Privacy Policy for Equipment Tracker Pro
Effective Date: September 3, 2026
Updated September 3, 2026: corrected the Notifications bullet in Section 2, which said that every notification the app shows is sent by our servers and "not generated on your phone", and listed maintenance and PM reminders among them. That stopped being true when reminders moved onto the device: the app now schedules a reminder about your own equipment, parts and PM schedules locally, at your device's own time, and our daily job skips them entirely rather than sending one. The bullet now separates the two mechanisms and says plainly that the device-scheduled reminders reach no server. What our servers still send is unchanged and still listed, with one clarification: the PM notification they send is for a schedule somebody else has assigned to you, not for your own. Previously updated August 29, 2026: version 6.34.0 added app performance and crash telemetry. Section 2 now has a bullet for it — launch timings and caught software errors sent to Expo, carrying a random per-launch session identifier and not your account — and the Expo entry in Section 11 now says Expo receives it, rather than describing Expo as push delivery only. Previously updated August 21, 2026: corrected the document against what the software actually does. Section 2 now states the two ways a tenant's recorded details do leave your workspace (a request alert, and billing a tenant on an invoice) instead of saying they never do; describes push notifications as remote rather than local, names the categories they cover and states that a notification can carry another person's name; describes the device identifier as pseudonymous rather than "fully anonymized", because the hash is stable; and adds bullets for invoices and payment records, diagnostic error reports, IP addresses and the website contact form, none of which had one. Section 3 now says that a scan result is also cached on our servers and that the automatic expiry for it is not switched on; it was published earlier the same day saying those cached results were not removed when an account is deleted, which was true of the software as it then stood — the deletion was corrected to reach them the same day, and this sentence with it. Section 5 now says a public equipment page also publishes the equipment's notes, states that the "Show site info on QR codes" control does not govern a vendor door sign, drops the warning that tenant tag pages could be listed — the rules were closed on August 16 and the warning should have gone with them — and says that a vendor check-in entry, which carries the visitor's name, company and stated reason for being there, is held somewhere readable without an account. Section 11 widens the Gemini entry to all four AI features and adds the four services that were missing from a list presented as complete: Expo for push delivery, Twilio for SMS, Google Workspace for email, and the QR image service the mobile app sends label contents to; it also adds Meta, which receives a hashed purchase event from our servers on a website subscription. Section 14 adds contact-form messages to what survives account deletion and names five kinds of record the deletion now reaches that it did not reach before — the diagnostic error reports, the cached AI scan results and the record of AI use, the shares you sent to other people, and any building transfer code you generated with the copy of the building behind it — states that an invoice keeps who it was addressed to after the building is deleted, and points anybody who no longer has the app at the new page at /delete-account, which can be read without an account and which says plainly that a subscription bought in an app store has to be cancelled in that store. Section 17 adds invoices to what a workspace holds and states that invoicing is owner-and-manager in the app while the records still sync to every member's device. Previously updated August 18, 2026: removed the TikTok Pixel from Section 12 — it has been removed from the website and no longer loads on any page. Previously updated August 16, 2026: revised Section 2 to cover unit and tenant records and building owners, Section 3 to cover condition, invoice and diagnostics scanning, Section 5 to cover what a tenant tag page publishes and to stop it implying that a tenant tag page is as hard to come across as an equipment page, Section 6 to state what the request form does and does not ask for and how alerts are routed, Section 7 to correct the status of previously uploaded diagnostic sessions, Section 8 to name the sharing feature by the label it actually carries in the app ("Send to User") and to correct where the data goes — into the recipient's Transfer Inbox inside their existing Equipment Tracker account, not to an email address — and Section 14 to cover the Archive, tenant request retention, what survives account deletion, and how the deletion control is actually labelled and operated. Previously updated August 11, 2026: added Section 5 (What a Public QR Page Publishes), Section 6 (Tenant Service Requests) and Section 7 (AI Diagnostics Stay on Your Device); later sections renumbered. Previously updated July 24, 2026: added Section 14, now Section 17 (Team Workspaces) and revised Sections 2, 5, and 11 to cover multi-user access to a workspace owner's data.
1. Introduction
Equipment Tracker Pro, owned and operated by Jonathan M. Curtis ("we," "our," or "us"), is committed to protecting your privacy. This Privacy Policy explains how our mobile application and web dashboard collect, use, and safeguard your information.
2. Data Collection & Usage
- Account Information: To utilize cloud backups and sharing features, we collect your email address for account authentication via Google Firebase Authentication.
- Camera & Photo Library: The app requires access to your device's camera and photo library to capture and store images of HVAC nameplates, equipment, parts, maintenance records (before/after photos), and building exteriors or site maps.
- Equipment & Parts Data: The app stores equipment specifications, serial numbers, model numbers, manufacturer information, parts catalogs, filter sizes, belt sizes, and other technical data you enter or that is extracted via AI scanning.
- Maintenance & Service Records: The app stores service history including work order numbers, technician notes, service dates, refrigerant logs, labor hours, and before/after maintenance photographs.
- Building & Site Information: If you enter site information, the app stores customer names, contact details (name, phone, email), billing addresses, and site-specific notes associated with your buildings. You can also record the party that owns a building — their name, a contact name, telephone number, email address, postal address and notes — which is often a private individual rather than a business. A building's owner is a record your buildings point at, so one owner can hold several buildings, and the owner is never published to a QR page or to any other publicly readable place.
- Units & Tenants: You can record the units within a building — suites, apartments or tenancies, including vacant ones — and, for each unit, the current occupant's name, telephone number, email address and notes. This information is never published to a QR page or a tenant tag page. It does leave your workspace in two ways, and both are things you set up yourself. First, an alert about a tenant service request carries the resident's name and what they reported to every email address and telephone number on that building's notification list — and if you have not set a tenant list, those alerts go to the building's vendor check-in contacts instead, who are usually people outside your business. See Section 6. Second, choosing Bill To: Tenant on an invoice freezes that resident's name, unit label, telephone number and email address onto the invoice, and you can send that invoice to anyone. Nothing else sends these details outside your workspace. When a resident submits a request from that unit's tag, we read the contact details already on file so that the resident does not have to hand over a telephone number you already hold, and we record them onto that request — a request keeps who was in the unit at the time, so a later change of tenancy does not rewrite who reported a problem last week. Only an account owner or a Manager can set or change who is in a unit; see Section 17.
- Local & Cloud Storage: By default, all data is stored locally on your device in a SQLite database. If you enable Cloud Backup (Pro feature), your data is securely synced to our Firebase database and accessible via the web dashboard at equipment-tracker.com. If you join a team workspace, the app erases the data on your device and downloads the workspace owner's data onto it instead — see Section 17.
- Web Dashboard Access: The web dashboard is a Pro feature that reads the cloud-synced data in your workspace to display buildings, equipment, parts, maintenance logs, and site inventory in a browser. All data displayed in the web dashboard originates from and is governed by the cloud backup data of the workspace it belongs to.
- Administrator Access: For the purposes of database maintenance, technical support, and system integrity, cloud-synced data is accessible to the application's system administrators.
- Team Workspace Access: If you invite team members into your workspace, all of your cloud-synced data — including customer names, contact details, and billing addresses — becomes accessible to every member you invite, in every role. If you join someone else's workspace, their data becomes accessible to you. See Section 17.
- Site Inventory: If you utilize the inventory management features, the app stores item categories, dimensions, quantities, and stock levels associated with your buildings.
- Device Identifiers: A secure session identifier is generated for your device strictly to enforce single-device license activation for Pro subscribers. Additionally, to enforce our free trial limitations and prevent abuse (such as creating multiple accounts on a single physical device to obtain additional free scans), we collect a cryptographically hashed, pseudonymous identifier of your physical device (IDFV on iOS and Android ID on Android). This identifier is hashed locally on your device (using SHA-256) before transmission to our servers. The hash cannot be turned back into the device identifier, and it is not used to track your location or identity. It is not anonymous, and we do not call it that: the hash is stable, so the same device always produces the same value, which is exactly what lets us tell that two accounts are on one phone. That is the only thing we use it for.
- Usage Analytics: The app tracks the number of AI scans performed (for free-tier enforcement), onboarding completion status, notification preferences, and scan disclaimer acknowledgements. Trial scan counts are securely stored in your Firestore account to sync limits across installs, while onboarding and disclaimer preferences are stored on-device only.
- Notifications: The app uses two kinds of notification, and only one of them involves our servers. Reminders about your own equipment, parts and PM schedules are scheduled by the app on your phone, at your device's own local time. The app reads the due dates already held on the device and asks the operating system to raise the reminder; nothing about them is sent to us, and they arrive with no signal and no internet connection. Everything else is a remote push notification, sent by our servers and travelling through Expo's push service and then Apple's or Google's before reaching you — see Section 11. For those, your device registers a push token with us and we store it against your account. They cover a guest technician's service submission, a tenant service request, a vendor checking into or out of a building, a PM schedule that somebody else has assigned to you, incoming shared data, and workspace and subscription notices. The text of a notification can carry another person's name — the technician who filed the report, the resident who reported the problem, or the vendor and their company — because that is what makes the notification useful. We also use the same channel to send a silent command to a device; see Section 17. You can disable notification categories in Settings.
- Invoices & Payment Records: If you raise invoices, the app stores the invoice and a frozen copy of who it was addressed to: the bill-to party's name, a contact name, telephone number, email address and postal address, alongside the line items, the tax rate you typed in, the totals, and your own business details as they read on the day it was issued. Where you bill a unit's occupant, that party is a tenant — often a private individual rather than a business. The app also stores the payments you record against an invoice: the date, the amount, the method (cash, cheque, card, ACH or other), a free-text reference you type, a note, and which member of your team recorded it. We do not process payments, and we never receive or store a card number — the reference box holds only what you choose to type into it.
- Diagnostic Error Reports: When part of the app fails, it uploads a technical error report to our database so we can find the fault: your user ID, the platform, where in the app it happened, the error message, the JavaScript stack trace, and the app version. These are write-only — they are not shown back to you anywhere in the app — but they are deleted along with your account. See Section 14.
- App Performance & Crash Telemetry: Since version 6.34.0 the app measures how long it takes to start — cold launch time, the time to load its program code, and the time until the first screen is ready to use — and sends those measurements, together with reports of software errors it catches, to Expo, the service that builds and delivers the app’s updates. See Section 11. Each app launch generates a fresh random session identifier that travels with these reports. We do not attach your account, name, email address or user ID to them, and this telemetry is not used to track you or to build a profile. It is separate from the Diagnostic Error Reports above, which do carry your user ID and go to our own database.
- IP Addresses: Our servers record the IP address of the browser that submits the SMS consent form on our website, which we use only to rate-limit that form against abuse. Our servers also capture the IP address and browser user agent of the browser that starts a web subscription checkout, and pass both to Meta with the purchase event described in Section 11. This is separate from the website cookies covered by Section 12.
- Website Contact Form: If you write to us through the contact form on equipment-tracker.com, we store the name, email address and message you type, together with any screenshots you attach, and email them to our support address. Screenshots attached to a contact message are stored at a web address readable by anyone holding the link, so treat an attached screenshot as readable by anyone given that link.
3. AI-Powered Data Extraction
When you use an AI feature, the images or text involved are sent to Google's Gemini API (via a secure Firebase Cloud Function) and the result is returned to the app and stored according to your local/cloud preferences. This applies to every AI feature in the app, and all of them require an internet connection:
- Nameplate scanning: photographs of equipment data plates, read for manufacturer, model, serial number and electrical specifications.
- AI Condition Scan: photographs of equipment, assessed for visible condition.
- Invoice and work-order scanning: photographs of service invoices, work orders and receipts. These may carry information about people other than you — a technician's name, a company name, a service description and costs written on somebody else's paperwork — and that is sent to Google along with the rest of the image.
- AI Diagnostics: the symptoms, measurements and notes you type into a troubleshooting conversation.
Images and text are transmitted securely and are subject to Google's data processing terms. We do not use any of it to train models.
We also keep a copy of the result on our servers. When a nameplate scan, a condition scan or an invoice scan comes back, we store the result against your account in a short-lived cache, so that a retry of the same tap — a dropped connection, a second press — returns the answer you already paid for instead of buying it again. The cache is meant to answer for a few minutes and then expire. The automatic expiry has not been switched on for this collection yet, so in practice those stored results stay on our servers until we remove them — but they are deleted along with your account (see Section 14). For an invoice or work-order scan, the stored result contains what was read off somebody else's paperwork. You can ask us to delete yours at any time at support@equipment-tracker.com.
4. Guest Technician Service Submissions
Equipment Tracker Pro supports guest service submissions via the public QR specification page. When a guest technician (a person who does not have an Equipment Tracker account) scans a Link Mode QR code and submits a service report through the web form, the following information is collected:
- Technician name and company/vendor name entered by the guest
- Service date, service type, work description, and parts replaced as entered by the guest
- Optional before and/or after service photographs uploaded by the guest
Guest submissions are stored temporarily in our Firebase Firestore database under the equipment owner's account namespace, in the incoming_maintenance collection. Service photos are stored in Firebase Storage under the incoming_maintenance_images/ path. Guest submissions remain pending until the account holder explicitly reviews and accepts or rejects them in their Transfer Inbox. They are not automatically added to the owner's maintenance records. The guest technician is not required to provide any personal account credentials or contact information beyond what they voluntarily enter in the form fields.
5. What a Public QR Page Publishes
A Link Mode QR code prints a link to a page we host for that piece of equipment. That page is readable by anyone who scans the code, without an account and without signing in — that is what the code is for. It is not indexed and cannot be listed or browsed; it can only be opened by someone who has the specific code.
The page publishes the equipment's specifications, its parts list, its service history, and any notes you have recorded against the equipment — that notes field is free text, so treat whatever you type there as readable by anyone who scans the code. By default it also publishes the site information for the building the equipment is in: the street address and the building contact's name, telephone number and email address. This is deliberate for commercial sites, so that a visiting vendor standing at the equipment has somebody to contact about access or building issues.
You can turn site information off, per building. In the app, open the building, open Site Info, and clear "Show site info on QR codes". While it is off, the address and contact details are not published, existing pages for that building are rewritten to remove them, and anyone scanning a code for that building sees a notice saying site information is turned off. Equipment specifications, parts and service history are still shown. We recommend turning it off for residential addresses, where the building contact is a private individual rather than a facilities manager.
One thing that control does not govern: the vendor door sign. It applies to equipment QR pages — the codes you stick on a machine, which anyone standing in front of it can scan. A vendor check-in door sign is different: you print it and hang it deliberately so that a visiting vendor knows who to call about the site, and it always carries the site address and the building contact's name, telephone number and email address, whether or not "Show site info on QR codes" is on. That is what the sign is for. If you do not want those details on a door, do not print the sign for that building.
What a vendor writes when they check in is not private either. A check-in entry records the name and the company the visitor types in, the area of the building and the reason they give for being there, and the time. Entries are stored in a place readable without an account, because the check-in page and the log a vendor is standing in front of have to be able to show them without anyone signing in. Treat a building's check-in log as readable by anybody, and do not put anything on a check-in door sign that you would not want a passer-by to scan. Deleting your account does not remove check-in entries that have already been made — see Section 14.
Service history entries shown on a public page carry the date, service type, description, technician name and vendor company. They do not carry any cost, labour rate, labour hours or materials cost you have recorded — those fields are never published to a public page.
A tenant tag publishes a page too. The page behind a tenant tag is readable by anyone who scans that tag, with no account and no sign-in. Like an equipment page, it cannot be listed or browsed — it can only be opened by someone holding that specific code. It shows the building name, the unit label, a short verify code, and whatever you have typed into that building's tenant information page and that unit's own version of it: the office name, telephone number, email address and hours, an after-hours number, what counts as an emergency, fire safety text, shutoff locations, utilities, trash and parking, current notices, any document links you add and any sections of your own. It never shows the tenant's name, telephone number or email address — those stay in your workspace. Treat anything you put on that page, including any link, as readable by anyone holding the card.
Replacing a tag retires the old page. If a card goes missing or a unit turns over, replacing the tag mints a new code and deletes the page the old card pointed at, so the old card resolves to nothing. Deleting a unit, or clearing its tag, does the same.
6. Tenant Service Requests
Account holders can print a QR code for the inside of a tenant's door — either one for the whole building or, since August 2026, one per unit. Scanning it opens a request form, not a service log.
What the form asks for. The form asks what is wrong, optionally the resident's name, and optionally up to three photographs. On a building-wide code it also asks which unit. It does not ask for a telephone number or an email address, and there is no field on it for either. If the account holder has recorded a tenant against that unit, we read that name, telephone number and email address from the unit's record when the request arrives and record them onto the request, so that the people who maintain the building can call back. That is how a resident is contacted without being asked to hand over details the landlord already holds.
Where it goes. A request goes to the account holder who printed the tag, and is visible to every member of their team in every role. Tenant photographs are stored separately from all other guest uploads, under a tenant_requests/ path in Firebase Storage, and are readable only by the account holder and their active team members after signing in. They are not publicly readable. This is a deliberate difference from guest technician photos, because a tenant request can contain images of the inside of somebody's home.
Who is alerted. An account holder can set a list of email addresses and telephone numbers to be alerted about tenant requests, separately from the list used for vendor check-in alerts. If a building has no tenant list set, alerts fall back to that building's vendor check-in recipients rather than being sent nowhere — a resident reporting no heat should not be met with silence because a second list was never filled in. A separate tenant list, where one exists, always wins. If you do not want tenant reports reaching your vendor contacts, set a tenant list. Alerts carry a link to the account holder's dashboard and never the photographs themselves. One request per code per hour is accepted, so a per-unit tag throttles per unit rather than for the whole building.
Tenant requests are held for review and never create a work order on their own.
If you are a resident who scanned a tag. You have no account with us and you are not asked to create one. What you write and any photographs you attach go to the people who maintain your building — the account holder who printed that tag and the members of their team — and to us, because we host and deliver it for them. We do not use it for any purpose of our own, we do not sell or share it, and we do not use it for advertising or to train models. If you want to know what has been recorded about you, or want something you sent removed, contact the people who maintain your building; you can also write to us at support@equipment-tracker.com and we will act on their instruction.
7. AI Diagnostics Are Stored Only on Your Device
The AI Diagnostics feature records a troubleshooting conversation about a fault, including symptoms, measurements and notes you type. As of 11 August 2026 these sessions are stored only on your device. They are not uploaded to our servers, are not included in cloud backup, are not shared with team members, and are not transferred with a building. Sessions that had already been uploaded before that date remain on our servers pending deletion. They are not used for anything, and you can ask us to delete yours at any time at support@equipment-tracker.com.
One consequence is worth stating plainly: because they are not backed up, a lost, wiped or replaced device loses its diagnostic history. The feature is not offline — individual questions you ask are still sent to Google's Gemini API to be answered, as described in Section 3 — but the resulting conversation is retained only locally.
8. Peer-to-Peer Data Sharing
If you utilize the "Send to User" feature, the specific equipment, parts, or maintenance data you choose to send is written to the Equipment Tracker account of the recipient you designate, where it waits in their Transfer Inbox until they accept or discard it. You designate that recipient by their email address or by their Push Username; either one is used only to locate an existing Equipment Tracker account, and if no account matches, nothing is sent. We do not email your data to the address you type. Shared data is stored in Firebase until the recipient claims or discards it, and we do not send it to anyone you have not designated. This describes the "Send to User" feature only — team workspaces work differently and are described in Section 17.
9. Data Import & Export
The app allows you to export your data as ZIP archives and import data from ZIP files. Exported archives may contain equipment records, parts data, maintenance logs, and associated images. You are responsible for the security of exported files once they leave the app. On Android, the app supports automated local backups to a Storage Access Framework (SAF) linked folder.
10. Professional Reports
The app can generate professional equipment reports, maintenance summaries, and building inventories. These reports may be shared via your device's native sharing capabilities. Report content is derived from data you have entered and is not transmitted to our servers.
11. Third-Party Services & Subscriptions
Your data is processed by the following third parties according to their respective privacy policies:
- Google Gemini API: Used for every AI feature in the app, as described in Section 3 — nameplate scanning, AI Condition Scan, invoice and work-order scanning, and AI Diagnostics. The photographs you scan and the troubleshooting text you type are sent to Google's servers for processing and are subject to Google's privacy policy.
- Google Firebase: Used for secure user authentication, database syncing, cloud storage, and peer-to-peer data transfers.
- Google Play Billing & Apple App Store: Used to securely process and verify in-app subscriptions on Android and iOS. We do not collect, process, or store your credit card or payment information.
- RevenueCat: Used to manage, verify, and synchronize subscription entitlements across Android, iOS, and the web dashboard. RevenueCat processes subscription status data according to their own privacy policy.
- Stripe: Used to process web-based subscription payments. Payment data is handled exclusively by Stripe and is not stored on our servers. Stripe processes payment data according to their own privacy policy.
- Expo (push delivery and app performance monitoring): Used to deliver the push notifications described in Section 2. Your device's push token and the title, body and payload of each notification pass through Expo's push service on the way to Apple's or Google's delivery network. Because a notification can name a technician, a resident or a vendor, those names pass through it too. Expo also receives the app performance and crash telemetry described in Section 2 — launch timings and caught software errors, carrying a per-launch random session identifier and not your account — and processes it under its own privacy policy.
- Twilio (SMS delivery): Used to send the text-message alerts described in Section 15 — vendor check-in and check-out alerts, and tenant service request alerts. The recipient's telephone number and the text of the alert, which can include a resident's or vendor's name and what they reported, are handed to Twilio to deliver.
- Google Workspace (Gmail) for email delivery: Used to send the email alerts and support email described in this policy — tenant request alerts, vendor check-in alerts, guest submission notices and contact-form messages. The recipient's email address and the contents of the message, including any names in it, pass through Google's mail service.
- QR image service (api.qrserver.com, operated by goQR.me in Germany): Used by the mobile app to draw the QR image on a label or tag when you preview or print one. The label's contents are sent to that service inside the web address of the image request. For a link-style label that is only the link. For a label you have configured to carry the data itself, it is whatever you told the label to carry — which can include the building contact's name, telephone number and email address, serial and model numbers, and the equipment's notes. The web dashboard's own label generator does not use this service — it draws QR codes inside your browser. Elsewhere on the website this service draws QR codes for plain links only, such as an app download link or a vendor check-in link, which carry no personal details.
- Meta (Conversions API): When a subscription is purchased through the website, our servers send a purchase event to Meta for advertising measurement. It carries the buyer's email address, telephone number, first and last name, city, state, postal code, country and account ID, each of them hashed before it is sent, together with the browser's IP address, its user agent, and Meta's own
_fbp/_fbccookie identifiers, which are sent as they are because Meta requires them that way. This is separate from the Meta Pixel that runs in your browser, described in Section 12. It does not run in the mobile app or on app-store purchases.
12. Website Analytics, Advertising & Tracking Technologies
Our marketing website (equipment-tracker.com) uses cookies and similar tracking technologies from the following third parties to understand site usage, measure advertising performance, and improve our marketing. Google Analytics, Google Ads conversion tracking and the Meta Pixel also load on the signed-in web dashboard and record page views there. Microsoft Clarity is loaded but is stopped as soon as a signed-in page opens, so dashboard sessions are not recorded in Clarity. None of these technologies are used in the mobile app.
- Google Analytics & Google Ads: We use Google Analytics to understand how visitors use our website, and Google Ads conversion tracking to measure the performance of our advertising campaigns. For more information, visit the Google Privacy Policy.
- Meta (Facebook) Pixel: We use the Meta Pixel to measure the effectiveness of our advertising and to show relevant ads to people who have visited our website. Meta may use this data for its own advertising purposes according to its own data policy. Meta also receives a purchase event from our servers — not from your browser — when a subscription is bought on the website; what that event carries is set out in the Meta entry in Section 11.
- Microsoft Clarity: We partner with Microsoft Clarity and Microsoft Advertising to capture how you use and interact with our website through behavioral metrics, heatmaps, and session replay to improve and market our products/services. Website usage data is captured using first and third-party cookies and other tracking technologies to determine the popularity of products/services and online activity. Additionally, we use this information for site optimization, fraud/security purposes, and advertising. For more information about how Microsoft collects and uses your data, visit the Microsoft Privacy Statement.
You can control or disable cookies at any time through your browser settings. Our mobile app does not use any of the tracking technologies described in this section.
If applicable privacy law grants you the right to opt out of the sale or sharing of personal information, or to exercise any other privacy right regarding these technologies, contact us at support@equipment-tracker.com.
13. Children's Privacy
Equipment Tracker is a professional tool designed for HVAC technicians and is not directed at children under the age of 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us immediately so we can delete it.
14. Data Retention & Deletion
Your local data remains on your device until you delete it. Cloud-synced data is retained as long as your account is active. You may delete your account and all associated cloud data at any time from the app's Settings menu: open Settings, find Delete Account under Account, and press and hold it — a short tap only explains that it needs a long press, which is deliberate so the control cannot be hit by accident. Holding it opens a confirmation in which you type the word DELETE; nothing is removed until you do. Upon account deletion we cancel any active Stripe subscriptions, delete your user data tree, your pending shares — both the ones waiting for you and the ones you sent to somebody else — your team records, your image files from our storage, the diagnostic error reports described in Section 2, the cached AI scan results described in Section 3 together with the record of when your account used the AI features, and any building transfer code you generated along with the copy of the building held behind it. Some records created outside that tree are not removed automatically — public equipment pages you published through a QR/Link Mode code, building check-in configurations and their notification contact lists, vendor check-in entries, guest technician submissions and their photos, tenant service requests and their photographs, SMS consent records for numbers that were added to a notification list, the hashed device record used to enforce the free scan limit, anything you have sent us through the website contact form together with the screenshots attached to it, and your reserved username. If any part of the deletion or subscription cancellation does not complete, your authentication account remains intact and deletion is halted. Contact us at support@equipment-tracker.com to have anything remaining removed, and we will remove it.
If you no longer have the app. You do not need to reinstall it to be deleted. Write to us at support@equipment-tracker.com from the address the account was created with and we will run the same deletion for you. https://equipment-tracker.com/delete-account sets out both routes and repeats the two lists above, and it can be read without an account. One thing worth knowing before you start: the deletion cancels a subscription bought on the website through Stripe, but it cannot cancel one bought through Google Play or the Apple App Store — those are held by the store, and you have to cancel them in the store's own account settings.
Tenant service requests. A request and its photographs stay in your workspace after you have dealt with it — marking a request handled does not delete it, and the app does not currently offer a control that does. They are not deleted automatically and are not on a fixed schedule. Contact us at support@equipment-tracker.com to have a request and its photographs removed, and we will remove them.
Deleting a building or a piece of equipment archives a summary of it. The record's photographs are destroyed straight away and irreversibly. A text summary — the title, the building name, the address and the equipment history — is moved into your Archive, which is part of your workspace and is visible to your team members. The site contact's name, telephone number and email address are deliberately not kept in the archive. You can remove a record permanently from the Archive at any time.
Invoices are the exception to that. An invoice is a financial record of a transaction that happened, so it keeps its own frozen copy of who it was addressed to — the name, telephone number, email address and postal address that were on it when it was issued — and it keeps them after the building it relates to has been deleted. Where you billed a unit's occupant, that is a tenant's name and contact details. This is deliberate: a document asking for money with no addressee is not a record of anything. Invoices and the payments recorded against them are deleted with your account, along with the rest of your data tree.
If you are a member of a team workspace, "your account" means your own account only. Deleting your account does not delete the workspace owner's data, and a workspace owner deleting their account does not erase copies already downloaded onto members' devices. Records identifying workspace members — including member email addresses — are stored under the workspace owner's team record rather than under the member's own account; contact us at support@equipment-tracker.com to have those removed.
15. Data Sales & Sharing
We do not sell, rent, or trade your personal data, equipment logs, maintenance records, or images to any third parties.
Mobile information and SMS opt-in data will not be shared with third parties or affiliates for marketing or promotional purposes. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
If you opt in to receive SMS notifications (such as vendor check-in and check-out alerts, or alerts that a resident has submitted a service request from a tenant tag), message frequency will vary depending on your account's activity and notification settings. Message and data rates may apply. You may opt out of SMS notifications at any time by removing your phone number in the app's notification settings, or by replying STOP to any message.
16. Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page with a revised effective date. We encourage you to review this policy periodically. Your continued use of the app after changes are posted constitutes your acceptance of those changes.
17. Team Workspaces
A subscriber on a Team plan (a "workspace owner") can invite other people ("team members") into their workspace using an invite code. This section explains what that means for the data in the workspace.
What team members can see. A team member can read all of the data in the workspace: equipment, parts, maintenance and service records, inventory, tools, work orders, PM schedules, photographs, invoices and the payments recorded against them, and building and site information — including customer names, contact details, and billing addresses. Access is not limited by building or by customer. Team members are assigned a role — Viewer, Tech, or Manager — which controls what they can change. Invoicing is the one record type a role also hides: the app shows invoices and payments to the workspace owner and to Managers only, and a Tech or a Viewer has no invoicing screen. That is a limit in the app, not on our servers — invoices still sync down onto a Tech's or a Viewer's device so that the rest of their data syncs correctly, so treat the figures on an invoice as reaching every device in the workspace. Everything else in the workspace is visible to all three roles.
Data on team members' devices. When a team member joins from the mobile app, the app erases the data already on that member's device and downloads a copy of the workspace onto it — including customer and billing information and photographs — so the app works offline. Members who use only the web dashboard do not receive a persistent local copy.
When a member leaves or is removed. Their access to the workspace ends immediately on our servers. The app erases the local copy from that member's device the next time it runs with an internet connection. We also send a silent push command to the member's device instructing the app to erase the workspace copy right away. This is best-effort: it only works if the device is online with notifications registered, and we cannot confirm the erase completed. If it does not arrive, the copy stays on that device until the app next runs with an internet connection. Anything a member has already exported, printed, or sent elsewhere is outside our reach entirely. Workspace owners should keep this in mind when deciding whom to invite and what information to keep in a workspace.
Information we hold about team members. For each member we store the email address of the account that redeemed the invite, the member's role, the date they joined, and any display name or notification email address set by the workspace owner or a manager. This is stored under the workspace owner's team record, not under the member's own account. Records a member creates are tagged with that member's user ID and display name. For work orders we also record the user ID of the last person to change the record; other record types do not record who edited them. These tags remain in the workspace owner's data after the member leaves.
Access follows the owner's subscription. Team members receive Pro features through the workspace owner's subscription. If that subscription ends or lapses, Pro-only functions stop working for every member of that workspace.
Who is responsible. The workspace owner decides who is invited and is responsible for the customer information in their workspace, including having the authority to make it available to the people they invite. See Section 10 of our Terms of Service.
18. Contact Us
If you have questions about this Privacy Policy, please contact us at: support@equipment-tracker.com