Trust & Compliance
Last Updated: August 27, 2026Learn how EquipmentFlow protects company data, secures user access, and supports responsible platform operations.
Security
Authentication, access controls, data isolation, and audit logging.
Privacy
How we collect, use, and protect personal and company data.
Legal
Terms of Service, Cookie Policy, and Acceptable Use Policy.
Data Protection
Data Processing Addendum, subprocessors, retention, and deletion.
Service Reliability
Incident communication, support contacts, and status reporting.
Responsible Disclosure
How to report security concerns privately and responsibly.
Security
EquipmentFlow is built with security controls at every layer of the application. The following controls are implemented and active in the production system.
Secure Authentication via Clerk
User sign-in and session management are handled by Clerk through supported email and Google sign-in flows. EquipmentFlow does not store Clerk account passwords.
Role-Based Permissions
Protected workflows combine company membership, roles, and granular server-side permissions. Authorized company leaders can configure access for their team.
Company-Level Data Isolation
Authenticated requests resolve an active company membership, and supported database and storage operations apply company or user scope.
Audit Logging
Supported significant actions produce timestamped audit or activity records with actor and change context for authorized review.
Server-Side Authorization
Protected API workflows enforce authorization on the server. Client-side visibility controls supplement, rather than replace, those checks.
Secure Invitation Tokens
Email invitation links and QR join tokens use unpredictable values and server-side validation. Invitations may expire, be revoked, or become invalid after use.
Protected File Storage
Uploaded files (equipment photos, JSA attachments, repair images) are stored in access-controlled object storage. Files are not publicly accessible without a valid authenticated session.
Encryption in Transit
Production web traffic is served over HTTPS through managed hosting.
For full security documentation, visit the Security page.
Privacy & Legal
EquipmentFlow's legal documents govern data handling, service terms, and acceptable use. Each document is reviewed and updated as the platform evolves.
Privacy Policy
ActiveWhat personal and company data we collect, how it's used, third-party services involved, your rights, and how to request deletion.
Terms of Service
ActiveConditions governing use of the platform — account responsibilities, current free access, data ownership, disclaimers, and limitation of liability.
Cookie Policy
v1.0The essential authentication, security, preference, and operational technologies used by EquipmentFlow.
Acceptable Use Policy
v1.0The permitted business uses, prohibited conduct, security rules, and enforcement process for the platform.
AI Usage & Disclaimer
v1.0Human-review requirements and limits for AI-generated recommendations, summaries, forecasts, and reports.
Safety & Inspection Disclaimer
v1.0The administrative-only limits on safety records, inspections, approvals, and operational notifications.
Fleet Inspection Disclaimer
v1.0Important limits on vehicle, trailer, roadworthiness, and fleet inspection workflows.
JSA Disclaimer
v1.0The responsibilities that remain with customers when creating, approving, and signing JSAs.
Maintenance Reminder Disclaimer
v1.0Why maintenance schedules, due dates, reminders, and alerts are convenience tools only.
QR & Barcode Scanning Disclaimer
v1.0QR codes and supported common barcodes identify records and workflows; they do not verify condition, maintenance, or authorization.
Electronic Signature Agreement
v1.0Consent, intent, recordkeeping, and responsibility rules for electronic acknowledgements and approvals.
Data Protection
Data Processing Addendum
EquipmentFlow offers a Data Processing Addendum (DPA) for organizations with specific compliance requirements. The DPA covers processor obligations, subprocessor disclosure, data-subject rights, breach notification, and international transfer mechanisms.
Data Processing Addendum
Full DPA text covering definitions, roles, subprocessors, security measures, international transfers, and breach notification.
Customer Data Ownership
All data you enter into EquipmentFlow — equipment records, repair histories, JSA documents, uploaded photos — belongs to your company. EquipmentFlow processes it solely to deliver the service. We do not sell, license, or transfer your operational data to third parties.
Data Retention
Company data is retained while the account is active and as needed for service, legal, audit, security, and dispute purposes. Deletion follows the account-deletion process and applicable recovery or retention windows described in the Privacy Policy.
Account & Company Deletion
Company owners can initiate company deletion from Settings. Deletion removes company access and schedules eligible company records and files for deletion, subject to legal, audit, security, and managed-recovery retention. Contact support@equipmentflowco.com before deletion if records must be exported.
Key Service Providers
The following third-party providers are currently integrated and operational in the EquipmentFlow production system:
| Provider | Purpose | Location |
|---|---|---|
| Clerk | User authentication and identity | United States |
| Resend | Transactional email delivery | United States |
| Replit | Application hosting and infrastructure | United States |
This list reflects providers verified as active in the production system. EquipmentFlow will update this list when providers are added or changed.
Compliance Roadmap
EquipmentFlow is a growing platform. The following reflects the current state of formal security and compliance programs honestly and accurately.
Service Reliability
System Status
Public system-status reporting is planned. A dedicated status page will be linked here when available.
EquipmentFlow does not publish uptime guarantees or service-level agreements at this time. The platform is operated with attention to availability, and incidents are addressed as promptly as resources allow.
Incident Communication
When significant service disruptions occur, EquipmentFlow will communicate with affected account owners via email. For time-sensitive issues, contact support@equipmentflowco.com directly.
Support Contact
For platform issues, company-access questions, or account-level concerns, contact support@equipmentflowco.com. You can also submit a request through the Support Center.
Report a Security Concern
If you discover a potential security vulnerability in EquipmentFlow, we ask that you report it privately. Responsible disclosure helps us protect all users.
Guidelines
- Provide a clear description of the issue
- Include steps to reproduce when possible
- Do not access, modify, or delete data that does not belong to you
- Do not publicly disclose the issue until it has been resolved
- Allow reasonable time for investigation before escalating
We review reports as resources allow and may contact the reporter for reproduction details, impact information, or coordinated-disclosure planning.
Report a Security Issue
Send a detailed report to our security team. Do not use public channels for unresolved vulnerabilities.
Report a Security IssueContact Information
Support
Account issues, bugs, company access
support@equipmentflowco.com
Security
Vulnerability reports only
Open secure report form
Privacy
Data & privacy inquiries
support@equipmentflowco.com
Privacy inquiries are currently handled by the support team at support@equipmentflowco.com.