Privacy Policy
Last updated: 2026-07-23
This Privacy Policy explains how Metiix, LLC, a Minnesota limited liability company ("Metiix", "we", "us", or "our"), collects, uses, discloses, and safeguards personal information in connection with the Snowmass snow-removal fleet dispatch platform and related websites, applications, and services (collectively, the "Service"). It applies to the operators, dispatchers, administrators, and customers of the organizations that subscribe to the Service. We act as a data processor (service provider) on behalf of our subscribing organizations for most operational data, and as a data controller for our own account and billing records.
Information we collect
We collect the information needed to operate the Service for your organization and its customers. The categories below describe what we collect and how it reaches us.
- Account and contact data — names, business email addresses, phone numbers, organization and role information, and authentication records such as the digest of your sign-in session token. Our sign-in is passwordless, so we do not store account passwords.
- Customer and property data — the property addresses, service locations, property boundaries, and service instructions that your organization enters so the Service can dispatch work.
- Usage and telemetry data — log entries, device and browser details, IP address, timestamps, feature interactions, and diagnostic information generated as you use the Service.
- GPS and precise location data — the real-time location of enrolled vehicles and operator devices, reported only during active runs, which the Service uses to assign and re-assign stops, detect arrivals at a property geofence, provide customer arrival estimates, and create service records. We do not track vehicles or devices between runs. Precise geolocation is treated as sensitive personal information under the California Privacy Rights Act and as sensitive data under several other state privacy laws, and we handle it as described in "How we use information" and "Sensitive personal information" below.
- Billing data — the subscription, active-vehicle counts, and payment records used to invoice your organization. Card details are handled by our payment processor; we do not store full card numbers.
- Communications and support data — messages, incident reports, photos, and any information you provide when you contact us or use in-app messaging.
- Cookies and similar technologies — a small number of strictly necessary first-party cookies and similar storage used for authentication and security (including a sign-in session cookie shared across Snowmass applications on the snowmass.io domain), and for remembering interface preferences such as your language and light/dark theme. We do not use advertising, analytics, or tracking cookies, and we do not permit third parties to place cookies for cross-context behavioral advertising.
How we use information
We use personal information to provide, secure, and improve the Service.
- To operate the Service — authenticate users, dispatch and re-assign work in real time, detect arrivals, log materials and incidents, and send operational and customer notifications.
- To bill and administer accounts — calculate the monthly base fee and seasonal per-active-vehicle fees, pass through SMS costs, and process payments.
- To secure the Service — detect, investigate, and prevent fraud, abuse, and unauthorized access, and to maintain audit and diagnostic logs.
- To support and communicate with you — respond to requests, send service and administrative messages, and share important changes.
- To improve the Service — analyze aggregated usage to understand performance and reliability and to develop new features.
- To comply with law — meet legal, tax, and regulatory obligations and enforce our agreements.
Sensitive personal information
We use and disclose sensitive personal information — including precise geolocation — only for the purposes permitted by applicable law: to provide the Service that your organization has requested, to detect and prevent security incidents and fraud, to ensure physical safety, for quality assurance, and to comply with law. We do not use sensitive personal information to infer characteristics about any individual, and we do not sell it or use it for advertising. Because our use stays within these permitted purposes, applicable law does not require us to offer a separate "Limit the Use of My Sensitive Personal Information" option.
Location tracking of operators
The Service continuously collects the precise location of enrolled vehicles and signed-in operator devices while a run is active. This location tracking is a core function of the Service: it is how work is assigned, arrivals are detected, customers are given accurate arrival estimates, and service is documented. We collect this data on the instruction of the subscribing organization — typically the operator's employer — and process it as that organization's service provider. Tracking is limited to active runs; the Service does not collect vehicle or device location when no run is active. While a run is paused, the Service still receives the vehicle's position so the run can resume, but assigns no new work; ending the run stops location collection. Subscribing organizations are responsible for providing their operators and drivers any notice of, and obtaining any consent to, location tracking and workplace monitoring that applicable law requires, including state statutes governing employee electronic monitoring and vehicle tracking devices. Operators with questions about how their location data is used should contact their organization, and may also contact us at privacy@snowmass.io.
Automated dispatch decisions
The Service uses an automated dispatch algorithm (our "swarm" engine) to decide, in real time, which service stop each vehicle is assigned next. These decisions are based on operational data — including the vehicle's GPS position, road travel times, the route-order settings your organization chooses, and the status of each stop — and are made without human involvement at the moment of assignment. They decide the order of work within a run that your organization has already configured and staffed; they do not make decisions about hiring, firing, discipline, compensation, or hours, and your organization's dispatchers can review, reserve, and override any assignment at any time.
If you are an operator or another individual affected by such a decision, this is your notice that it is made by automated processing of personal information. Where applicable law gives you rights regarding automated decision-making or profiling, you may exercise them by contacting privacy@snowmass.io or through your organization. In particular, Québec residents may ask to be informed of the personal information used and of the principal reasons and the principal factors that led to the decision, to have that personal information corrected, and to submit observations to a member of our personnel who is in a position to review the decision; Minnesota residents may question the result of profiling that produces a legally significant effect.
Legal bases for processing
Where the laws of Canada, Quebec, or a US state apply, we rely on one or more of the following legal bases: performance of our contract with your organization; our legitimate interests in operating, securing, and improving the Service; compliance with a legal obligation; and consent, where consent is required (for example, for certain SMS communications). Where we act as a processor on behalf of your organization, that organization is responsible for establishing the appropriate legal basis for the data it directs us to process.
How we share information
We do not sell personal information, and we do not share it for cross-context behavioral advertising. We have not sold or shared personal information, as those terms are defined in the California Consumer Privacy Act, in the preceding twelve (12) months, including the personal information of anyone under 16. We disclose personal information only in the limited circumstances below.
Where we receive personal information as a service provider or processor on behalf of a subscribing organization, we process it only to provide the contracted services. We do not sell that information, share it for cross-context behavioral advertising, retain, use, or disclose it for any purpose other than the business purposes specified in our agreement with that organization or as otherwise permitted by law, and we do not use it outside our direct business relationship with that organization or combine it with personal information obtained from other sources except as the California Consumer Privacy Act permits. A Data Processing Addendum reflecting these commitments is published at snowmass.io/dpa and is available to subscribing organizations on request at privacy@snowmass.io.
We engage service providers (sub-processors) that process information on our behalf under contractual confidentiality and security obligations. Our current categories of sub-processors include:
- Cloud hosting and database infrastructure — to host the Service and store data.
- Stripe — to process subscription payments and billing.
- Twilio — to deliver SMS and voice notifications.
- Email delivery (Amazon SES) — to send transactional and account email.
- OpenRouteService — to compute travel-time matrices and directions for dispatch.
- Google Places — to geocode addresses and power address autocomplete.
- Honeybadger — application error and performance monitoring.
Other disclosures
We may also disclose information to your own organization and its authorized administrators; to comply with law, legal process, or a lawful request; to protect the rights, safety, and security of Metiix, our users, or the public; and in connection with a merger, acquisition, financing, or sale of assets, in which case we will continue to protect personal information consistent with this policy.
Data retention
We retain personal information only as long as needed for the purposes described in this policy, and different data has very different lifespans. Our standard retention periods are:
- High-frequency GPS pings — automatically deleted approximately 72 hours after they are recorded. Before deletion, pings are summarized into service records (arrival and departure times, route and stop summaries, and time-on-site) that form part of your organization's service history.
- Service records, incident reports, and photos — retained for the life of your organization's account as its service-documentation history, or until your organization deletes them or instructs us to, since organizations rely on these records as proof of service.
- Account, subscription, and billing records — retained while your account is active and for up to seven (7) years afterward to meet tax, accounting, and legal obligations.
- Sign-in codes and sessions — one-time sign-in codes expire within 15 minutes; a session token stops working the moment the session expires or is revoked, and the underlying session record is retained for up to twelve (12) months for security auditing before deletion.
- Security, diagnostic, and audit logs — retained for up to twelve (12) months unless needed longer for an active investigation or legal obligation.
Deletion and de-identification
When we no longer need information, we delete or de-identify it. Where we maintain de-identified data, we commit to maintaining and using it only in de-identified form and not to attempt to re-identify it, and we require the same of anyone we disclose it to. Where we process data on a subscribing organization's behalf, we follow that organization's retention and deletion instructions and, on termination, make its data available for export before deletion as described in our Terms of Service.
Security
We use administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit, access controls, session-token hashing, tenant isolation between organizations, and monitoring. No method of transmission or storage is perfectly secure, so we cannot guarantee absolute security.
We maintain a documented process for confidentiality and security incidents — any unauthorized access, use, or communication of personal information, or its loss. If an incident occurs, we act promptly to contain and investigate it and to reduce the risk of harm, and we record every incident in an incident register that we retain for at least five years. Where an incident presents a risk of serious injury (Québec Law 25) or a real risk of significant harm (PIPEDA), or where otherwise required by applicable law, we notify the affected individuals and the relevant authorities — including the Commission d'accès à l'information du Québec and/or the Office of the Privacy Commissioner of Canada — promptly, and where the affected data belongs to a subscribing organization we notify that organization without undue delay so it can meet its own obligations.
International data transfers
The Service is operated from the United States. Personal information is stored and processed in the United States and may be processed by our sub-processors in other countries, and while there it may be accessible to the courts and authorities of those countries under their laws. Where we transfer personal information across borders, we use contractual and technical safeguards designed to ensure it receives protection consistent with applicable Canadian and Québec law.
If you are in Québec: personal information collected in Québec is communicated outside Québec — principally to the United States — for the hosting, processing, and sub-processing described in this policy. Before making such communications we assess, and document in a privacy assessment, the sensitivity of the information, the purposes for which it is used, the protection measures applied, and the legal framework of the destination jurisdiction, and we proceed only where the assessment establishes that the information will receive adequate protection. Our agreements with sub-processors include binding confidentiality and security obligations.
Your privacy rights
Depending on where you live, you may have the right to know and access the personal information we hold about you, to correct or delete it, to obtain a portable copy, to opt out of the sale or sharing of personal information and of certain profiling, to limit the use of sensitive personal information, and not to be discriminated against or retaliated against for exercising any of these rights. Residents of California, Minnesota, Colorado, Connecticut, Virginia, Texas, Oregon, and other states with comprehensive privacy laws hold some or all of these rights; Minnesota and Oregon residents may also request a list of the specific third parties to which personal information has been disclosed, and Minnesota residents may question the result of profiling that produces a legally significant effect. Canadian users' rights under PIPEDA and Quebec's Law 25 are described in the section titled "Canadian privacy rights (PIPEDA and Québec Law 25)" below and include access, rectification, portability, and information about automated decision-making.
How to submit a request. Email privacy@snowmass.io from the email address associated with your account, or with enough information for us to locate your records. Because sign-in to the Service is verified by email, we will ordinarily verify your identity by confirming control of that email address; we may ask for additional information where necessary, and we will only use it to verify your request. You may use an authorized agent to submit a request on your behalf if the agent provides your signed permission and, where required, you verify your identity directly with us. We do not charge a fee for requests except where the law allows for repetitive or unfounded requests.
Timing. We will confirm receipt of a rights request within ten (10) business days and respond within forty-five (45) days, which we may extend by a further forty-five (45) days where reasonably necessary; we will tell you if we need an extension. We honor opt-out requests within fifteen (15) business days.
Appeals. If we decline to act on your request, we will tell you why and how to appeal. To appeal, reply to our decision or email privacy@snowmass.io with the subject "Privacy Appeal" within a reasonable time; a person not involved in the original decision will review it, and we will respond in writing within forty-five (45) days (sixty (60) days for Virginia residents) explaining the outcome and the reasons. If your appeal is denied, you may contact your state Attorney General — for Minnesota residents, the Minnesota Attorney General at ag.state.mn.us — or other supervisory authority to submit a complaint.
Requests about data we process for your snow-removal contractor. Much of the data in the Service — including homeowner names, property addresses, service records, and operator location history — is controlled by the subscribing organization (your snow-removal contractor or employer), and we process it as that organization's service provider. If you send us a request about that data, we will forward it to the organization within a reasonable time and assist that organization in responding, but the organization is responsible for the substantive response. You can reach them directly for the fastest handling.
Opt-out preference signals. Our websites and applications recognize the Global Privacy Control (GPC) and similar legally recognized opt-out preference signals. Because we do not sell personal information or share it for cross-context behavioral advertising, receiving such a signal does not change how we handle your data; if our practices ever change, browsers and devices transmitting an opt-out signal will be treated as having opted out for that browser or device.
Privacy Officer (person in charge of the protection of personal information)
Metiix has designated a person in charge of the protection of personal information (Privacy Officer / Responsable de la protection des renseignements personnels), who ensures compliance with this policy and applicable privacy law, approves our privacy practices and assessments, handles requests for access, rectification, portability, and deletion, and responds to privacy complaints. This designation and contact information are published here as required by Québec law.
You can reach the Privacy Officer at privacy@snowmass.io, or by mail to the Privacy Officer, Metiix, LLC, in Minnesota, USA. We will provide the Privacy Officer's current name on request and in our responses to privacy requests.
Canadian privacy rights (PIPEDA and Québec Law 25)
We handle personal information of Canadian users in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and, for Québec, the Act respecting the protection of personal information in the private sector as amended by Law 25. We follow PIPEDA's ten fair-information principles, including accountability: we remain responsible for personal information in our possession or custody, including information transferred to sub-processors for processing on our behalf, which we protect through contractual and other means.
Consent. Where consent is the applicable basis for processing, we request it for each purpose, in clear and simple language, and separately from any other terms, and it must be free and informed. We request express consent before collecting or using sensitive personal information for any purpose beyond operating the Service you or your organization requested. You may refuse or withdraw consent at any time, subject to legal or contractual restrictions and reasonable notice; withdrawal does not affect processing that occurred before it.
Subject to applicable law, Canadian users have the following rights, exercisable by contacting our Privacy Officer at privacy@snowmass.io:
- Access — obtain confirmation that we hold personal information about you and receive a copy of it.
- Rectification — have inaccurate, incomplete, or equivocal personal information corrected.
- Deletion and de-indexing — request deletion where the law permits and, in Québec, request that dissemination of your personal information cease or that a hyperlink attached to your name be de-indexed where dissemination contravenes the law or a court order or causes you serious injury.
- Portability (Québec) — receive computerized personal information collected from you in a structured, commonly used technological format, or have it communicated to another organization authorized to collect it.
- Withdrawal of consent — withdraw consent to processing that relies on it.
- Automated decisions — the information and review rights described in the "Automated dispatch decisions" section.
- Challenge compliance — complain to our Privacy Officer first; you may also, at any time, complain to the Office of the Privacy Commissioner of Canada or, in Québec, the Commission d'accès à l'information (CAI).
- Because much of the personal information we process is under the responsibility of your subscribing organization, we may refer your request to that organization and will assist it in responding within the timelines the law imposes (30 days in most cases).
Children's privacy
The Service is a business tool intended for use by organizations and their personnel. It is not directed to children, and we do not knowingly collect personal information from anyone under the age of majority in their jurisdiction. If you believe a child has provided us information, please contact us so we can delete it.
Text messages, email, and consent (TCPA and CASL)
The Service sends operational electronic messages — for example customer arrival estimates, operator alerts, and sign-in codes — by SMS (through Twilio) and email (through Amazon SES). Message and data rates may apply, and message frequency varies with fleet activity.
United States (TCPA). By providing a mobile number and enabling these messages, the relevant party consents to receive them, consistent with the Telephone Consumer Protection Act and related rules. Recipients can opt out of SMS at any time by replying STOP to any message, or reply HELP for assistance.
Canada (CASL). Where Canada's Anti-Spam Legislation applies, commercial electronic messages are sent only with the recipient's express consent (or another form of consent CASL recognizes) and identify the sender with a mailing address and contact information. Recipients can opt out at no cost — by replying STOP to any SMS, and by turning off notifications in the customer portal's notification settings or by asking the sending organization to stop — and opt-outs take effect promptly and within ten (10) business days; we keep records of consents and opt-outs. Purely transactional or service messages that you or your organization requested — such as an arrival estimate for your own property — may not be commercial electronic messages under CASL.
Responsibility. Your organization is the sender of notifications to its own customers and is responsible for obtaining and documenting the consent required by applicable law — including express consent under CASL for Canadian recipients — before enabling those notifications. Metiix provides the supporting mechanisms in the Service: consent verification, quiet-hours controls, automatic STOP and unsubscribe handling, and suppression of further messages to opted-out numbers and addresses.
Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, provide additional notice. Your continued use of the Service after an update means you accept the revised policy.
Contact us
If you have questions about this Privacy Policy or how we handle personal information, contact Metiix, LLC at privacy@snowmass.io. We will do our best to resolve your concern.
This Privacy Policy is provided for general information about our practices. Your organization should consider how this policy applies to its own obligations and to the personal information it directs us to process.