Privacy policy
Effective 2026-05-08 · Draft (replace with counsel-reviewed copy before production launch).
What we collect
- Account data: name, email, password hash (argon2), organization name + web address.
- Operational data: customers, sites, assets, jobs, photos, signatures, GPS pins you create. This is your data.
- Telemetry: IP address + user agent on requests (used for rate-limiting + audit). Held 30 days.
- Cookies: a session cookie and a CSRF cookie. No third-party tracking.
What we do not collect
- We do not buy advertising data or run ad-network pixels.
- We do not sell your data to anyone.
- We do not read your customer's information for our own use.
Sub-processors
We rely on the following sub-processors. Each has a DPA on file.
- Postgres hosting (Neon)
- Object storage (Cloudflare R2)
- Email delivery (Resend)
- SMS delivery (Twilio)
- Payments (Stripe)
- Accounting sync (Intuit QuickBooks)
Your rights
You can export, correct, or delete your data at any time via Settings → Data export. Subject-access requests for your customers' data are handled by you as the data controller; contact us for assistance.
Security
Passwords are hashed with argon2id. Connections use TLS 1.2+. Sensitive fields (OAuth tokens) are encrypted at rest. Multi-tenant isolation is enforced at the data layer; cross-org access is impossible by design.
Contact
Privacy inquiries: privacy@fidalgosystems.com.