Choices and Rights

Depending on your role and jurisdiction, you may be able to: access, correct, or export your company's data directly within the Service (CSV export and print/PDF reports are available for most record types); request deletion of your account or company's data by contacting us; and opt in or out of optional critical-alert emails from your account settings. If your company is based somewhere with specific statutory privacy rights (for example, GDPR in the EU/UK or the CCPA/CPRA in California), contact us and we'll work with you to fulfill applicable requests.

8. International Data

Our infrastructure is hosted in [Region/Country - confirm with hosting provider]. If you access the Service from outside that region, your information will be transferred there.

9. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we'll provide reasonable notice (such as an in-app notice or email) before they take effect.

10. Contact

Questions about this Privacy Policy, or a data request? Reach us at privacy@5thbull.com.

v1.0