Effective Date: August 16, 2026
Updated August 16, 2026: revised Section 2 to cover unit and tenant records and building owners, Section 3 to cover condition, invoice and diagnostics scanning, Section 5 to cover what a tenant tag page publishes and to stop it implying that a tenant tag page is as hard to come across as an equipment page, Section 6 to state what the request form does and does not ask for and how alerts are routed, Section 7 to correct the status of previously uploaded diagnostic sessions, Section 8 to name the sharing feature by the label it actually carries in the app ("Send to User") and to correct where the data goes — into the recipient's Transfer Inbox inside their existing Equipment Tracker account, not to an email address — and Section 14 to cover the Archive, tenant request retention, what survives account deletion, and how the deletion control is actually labelled and operated. Previously updated August 11, 2026: added Section 5 (What a Public QR Page Publishes), Section 6 (Tenant Service Requests) and Section 7 (AI Diagnostics Stay on Your Device); later sections renumbered. Previously updated July 24, 2026: added Section 14, now Section 17 (Team Workspaces) and revised Sections 2, 5, and 11 to cover multi-user access to a workspace owner's data.
Equipment Tracker Pro, owned and operated by Jonathan M. Curtis ("we," "our," or "us"), is committed to protecting your privacy. This Privacy Policy explains how our mobile application and web dashboard collect, use, and safeguard your information.
When you use an AI feature, the images or text involved are sent to Google's Gemini API (via a secure Firebase Cloud Function) and the result is returned to the app and stored according to your local/cloud preferences. This applies to every AI feature in the app, and all of them require an internet connection:
Images and text are transmitted securely and are subject to Google's data processing terms. We do not use any of it to train models.
Equipment Tracker Pro supports guest service submissions via the public QR specification page. When a guest technician (a person who does not have an Equipment Tracker account) scans a Link Mode QR code and submits a service report through the web form, the following information is collected:
Guest submissions are stored temporarily in our Firebase Firestore database under the equipment owner's account namespace, in the incoming_maintenance collection. Service photos are stored in Firebase Storage under the incoming_maintenance_images/ path. Guest submissions remain pending until the account holder explicitly reviews and accepts or rejects them in their Transfer Inbox. They are not automatically added to the owner's maintenance records. The guest technician is not required to provide any personal account credentials or contact information beyond what they voluntarily enter in the form fields.
A Link Mode QR code prints a link to a page we host for that piece of equipment. That page is readable by anyone who scans the code, without an account and without signing in — that is what the code is for. It is not indexed and cannot be listed or browsed; it can only be opened by someone who has the specific code.
The page publishes the equipment's specifications, its parts list, and its service history. By default it also publishes the site information for the building the equipment is in: the street address and the building contact's name, telephone number and email address. This is deliberate for commercial sites, so that a visiting vendor standing at the equipment has somebody to contact about access or building issues.
You can turn site information off, per building. In the app, open the building, open Site Info, and clear "Show site info on QR codes". While it is off, the address and contact details are not published, existing pages for that building are rewritten to remove them, and anyone scanning a code for that building sees a notice saying site information is turned off. Equipment specifications, parts and service history are still shown. We recommend turning it off for residential addresses, where the building contact is a private individual rather than a facilities manager.
Service history entries shown on a public page carry the date, service type, description, technician name and vendor company. They do not carry any cost, labour rate, labour hours or materials cost you have recorded — those fields are never published to a public page.
A tenant tag publishes a page too, but do not assume it is as hard to find. The page behind a tenant tag is readable by anyone who scans that tag, with no account and no sign-in. Unlike an equipment page, we do not currently restrict listing of the collections these pages are stored in, so treat a tenant tag page as findable by someone who never saw the card rather than as reachable only by scanning it. It shows the building name, the unit label, a short verify code, and whatever you have typed into that building's tenant information page and that unit's own version of it: the office name, telephone number, email address and hours, an after-hours number, what counts as an emergency, fire safety text, shutoff locations, utilities, trash and parking, current notices, any document links you add and any sections of your own. It never shows the tenant's name, telephone number or email address — those stay in your workspace. Treat anything you put on that page, including any link, as readable by anyone holding the card.
Replacing a tag retires the old page. If a card goes missing or a unit turns over, replacing the tag mints a new code and deletes the page the old card pointed at, so the old card resolves to nothing. Deleting a unit, or clearing its tag, does the same.
Account holders can print a QR code for the inside of a tenant's door — either one for the whole building or, since August 2026, one per unit. Scanning it opens a request form, not a service log.
What the form asks for. The form asks what is wrong, optionally the resident's name, and optionally up to three photographs. On a building-wide code it also asks which unit. It does not ask for a telephone number or an email address, and there is no field on it for either. If the account holder has recorded a tenant against that unit, we read that name, telephone number and email address from the unit's record when the request arrives and record them onto the request, so that the people who maintain the building can call back. That is how a resident is contacted without being asked to hand over details the landlord already holds.
Where it goes. A request goes to the account holder who printed the tag, and is visible to every member of their team in every role. Tenant photographs are stored separately from all other guest uploads, under a tenant_requests/ path in Firebase Storage, and are readable only by the account holder and their active team members after signing in. They are not publicly readable. This is a deliberate difference from guest technician photos, because a tenant request can contain images of the inside of somebody's home.
Who is alerted. An account holder can set a list of email addresses and telephone numbers to be alerted about tenant requests, separately from the list used for vendor check-in alerts. If a building has no tenant list set, alerts fall back to that building's vendor check-in recipients rather than being sent nowhere — a resident reporting no heat should not be met with silence because a second list was never filled in. A separate tenant list, where one exists, always wins. If you do not want tenant reports reaching your vendor contacts, set a tenant list. Alerts carry a link to the account holder's dashboard and never the photographs themselves. One request per code per hour is accepted, so a per-unit tag throttles per unit rather than for the whole building.
Tenant requests are held for review and never create a work order on their own.
If you are a resident who scanned a tag. You have no account with us and you are not asked to create one. What you write and any photographs you attach go to the people who maintain your building — the account holder who printed that tag and the members of their team — and to us, because we host and deliver it for them. We do not use it for any purpose of our own, we do not sell or share it, and we do not use it for advertising or to train models. If you want to know what has been recorded about you, or want something you sent removed, contact the people who maintain your building; you can also write to us at support@equipment-tracker.com and we will act on their instruction.
The AI Diagnostics feature records a troubleshooting conversation about a fault, including symptoms, measurements and notes you type. As of 11 August 2026 these sessions are stored only on your device. They are not uploaded to our servers, are not included in cloud backup, are not shared with team members, and are not transferred with a building. Sessions that had already been uploaded before that date remain on our servers pending deletion. They are not used for anything, and you can ask us to delete yours at any time at support@equipment-tracker.com.
One consequence is worth stating plainly: because they are not backed up, a lost, wiped or replaced device loses its diagnostic history. The feature is not offline — individual questions you ask are still sent to Google's Gemini API to be answered, as described in Section 3 — but the resulting conversation is retained only locally.
If you utilize the "Send to User" feature, the specific equipment, parts, or maintenance data you choose to send is written to the Equipment Tracker account of the recipient you designate, where it waits in their Transfer Inbox until they accept or discard it. You designate that recipient by their email address or by their Push Username; either one is used only to locate an existing Equipment Tracker account, and if no account matches, nothing is sent. We do not email your data to the address you type. Shared data is stored in Firebase until the recipient claims or discards it, and we do not send it to anyone you have not designated. This describes the "Send to User" feature only — team workspaces work differently and are described in Section 17.
The app allows you to export your data as ZIP archives and import data from ZIP files. Exported archives may contain equipment records, parts data, maintenance logs, and associated images. You are responsible for the security of exported files once they leave the app. On Android, the app supports automated local backups to a Storage Access Framework (SAF) linked folder.
The app can generate professional equipment reports, maintenance summaries, and building inventories. These reports may be shared via your device's native sharing capabilities. Report content is derived from data you have entered and is not transmitted to our servers.
Your data is processed by the following third parties according to their respective privacy policies:
Our marketing website (equipment-tracker.com) uses cookies and similar tracking technologies from the following third parties to understand site usage, measure advertising performance, and improve our marketing. Google Analytics, Google Ads conversion tracking, the Meta Pixel and the TikTok Pixel also load on the signed-in web dashboard and record page views there. Microsoft Clarity is loaded but is stopped as soon as a signed-in page opens, so dashboard sessions are not recorded in Clarity. None of these technologies are used in the mobile app.
You can control or disable cookies at any time through your browser settings. Our mobile app does not use any of the tracking technologies described in this section.
If applicable privacy law grants you the right to opt out of the sale or sharing of personal information, or to exercise any other privacy right regarding these technologies, contact us at support@equipment-tracker.com.
Equipment Tracker is a professional tool designed for HVAC technicians and is not directed at children under the age of 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us immediately so we can delete it.
Your local data remains on your device until you delete it. Cloud-synced data is retained as long as your account is active. You may delete your account and all associated cloud data at any time from the app's Settings menu: open Settings, find Delete Account under Account, and press and hold it — a short tap only explains that it needs a long press, which is deliberate so the control cannot be hit by accident. Holding it opens a confirmation in which you type the word DELETE; nothing is removed until you do. Upon account deletion we cancel any active Stripe subscriptions, delete your user data tree, your pending shares, your team records, and your image files from our storage. Some records created outside that tree are not removed automatically — public equipment pages you published through a QR/Link Mode code, building check-in configurations and their notification contact lists, vendor check-in entries, guest technician submissions and their photos, tenant service requests and their photographs, SMS consent records for numbers that were added to a notification list, the anonymised device record used to enforce the free scan limit, and your reserved username. If any part of the deletion or subscription cancellation does not complete, your authentication account remains intact and deletion is halted. Contact us at support@equipment-tracker.com to have anything remaining removed, and we will remove it.
Tenant service requests. A request and its photographs stay in your workspace after you have dealt with it — marking a request handled does not delete it, and the app does not currently offer a control that does. They are not deleted automatically and are not on a fixed schedule. Contact us at support@equipment-tracker.com to have a request and its photographs removed, and we will remove them.
Deleting a building or a piece of equipment archives a summary of it. The record's photographs are destroyed straight away and irreversibly. A text summary — the title, the building name, the address and the equipment history — is moved into your Archive, which is part of your workspace and is visible to your team members. The site contact's name, telephone number and email address are deliberately not kept in the archive. You can remove a record permanently from the Archive at any time.
If you are a member of a team workspace, "your account" means your own account only. Deleting your account does not delete the workspace owner's data, and a workspace owner deleting their account does not erase copies already downloaded onto members' devices. Records identifying workspace members — including member email addresses — are stored under the workspace owner's team record rather than under the member's own account; contact us at support@equipment-tracker.com to have those removed.
We do not sell, rent, or trade your personal data, equipment logs, maintenance records, or images to any third parties.
Mobile information and SMS opt-in data will not be shared with third parties or affiliates for marketing or promotional purposes. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
If you opt in to receive SMS notifications (such as vendor check-in and check-out alerts, or alerts that a resident has submitted a service request from a tenant tag), message frequency will vary depending on your account's activity and notification settings. Message and data rates may apply. You may opt out of SMS notifications at any time by removing your phone number in the app's notification settings, or by replying STOP to any message.
We may update this Privacy Policy from time to time. Any changes will be posted on this page with a revised effective date. We encourage you to review this policy periodically. Your continued use of the app after changes are posted constitutes your acceptance of those changes.
A subscriber on a Team plan (a "workspace owner") can invite other people ("team members") into their workspace using an invite code. This section explains what that means for the data in the workspace.
What team members can see. A team member can read all of the data in the workspace: equipment, parts, maintenance and service records, inventory, tools, work orders, PM schedules, photographs, and building and site information — including customer names, contact details, and billing addresses. Access is not limited by building, by customer, or by record type. Team members are assigned a role — Viewer, Tech, or Manager — which controls what they can change, not what they can see. All three roles can see everything in the workspace.
Data on team members' devices. When a team member joins from the mobile app, the app erases the data already on that member's device and downloads a copy of the workspace onto it — including customer and billing information and photographs — so the app works offline. Members who use only the web dashboard do not receive a persistent local copy.
When a member leaves or is removed. Their access to the workspace ends immediately on our servers. The app erases the local copy from that member's device the next time it runs with an internet connection. We also send a silent push command to the member's device instructing the app to erase the workspace copy right away. This is best-effort: it only works if the device is online with notifications registered, and we cannot confirm the erase completed. If it does not arrive, the copy stays on that device until the app next runs with an internet connection. Anything a member has already exported, printed, or sent elsewhere is outside our reach entirely. Workspace owners should keep this in mind when deciding whom to invite and what information to keep in a workspace.
Information we hold about team members. For each member we store the email address of the account that redeemed the invite, the member's role, the date they joined, and any display name or notification email address set by the workspace owner or a manager. This is stored under the workspace owner's team record, not under the member's own account. Records a member creates are tagged with that member's user ID and display name. For work orders we also record the user ID of the last person to change the record; other record types do not record who edited them. These tags remain in the workspace owner's data after the member leaves.
Access follows the owner's subscription. Team members receive Pro features through the workspace owner's subscription. If that subscription ends or lapses, Pro-only functions stop working for every member of that workspace.
Who is responsible. The workspace owner decides who is invited and is responsible for the customer information in their workspace, including having the authority to make it available to the people they invite. See Section 10 of our Terms of Service.
If you have questions about this Privacy Policy, please contact us at: support@equipment-tracker.com