Privacy
How this website and the SXT Ops Companion browser extension handle your information. The SXT Ops service itself is covered by the SXT Ops customer agreement.
Privacy on this site
This site collects what you type into the access request form: company, station codes, fleet size, the systems you use, and your name, role, email and phone. We use it only to reply to you and set up a walkthrough. We do not sell it or share it with advertisers.
We keep a one-way hash of your IP address to stop spam, never the address itself. The site sets no tracking cookies and loads no analytics.
The Questions assistant sends your question, and up to the last four messages of the conversation, to our AI provider, Inception Labs, which writes the answer. It sends nothing else about you. SXT Ops doesn't store or log what you type there; the conversation is kept only in your browser tab and is gone when you close it. Please don't type names, emails, phone numbers or other personal details into the assistant. When the AI provider isn't set up or is busy, the assistant answers from our help articles and sends nothing to the provider.
The site and the app serve their own fonts, so a page load sends nothing to a font service. Our hosting providers process requests on our behalf.
To see or delete what we hold about you, email hello@sxt-ops.com. We confirm deletion in writing.
How your data is protected
Everything between your browser and SXT Ops travels over HTTPS. Each company's data is kept separate, and every screen is limited by role.
Two-step sign-in secrets are stored encrypted. SXT Ops can also encrypt associates' phone numbers, injury and medical details, and text-message consent records inside the database, with a key kept apart from the data and from backups. We switch that on only after the key is saved offline, so a lost key can never cost you records. Ask us whether it is on yet.
Backups never leave our server unencrypted. Any copy kept elsewhere is encrypted first with a key that only we hold offline.
Other records, such as names, emails, write-ups, attendance, messages, incident descriptions, vehicle and repair records, and uploaded files and photos, are stored on our server without that extra layer and are protected by access roles, the server's own security and HTTPS. Our hosting provider's disks are not confirmed to be encrypted.
SXT Ops Companion privacy policy
This policy covers the SXT Ops Companion extension for Chrome, published by SOPHIA XT LLC ("we"). The SXT Ops service itself is covered by the SXT Ops customer agreement and privacy policy.
What the extension is for
It connects your browser to your SXT Ops account so it can send the report files you download to SXT Ops, show which of today's reports are still missing, alert you to work waiting on you, and search your company's associates, vans and repair orders.
What it looks at on your computer
If you turn on report downloads, the extension is told when a download finishes and reads that download's file name, file type, size and the site it came from. It uses the site only to tell whether the download came from Amazon Logistics (logistics.amazon.com), and keeps only that yes or no, never the web address, the page you were on or the site's name.
It reads a file's contents only to send it to SXT Ops: a file you choose or drag in, or, if you allow it, a CSV or Excel report you just downloaded that it finds in your Downloads folder with the same name and size. Allowing the Downloads folder is a separate choice on the send list. You can stop it there with "Stop reading my Downloads folder", or in Chrome's settings for the extension.
It does not read, record or change the content of any web page, including Amazon's Logistics portal and Cortex, and it never asks for or sees an Amazon password or session. "Open in Amazon" opens a page in a new tab only when you click it. It cannot see your browsing history, passwords or cookies.
What it sends to SXT Ops
- Report files it sends for you, with their names, sizes, a SHA-256 fingerprint so SXT Ops can tell whether it already has the file, and whether each came from Amazon Logistics. They go to your company's SXT Ops account and are processed like any file you upload in the app.
- Your searches (the text you type, at least 2 characters) and requests for your alert summary and today's report list.
- A pairing code when you connect, a random device credential after that, a label such as "Chrome on Windows", the extension's version, and a public key that proves requests come from your browser.
- A health check every 15 minutes or so while it is working: the extension and Chrome versions, how it was installed, the operating system family, which permissions are on, counts of files by state on the send list, when it last sent a file, the last error code and the computer's clock. It holds no names, file names or web addresses.
It sends nothing to anyone other than SXT Ops. It has no analytics, advertising or tracking code. The support code on the Diagnostics page is made from the same kind of health details, holds no name, email, company or file name, and goes nowhere unless you copy it and send it to someone.
What it stores on your computer
Your connection to SXT Ops (a device credential and a key that can't be copied out through the browser), your settings, the last alert summary (which can name drivers who messaged dispatch, never what they wrote), today's report list, and the send list. The send list keeps a copy of each file only until SXT Ops has it, and at most 7 days for a file that failed to send, then deletes it. It keeps each file's name and status for 14 days so you can see what happened. These copies are kept as plain files in Chrome's storage on your computer; the same file is already in your Downloads folder, so the protection is deleting the copy as soon as it is no longer needed.
On a shared computer, the connection is kept in memory only and ends when Chrome closes or the session runs out, and that person's send list and alerts are deleted. Disconnecting in the extension deletes the connection and the alert summary; files still waiting are kept for 7 days in case you pair again as the same person, and are never sent to a different account. Removing the extension deletes all of it from your computer, but it doesn't disconnect the browser on our side: remove it in My account, or it expires after 30 days without use.
What SXT Ops keeps
For each connected browser: its label, extension version, when it was connected and last used, a one-way hash of its credential, its public key, and the latest health check described above. Your company's owners and managers can see who paired each browser and its label, version, health and counts in SXT Ops; SXT Ops staff see only totals for your company. Uploaded files are handled under your company's SXT Ops agreement: the original file is deleted 30 days after it arrives, and imported rows stay with your company's records. Searches and file fingerprint checks are sent in the body of an encrypted request, never in a web address, and SXT Ops doesn't store or log them. A connection stays on our side until you or your company's owner removes it, or it expires after 30 days without use and after 180 days in any case.
Who can see it
Only people in your company with the right SXT Ops role can see files you send, following the same rules as the app. We don't sell data from the extension, share it with advertisers, or use it for anything other than running SXT Ops for your company. Our hosting providers process it on our behalf.
Your controls
You can turn report downloads, Downloads folder access and each kind of notification on or off, set quiet hours and reminder times, disconnect the extension from its settings, or remove any connected browser from My account in SXT Ops. Signing out all other devices in My account, or changing your password, also disconnects every browser. Your company's owner removes every connection of a user by deactivating that user or changing their role.
Security
Connections use HTTPS. Credentials are stored as one-way hashes on our side, rotate regularly, and are tied to a key held by your browser. The extension accepts requests only from its own pages, and SXT Ops accepts extension requests only from the published extension.
Children
SXT Ops is a business tool and is not meant for children.
Changes
We will post changes here with a new effective date. If a change widens what the extension looks at or sends, the extension will ask for your agreement before it takes effect.