Privacy Policy
Effective: 2026-06-22 · Last updated: 2026-07-01
Who we are
Holler is a workplace notification service operated by Brightstack Labs ("Brightstack Labs," "we," "us," or "Holler"). A worker can send an alert asking for help, and the people designated as responders are notified by push notification and email. This policy explains what data we collect, why, who we share it with, and the choices you have.
Questions or requests: privacy@hollerhq.com.
What we collect and why
We collect only what we need to run the Service. The categories below match what the app actually stores.
- Account email. Used as your login identity and to send sign-in confirmation and service messages. Verified by a confirmation link at signup.
- Password. Stored only as a salted hash by our authentication provider. We never see or store your plain password.
- Display name. Shown to others in your group so people know who fired, claimed, or commented on an alert.
- Phone number (optional). Collected so we can send SMS alerts when the SMS feature becomes available. SMS is not active today, and we do not currently send SMS or verify phone numbers. If you do not enter a phone number, the Service still works over push and email.
- Group and role membership. Which groups you belong to, your roles (Admin, Support, Floor), your shift assignment, and your availability (whether you have marked yourself away). Used to route alerts to the right people.
- Alert content and custom fields. The alert type, priority, location, and any custom field values entered when an alert is fired, plus who fired it, who claimed it, and the cause code and resolution notes recorded when it is resolved. This is free text and is stored as you enter it.
- Comments. Free-text notes added to an alert, shown to everyone in the group and attributed to their author.
- Activity history. A record of status changes on each alert (fired, claimed, resolved, canceled) with timestamps and who acted, used for the history view and reports.
- Device push tokens. When you enable push notifications on a mobile device, we store the push token for that device so we can deliver alerts. Removed when you sign out or the device unregisters.
- Billing identifiers. If and when you buy a paid plan, our payment processor assigns identifiers we store to manage your subscription. We do not store full card numbers.
- Logs and error data. Our servers and providers keep operational logs (such as timestamps, request and delivery status, and error messages) used to run, secure, and debug the Service.
How we use your data
- To provide the Service: route alerts, deliver notifications, and track claims and resolutions.
- To authenticate you and keep your account secure.
- To provide reports and history to your group.
- To respond to support requests.
- To operate, maintain, debug, and improve the Service, including aggregated, de-identified statistics that do not identify you.
- To handle billing if you are on a paid plan.
- To meet legal obligations and enforce our Terms.
We do not sell your personal data, and we do not share it with third parties for their own advertising or marketing.
Service providers we share data with
We use a small set of service providers (sub-processors) to run the Service. Each one only receives the data it needs for its job.
- Supabase. Hosts our database and handles authentication. Stores your account, profile, group, alert, comment, and device-token data, and the hashed password.
- Vercel. Hosts the Holler web app and serves it to your browser. Processes standard request and connection data.
- Resend.Sends our email notifications. Receives the recipient's email address and the contents of the alert email (alert type, group name, location, who reported it, time, and any custom field values).
- Expo. Delivers mobile push notifications. Receives the device push token and the push message (alert title and a short summary). Expo passes the message to Apple and Google for delivery.
- Apple Push Notification service and Google Firebase Cloud Messaging. The operating-system push services that deliver notifications to iPhones and Android phones.
- Cloudflare. Manages our domain (DNS) and routes inbound email sent to our addresses.
Not active yet.When SMS becomes available, we plan to use a third-party messaging provider to send text messages, which would receive the recipient's phone number and the alert text. When paid plans go live, we plan to use Stripe to process payments, which would receive billing and payment details. Neither is in use today, and this policy will be updated before either is turned on.
We may also disclose data if required by law, to protect our rights or the safety of others, or in connection with a merger, acquisition, or sale of assets, in which case we will require the recipient to honor this policy.
Security
We take reasonable measures to protect your data:
- Data is encrypted in transit (TLS) and at rest on our managed database.
- Passwords are stored only as salted hashes by our authentication provider.
- Access between groups is isolated by row-level security, so one group cannot see another group's data.
Your data is not end-to-end encrypted. Alert text, comments, and custom fields are stored as readable text so the Service can display, route, and email them. That means Holler staff and the service providers above can access this data as needed to run the Service. Do not enter anything into Holler that you would not want stored this way, and do not enter export-controlled data (see our Terms of Service). No method of transmission or storage is perfectly secure.
Where your data is stored
Your data is stored and processed in the United States by the providers listed above. If you use the Service from outside the United States, you understand that your data will be processed in the United States.
How long we keep it, and how to delete it
We keep your data for as long as your account is active, so your history and reports stay intact. We do not run a fixed automatic purge.
When you delete your account, we remove your login, your profile (name, email, and phone), your group memberships, and your device notification tokens. Because Holler is a workplace tool, the alerts and comments created in a group are that workplace's operational records (used for reporting and root-cause analysis): we keep them, but your name is removed from them (shown as a former member) and they are no longer linked to your account. We may also keep limited billing records where the law requires. You can delete your account yourself in the app right away (see below); if you ask us by email instead, we complete it within 30 days.
Deleting your account
You can delete your account yourself, at any time, from within the app: go to Settings and choose Delete account. Deletion is immediate and permanent. The steps, and what is kept or removed, are also on our account deletion page.
If you no longer have the app, email privacy@hollerhq.com from the address on your account, or support@hollerhq.com, and we will delete it as described above.
Children
Holler is a workplace tool meant for adults. It is not directed to children, and we do not knowingly collect personal data from anyone under 13. If you believe a child has given us personal data, contact privacy@hollerhq.com and we will delete it.
Your California privacy rights
If you are a California resident, the California Consumer Privacy Act, as amended by the CPRA, gives you the right to:
- Know what personal information we collect about you and how we use and share it.
- Access a copy of your personal information.
- Correct inaccurate personal information.
- Delete your personal information, subject to legal exceptions.
- Not be discriminated against for exercising these rights.
We do not sell or share your personal information as those terms are defined under California law, and we do not use sensitive personal information for purposes that would trigger a right to limit. To exercise any of these rights, email privacy@hollerhq.com. We will verify your request using your account email and respond as required by law. You may use an authorized agent where the law allows.
If you are in the EEA or UK
Holler is operated from the United States and is built for U.S. workplaces. We do not target the Service to the European Economic Area or the United Kingdom. If data protection law there applies to you, you may have rights to access, correct, delete, restrict, or object to the processing of your personal data, and to data portability. To make a request, contact privacy@hollerhq.com, and we will honor rights that apply to you. Where we process your data, we rely on performing our contract with you, your consent, and our legitimate interest in operating and securing the Service.
Changes to this policy
We may update this policy. If a change is material, we will update the "Last updated" date above and give notice by email or an in-product notice before it takes effect. Continuing to use the Service after a change takes effect means you accept the updated policy.
Contact
Privacy requests: privacy@hollerhq.com
Everything else: support@hollerhq.com