Privacy · draft · counsel review required
Privacy, written down honestly — including what is not decided.
This is a working draft, not a published privacy notice. Retention periods, jurisdictions and lawful bases need qualified counsel review before any real record is processed. Nothing here should be read as a compliance claim.
No product-data collection on these pages
- These pages are static files. The site code has no sign-in, form, cookie or analytics script.
- No customer records, photos or credentials are included in this static site.
- Fonts are served from this site. A hosting provider still handles visitor requests and network metadata; its account settings and any applicable notice need review before public service.
Planned data categories for the product
| Category | Examples | Why it exists |
|---|---|---|
| Workspace and membership | Business name, member roles, invitations, timezone and currency | Tenant isolation, authorization and correct financial context |
| Case evidence | Job reference, equipment and part labels, photos, supplier documents | Proving what happened to the failed part |
| Custody and return records | Location events, RMA references, deadline types and dates | Knowing where the part is and what the supplier requires |
| Financial records | Expectations, vendor decisions, posted credits, allocations, write-offs | Reconciling credits without deciding eligibility |
| Operational metadata | Request and job identifiers, stage timing, error codes | Running the service without logging document contents |
| Audit history | Actor, action, revision, reason and timestamps | Proving who changed what, append-only |
Contact details and homeowner addresses are not required by the product. Serial numbers and part records are commercial data and are treated accordingly.
Proposed retention windows
| Data class | Proposed live retention | Deletion behavior |
|---|---|---|
| Rejected or quarantined input | 7 days maximum | Purge bytes and previews; keep only a minimal rejection code or hash if justified |
| Active case evidence | While the workspace is active; initial configurable policy 24 months | Warn before retention deletion; allow authorized export; holds need a reason and expiry review |
| Application logs | 30 days | Identifiers and timing only — no raw document content |
| Security and audit metadata | Initial 12 months, policy review required | Pseudonymize departed users where possible |
| Exports | 7 days | The snapshot stays under case retention; regeneration requires authorization |
| Deleted workspace | Live purge target within 30 days of an approved request | Revoke access immediately; enumerate exceptions and backup expiry |
| Backups | Proposed upper target 35 days | Not promised until the selected backup configuration is verified and restored |
These are product defaults proposed for review, not statements of statutory retention or legal compliance. A legal hold, where one applies, must record scope, reason, authorizing owner and a review date.
Rights and requests
- Access and export — an authorized export of a workspace's records, produced as a private snapshot artifact with its coverage and limitations.
- Correction — extracted values keep their original source and proposed value; human corrections create a new version rather than overwriting history.
- Account removal — removing one person does not erase the business's shared records.
- Workspace deletion — a different operation from account removal: access is revoked first, live derivatives are purged, and a minimal receipt records remaining retention exceptions.
No request channel is published yet, and no contact address is invented here. Enabling real requests requires the counsel review named at the top of this page.
On-device drafts
Optional field drafts are stored in the browser on the device, not in a secure vault. On a shared or unlocked device they may be readable by someone else, and the operating system may evict them. Drafts hold intake fields and scrubbed photos only — no financial values and no workspace-wide case cache.
The default expiry is 24 hours, enforced whenever the application runs. Cleanup while the app is closed is not guaranteed. Logging out or switching workspace warns about unsynced drafts and purges local storage after the warning is resolved.
What remains open
- Jurisdiction-specific review for India and the United States, including breach notification and cross-border processing.
- Processor contracts and actual provider retention controls.
- Prohibited data classes for the initial product: payment-card data, passwords, medical records and export-controlled manufacturing documents.
No DPDP, GDPR, SOC 2 or equivalent compliance is claimed anywhere on this site.