Privacy Policy for Equipment Tracker Pro

Effective Date: September 30, 2026

Updated September 25, 2026: Section 11 now describes the web page each created invoice has, which shows the whole invoice to anybody with its link, and says that we keep a record of a business agreeing to the platform fee. Previously updated September 24, 2026: Section 11 now describes taking payment on your invoices — what passes between us and Stripe when a business sets up online payments and when its customer pays, what the public payment page shows, and the PayPal and Venmo usernames a business can print on its invoices — and Section 14 lists the payment records that survive account deletion. Previously updated September 7, 2026: a line-by-line check of this policy against the code corrected it in three ways. It now describes flows it had never described: sending a work order to a contractor on another account, which carries the site address, the building contact and a resident's own words and photographs out of your workspace; transferring a whole building behind a six-character code; the Device Report you can send us from Settings; your company profile; SMS consent records; the operational logs our servers write, which record the telephone number and text of a message sent to our SMS number and the email addresses our alerts went to; and what a full backup archive actually contains. It corrects things that were wrong: guest submissions are held in a shared collection stamped with your account, not inside it; AI Diagnostics sends the conversation so far, the equipment record and that unit's five most recent service log entries on every turn, not only the words you type, and a record that a session happened does reach our servers even though the conversation does not; those sessions stopped being uploaded on August 12, 2026, not August 11; the web dashboard does record your language; a member record is tagged with an email address where no display name is set; a public service history entry also lists the parts used; the record behind a vendor door sign also holds the customer name and whatever message you have written on the sign; the contact form also stores a company and a role; and the sentence about opting out of text messages named a screen that holds no telephone numbers. It corrects what deletion does: tenant service requests and their photographs, and a departing member's own team record, are removed by the deletion now and have been since early September, while work orders dispatched to or received from another contractor are not, and are now listed among what survives — and both Section 14 and the page at /delete-account now describe the deletion control on the web dashboard alongside the one in the app. Section 11 adds two third parties your browser contacts that were never listed — Google's font servers, on every page of the website and of the signed-in dashboard, and Apple's App Store ratings service, on every page except this policy and our Terms — and says that every account is registered with RevenueCat under its user ID the moment it is created, whether or not it ever buys anything. Section 17 now says what "all of the data in the workspace" really covers, including the units in each building and who is in them. Nothing about the software changed for any of this; the document was describing it wrongly, or not at all. Previously updated September 6, 2026: Section 2 now has a bullet for the language and the time zone held on your account. The app has written both since August 27, 2026, so that a message composed on our servers can reach you in the language the app is set to and be timed against your own clock rather than ours — the two facts the September 3 correction below describes our servers as needing, without saying that we store them. The omission is corrected here rather than the practice: nothing about what the app records has changed. Previously updated September 3, 2026: corrected the Notifications bullet in Section 2, which said that every notification the app shows is sent by our servers and "not generated on your phone", and listed maintenance and PM reminders among them. That stopped being true when reminders moved onto the device: the app now schedules a reminder about your own equipment, parts and PM schedules locally, at your device's own time, and our daily job skips them entirely rather than sending one. The bullet now separates the two mechanisms and says plainly that the device-scheduled reminders reach no server. What our servers still send is unchanged and still listed, with one clarification: the PM notification they send is for a schedule somebody else has assigned to you, not for your own. Previously updated August 29, 2026: version 6.34.0 added app performance and crash telemetry. Section 2 now has a bullet for it — launch timings and caught software errors sent to Expo, carrying a random per-launch session identifier and not your account — and the Expo entry in Section 11 now says Expo receives it, rather than describing Expo as push delivery only. Previously updated August 21, 2026: corrected the document against what the software actually does. Section 2 now states the two ways a tenant's recorded details do leave your workspace (a request alert, and billing a tenant on an invoice) instead of saying they never do; describes push notifications as remote rather than local, names the categories they cover and states that a notification can carry another person's name; describes the device identifier as pseudonymous rather than "fully anonymized", because the hash is stable; and adds bullets for invoices and payment records, diagnostic error reports, IP addresses and the website contact form, none of which had one. Section 3 now says that a scan result is also cached on our servers and that the automatic expiry for it is not switched on; it was published earlier the same day saying those cached results were not removed when an account is deleted, which was true of the software as it then stood — the deletion was corrected to reach them the same day, and this sentence with it. Section 5 now says a public equipment page also publishes the equipment's notes, states that the "Show site info on QR codes" control does not govern a vendor door sign, drops the warning that tenant tag pages could be listed — the rules were closed on August 16 and the warning should have gone with them — and says that a vendor check-in entry, which carries the visitor's name, company and stated reason for being there, is held somewhere readable without an account. Section 11 widens the Gemini entry to all four AI features and adds the four services that were missing from a list presented as complete: Expo for push delivery, Twilio for SMS, Google Workspace for email, and the QR image service the mobile app sends label contents to; it also adds Meta, which receives a hashed purchase event from our servers on a website subscription. Section 14 adds contact-form messages to what survives account deletion and names five kinds of record the deletion now reaches that it did not reach before — the diagnostic error reports, the cached AI scan results and the record of AI use, the shares you sent to other people, and any building transfer code you generated with the copy of the building behind it — states that an invoice keeps who it was addressed to after the building is deleted, and points anybody who no longer has the app at the new page at /delete-account, which can be read without an account and which says plainly that a subscription bought in an app store has to be cancelled in that store. Section 17 adds invoices to what a workspace holds and states that invoicing is owner-and-manager in the app while the records still sync to every member's device. Previously updated August 18, 2026: removed the TikTok Pixel from Section 12 — it has been removed from the website and no longer loads on any page. Previously updated August 16, 2026: revised Section 2 to cover unit and tenant records and building owners, Section 3 to cover condition, invoice and diagnostics scanning, Section 5 to cover what a tenant tag page publishes and to stop it implying that a tenant tag page is as hard to come across as an equipment page, Section 6 to state what the request form does and does not ask for and how alerts are routed, Section 7 to correct the status of previously uploaded diagnostic sessions, Section 8 to name the sharing feature by the label it actually carries in the app ("Send to User") and to correct where the data goes — into the recipient's Transfer Inbox inside their existing Equipment Tracker account, not to an email address — and Section 14 to cover the Archive, tenant request retention, what survives account deletion, and how the deletion control is actually labelled and operated. Previously updated August 11, 2026: added Section 5 (What a Public QR Page Publishes), Section 6 (Tenant Service Requests) and Section 7 (AI Diagnostics Stay on Your Device); later sections renumbered. Previously updated July 24, 2026: added Section 14, now Section 17 (Team Workspaces) and revised Sections 2, 5, and 11 to cover multi-user access to a workspace owner's data.

1. Introduction

Equipment Tracker Pro, owned and operated by Jonathan M. Curtis ("we," "our," or "us"), is committed to protecting your privacy. This Privacy Policy explains how our mobile application and web dashboard collect, use, and safeguard your information.

2. Data Collection & Usage

3. AI-Powered Data Extraction

When you use an AI feature, the images or text involved are sent to Google's Gemini API (via a secure Firebase Cloud Function) and the result is returned to the app and stored according to your local/cloud preferences. This applies to every AI feature in the app, and all of them require an internet connection:

Images and text are transmitted securely and are subject to Google's data processing terms. We do not use any of it to train models.

We also keep a copy of the result on our servers. When a nameplate scan, a condition scan or an invoice scan comes back, we store the result against your account in a short-lived cache, so that a retry of the same tap — a dropped connection, a second press — returns the answer you already paid for instead of buying it again. The cache is meant to answer for a few minutes and then expire. The automatic expiry has not been switched on for this collection yet, so in practice those stored results stay on our servers until we remove them — but they are deleted along with your account (see Section 14). For an invoice or work-order scan, the stored result contains what was read off somebody else's paperwork. You can ask us to delete yours at any time at support@equipment-tracker.com.

4. Guest Technician Service Submissions

Equipment Tracker Pro supports guest service submissions via the public QR specification page. When a guest technician (a person who does not have an Equipment Tracker account) scans a Link Mode QR code and submits a service report through the web form, the following information is collected:

Guest submissions are stored in our Firebase Firestore database in a shared incoming_maintenance collection, each one stamped with the account it was sent to rather than filed inside that account's own records. Because they sit outside that account's data, closing the account does not remove a submission still waiting in the Transfer Inbox, or the photographs attached to it — see Section 14. Service photos are stored in Firebase Storage under the incoming_maintenance_images/ path. Guest submissions remain pending until the account holder explicitly reviews and accepts or rejects them in their Transfer Inbox. They are not automatically added to the owner's maintenance records. The guest technician is not required to provide any personal account credentials or contact information beyond what they voluntarily enter in the form fields.

5. What a Public QR Page Publishes

A Link Mode QR code prints a link to a page we host for that piece of equipment. That page is readable by anyone who scans the code, without an account and without signing in — that is what the code is for. It is not indexed and cannot be listed or browsed; it can only be opened by someone who has the specific code.

The page publishes the equipment's specifications, its parts list, its service history, and any notes you have recorded against the equipment — that notes field is free text, so treat whatever you type there as readable by anyone who scans the code. By default it also publishes the site information for the building the equipment is in: the street address and the building contact's name, telephone number and email address. The customer name you have recorded for that building is published in the page's underlying record as well, readable by anyone holding the code, even though the page itself does not print it. This is deliberate for commercial sites, so that a visiting vendor standing at the equipment has somebody to contact about access or building issues.

You can turn site information off, per building. In the app, open the building, open Site Info, and clear "Show site info on QR codes". While it is off, the address and contact details are not published, existing pages for that building are rewritten to remove them, and anyone scanning a code for that building sees a notice saying site information is turned off. Equipment specifications, parts and service history are still shown. We recommend turning it off for residential addresses, where the building contact is a private individual rather than a facilities manager.

One thing that control does not govern: the vendor door sign. It applies to equipment QR pages — the codes you stick on a machine, which anyone standing in front of it can scan. A vendor check-in door sign is different: you print it and hang it deliberately so that a visiting vendor knows who to call about the site, and the page it leads to always carries the site address, the customer name and the building contact's name, telephone number and email address, whether or not "Show site info on QR codes" is on — and the record behind that page, which is readable without an account, also holds any sign message you have written for vendors, so do not put a gate code or anything else you would not want a stranger to read into that message. That is what the sign is for. The sheet itself also prints whatever message you have written for the sign, so treat that message — which people commonly use for a gate code or a direct number — as readable by anyone who walks past the door. If you do not want those details on a door, do not print the sign for that building.

What a vendor writes when they check in is not private either. A check-in entry records the name and the company the visitor types in, the area of the building and the reason they give for being there, and the time. Entries are stored in a place readable without an account, because the check-in page and the log a vendor is standing in front of have to be able to show them without anyone signing in. Treat a building's check-in log as readable by anybody, and do not put anything on a check-in door sign that you would not want a passer-by to scan. Deleting your account does not remove check-in entries that have already been made — see Section 14.

Service history entries shown on a public page carry the date, service type, description, technician name, vendor company and the parts replaced. They do not carry any cost, labour rate, labour hours or materials cost you have recorded — those fields are never published to a public page.

A tenant tag publishes a page too. The page behind a tenant tag is readable by anyone who scans that tag, with no account and no sign-in. Like an equipment page, it cannot be listed or browsed — it can only be opened by someone holding that specific code. It shows the building name, the unit label, a short verify code, and whatever you have typed into that building's tenant information page and that unit's own version of it: the office name, telephone number, email address and hours, an after-hours number, what counts as an emergency, fire safety text, shutoff locations, utilities, trash and parking, current notices, any document links you add and any sections of your own. It never shows the tenant's name, telephone number or email address — those stay in your workspace. Treat anything you put on that page, including any link, as readable by anyone holding the card.

Replacing a tag retires the old page. If a card goes missing or a unit turns over, replacing the tag mints a new code and deletes the page the old card pointed at, so the old card resolves to nothing. Deleting a unit, or clearing its tag, does the same. Since September 2026 the printed door tag also shows the unit's short verify code, the same code the page shows.

Your own sticker address (Team plans). A workspace owner or a Manager on a Team plan can have the workspace's live QR codes and tags use a web address the workspace owns, such as tags.yourcompany.com, instead of equipment-tracker.com. When one is saved:

Downloading your sticker pages. The same people can download a file holding a copy of every live public page in the workspace, with its photographs and a spreadsheet listing every code. It carries only what the public pages already publish, never tenants' names or contact details and never costs. Once downloaded it is outside our reach; the workspace decides where it is kept and who can see it.

6. Tenant Service Requests

Account holders can print a QR code for the inside of a tenant's door — either one for the whole building or, since August 2026, one per unit. Scanning it opens a request form, not a service log.

What the form asks for. The form asks what is wrong, optionally the resident's name, and optionally up to three photographs. On a building-wide code it also asks which unit. It does not ask for a telephone number or an email address, and there is no field on it for either. If the account holder has recorded a tenant against that unit, we read that name, telephone number and email address from the unit's record when the request arrives and record them onto the request, so that the people who maintain the building can call back. That is how a resident is contacted without being asked to hand over details the landlord already holds.

Where it goes. A request goes to the account holder who printed the tag, and is visible to every member of their team in every role. Tenant photographs are stored separately from all other guest uploads, under a tenant_requests/ path in Firebase Storage, and are readable only by the account holder and their active team members after signing in. They are not publicly readable. This is a deliberate difference from guest technician photos, because a tenant request can contain images of the inside of somebody's home.

Who is alerted. An account holder can set a list of email addresses and telephone numbers to be alerted about tenant requests, separately from the list used for vendor check-in alerts. If a building has no tenant list set, alerts fall back to that building's vendor check-in recipients rather than being sent nowhere — a resident reporting no heat should not be met with silence because a second list was never filled in. A separate tenant list, where one exists, always wins. If you do not want tenant reports reaching your vendor contacts, set a tenant list. Alerts carry a link to the account holder's dashboard and never the photographs themselves. One request per code per hour is accepted, so a per-unit tag throttles per unit rather than for the whole building.

Tenant requests are held for review and never create a work order on their own.

If you are a resident who scanned a tag. You have no account with us and you are not asked to create one. What you write and any photographs you attach go to the people who maintain your building — the account holder who printed that tag and the members of their team — and to us, because we host and deliver it for them. If they hand the job to an outside contractor who also uses Equipment Tracker, your name and what you reported go to that contractor with it, and — when they hand it over from our web dashboard rather than the phone app — your photographs go with it too. We do not use it for any purpose of our own, we do not sell or share it, and we do not use it for advertising or to train models. If you want to know what has been recorded about you, or want something you sent removed, contact the people who maintain your building; you can also write to us at support@equipment-tracker.com and we will act on their instruction.

7. AI Diagnostics Are Stored Only on Your Device

The AI Diagnostics feature records a troubleshooting conversation about a fault, including symptoms, measurements and notes you type. Since an update published on 12 August 2026 these sessions are stored only on your device. The conversation itself is not uploaded to our servers, is not included in cloud backup, is not shared with team members, and is not transferred with a building. One thing about a session does reach us. Each time you send a turn, our server writes a small row against your account recording that session's own identifier, when it opened, when it was last used, how many turns it has run and how many free scans it has consumed — that row is how a follow-up question is recognised as part of a conversation you have already paid for. It holds none of what you typed and none of what the AI answered, and it is deleted with your account (see Section 14). Sessions that had already been uploaded before that date remain on our servers pending deletion. They are not used for anything, and you can ask us to delete yours at any time at support@equipment-tracker.com.

One consequence is worth stating plainly: because they are not backed up, a lost, wiped or replaced device loses its diagnostic history. The feature is not offline. Every turn you send goes out through our Cloud Function to Google's Gemini API to be answered, as described in Section 3, and it does not travel alone: the conversation so far, the equipment record the session is attached to, and that unit's five most recent service log entries go with it, so the answer takes the machine's history into account. The answer comes back to the phone and the conversation it builds up is retained only locally.

8. Peer-to-Peer Data Sharing

If you utilize the "Send to User" feature, the specific equipment, parts, or maintenance data you choose to send is written to the Equipment Tracker account of the recipient you designate, where it waits in their Transfer Inbox until they accept or discard it. You designate that recipient by their email address or by their Push Username; either one is used only to locate an existing Equipment Tracker account, and if no account matches, nothing is sent. A Push Username is public within the product: every username, together with the account ID behind it, can be read by any signed-in Equipment Tracker account. Choose one you are content for other users to see. We do not email your data to the address you type. Your own account travels with what you send. The transfer record carries your email address — and your Push Username as well, if you have set one — and the person you sent it to can read the whole record: setting a username changes what the app shows them, not what the record holds. Shared data is stored in Firebase until the recipient claims or discards it, and we do not send it to anyone you have not designated. This describes the "Send to User" feature only — team workspaces work differently and are described in Section 17.

Sending a work order to another contractor. A Pro subscriber can send a work order to another Equipment Tracker account that also has Pro — normally a subcontractor, though nothing stops you sending one to somebody already on your team. You designate the recipient by email address or Push Username, exactly as above. What travels is the work order itself; the piece of equipment it is about, with up to twenty-four of its photographs, its parts and up to eight photographs per part; and enough of the site for somebody to find it and know who to call — the building name, the customer name, the street address, your site notes, and the building contact's name, telephone number and email address — plus up to twelve site photographs and any note you type. The record is written by our servers to a place both accounts can read and neither can write. It carries your Push Username or, if you have not set one, your email address, and the recipient's phone is sent a notification naming you. When the job comes back, the same record holds what the contractor claims for it — hours, labour, materials, other costs and a total — any purchase order number you supply, and a link to the invoice the contractor attached, which can be a PDF or a picture held in our cloud storage. These dispatch records are not removed when either account is deleted; write to support@equipment-tracker.com to have one removed. We also remember who you have sent to. The app and the dashboard keep, on your own account on our servers, the email addresses or Push Usernames of the people you most recently sent a work order to — the last eight — and of the people you most recently shared data with — the last twenty — so that the same list offers itself on your phone and in your browser. Alongside them we store the time the list last changed, and nothing else. It is never shown to the people on it, and it is deleted with your account.

Transferring a building. Separately from Send to User, you can hand a whole building to another Equipment Tracker account by generating a six-character transfer code. Generating one writes a complete copy of that building to our servers: its equipment, parts and service history with their photographs, its inventory and tools, its work orders, PM schedules and tool check-out history, its site photographs, and its site record — the street address and the building contact's name, telephone number and email address. The copy also carries your own email address, which the recipient sees. It does not include the building's units and tenants, its owner record, or its invoices. The code is the only key: anyone signed in to any Equipment Tracker account who has it can read that copy, and can take the building with it for seven days, so treat the code like a password and give it only to the person you mean. The copy is not deleted when the transfer is claimed or when the code expires; it stays on our servers until you delete your account (Section 14) or ask us to remove it.

9. Data Import & Export

The app can export your data as a ZIP archive and import data from one. A full backup is a complete copy: it contains the app's entire database file and a settings file, which together carry your equipment, parts, inventory, maintenance logs and their photographs, your tools and their checkout history, PM schedules, work orders, invoices and the payments recorded against them, AI diagnostic conversations, your company profile and invoice defaults, any AI key held on the device, and everything you have recorded for each location — the customer and contact name, telephone number and email address, the billing address, the phone numbers and email addresses on that location's alert lists, and the units inside it with the current occupant's name, telephone number and email address. A per-location or per-unit export is narrower, but still includes that location's full contact, alert-list and billing record. Archives are not password-protected, so you are responsible for the security of an exported file once it leaves the app. On Android, the app supports automated local backups to a Storage Access Framework (SAF) linked folder.

10. Professional Reports

The app can generate professional equipment reports, maintenance summaries, and building inventories. These reports may be shared via your device's native sharing capabilities. Report content is derived from data you have entered and is not transmitted to our servers.

11. Third-Party Services & Subscriptions

Your data is processed by the following third parties according to their respective privacy policies:

12. Website Analytics, Advertising & Tracking Technologies

Our marketing website (equipment-tracker.com) uses cookies and similar tracking technologies from the following third parties to understand site usage, measure advertising performance, and improve our marketing. Google Analytics, Google Ads conversion tracking and the Meta Pixel also load on the signed-in web dashboard and record page views there. Microsoft Clarity is loaded but is stopped as soon as a signed-in page opens, so dashboard sessions are not recorded in Clarity. None of these technologies are used in the mobile app.

You can control or disable cookies at any time through your browser settings. Our mobile app does not use any of the tracking technologies described in this section.

If applicable privacy law grants you the right to opt out of the sale or sharing of personal information, or to exercise any other privacy right regarding these technologies, contact us at support@equipment-tracker.com.

13. Children's Privacy

Equipment Tracker is a professional tool designed for HVAC technicians and is not directed at children under the age of 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us immediately so we can delete it.

14. Data Retention & Deletion

Your local data remains on your device until you delete it. Cloud-synced data is retained as long as your account is active. You may delete your account and all associated cloud data at any time from the app's Settings menu: open Settings, find Delete Account under Account, and press and hold it — a short tap only explains that it needs a long press, which is deliberate so the control cannot be hit by accident. Holding it opens a confirmation in which you type the word DELETE; nothing is removed until you do. The web dashboard has the same control: sign in at equipment-tracker.com, open Account, and use Delete Account at the bottom of the page. It asks you to type the word DELETE and then runs the same deletion as the app; if you have not signed in for a while it will ask you to prove it is still you before it can remove the sign-in account at the end — your password if you signed up with one, or a Google or Apple sign-in window if you came in that way — and that check arrives after the data has already gone, so finish it rather than closing the tab. Upon account deletion we cancel any active Stripe subscriptions, delete your user data tree, your pending shares — both the ones waiting for you and the ones you sent to somebody else — your team records, your image files from our storage, the diagnostic error reports described in Section 2, the cached AI scan results described in Section 3 together with the record of when your account used the AI features, any building transfer code you generated along with the copy of the building held behind it, and the tenant service requests submitted to your buildings together with the photographs residents sent with them. Some records created outside that tree are not removed automatically — public equipment pages you published through a QR/Link Mode code, building check-in configurations and their notification contact lists, vendor check-in entries, guest technician submissions and their photos, work orders you sent to another contractor or received from one (each carries the work order, the equipment and the site's address and contact details, and is kept for both parties as the record of the hand-off), SMS consent records for numbers that were added to a notification list, the hashed device record used to enforce the free scan limit, anything you have sent us through the website contact form together with the screenshots attached to it, the record of your business's Stripe account and the Pay online links minted for your invoices (Section 11), and your reserved username. Your Stripe account itself belongs to your business and is not closed by deleting your Equipment Tracker account; close it with Stripe. If any part of the deletion or subscription cancellation does not complete, your authentication account remains intact and deletion is halted. Contact us at support@equipment-tracker.com to have anything remaining removed, and we will remove it.

If you no longer have the app. You do not need to reinstall it to be deleted. Sign in to the web dashboard and use the Delete Account control on its Account page, or write to us at support@equipment-tracker.com from the address the account was created with and we will run the same deletion for you. https://equipment-tracker.com/delete-account sets out all three routes and repeats the two lists above, and it can be read without an account. One thing worth knowing before you start: the deletion cancels a subscription bought on the website through Stripe, but it cannot cancel one bought through Google Play or the Apple App Store — those are held by the store, and you have to cancel them in the store's own account settings.

Tenant service requests. A request and its photographs stay in your workspace after you have dealt with it — marking a request handled does not delete it. Deleting one is a separate control. On the phone, open the Transfer Inbox, go to the Tenants tab, and use Delete this request and its photos at the bottom of the request. On the web dashboard, open Inbox and use the DELETE button on the request. Either one removes the photographs from our storage first and the request itself after them, and if a photograph cannot be removed the request is kept so that you can try again rather than losing the only record of where those pictures are. A Viewer cannot use it. Requests are not deleted on any schedule, and they are deleted with your account along with the rest of your data. If you would rather we removed one, contact us at support@equipment-tracker.com and we will remove it.

Deleting a building or a piece of equipment archives a summary of it. The record's photographs are destroyed straight away and irreversibly. A text summary — the title, the building name, the address and the equipment history — is moved into your Archive, which is part of your workspace and is visible to your team members. The site contact's name, telephone number and email address are deliberately not kept in the archive. You can remove a record permanently from the Archive at any time.

Invoices are the exception to that. An invoice is a financial record of a transaction that happened, so it keeps its own frozen copy of who it was addressed to — the name, telephone number, email address and postal address that were on it when it was issued — and it keeps them after the building it relates to has been deleted. Where you billed a unit's occupant, that is a tenant's name and contact details. This is deliberate: a document asking for money with no addressee is not a record of anything. Invoices and the payments recorded against them are deleted with your account, along with the rest of your data tree.

If you are a member of a team workspace, "your account" means your own account only. Deleting your account does not delete the workspace owner's data, and a workspace owner deleting their account does not erase copies already downloaded onto members' devices. Your member record — the email address, role and join date, and any name or notification address the owner set for you — is stored under the workspace owner's team record rather than under your own account, and deleting your account removes it from there as part of the same deletion. What the deletion does not reach is the tag the app put on the records you created or changed while you were a member: your user ID and your display name, or your email address where you never set a display name, and on the records named in Section 17 the user ID of the last person to change them. Those stay in the owner's data because they are part of the owner's records; contact us at support@equipment-tracker.com if you want them removed and we will remove them.

15. Data Sales & Sharing

We do not sell, rent, or trade your personal data, equipment logs, maintenance records, or images to any third parties.

Mobile information and SMS opt-in data will not be shared with third parties or affiliates for marketing or promotional purposes. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.

If you opt in to receive SMS notifications (such as vendor check-in and check-out alerts, or alerts that a resident has submitted a service request from a tenant tag), message frequency will vary depending on your account's activity and notification settings. Message and data rates may apply. A number is added to a building's notification list by the workspace owner or a Manager, in that building's Site Info — under Vendor Check-In — Notify Phones (SMS Text Alerts) and under the tenant alerts' Text Alerts list, both of which the web dashboard labels Notify Phones (SMS) — and it can be removed there at any time. There is no list of telephone numbers in the app's notification settings; that screen carries push switches only. If it is your number and you are not the person who added it, reply STOP to any message: our servers record the opt-out against your number and send nothing further to it unless you reply START.

16. Changes to This Policy

We may update this Privacy Policy from time to time. Any changes will be posted on this page with a revised effective date. We encourage you to review this policy periodically. Your continued use of the app after changes are posted constitutes your acceptance of those changes.

17. Team Workspaces

A subscriber on a Team plan (a "workspace owner") can invite other people ("team members") into their workspace using an invite code. This section explains what that means for the data in the workspace.

What team members can see. A team member can read all of the data in the workspace: equipment, parts, maintenance and service records, inventory, tools and their check-out history, work orders, PM schedules, photographs, invoices and the payments recorded against them, and building and site information — including customer names, contact details, and billing addresses. "All of the data" is meant literally, so it also takes in the building owners you have recorded, the units in each building and who is in them, with the tenant's name, telephone number, email address and notes, the tenant service requests residents have sent and the photographs attached to them (see Section 6), guest technician submissions, vendor check-in entries, each building's check-in and tenant notification lists with the email addresses and telephone numbers on them, the Archive, and your company profile. A member can also read the list of members — each one's email address, role and join date — and the account profile we keep for you: your push notification token, the language and time zone the app recorded, and your username. Access is not limited by building or by customer. Team members are assigned a role — Viewer, Tech, or Manager — which controls what they can change. Invoicing is the one record type a role also hides: the app shows invoices and payments to the workspace owner and to Managers only, and a Tech or a Viewer has no invoicing screen. That is a limit in the app, not on our servers — invoices still sync down onto a Tech's or a Viewer's device so that the rest of their data syncs correctly, so treat the figures on an invoice as reaching every device in the workspace. Everything else in the workspace is visible to all three roles.

Data on team members' devices. When a team member joins from the mobile app, the app erases the data already on that member's device and downloads a copy of the workspace onto it — including customer and billing information and photographs — so the app works offline. Members who use only the web dashboard do not receive a copy of the workspace's records: the dashboard reads them from our servers each time and holds them only in the page's memory. A few smaller things are written into that browser and stay there until its site data is cleared, and leaving the workspace does not clear them — the workspace's company profile (name, telephone number, email address, logo and technician name), the email addresses of the last eight contractors that member sent a work order to from the dashboard, the filter selections each list screen remembers, which include the names of the buildings that were selected, and, if a spreadsheet import was started on the dashboard and never finished or restarted, the building name, equipment name, serial number and model number of the rows it had already worked through.

When a member leaves or is removed. Their access to the workspace ends immediately on our servers. The app erases the local copy from that member's device the next time it runs with an internet connection. We also send a silent push command to the member's device instructing the app to erase the workspace copy right away. This is best-effort: it only works if the device is online with notifications registered, and we cannot confirm the erase completed. If it does not arrive, the copy stays on that device until the app next runs with an internet connection. Anything a member has already exported, printed, or sent elsewhere is outside our reach entirely. Workspace owners should keep this in mind when deciding whom to invite and what information to keep in a workspace.

Information we hold about team members. For each member we store the email address of the account that redeemed the invite, the member's role, the date they joined, whether the invite was accepted under our Terms and which version of them was current at the time, and any display name, notification email address or work-order assignment email preference set by the workspace owner or a manager. That is stored under the workspace owner's team record. Under the member's own account we also write a pointer to the workspace — its ID, the owner's ID, the member's role and when it was last written — and when the member is removed that pointer is replaced by an instruction telling their app to erase its copy of the workspace. Records a member creates are tagged with that member's user ID and display name — or, where the member has not set a display name, with their email address instead. For work orders we also record the user ID of the last person to change the record. Two other records carry the same tag, both written from the dashboard: the service record the dashboard creates when a member completes or updates a work order there, and any equipment record that a CSV re-import on the dashboard updates. No other record type records who edited it. These tags remain in the workspace owner's data after the member leaves.

Access follows the owner's subscription. Team members receive Pro features through the workspace owner's subscription. If that subscription ends or lapses, Pro-only functions stop working for every member of that workspace.

Who is responsible. The workspace owner decides who is invited and is responsible for the customer information in their workspace, including having the authority to make it available to the people they invite. See Section 10 of our Terms of Service.

18. Contact Us

If you have questions about this Privacy Policy, please contact us at: support@equipment-tracker.com