Skip to main content
This site is brand new. We're improving it every day, and we'd rather hear what's wrong with it than not.

Privacy

What we collect, and what we don't

This site asks New Mexico licensees to trust it with compliance data, so it owes you a straight answer about where that data goes. Short version: your inventory never leaves your browser, and everything else we hold is listed below.

Last updated September 30, 2026.

No file you open here is ever uploaded

Every tool that accepts a file — the Migration Readiness Analyzer, Organize your files, and the reconciliation tool — runs entirely as JavaScript on your own machine. Whatever you load is read, parsed and processed inside the browser tab. It is never sent to us, never stored, and never transmitted to any third party. There is no database table on this site capable of holding inventory or plant records — our build fails automatically if one is ever added.

Nothing you open persists. Close the tab and it is gone; there is nothing to delete afterwards and no copy on our side to ask us about.

You can verify this yourself: open your browser's developer tools, switch to the Network tab, and load a file. You will see no upload.

What we do collect

Waitlist signups

If you submit the waitlist form, we store the email address you enter, plus the business name, license type and notes if you choose to provide them. We use this only to contact you about the service you signed up for. We do not sell it, share it, or send unrelated marketing. A new signup gets one confirmation email, sent through Resend, telling you what the list is for and how to reply if you want off it.

Recommendations you send us

If you use the recommendations form, we store what you wrote, the category you picked, the page you were on when you wrote it, and your email address if you chose to leave one. If you happen to be signed in, your account is recorded alongside it so we can follow up. Your note is what you typed — the analyzer attaches nothing to it, and your inventory file is not included.

Saved readiness summaries

If you sign in and choose to save a summary, we store your score, your total and clean record counts, and how many findings of each type — plus the label you typed, if any. Never a batch or tag number, strain, quantity, or room. It is visible only in your own portal; nobody else can see it. When you sign in, our private team channel gets a note with your email's domain — not the full address — and the rough location our host reports for your connection.

A hashed form of your IP address

When you submit a form or use the assistant, we store a salted one-way hash of your IP address — never the address itself. It exists to rate-limit abuse. It cannot be reversed back into an IP.

A notification that someone visited

We run this site ourselves and want to know when it's being used, so the first time in a browsing session you open each part of the site (the home pages, the tools, or RR Software) sends a short message to a private team chat channel: which part, the city and state our host reports for your connection, your device type and browser family (for example “iPhone/Safari”), the website that linked you here if any, and campaign tags from the link if it had them. When you leave, the same message is updated with how long you stayed. Those details are not stored in our database. Two small cookies, readable only by our server, remember for up to a day that the message was already sent (and which message to update when you leave). None of this includes your IP address, your name, your email, the pages you read, or anything from the analyzer.

Page views

We use Vercel Web Analytics, which is served from this domain rather than a third-party tracker. It records page views and referrers. It sets no cookies, does not follow you across other websites, and never receives anything from the analyzer.

The AI features, specifically

Ask about the migration — or dictate what you have

What you type or say to the assistant is sent to our server, which forwards it to Anthropic's Claude API to generate an answer — that includes dictation: the microphone converts speech to text in your browser first, and that text is sent the same way typed text is. Naming what's on your shelves one item at a time — “two pounds of Blue Dream, fourteen jars of gummies” — is exactly what this is built for, and Claude may hand back a structured list of what it heard so you can export it as Excel, CSV, PDF, or plain text; that export is built in your own browser from the reply already sitting there, not a second request, and the file itself is never sent anywhere. What still doesn't belong here is a full inventory export, a state-system report, license numbers, or anything else you wouldn't say out loud to a person — that stays in the analyzer, which never leaves your browser. The assistant has no access to your uploaded files and never will. Conversations aren't stored on our servers, and neither are the items it extracts — once the reply reaches your browser, our side of it is done.

Explain my findings

This is opt-in and off by default. When you use it, we send aggregate counts only — how many findings of each type and severity, your license type, and your score. No batch or tag numbers, no strain or product names, no quantities, no room names, no facility name. The page shows you the exact payload before you send it, and our server rejects any request containing more than that.

What we never collect

  • Your BioTrack or NMS2S credentials — we never ask for them and have no way to use them.
  • Any inventory record, plant record, batch number, strain, quantity or room from a file you upload. The one exception is what you choose to type or say to the AI assistant — see “The AI features” above.
  • Your uploaded files. They are not stored, cached, or queued anywhere.
  • Your raw IP address.
  • Anything via third-party advertising or tracking scripts. There are none on this site.

Security

How the data we hold is protected

Waitlist entries, recommendations and saved summaries live in a Postgres database with row-level security enabled and no public access policies — they are unreachable except through our own server-side code. Secrets are held as environment variables on the server and are never sent to the browser. The site is served over HTTPS only, with HSTS.

Removing your data

Ask and we will delete your waitlist entry or a recommendation you sent. Email the address on your signup confirmation, or reach us through the contact route you used.

Third parties we rely on

Hosting and analytics: Vercel. Database: Supabase. AI responses: Anthropic. Team notifications: Discord. Outbound email: Resend, which sends only the waitlist confirmation described above — your email address and nothing else. Each processes only what is described above — in Discord's case, the visit and signup notices described in “What we do collect,” delivered to a private channel only we can read. We are not affiliated with the New Mexico Cannabis Control Division, Real Time Solutions, or BioTrack, and none of them receive data from this site.

Changes

If what we collect changes, this page changes in the same release. The date at the top reflects the last review.

Roadrunner Compliance is an independent, operator-built preparation aid. It is not affiliated with, endorsed by, or reviewed by the New Mexico Cannabis Control Division (CCD), Real Time Solutions (RTS), or BioTrack. It has no connection to any state system. It does not transmit data to, or receive data from, BioTrack or NMS2S. Nothing here is legal advice. Dates, rules and requirements can change — verify everything against official CCD communications and applicable NMAC, including 16.8.7.15 NMAC.

Back to the analyzer