Privacy Policy for Equipment Tracker Pro
Effective Date: September 30, 2026
Updated September 25, 2026: Section 11 now describes the web page each created invoice has, which shows the whole invoice to anybody with its link, and says that we keep a record of a business agreeing to the platform fee. Previously updated September 24, 2026: Section 11 now describes taking payment on your invoices — what passes between us and Stripe when a business sets up online payments and when its customer pays, what the public payment page shows, and the PayPal and Venmo usernames a business can print on its invoices — and Section 14 lists the payment records that survive account deletion. Previously updated September 7, 2026: a line-by-line check of this policy against the code corrected it in three ways. It now describes flows it had never described: sending a work order to a contractor on another account, which carries the site address, the building contact and a resident's own words and photographs out of your workspace; transferring a whole building behind a six-character code; the Device Report you can send us from Settings; your company profile; SMS consent records; the operational logs our servers write, which record the telephone number and text of a message sent to our SMS number and the email addresses our alerts went to; and what a full backup archive actually contains. It corrects things that were wrong: guest submissions are held in a shared collection stamped with your account, not inside it; AI Diagnostics sends the conversation so far, the equipment record and that unit's five most recent service log entries on every turn, not only the words you type, and a record that a session happened does reach our servers even though the conversation does not; those sessions stopped being uploaded on August 12, 2026, not August 11; the web dashboard does record your language; a member record is tagged with an email address where no display name is set; a public service history entry also lists the parts used; the record behind a vendor door sign also holds the customer name and whatever message you have written on the sign; the contact form also stores a company and a role; and the sentence about opting out of text messages named a screen that holds no telephone numbers. It corrects what deletion does: tenant service requests and their photographs, and a departing member's own team record, are removed by the deletion now and have been since early September, while work orders dispatched to or received from another contractor are not, and are now listed among what survives — and both Section 14 and the page at /delete-account now describe the deletion control on the web dashboard alongside the one in the app. Section 11 adds two third parties your browser contacts that were never listed — Google's font servers, on every page of the website and of the signed-in dashboard, and Apple's App Store ratings service, on every page except this policy and our Terms — and says that every account is registered with RevenueCat under its user ID the moment it is created, whether or not it ever buys anything. Section 17 now says what "all of the data in the workspace" really covers, including the units in each building and who is in them. Nothing about the software changed for any of this; the document was describing it wrongly, or not at all. Previously updated September 6, 2026: Section 2 now has a bullet for the language and the time zone held on your account. The app has written both since August 27, 2026, so that a message composed on our servers can reach you in the language the app is set to and be timed against your own clock rather than ours — the two facts the September 3 correction below describes our servers as needing, without saying that we store them. The omission is corrected here rather than the practice: nothing about what the app records has changed. Previously updated September 3, 2026: corrected the Notifications bullet in Section 2, which said that every notification the app shows is sent by our servers and "not generated on your phone", and listed maintenance and PM reminders among them. That stopped being true when reminders moved onto the device: the app now schedules a reminder about your own equipment, parts and PM schedules locally, at your device's own time, and our daily job skips them entirely rather than sending one. The bullet now separates the two mechanisms and says plainly that the device-scheduled reminders reach no server. What our servers still send is unchanged and still listed, with one clarification: the PM notification they send is for a schedule somebody else has assigned to you, not for your own. Previously updated August 29, 2026: version 6.34.0 added app performance and crash telemetry. Section 2 now has a bullet for it — launch timings and caught software errors sent to Expo, carrying a random per-launch session identifier and not your account — and the Expo entry in Section 11 now says Expo receives it, rather than describing Expo as push delivery only. Previously updated August 21, 2026: corrected the document against what the software actually does. Section 2 now states the two ways a tenant's recorded details do leave your workspace (a request alert, and billing a tenant on an invoice) instead of saying they never do; describes push notifications as remote rather than local, names the categories they cover and states that a notification can carry another person's name; describes the device identifier as pseudonymous rather than "fully anonymized", because the hash is stable; and adds bullets for invoices and payment records, diagnostic error reports, IP addresses and the website contact form, none of which had one. Section 3 now says that a scan result is also cached on our servers and that the automatic expiry for it is not switched on; it was published earlier the same day saying those cached results were not removed when an account is deleted, which was true of the software as it then stood — the deletion was corrected to reach them the same day, and this sentence with it. Section 5 now says a public equipment page also publishes the equipment's notes, states that the "Show site info on QR codes" control does not govern a vendor door sign, drops the warning that tenant tag pages could be listed — the rules were closed on August 16 and the warning should have gone with them — and says that a vendor check-in entry, which carries the visitor's name, company and stated reason for being there, is held somewhere readable without an account. Section 11 widens the Gemini entry to all four AI features and adds the four services that were missing from a list presented as complete: Expo for push delivery, Twilio for SMS, Google Workspace for email, and the QR image service the mobile app sends label contents to; it also adds Meta, which receives a hashed purchase event from our servers on a website subscription. Section 14 adds contact-form messages to what survives account deletion and names five kinds of record the deletion now reaches that it did not reach before — the diagnostic error reports, the cached AI scan results and the record of AI use, the shares you sent to other people, and any building transfer code you generated with the copy of the building behind it — states that an invoice keeps who it was addressed to after the building is deleted, and points anybody who no longer has the app at the new page at /delete-account, which can be read without an account and which says plainly that a subscription bought in an app store has to be cancelled in that store. Section 17 adds invoices to what a workspace holds and states that invoicing is owner-and-manager in the app while the records still sync to every member's device. Previously updated August 18, 2026: removed the TikTok Pixel from Section 12 — it has been removed from the website and no longer loads on any page. Previously updated August 16, 2026: revised Section 2 to cover unit and tenant records and building owners, Section 3 to cover condition, invoice and diagnostics scanning, Section 5 to cover what a tenant tag page publishes and to stop it implying that a tenant tag page is as hard to come across as an equipment page, Section 6 to state what the request form does and does not ask for and how alerts are routed, Section 7 to correct the status of previously uploaded diagnostic sessions, Section 8 to name the sharing feature by the label it actually carries in the app ("Send to User") and to correct where the data goes — into the recipient's Transfer Inbox inside their existing Equipment Tracker account, not to an email address — and Section 14 to cover the Archive, tenant request retention, what survives account deletion, and how the deletion control is actually labelled and operated. Previously updated August 11, 2026: added Section 5 (What a Public QR Page Publishes), Section 6 (Tenant Service Requests) and Section 7 (AI Diagnostics Stay on Your Device); later sections renumbered. Previously updated July 24, 2026: added Section 14, now Section 17 (Team Workspaces) and revised Sections 2, 5, and 11 to cover multi-user access to a workspace owner's data.
1. Introduction
Equipment Tracker Pro, owned and operated by Jonathan M. Curtis ("we," "our," or "us"), is committed to protecting your privacy. This Privacy Policy explains how our mobile application and web dashboard collect, use, and safeguard your information.
2. Data Collection & Usage
- Account Information: To utilize cloud backups and sharing features, we collect your email address for account authentication via Google Firebase Authentication. You can also sign in with Google or with Apple; the sign-in itself happens with that company, and we receive from it your email address and the name on that account. The app uses that name — or, if your account has no name, your email address — as the name it records on the records you create, and as the technician name it fills in when you complete a work order, unless a team member's name is already on the job. You can change the technician name before saving; if you do not, it is written onto the service record, and a service record on a public QR page shows its technician name (Section 5).
- Camera & Photo Library: The app requires access to your device's camera and photo library to capture and store images of HVAC nameplates, equipment, parts, maintenance records (before/after photos), and building exteriors or site maps.
- Equipment & Parts Data: The app stores equipment specifications, serial numbers, model numbers, manufacturer information, parts catalogs, filter sizes, belt sizes, and other technical data you enter or that is extracted via AI scanning.
- Maintenance & Service Records: The app stores service history including work order numbers, technician notes, service dates, refrigerant logs, labor hours, and before/after maintenance photographs.
- Building & Site Information: If you enter site information, the app stores customer names, contact details (name, phone, email), billing addresses, and site-specific notes associated with your buildings. You can also record the party that owns a building — their name, a contact name, telephone number, email address, postal address and notes — which is often a private individual rather than a business. A building's owner is a record your buildings point at, so one owner can hold several buildings, and the owner is never published to a QR page or to any other publicly readable place.
- Units & Tenants: You can record the units within a building — suites, apartments or tenancies, including vacant ones — and, for each unit, the current occupant's name, telephone number, email address and notes. This information is never published to a QR page or a tenant tag page. It does leave your workspace in three ways, and all three are things you do yourself. First, an alert about a tenant service request carries the resident's name and what they reported to every email address and telephone number on that building's notification list — and if you have not set a tenant list, those alerts go to the building's vendor check-in contacts instead, who are usually people outside your business. See Section 6. Second, choosing Bill To: Tenant on an invoice freezes that resident's name, unit label, telephone number and email address onto the invoice, and you can send that invoice to anyone. Third, if you turn a tenant service request into a work order and send that work order to a contractor on another Equipment Tracker account, the resident's name, the unit, what they reported and — when you do it from the dashboard — the photographs they attached travel with the job into that contractor's account. Nothing else sends these details outside your workspace. When a resident submits a request from that unit's tag, we read the contact details already on file so that the resident does not have to hand over a telephone number you already hold, and we record them onto that request — a request keeps who was in the unit at the time, so a later change of tenancy does not rewrite who reported a problem last week. Only an account owner or a Manager can set or change who is in a unit; see Section 17.
- Local & Cloud Storage: By default, all data is stored locally on your device in a SQLite database. If you enable Cloud Backup (Pro feature), your data is securely synced to our Firebase database and accessible via the web dashboard at equipment-tracker.com. If you join a team workspace, the app erases the data on your device and downloads the workspace owner's data onto it instead — see Section 17.
- Web Dashboard Access: The web dashboard is a Pro feature that reads the cloud-synced data in your workspace to display buildings, equipment, parts, maintenance logs, and site inventory in a browser. All data displayed in the web dashboard originates from and is governed by the cloud backup data of the workspace it belongs to.
- Administrator Access: For the purposes of database maintenance, technical support, and system integrity, cloud-synced data is accessible to the application's system administrators.
- Team Workspace Access: If you invite team members into your workspace, all of your cloud-synced data — including customer names, contact details, and billing addresses — becomes accessible to every member you invite, in every role. If you join someone else's workspace, their data becomes accessible to you. See Section 17.
- Site Inventory: If you utilize the inventory management features, the app stores item categories, dimensions, quantities, and stock levels associated with your buildings.
- Device Identifiers: A secure session identifier is generated for your device strictly to enforce single-device license activation for Pro subscribers. Additionally, to enforce our free trial limitations and prevent abuse (such as creating multiple accounts on a single physical device to obtain additional free scans), we collect a cryptographically hashed, pseudonymous identifier of your physical device (IDFV on iOS and Android ID on Android). This identifier is hashed locally on your device (using SHA-256) before transmission to our servers. The hash cannot be turned back into the device identifier, and it is not used to track your location or identity. It is not anonymous, and we do not call it that: the hash is stable, so the same device always produces the same value, which is exactly what lets us tell that two accounts are on one phone. That is the only thing we use it for.
- Usage Analytics: The app tracks the number of AI scans performed (for free-tier enforcement), onboarding completion status, notification preferences, and scan disclaimer acknowledgements. Trial scan counts are securely stored in your Firestore account to sync limits across installs, while onboarding and disclaimer preferences are stored on-device only.
- Notifications: The app uses two kinds of notification, and only one of them involves our servers. Reminders about your own equipment, parts, PM schedules and work orders are scheduled by the app on your phone, at your device's own local time. The app reads the due dates already held on the device and asks the operating system to raise the reminder; nothing about them is sent to us, and they arrive with no signal and no internet connection. Everything else is a remote push notification, sent by our servers and travelling through Expo's push service and then Apple's or Google's before reaching you — see Section 11. For those, your device registers a push token with us and we store it against your account. They cover a guest technician's service submission, a tenant service request, a vendor checking into or out of a building, a PM schedule that somebody else has assigned to you, incoming shared data, a work order another contractor has sent you and every step of its return, and workspace and subscription notices. The text of a notification can carry another person's name — the technician who filed the report, the resident who reported the problem, or the vendor and their company — because that is what makes the notification useful. We also use the same channel to send a silent command to a device; see Section 17. You can disable notification categories in Settings.
- Language & Time Zone: Your account profile records two things about how to address you: the language the app is set to, and your device’s time zone as a region name, such as America/Detroit. The app writes both when you sign in and again whenever you change your language; the web dashboard writes the language whenever you are signed in to it, and never the time zone. They exist for the notifications, emails and text messages described above, all of which are composed on our servers, where the app’s own language setting cannot reach. Without the language, a reminder arrives in English however you have set the app. Without the time zone, it is timed against our own clock in Michigan, so an item falling near midnight can be reported a day early or a day late. We use them for nothing else. A time zone is a clock shared by everyone in a region rather than a place — it does say roughly which part of the world you keep time in, and we would rather write that down than call it anonymous, but it is not a position and we do not use it to work one out.
- Company Profile: If you fill in the company profile in Settings, the app stores your business name, telephone number and email address, your own name and title as you want them printed, your logo, and your invoice defaults — the labour rate, tax rate, payment terms and invoice number prefix. This syncs to your account like the rest of your data, is readable by every member of your team (Section 17), and is printed on reports, labels and invoices. Your logo is also copied to a web address readable by anyone who has it, so that a label can show it; do not use an image you would not want public.
- Invoices & Payment Records: If you raise invoices, the app stores the invoice and a frozen copy of who it was addressed to: the bill-to party's name, a contact name, telephone number, email address and postal address, alongside the line items, the tax rate you typed in, the totals, and your own business details as they read on the day it was issued. Where you bill a unit's occupant, that party is a tenant — often a private individual rather than a business. The app also stores the payments you record against an invoice: the date, the amount, the method (cash, cheque, card, ACH or other), a free-text reference you type, a note, and which member of your team recorded it. We do not process payments, and we never receive or store a card number — the reference box holds only what you choose to type into it.
- Diagnostic Error Reports: When part of the app fails, it uploads a technical error report to our database so we can find the fault: your user ID, the platform, where in the app it happened, the error message, the JavaScript stack trace, and the app version. These are write-only — they are not shown back to you anywhere in the app — but they are deleted along with your account. See Section 14.
- Device Reports: Settings has a Device Report screen that gathers what the phone is holding — the app and update versions and the device model; your user ID, the first four characters of your email address together with its domain, your subscription plan, and your workspace name and role; the crash messages recorded on the phone; the list of photographs waiting to upload; how many rows each local table holds; what files are on disk; and the names and sizes of the app's stored settings, with the contents of a short list of diagnostic keys — and lets you copy it, share it, save it, or send it to us. Nothing is sent unless you press Send. When you do, the report is written to your own account on our servers, where we read it to diagnose the problem you reported. A crash message is raw text from the moment the app failed, and it can contain a customer's address, a serial number or a note off a nameplate; the report warns you of this before you send it. Device Reports are deleted along with your account.
- App Performance & Crash Telemetry: Since version 6.34.0 the app measures how long it takes to start — cold launch time, the time to load its program code, and the time until the first screen is ready to use — and sends those measurements, together with reports of software errors it catches, to Expo, the service that builds and delivers the app’s updates. See Section 11. Each app launch generates a fresh random session identifier that travels with these reports. We do not attach your account, name, email address or user ID to them, and this telemetry is not used to track you or to build a profile. It is separate from the Diagnostic Error Reports above, which do carry your user ID and go to our own database.
- IP Addresses: Our servers record the IP address of the browser that submits the SMS consent form on our website, which we use only to rate-limit that form against abuse. Our servers also capture the IP address and browser user agent of the browser that starts a web subscription checkout, and pass both to Meta with the purchase event described in Section 11. This is separate from the website cookies covered by Section 12.
- SMS consent records: When somebody confirms on our website that they agree to receive text alerts, we store against their telephone number the name and company they typed, the consent wording they agreed to, the language of the page, the time, and whether they have since replied STOP or START to a message. The record is looked up by the number: anyone signed in to an Equipment Tracker account who knows a telephone number can read its consent status and the name and company on it, because the app and dashboard show that status next to each number on a notification list. It cannot be listed — a number has to be known to be looked up. Consent records are not removed when the account that added the number is deleted (Section 14).
- Server logs: Our Cloud Functions write operational logs to Google Cloud. Those logs record, among other things, the telephone number and text of any message sent to our SMS number — including a reply that is not STOP or START — the telephone number and IP address behind an SMS consent submission, and the email addresses our alerts were sent to. They are used only to diagnose faults and are kept for the retention period set on our Google Cloud project.
- Website Contact Form: If you write to us through the contact form on equipment-tracker.com, we store the name, email address, company and role the form collects and the message you type, together with any screenshots you attach, and email all of it to our support address. The role is a short menu with a default answer, so one is recorded against your message whether or not you change it. Screenshots attached to a contact message are stored at a web address readable by anyone holding the link, so treat an attached screenshot as readable by anyone given that link.
3. AI-Powered Data Extraction
When you use an AI feature, the images or text involved are sent to Google's Gemini API (via a secure Firebase Cloud Function) and the result is returned to the app and stored according to your local/cloud preferences. This applies to every AI feature in the app, and all of them require an internet connection:
- Nameplate scanning: photographs of equipment data plates, read for manufacturer, model, serial number and electrical specifications.
- AI Condition Scan: photographs of equipment, assessed for visible condition.
- Invoice and work-order scanning: photographs of service invoices, work orders and receipts. These may carry information about people other than you — a technician's name, a company name, a service description and costs written on somebody else's paperwork — and that is sent to Google along with the rest of the image.
- AI Diagnostics: the symptoms, measurements and notes you type into a troubleshooting conversation, any photographs you attach to it — including ones already saved against that equipment or its parts — and, so that the model knows what it is looking at, the equipment's own record: its name, manufacturer, model and serial number, its specifications and the notes you have written on it, together with its five most recent service log entries — the date, the service type, the description and the parts used.
Images and text are transmitted securely and are subject to Google's data processing terms. We do not use any of it to train models.
We also keep a copy of the result on our servers. When a nameplate scan, a condition scan or an invoice scan comes back, we store the result against your account in a short-lived cache, so that a retry of the same tap — a dropped connection, a second press — returns the answer you already paid for instead of buying it again. The cache is meant to answer for a few minutes and then expire. The automatic expiry has not been switched on for this collection yet, so in practice those stored results stay on our servers until we remove them — but they are deleted along with your account (see Section 14). For an invoice or work-order scan, the stored result contains what was read off somebody else's paperwork. You can ask us to delete yours at any time at support@equipment-tracker.com.
4. Guest Technician Service Submissions
Equipment Tracker Pro supports guest service submissions via the public QR specification page. When a guest technician (a person who does not have an Equipment Tracker account) scans a Link Mode QR code and submits a service report through the web form, the following information is collected:
- Technician name and company/vendor name entered by the guest
- Service date, service type, work description, and parts replaced as entered by the guest
- Optional before and/or after service photographs uploaded by the guest
Guest submissions are stored in our Firebase Firestore database in a shared incoming_maintenance collection, each one stamped with the account it was sent to rather than filed inside that account's own records. Because they sit outside that account's data, closing the account does not remove a submission still waiting in the Transfer Inbox, or the photographs attached to it — see Section 14. Service photos are stored in Firebase Storage under the incoming_maintenance_images/ path. Guest submissions remain pending until the account holder explicitly reviews and accepts or rejects them in their Transfer Inbox. They are not automatically added to the owner's maintenance records. The guest technician is not required to provide any personal account credentials or contact information beyond what they voluntarily enter in the form fields.
5. What a Public QR Page Publishes
A Link Mode QR code prints a link to a page we host for that piece of equipment. That page is readable by anyone who scans the code, without an account and without signing in — that is what the code is for. It is not indexed and cannot be listed or browsed; it can only be opened by someone who has the specific code.
The page publishes the equipment's specifications, its parts list, its service history, and any notes you have recorded against the equipment — that notes field is free text, so treat whatever you type there as readable by anyone who scans the code. By default it also publishes the site information for the building the equipment is in: the street address and the building contact's name, telephone number and email address. The customer name you have recorded for that building is published in the page's underlying record as well, readable by anyone holding the code, even though the page itself does not print it. This is deliberate for commercial sites, so that a visiting vendor standing at the equipment has somebody to contact about access or building issues.
You can turn site information off, per building. In the app, open the building, open Site Info, and clear "Show site info on QR codes". While it is off, the address and contact details are not published, existing pages for that building are rewritten to remove them, and anyone scanning a code for that building sees a notice saying site information is turned off. Equipment specifications, parts and service history are still shown. We recommend turning it off for residential addresses, where the building contact is a private individual rather than a facilities manager.
One thing that control does not govern: the vendor door sign. It applies to equipment QR pages — the codes you stick on a machine, which anyone standing in front of it can scan. A vendor check-in door sign is different: you print it and hang it deliberately so that a visiting vendor knows who to call about the site, and the page it leads to always carries the site address, the customer name and the building contact's name, telephone number and email address, whether or not "Show site info on QR codes" is on — and the record behind that page, which is readable without an account, also holds any sign message you have written for vendors, so do not put a gate code or anything else you would not want a stranger to read into that message. That is what the sign is for. The sheet itself also prints whatever message you have written for the sign, so treat that message — which people commonly use for a gate code or a direct number — as readable by anyone who walks past the door. If you do not want those details on a door, do not print the sign for that building.
What a vendor writes when they check in is not private either. A check-in entry records the name and the company the visitor types in, the area of the building and the reason they give for being there, and the time. Entries are stored in a place readable without an account, because the check-in page and the log a vendor is standing in front of have to be able to show them without anyone signing in. Treat a building's check-in log as readable by anybody, and do not put anything on a check-in door sign that you would not want a passer-by to scan. Deleting your account does not remove check-in entries that have already been made — see Section 14.
Service history entries shown on a public page carry the date, service type, description, technician name, vendor company and the parts replaced. They do not carry any cost, labour rate, labour hours or materials cost you have recorded — those fields are never published to a public page.
A tenant tag publishes a page too. The page behind a tenant tag is readable by anyone who scans that tag, with no account and no sign-in. Like an equipment page, it cannot be listed or browsed — it can only be opened by someone holding that specific code. It shows the building name, the unit label, a short verify code, and whatever you have typed into that building's tenant information page and that unit's own version of it: the office name, telephone number, email address and hours, an after-hours number, what counts as an emergency, fire safety text, shutoff locations, utilities, trash and parking, current notices, any document links you add and any sections of your own. It never shows the tenant's name, telephone number or email address — those stay in your workspace. Treat anything you put on that page, including any link, as readable by anyone holding the card.
Replacing a tag retires the old page. If a card goes missing or a unit turns over, replacing the tag mints a new code and deletes the page the old card pointed at, so the old card resolves to nothing. Deleting a unit, or clearing its tag, does the same. Since September 2026 the printed door tag also shows the unit's short verify code, the same code the page shows.
Your own sticker address (Team plans). A workspace owner or a Manager on a Team plan can have the workspace's live QR codes and tags use a web address the workspace owns, such as tags.yourcompany.com, instead of equipment-tracker.com. When one is saved:
- We store the address in the workspace's record, and connect it to our hosting provider (Google Firebase Hosting), which issues a security certificate for it. Every member of the workspace can see the address.
- We email the DNS records to add to the email address of the account that saved it, and one further email to the workspace owner and that account when the address starts working. The address record does not store anyone's email address.
- Our servers check the address every 30 minutes for up to 14 days after it is saved, and whenever someone presses Check, by reading one small public file at that address. The check reads nothing else there.
- Once it works, codes printed or shared afterwards carry that address. The pages behind them are the same public pages this section describes, with the same content, served under that address. Whoever controls that domain controls where those codes lead: if it is pointed somewhere else, the codes go there, and we no longer control what they show.
- Stopping use of the address, or changing it, disconnects it from our hosting. Codes already printed with it then stop opening our pages unless the domain is pointed somewhere that answers them.
Downloading your sticker pages. The same people can download a file holding a copy of every live public page in the workspace, with its photographs and a spreadsheet listing every code. It carries only what the public pages already publish, never tenants' names or contact details and never costs. Once downloaded it is outside our reach; the workspace decides where it is kept and who can see it.
6. Tenant Service Requests
Account holders can print a QR code for the inside of a tenant's door — either one for the whole building or, since August 2026, one per unit. Scanning it opens a request form, not a service log.
What the form asks for. The form asks what is wrong, optionally the resident's name, and optionally up to three photographs. On a building-wide code it also asks which unit. It does not ask for a telephone number or an email address, and there is no field on it for either. If the account holder has recorded a tenant against that unit, we read that name, telephone number and email address from the unit's record when the request arrives and record them onto the request, so that the people who maintain the building can call back. That is how a resident is contacted without being asked to hand over details the landlord already holds.
Where it goes. A request goes to the account holder who printed the tag, and is visible to every member of their team in every role. Tenant photographs are stored separately from all other guest uploads, under a tenant_requests/ path in Firebase Storage, and are readable only by the account holder and their active team members after signing in. They are not publicly readable. This is a deliberate difference from guest technician photos, because a tenant request can contain images of the inside of somebody's home.
Who is alerted. An account holder can set a list of email addresses and telephone numbers to be alerted about tenant requests, separately from the list used for vendor check-in alerts. If a building has no tenant list set, alerts fall back to that building's vendor check-in recipients rather than being sent nowhere — a resident reporting no heat should not be met with silence because a second list was never filled in. A separate tenant list, where one exists, always wins. If you do not want tenant reports reaching your vendor contacts, set a tenant list. Alerts carry a link to the account holder's dashboard and never the photographs themselves. One request per code per hour is accepted, so a per-unit tag throttles per unit rather than for the whole building.
Tenant requests are held for review and never create a work order on their own.
If you are a resident who scanned a tag. You have no account with us and you are not asked to create one. What you write and any photographs you attach go to the people who maintain your building — the account holder who printed that tag and the members of their team — and to us, because we host and deliver it for them. If they hand the job to an outside contractor who also uses Equipment Tracker, your name and what you reported go to that contractor with it, and — when they hand it over from our web dashboard rather than the phone app — your photographs go with it too. We do not use it for any purpose of our own, we do not sell or share it, and we do not use it for advertising or to train models. If you want to know what has been recorded about you, or want something you sent removed, contact the people who maintain your building; you can also write to us at support@equipment-tracker.com and we will act on their instruction.
7. AI Diagnostics Are Stored Only on Your Device
The AI Diagnostics feature records a troubleshooting conversation about a fault, including symptoms, measurements and notes you type. Since an update published on 12 August 2026 these sessions are stored only on your device. The conversation itself is not uploaded to our servers, is not included in cloud backup, is not shared with team members, and is not transferred with a building. One thing about a session does reach us. Each time you send a turn, our server writes a small row against your account recording that session's own identifier, when it opened, when it was last used, how many turns it has run and how many free scans it has consumed — that row is how a follow-up question is recognised as part of a conversation you have already paid for. It holds none of what you typed and none of what the AI answered, and it is deleted with your account (see Section 14). Sessions that had already been uploaded before that date remain on our servers pending deletion. They are not used for anything, and you can ask us to delete yours at any time at support@equipment-tracker.com.
One consequence is worth stating plainly: because they are not backed up, a lost, wiped or replaced device loses its diagnostic history. The feature is not offline. Every turn you send goes out through our Cloud Function to Google's Gemini API to be answered, as described in Section 3, and it does not travel alone: the conversation so far, the equipment record the session is attached to, and that unit's five most recent service log entries go with it, so the answer takes the machine's history into account. The answer comes back to the phone and the conversation it builds up is retained only locally.
8. Peer-to-Peer Data Sharing
If you utilize the "Send to User" feature, the specific equipment, parts, or maintenance data you choose to send is written to the Equipment Tracker account of the recipient you designate, where it waits in their Transfer Inbox until they accept or discard it. You designate that recipient by their email address or by their Push Username; either one is used only to locate an existing Equipment Tracker account, and if no account matches, nothing is sent. A Push Username is public within the product: every username, together with the account ID behind it, can be read by any signed-in Equipment Tracker account. Choose one you are content for other users to see. We do not email your data to the address you type. Your own account travels with what you send. The transfer record carries your email address — and your Push Username as well, if you have set one — and the person you sent it to can read the whole record: setting a username changes what the app shows them, not what the record holds. Shared data is stored in Firebase until the recipient claims or discards it, and we do not send it to anyone you have not designated. This describes the "Send to User" feature only — team workspaces work differently and are described in Section 17.
Sending a work order to another contractor. A Pro subscriber can send a work order to another Equipment Tracker account that also has Pro — normally a subcontractor, though nothing stops you sending one to somebody already on your team. You designate the recipient by email address or Push Username, exactly as above. What travels is the work order itself; the piece of equipment it is about, with up to twenty-four of its photographs, its parts and up to eight photographs per part; and enough of the site for somebody to find it and know who to call — the building name, the customer name, the street address, your site notes, and the building contact's name, telephone number and email address — plus up to twelve site photographs and any note you type. The record is written by our servers to a place both accounts can read and neither can write. It carries your Push Username or, if you have not set one, your email address, and the recipient's phone is sent a notification naming you. When the job comes back, the same record holds what the contractor claims for it — hours, labour, materials, other costs and a total — any purchase order number you supply, and a link to the invoice the contractor attached, which can be a PDF or a picture held in our cloud storage. These dispatch records are not removed when either account is deleted; write to support@equipment-tracker.com to have one removed. We also remember who you have sent to. The app and the dashboard keep, on your own account on our servers, the email addresses or Push Usernames of the people you most recently sent a work order to — the last eight — and of the people you most recently shared data with — the last twenty — so that the same list offers itself on your phone and in your browser. Alongside them we store the time the list last changed, and nothing else. It is never shown to the people on it, and it is deleted with your account.
Transferring a building. Separately from Send to User, you can hand a whole building to another Equipment Tracker account by generating a six-character transfer code. Generating one writes a complete copy of that building to our servers: its equipment, parts and service history with their photographs, its inventory and tools, its work orders, PM schedules and tool check-out history, its site photographs, and its site record — the street address and the building contact's name, telephone number and email address. The copy also carries your own email address, which the recipient sees. It does not include the building's units and tenants, its owner record, or its invoices. The code is the only key: anyone signed in to any Equipment Tracker account who has it can read that copy, and can take the building with it for seven days, so treat the code like a password and give it only to the person you mean. The copy is not deleted when the transfer is claimed or when the code expires; it stays on our servers until you delete your account (Section 14) or ask us to remove it.
9. Data Import & Export
The app can export your data as a ZIP archive and import data from one. A full backup is a complete copy: it contains the app's entire database file and a settings file, which together carry your equipment, parts, inventory, maintenance logs and their photographs, your tools and their checkout history, PM schedules, work orders, invoices and the payments recorded against them, AI diagnostic conversations, your company profile and invoice defaults, any AI key held on the device, and everything you have recorded for each location — the customer and contact name, telephone number and email address, the billing address, the phone numbers and email addresses on that location's alert lists, and the units inside it with the current occupant's name, telephone number and email address. A per-location or per-unit export is narrower, but still includes that location's full contact, alert-list and billing record. Archives are not password-protected, so you are responsible for the security of an exported file once it leaves the app. On Android, the app supports automated local backups to a Storage Access Framework (SAF) linked folder.
10. Professional Reports
The app can generate professional equipment reports, maintenance summaries, and building inventories. These reports may be shared via your device's native sharing capabilities. Report content is derived from data you have entered and is not transmitted to our servers.
11. Third-Party Services & Subscriptions
Your data is processed by the following third parties according to their respective privacy policies:
- Google Gemini API: Used for every AI feature in the app, as described in Section 3 — nameplate scanning, AI Condition Scan, invoice and work-order scanning, and AI Diagnostics. The photographs you scan and the troubleshooting text you type are sent to Google's servers for processing and are subject to Google's privacy policy.
- Google Firebase: Used for secure user authentication, database syncing, cloud storage, and peer-to-peer data transfers.
- Google Play Billing & Apple App Store: Used to securely process and verify in-app subscriptions on Android and iOS. We do not collect, process, or store your credit card or payment information.
- RevenueCat: Used to manage, verify, and synchronize subscription entitlements across Android, iOS, and the web dashboard. RevenueCat processes subscription status data according to their own privacy policy. Every account is registered with RevenueCat under its user ID at the moment it is created, whether or not it ever buys anything, so that a purchase made later on any platform can be matched to the right account. What our servers send RevenueCat for a free account is that user ID and nothing else; no name or email address goes to it from us.
- Stripe (subscriptions): Used to process web-based subscription payments. Payment data is handled exclusively by Stripe and is not stored on our servers. Stripe processes payment data according to their own privacy policy.
- Stripe (payments on your invoices): A business can let its customers pay its invoices online through the business's own Stripe account (Terms, Section 20).
- Setting it up. When the account owner sets up online payments, our servers ask Stripe to open an account for the business and send Stripe the email address the owner signs in with and the owner's Equipment Tracker user ID. The owner then gives Stripe the business's details, identity documents and bank account on Stripe's own pages; none of that reaches us. We store the Stripe account ID and what Stripe reports about it: whether it can take payments and receive payouts, whether its details are complete, and how many items Stripe still needs. We also store the owner's agreement to the platform fee: the Terms version, the time, the user ID that agreed, and the rate in force.
- A customer paying. We send Stripe the invoice number and the amount owed, and the customer enters their card or bank details on Stripe's own page; we never see or store them. Stripe tells us the result, and we record the payment on the invoice with the amount, the date, whether it was by card or by bank, and Stripe's reference for it. Stripe may send the customer a receipt, and processes the customer's details under its own privacy policy.
- The invoice's web page. Each created invoice has a web page whose link carries a random code, and anybody who has the link can open it. It shows the whole invoice: the business's name, telephone number and email address; the name, contact, telephone number, email address and postal address the invoice is billed to; every line, the totals, the note to the customer and the payments recorded against it; and the PayPal and Venmo usernames the business has switched on. The page is marked so search engines do not list it. To limit abuse, our servers count requests to it by a keyed hash of the requesting IP address — never the address itself — and each count expires after one hour.
- PayPal and Venmo: A business can enter its PayPal or Venmo username in Company Profile. We store it with the company profile, and it is printed on the business's invoices as a link and a QR code that open PayPal or Venmo with the amount owed filled in. A payment made that way goes directly between the customer and the business; nothing about it is sent to us, and PayPal and Venmo process it under their own privacy policies.
- Expo (push delivery and app performance monitoring): Used to deliver the push notifications described in Section 2. Your device's push token and the title, body and payload of each notification pass through Expo's push service on the way to Apple's or Google's delivery network. Because a notification can name a technician, a resident or a vendor, those names pass through it too — and when another Equipment Tracker user sends you data, the notification names them by their Push Username, or by their email address if they have not set one. Expo also receives the app performance and crash telemetry described in Section 2 — launch timings and caught software errors, carrying a per-launch random session identifier and not your account — and processes it under its own privacy policy.
- Twilio (SMS delivery): Used to send the text-message alerts described in Section 15 — vendor check-in and check-out alerts, and tenant service request alerts. The recipient's telephone number and the text of the alert, which can include a resident's or vendor's name and what they reported, are handed to Twilio to deliver.
- Google Workspace (Gmail) for email delivery: Used to send the email alerts and support email described in this policy — tenant request alerts, vendor check-in alerts, guest submission notices and contact-form messages. The recipient's email address and the contents of the message, including any names in it, pass through Google's mail service.
- QR image service (api.qrserver.com, operated by goQR.me in Germany): Used by the mobile app to draw the QR image on a label or tag when you preview or print one. The label's contents are sent to that service inside the web address of the image request. For a link-style label that is only the link. For a label you have configured to carry the data itself, it is whatever you told the label to carry — which can include the building contact's name, telephone number and email address, serial and model numbers, and the equipment's notes. The web dashboard's own label generator does not use this service — it draws QR codes inside your browser. Elsewhere on the website this service draws QR codes for plain links only, such as an app download link or a vendor check-in link, which carry no personal details.
- Google Fonts: Every page of our website and of the signed-in dashboard, except this policy and our Terms, loads its typefaces from Google's font servers, so your browser's IP address and user agent reach Google on every page view — including the public tenant request, vendor check-in and QR pages. Google is not told which page you are on, nothing else is sent, and no cookie is set.
- Apple (App Store lookup): Every page of our website except this policy and our Terms, and every page of the signed-in dashboard, asks Apple's public App Store lookup service for our current App Store rating, so your browser's IP address and user agent reach Apple on every page view. Two pages ask a second time from the page itself: the Compare page every time, and the home page only when our own stored copy of the rating cannot be read. Nothing about you is sent with any of these requests.
- Meta (Conversions API): When a subscription is purchased through the website, our servers send a purchase event to Meta for advertising measurement. It carries the buyer's email address, telephone number, first and last name, city, state, postal code, country and account ID, each of them hashed before it is sent, together with the browser's IP address, its user agent, and Meta's own
_fbp/_fbccookie identifiers, which are sent as they are because Meta requires them that way. This is separate from the Meta Pixel that runs in your browser, described in Section 12. It does not run in the mobile app or on app-store purchases.
12. Website Analytics, Advertising & Tracking Technologies
Our marketing website (equipment-tracker.com) uses cookies and similar tracking technologies from the following third parties to understand site usage, measure advertising performance, and improve our marketing. Google Analytics, Google Ads conversion tracking and the Meta Pixel also load on the signed-in web dashboard and record page views there. Microsoft Clarity is loaded but is stopped as soon as a signed-in page opens, so dashboard sessions are not recorded in Clarity. None of these technologies are used in the mobile app.
- Google Analytics & Google Ads: We use Google Analytics to understand how visitors use our website, and Google Ads conversion tracking to measure the performance of our advertising campaigns. For more information, visit the Google Privacy Policy.
- Meta (Facebook) Pixel: We use the Meta Pixel to measure the effectiveness of our advertising and to show relevant ads to people who have visited our website. Meta may use this data for its own advertising purposes according to its own data policy. Meta also receives a purchase event from our servers — not from your browser — when a subscription is bought on the website; what that event carries is set out in the Meta entry in Section 11.
- Microsoft Clarity: We partner with Microsoft Clarity and Microsoft Advertising to capture how you use and interact with our website through behavioral metrics, heatmaps, and session replay to improve and market our products/services. Website usage data is captured using first and third-party cookies and other tracking technologies to determine the popularity of products/services and online activity. Additionally, we use this information for site optimization, fraud/security purposes, and advertising. For more information about how Microsoft collects and uses your data, visit the Microsoft Privacy Statement.
You can control or disable cookies at any time through your browser settings. Our mobile app does not use any of the tracking technologies described in this section.
If applicable privacy law grants you the right to opt out of the sale or sharing of personal information, or to exercise any other privacy right regarding these technologies, contact us at support@equipment-tracker.com.
13. Children's Privacy
Equipment Tracker is a professional tool designed for HVAC technicians and is not directed at children under the age of 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us immediately so we can delete it.
14. Data Retention & Deletion
Your local data remains on your device until you delete it. Cloud-synced data is retained as long as your account is active. You may delete your account and all associated cloud data at any time from the app's Settings menu: open Settings, find Delete Account under Account, and press and hold it — a short tap only explains that it needs a long press, which is deliberate so the control cannot be hit by accident. Holding it opens a confirmation in which you type the word DELETE; nothing is removed until you do. The web dashboard has the same control: sign in at equipment-tracker.com, open Account, and use Delete Account at the bottom of the page. It asks you to type the word DELETE and then runs the same deletion as the app; if you have not signed in for a while it will ask you to prove it is still you before it can remove the sign-in account at the end — your password if you signed up with one, or a Google or Apple sign-in window if you came in that way — and that check arrives after the data has already gone, so finish it rather than closing the tab. Upon account deletion we cancel any active Stripe subscriptions, delete your user data tree, your pending shares — both the ones waiting for you and the ones you sent to somebody else — your team records, your image files from our storage, the diagnostic error reports described in Section 2, the cached AI scan results described in Section 3 together with the record of when your account used the AI features, any building transfer code you generated along with the copy of the building held behind it, and the tenant service requests submitted to your buildings together with the photographs residents sent with them. Some records created outside that tree are not removed automatically — public equipment pages you published through a QR/Link Mode code, building check-in configurations and their notification contact lists, vendor check-in entries, guest technician submissions and their photos, work orders you sent to another contractor or received from one (each carries the work order, the equipment and the site's address and contact details, and is kept for both parties as the record of the hand-off), SMS consent records for numbers that were added to a notification list, the hashed device record used to enforce the free scan limit, anything you have sent us through the website contact form together with the screenshots attached to it, the record of your business's Stripe account and the Pay online links minted for your invoices (Section 11), and your reserved username. Your Stripe account itself belongs to your business and is not closed by deleting your Equipment Tracker account; close it with Stripe. If any part of the deletion or subscription cancellation does not complete, your authentication account remains intact and deletion is halted. Contact us at support@equipment-tracker.com to have anything remaining removed, and we will remove it.
If you no longer have the app. You do not need to reinstall it to be deleted. Sign in to the web dashboard and use the Delete Account control on its Account page, or write to us at support@equipment-tracker.com from the address the account was created with and we will run the same deletion for you. https://equipment-tracker.com/delete-account sets out all three routes and repeats the two lists above, and it can be read without an account. One thing worth knowing before you start: the deletion cancels a subscription bought on the website through Stripe, but it cannot cancel one bought through Google Play or the Apple App Store — those are held by the store, and you have to cancel them in the store's own account settings.
Tenant service requests. A request and its photographs stay in your workspace after you have dealt with it — marking a request handled does not delete it. Deleting one is a separate control. On the phone, open the Transfer Inbox, go to the Tenants tab, and use Delete this request and its photos at the bottom of the request. On the web dashboard, open Inbox and use the DELETE button on the request. Either one removes the photographs from our storage first and the request itself after them, and if a photograph cannot be removed the request is kept so that you can try again rather than losing the only record of where those pictures are. A Viewer cannot use it. Requests are not deleted on any schedule, and they are deleted with your account along with the rest of your data. If you would rather we removed one, contact us at support@equipment-tracker.com and we will remove it.
Deleting a building or a piece of equipment archives a summary of it. The record's photographs are destroyed straight away and irreversibly. A text summary — the title, the building name, the address and the equipment history — is moved into your Archive, which is part of your workspace and is visible to your team members. The site contact's name, telephone number and email address are deliberately not kept in the archive. You can remove a record permanently from the Archive at any time.
Invoices are the exception to that. An invoice is a financial record of a transaction that happened, so it keeps its own frozen copy of who it was addressed to — the name, telephone number, email address and postal address that were on it when it was issued — and it keeps them after the building it relates to has been deleted. Where you billed a unit's occupant, that is a tenant's name and contact details. This is deliberate: a document asking for money with no addressee is not a record of anything. Invoices and the payments recorded against them are deleted with your account, along with the rest of your data tree.
If you are a member of a team workspace, "your account" means your own account only. Deleting your account does not delete the workspace owner's data, and a workspace owner deleting their account does not erase copies already downloaded onto members' devices. Your member record — the email address, role and join date, and any name or notification address the owner set for you — is stored under the workspace owner's team record rather than under your own account, and deleting your account removes it from there as part of the same deletion. What the deletion does not reach is the tag the app put on the records you created or changed while you were a member: your user ID and your display name, or your email address where you never set a display name, and on the records named in Section 17 the user ID of the last person to change them. Those stay in the owner's data because they are part of the owner's records; contact us at support@equipment-tracker.com if you want them removed and we will remove them.
15. Data Sales & Sharing
We do not sell, rent, or trade your personal data, equipment logs, maintenance records, or images to any third parties.
Mobile information and SMS opt-in data will not be shared with third parties or affiliates for marketing or promotional purposes. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
If you opt in to receive SMS notifications (such as vendor check-in and check-out alerts, or alerts that a resident has submitted a service request from a tenant tag), message frequency will vary depending on your account's activity and notification settings. Message and data rates may apply. A number is added to a building's notification list by the workspace owner or a Manager, in that building's Site Info — under Vendor Check-In — Notify Phones (SMS Text Alerts) and under the tenant alerts' Text Alerts list, both of which the web dashboard labels Notify Phones (SMS) — and it can be removed there at any time. There is no list of telephone numbers in the app's notification settings; that screen carries push switches only. If it is your number and you are not the person who added it, reply STOP to any message: our servers record the opt-out against your number and send nothing further to it unless you reply START.
16. Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page with a revised effective date. We encourage you to review this policy periodically. Your continued use of the app after changes are posted constitutes your acceptance of those changes.
17. Team Workspaces
A subscriber on a Team plan (a "workspace owner") can invite other people ("team members") into their workspace using an invite code. This section explains what that means for the data in the workspace.
What team members can see. A team member can read all of the data in the workspace: equipment, parts, maintenance and service records, inventory, tools and their check-out history, work orders, PM schedules, photographs, invoices and the payments recorded against them, and building and site information — including customer names, contact details, and billing addresses. "All of the data" is meant literally, so it also takes in the building owners you have recorded, the units in each building and who is in them, with the tenant's name, telephone number, email address and notes, the tenant service requests residents have sent and the photographs attached to them (see Section 6), guest technician submissions, vendor check-in entries, each building's check-in and tenant notification lists with the email addresses and telephone numbers on them, the Archive, and your company profile. A member can also read the list of members — each one's email address, role and join date — and the account profile we keep for you: your push notification token, the language and time zone the app recorded, and your username. Access is not limited by building or by customer. Team members are assigned a role — Viewer, Tech, or Manager — which controls what they can change. Invoicing is the one record type a role also hides: the app shows invoices and payments to the workspace owner and to Managers only, and a Tech or a Viewer has no invoicing screen. That is a limit in the app, not on our servers — invoices still sync down onto a Tech's or a Viewer's device so that the rest of their data syncs correctly, so treat the figures on an invoice as reaching every device in the workspace. Everything else in the workspace is visible to all three roles.
Data on team members' devices. When a team member joins from the mobile app, the app erases the data already on that member's device and downloads a copy of the workspace onto it — including customer and billing information and photographs — so the app works offline. Members who use only the web dashboard do not receive a copy of the workspace's records: the dashboard reads them from our servers each time and holds them only in the page's memory. A few smaller things are written into that browser and stay there until its site data is cleared, and leaving the workspace does not clear them — the workspace's company profile (name, telephone number, email address, logo and technician name), the email addresses of the last eight contractors that member sent a work order to from the dashboard, the filter selections each list screen remembers, which include the names of the buildings that were selected, and, if a spreadsheet import was started on the dashboard and never finished or restarted, the building name, equipment name, serial number and model number of the rows it had already worked through.
When a member leaves or is removed. Their access to the workspace ends immediately on our servers. The app erases the local copy from that member's device the next time it runs with an internet connection. We also send a silent push command to the member's device instructing the app to erase the workspace copy right away. This is best-effort: it only works if the device is online with notifications registered, and we cannot confirm the erase completed. If it does not arrive, the copy stays on that device until the app next runs with an internet connection. Anything a member has already exported, printed, or sent elsewhere is outside our reach entirely. Workspace owners should keep this in mind when deciding whom to invite and what information to keep in a workspace.
Information we hold about team members. For each member we store the email address of the account that redeemed the invite, the member's role, the date they joined, whether the invite was accepted under our Terms and which version of them was current at the time, and any display name, notification email address or work-order assignment email preference set by the workspace owner or a manager. That is stored under the workspace owner's team record. Under the member's own account we also write a pointer to the workspace — its ID, the owner's ID, the member's role and when it was last written — and when the member is removed that pointer is replaced by an instruction telling their app to erase its copy of the workspace. Records a member creates are tagged with that member's user ID and display name — or, where the member has not set a display name, with their email address instead. For work orders we also record the user ID of the last person to change the record. Two other records carry the same tag, both written from the dashboard: the service record the dashboard creates when a member completes or updates a work order there, and any equipment record that a CSV re-import on the dashboard updates. No other record type records who edited it. These tags remain in the workspace owner's data after the member leaves.
Access follows the owner's subscription. Team members receive Pro features through the workspace owner's subscription. If that subscription ends or lapses, Pro-only functions stop working for every member of that workspace.
Who is responsible. The workspace owner decides who is invited and is responsible for the customer information in their workspace, including having the authority to make it available to the people they invite. See Section 10 of our Terms of Service.
18. Contact Us
If you have questions about this Privacy Policy, please contact us at: support@equipment-tracker.com