What this page covers
Harrison Ward Technology runs BandWagon. We use a small number of outside services to host it and deliver messages. Each service gets only the data it needs for its job. Several services are used only if an organization or a person turns on the related feature. We do not sell personal information, and sponsors get no participant data.
Some tools we run ourselves on our own servers, so no outside company receives data through them. These include our deployment platform (Coolify), our status monitoring (Uptime Kuma), our error monitoring (the local error log and a self-hosted GlitchTip), and our AI gateway (LiteLLM).
Current list
| Service | Purpose | Data it receives | When it is used |
|---|---|---|---|
| IONOS Always used | Cloud servers that run BandWagon, its database, and its cache. S3-compatible private object storage for driver documents and other uploaded files. | All service data, including account, household, event, and ride records. Sensitive profile fields such as phone numbers, exact addresses, and credentials are encrypted before storage. Message delivery logs record the number or email address each message was sent to, for troubleshooting and abuse limits. Uploaded driver documents. | Always. |
| Cloudflare Always used | DNS, network security, and Turnstile bot protection on sign-in and contact forms. Custom hostname certificates when a community uses its own domain. | IP address, browser and request details, and bot-check signals. Community hostnames. | Always for DNS, security, and Turnstile. Custom hostnames only if the organization adds its own domain. |
| SMTP2GO Always used | Sends email, such as sign-in codes, ride notices, and account and privacy notices. | Email address, message subject and text, and delivery status. | Always. A verified email is required for an account. |
| Twilio Only if enabled | Sends text messages (SMS and RCS) and handles STOP and HELP replies. | Mobile number, message text, and delivery status. | Only if a person adds a mobile number, for sign-in codes they request or text notices they opt in to. Ride text notices also require the organization to turn on text messaging. |
| Web push services (Apple, Google, Microsoft, Mozilla) Only if enabled | Delivers browser and installed-app notifications through the push service built into each browser. | A push subscription address for the device and an encrypted notification. The push service cannot read the message. | Only if a person turns on notifications on a device. |
| Google Maps Platform (Geocoding and Routes) Only if enabled | Turns an entered address into a general area and map coordinates. Suggests rides that fit a driver's route when RouteAssist is on. | Addresses or coordinates for pickup, drop-off, and event locations. No names or contact details are sent. | When the platform has mapping configured and someone enters an address. Route suggestions only if the organization turns on RouteAssist. |
| Google Calendar Only if enabled | Reads events from a calendar an admin chooses to connect. | The connected Google account identifier, the selected calendars, and event details. Access tokens are encrypted. | Only if an organization admin connects a Google calendar. |
| Microsoft Graph (Microsoft 365 calendars) Only if enabled | Reads events from a Microsoft calendar an admin chooses to connect. | The connected Microsoft account identifier, the selected calendars, and event details. Access tokens are encrypted. | Only if an organization admin connects a Microsoft calendar. |
| Google Document AI Only if enabled | Reads fields from a driver's license image to help an admin review it. A person always makes the approval decision. | The uploaded driver's license image and the fields read from it. | Only if the organization turns on AI document review. |
| AI model providers, through our self-hosted LiteLLM gateway Only if enabled | Optional help with admin tasks, such as turning event details into calendar entries or reading an insurance card image for review. The gateway routes each request to one of the model providers we have approved, so the provider can vary. We update this list before approving a new provider. | Only the text or image needed for the task the organization turned on. | Only if the organization turns on the specific AI feature. Matching, eligibility, and safety rules never use AI. |
| Stripe Only if enabled | Processes optional donations and sponsor payments on a Stripe-hosted checkout page. | Payment amount and status, and what the payer enters on the Stripe page. Card details go to Stripe and are never stored by BandWagon. | Only if someone chooses to give. |
| DoDomain Only if enabled | Guided DNS setup when an organization connects its own domain. | The domain name and the DNS records needed to connect it. No member data. | Only if an organization uses automatic custom domain setup. |
Where data is processed
BandWagon is operated from the United States and uses United States production hosting. Some providers may process data in other countries to deliver their service, as described in the Privacy Policy.
Changes to this list
When we add a provider that receives member data, we will update this page with a new version number before the provider is used. Organizations that have accepted the Organization Agreement will be told about material changes.
Questions
Contact [email protected].