Security

How we handle evening dispatch data

Aligned with the Privacy Policy and Terms. This page summarizes operational safeguards for NEMT desks — not a substitute for the legal documents.

What data is uploaded

Depending on how your team uses AssignRide, uploads may include QRyde-related schedule PDFs or portal exports, period Excel workbooks, and company configuration (roster, rates, and similar operational data you choose to store).

Do not upload protected health information (PHI) until a Business Associate Agreement is in place — see the Privacy Policy and contact legal@assignride.com.

What data is stored

Company-scoped operational data (schedules, rates, roster, workbook state) is stored for your workspace so the evening flow can continue across sessions. Account and billing records are retained as described in the Privacy Policy.

PDF manifest content is processed in isolated server memory and is not written to disk for long-term storage, per the Privacy Policy.

Where data is processed

The Service runs on hosted cloud infrastructure. The Privacy Policy notes processing over encrypted HTTPS and infrastructure in SOC 2-compliant data centers. Exact cloud region listings for marketing claims should stay aligned with legal — see Privacy Policy.

Retention periods

  • PDF manifest content: deleted immediately after processing
  • Rate / monitor CSV handled in-browser for some flows: session only when applicable
  • Server request logs: 30 days
  • Account data: duration of account + 90 days after deletion
  • Billing records: 7 years (legal requirement)

Encryption

Data in transit is encrypted via TLS 1.2 or higher (HTTPS). Additional encryption and key-management details for data at rest should be confirmed with engineering/legal before stronger public claims — see developer notes in docs/MARKETING_CONTENT_TODO.md.

Access controls

Access uses authenticated sessions (Google OAuth via NextAuth). New companies request activation; an AssignRide admin approves before dispatch features unlock. Application roles limit who can manage team and company settings within an activated workspace.

Account separation

Operational data is scoped by company. Users belong to a company workspace; marketing and product copy should not imply cross-tenant data sharing.

Audit logging

Server request logs are retained for a limited period (see retention). Granular product-level audit trails for every dispatch action — if marketed — must match what the product currently records. Treat deeper audit claims as pending verification.

Subprocessors

Subprocessors include hosting, database, authentication, billing (Stripe), and messaging providers used for WhatsApp delivery. A public subprocessor list with legal sign-off is marked as a placeholder until published — contact privacy@assignride.com for the current list.

Data deletion

Account deletion and related rights are described in the Privacy Policy. Because manifest PDF content is not retained after processing, access/deletion requests cannot recover rider data that only appeared in those uploads.

BAA request process

Email legal@assignride.com to request a Business Associate Agreement. Do not upload PHI without a signed BAA. AssignRide does not use the phrase “HIPAA compliant” as a blanket marketing claim on this page.

Security contact

Security issues: security@assignride.com

Privacy: privacy@assignride.com

Legal / BAA: legal@assignride.com

Operator: AEM Spectrum Consulting LLC (see Privacy Policy)

Full legal detail: Privacy Policy and Terms of Service. We did not rewrite those documents as part of this marketing update.

Questions before you request access?

Book a demo and ask about data handling for your desk — or read Privacy and Terms first.

Access is reviewed before a production workspace is activated.