← Back to MRO Tracker
MRO Tracker

Privacy Policy

Last updated: [DATE]

This is a template, not legal advice. It's written to accurately describe what this specific application actually does with data, based on how it's built — but it has not been reviewed by a lawyer, doesn't address every jurisdiction's requirements (GDPR, CCPA, etc. are not specifically covered), and should not be published or relied on for real commercial use without review by a qualified attorney, especially now that the app processes payments.

This Privacy Policy describes what information MRO Tracker ("we," "our," "the Service") collects, how it's used, and who it's shared with.

Information We Collect

CategoryWhat's collected
Account informationEmail address and password (password is not visible to us — it's managed by our authentication provider).
Task dataTask descriptions, timestamps, and due dates that you or your organization enter into the Service.
Login activityLogin timestamps, IP address, and browser/device information, used for account security and audit history.
Organization dataOrganization name, uploaded logo image, and admin/member assignments.
Billing informationSubscription plan, seat count, and billing status. Payment card details are handled entirely by our payment processor (Stripe) — we never receive or store your full card number.

We do not run advertising, third-party ad trackers, or analytics pixels in the Service.

How We Use Information

Who We Share Information With

We use the following third-party service providers to operate the Service. Each processes a limited set of data as necessary to perform its function:

ProviderPurpose
NetlifyApplication hosting and account authentication.
SupabaseDatabase storage for task, organization, and login-history data.
StripePayment processing and subscription billing.
ResendDelivery of report and notification emails.

We do not sell personal information to third parties.

Data Retention

We retain account and task data for as long as your account or organization remains active, plus a reasonable period afterward for backup and legal purposes. Login history is retained to support security auditing. You can request deletion as described below.

Your Choices

You can ask your organization's administrator, or contact us directly, to access, correct, or delete your account information. Organization administrators can manage and remove members directly within the Service.

Security

We rely on our infrastructure providers' security practices (encryption in transit, access controls) and apply role-based permissions within the Service so that organization data is only accessible to that organization's administrators and authorized super administrators.

Children's Privacy

The Service is intended for business use and is not directed at children. We do not knowingly collect information from children.

Changes to This Policy

We may update this policy from time to time. We'll update the "Last updated" date above when we do.

Contact Us

Questions about this policy? Contact us.