Legal
Privacy Policy
Last updated: July 20, 2026
PapaSpuds LLC ("we," "us," or "our") operates AgBaseline, a collateral inspection and field inventory application for agricultural lenders (the "Service"). This Privacy Policy explains what information we collect, how we use it, and the choices you have.
AgBaseline is the successor to AgCollateral360. This Policy applies to AgBaseline going forward and supersedes AgCollateral360's separate privacy policy. AgBaseline is a separate product from My AgCounts, which continues to operate independently under its own privacy policy.
Information We Collect
We collect the following categories of information:
- Account information: your email address and profile details (such as your display name), managed through our identity provider, Microsoft Entra External ID. We never see or store your plaintext password — authentication credentials are held by our identity provider, not by us.
- Inspection data: borrower names, dates, credit facility details, collateral and borrowing-base figures, findings, observations, and inspector notes that you create while using the Service.
- Field-count data: site location names, inventory/livestock line-item counts, notes, and photographs recorded during a field inspection.
- Location data: GPS coordinates, only when an inspector chooses to capture them for a specific field-count site location. This is an explicit, optional action, not automatic background collection.
- Audit and usage data: a record of actions taken within the Service (created, edited, deleted, shared, reassigned, etc.), each tied to the account that performed it and a server-side timestamp, for accountability and compliance purposes.
- Device and technical data: basic technical information (browser type, device type, IP address) collected automatically as part of operating and securing the Service.
How We Use Information
- To provide, maintain, and improve the Service.
- To generate inspection reports (Word document exports and, at your request, an AI-assisted narrative draft) containing the inspection and field-count data you've entered.
- To communicate with you about your account.
- To maintain an audit trail for compliance and dispute-resolution purposes, consistent with the Service's purpose as a record-keeping tool for regulated lending institutions.
- To detect, investigate, and prevent fraud, abuse, or security issues.
Who We Share Information With
We do not sell your personal information. We share information only with the following categories of service providers, each of whom processes it solely to provide their respective service to us:
- Microsoft Azure — database hosting and application hosting.
- Microsoft Entra External ID — authentication and identity management.
- Anthropic — generates an AI-assisted first draft of an inspection's narrative report, when an inspector requests one; only that inspection's own data is sent for that request.
- Cloudflare — DNS and inbound email routing for our domain.
If you belong to an organization within the Service, your inspection data, field-count data, audit trail entries, and profile information are visible to other Managers and Admins of that organization, consistent with the org/role access model described in our Security page.
Data Retention
We retain inspection records, field counts, photographs, and audit logs until the associated account or organization requests deletion. Deletion within the Service is a soft delete — the record is removed from normal views and an organization Admin can restore it — rather than an immediate, irreversible destruction. Completed inspections are treated as institutional records belonging to the organization: if an individual inspector's account is later disabled, their inspection and audit history are preserved with their name retained as an attribution record, rather than deleted.
Your Choices
- You can update your profile information through your organization's Admin or your identity provider account settings.
- Multi-factor authentication is required for all accounts and is managed through our identity provider, not a per-user opt-in.
- To request access to, correction of, or deletion of your personal information, contact us using the details below; requests are subject to the record-preservation obligations described under Data Retention above for data your organization needs to retain as an institutional record.
Security
We use industry-standard safeguards, including encrypted connections (HTTPS/TLS), organization-scoped database access controls, and mandatory multi-factor authentication, to protect your information. See our Security page for full detail. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
Children's Privacy
The Service is intended for business use by adults working in agricultural lending and collateral inspection. It is not directed at, and we do not knowingly collect information from, individuals under 18.
Changes to This Policy
We may update this Privacy Policy from time to time. We'll update the "Last updated" date above when we do. Continued use of the Service after a change constitutes acceptance of the updated policy.
Contact Us
Questions about this Privacy Policy or your data can be sent to [email protected].