Skip to content

Privacy notice

What this system stores, and who can read it.

Written against what the software actually does, section by section.

This is a placeholder and must be reviewed by a lawyer before launch. What follows is an accurate description of what the software actually does with data, which is the right starting point for the real document.

01

What we store

Company details supplied at signup, the name, email and phone of each user, the content of every request and message, and quotes and bookings made against them.

02

Passwords

Stored only as a PBKDF2-SHA256 hash with a per-user salt. We cannot read your password, and a copy of the database would not reveal it.

03

Sessions

The sign-in cookie holds a random token. The database stores only a SHA-256 hash of it, so a database leak does not yield usable sessions.

04

Who sees your requests

Users inside your own company, and our staff. Requests are scoped by company at the query level, so one customer cannot address another customer’s records.

05

Internal notes

Our staff can attach notes to a request that are marked internal. These are filtered out of every customer-facing query.

06

Where it lives

Cloudflare D1 and R2, in Cloudflare’s North American region.

07

Audit trail

Status changes record who made them, when, and from what IP address.

08

Third parties

None. There is no analytics, no advertising, and no data broker in this system.

Something here not clear? Ask the desk.