Privacy Policy
Last Updated: August 27, 2026How EquipmentFlow collects, uses, discloses, secures, and retains personal information in connection with its business operations platform.
1. Scope and Controller
This Privacy Policy explains how EquipmentFlow processes personal information when you visit a public EquipmentFlow page, create or use an account, receive an invitation, contact us, use the web or mobile Service, or interact with our support and billing channels. EquipmentFlow is the business responsible for the Service-side processing described here. For Customer Data that a company uploads about its workers, contractors, customers, or other individuals, the Customer may be the controller and EquipmentFlow may act as its processor under the Data Processing Addendum.
2. Information We Collect
Account and identity information
We receive names, email addresses, phone numbers, profile images, job roles, company membership, authentication events, and account-security information through account creation, invitations, sign-in, and profile management. Clerk provides identity and authentication services; EquipmentFlow does not store your Clerk password.
Customer operational data
Customers may enter equipment, fleet, vehicle, trailer, job-site, checkout, repair, parts, maintenance, inspection, JSA, timesheet, receipt, purchase, crew, signature, folder, document, QR or barcode identifier, notification, expense, and audit information. Receipt images, uploaded photos, files, notes, signatures, and records may contain personal information chosen by the Customer.
Access and service information
EquipmentFlow records company access, enabled features, support status, and service communications needed to administer the account. EquipmentFlow is currently available without a subscription charge or payment card.
Usage, device, and security information
We collect IP address, browser and device characteristics, approximate location derived from IP, request timestamps, pages or features used, referral information, error data, authentication events, and security or audit events. We use this information to secure, operate, troubleshoot, and improve the Service.
Communications
We collect the contents and metadata of support requests, sales inquiries, privacy requests, invitation messages, and other communications sent to us or through the Service.
3. How We Use Information
- Provide equipment, fleet, maintenance, inspection, JSA, timesheet, receipt, reporting, QR and barcode scanning, account, and collaboration workflows;
- Authenticate users, manage company membership, enforce permissions, and prevent unauthorized access;
- Administer company access, feature availability, service communications, and support;
- Send invitations, service notices, agreement prompts, reminders, security alerts, and transactional communications;
- Host, back up, synchronize, search, display, export, and preserve Customer Data at the Customer’s direction;
- Maintain audit logs, investigate incidents, prevent fraud and abuse, and enforce our agreements;
- Measure performance, diagnose failures, develop features, and improve reliability; and
- Comply with legal obligations and respond to lawful requests.
4. Service Providers and Disclosures
We disclose information only as reasonably necessary to operate the Service, comply with law, protect rights, or complete a transaction. Current service providers include:
- Clerk: authentication, identity, session, email verification, and security features;
- Resend: transactional email delivery for invitations, alerts, and service messages;
- Replit: cloud hosting, application infrastructure, PostgreSQL database, and object storage; and
- Other Customer-authorized integrations: only where enabled by the Customer or required by a requested workflow.
We may disclose information to professional advisers, law enforcement, courts, regulators, acquirers, or successors when legally required or reasonably necessary to protect the Service and its users.
5. Customer Data and Processing Instructions
Customers retain ownership or control of Customer Data. EquipmentFlow processes Customer Data to provide the Service and under the Customer’s instructions, subject to the Data Processing Addendum where applicable. Customers are responsible for providing notices, obtaining permissions, choosing lawful retention periods, responding to individuals, and not uploading data they are not authorized to provide.
6. Cookies and Similar Technologies
EquipmentFlow uses session, authentication, security, preference, and limited operational technologies. Details, browser controls, and third-party cookie information are in the Cookie Policy. Essential technologies are required for sign-in, company isolation, security, and core workflows.
Supported workflows may temporarily store application data, queued records, attachments, preferences, and synchronization status in browser or device storage. This local information supports continuity and selected offline workflows and synchronizes when connectivity and the applicable service are available.
7. Security
We use administrative, technical, and organizational safeguards appropriate to the Service, including access controls, company scoping, encrypted transmission, protected storage, authentication controls, logging, backups, and monitoring. No system is completely secure, and EquipmentFlow cannot guarantee security, uninterrupted availability, or that data will never be lost, altered, or exposed. See the Security page for a description of our current practices.
8. Retention and Deletion
We retain information for the period necessary to provide the Service, preserve accepted agreements and audit records, resolve disputes, enforce contracts, comply with law, and maintain backups. Customer account deletion follows the applicable account and subscription process. Backup copies may persist for a limited period before secure rotation. Some records may be retained where deletion would impair legal, security, fraud-prevention, or accounting obligations.
9. Individual Rights
Depending on location and role, you may request access, correction, deletion, portability, restriction, objection, or information about processing. If your data is contained in a Customer account, we may direct the request to that Customer because the Customer controls the operational record. Contact us at support@equipmentflowco.com; we may verify identity before responding.
10. International Processing and Children
EquipmentFlow and its service providers may process information in the United States and other locations where they operate, using legally recognized transfer mechanisms where required. The Service is for business users and is not directed to children under 16. We do not knowingly solicit personal information from children.
11. Policy Changes
We may update this Privacy Policy to reflect legal, technical, or operational changes. We will update the version, effective date, and “What’s Changed” information and provide notice for material changes where required. The public page does not itself record acceptance of a contractual agreement; acceptance is handled only through the authenticated agreement workflow when a document is assigned and required.
12. Privacy Contact
Questions about this document or a request for legal/privacy support may be sent to support@equipmentflowco.com. Security reports should be submitted through the security report form.