CONSTRUCTION TOOL TRACKING
Privacy Policy Draft
A plain-language privacy policy draft for TakeMoveReturn. Legal review is required before production publication.
PRIVACY DRAFT
Privacy Policy
This plain-language draft explains the data TakeMoveReturn is designed to handle. It is not effective until the operating entity, service providers, contact details, and retention rules are reviewed and published.
1. Status and scope
This is a product and legal draft for TakeMoveReturn, a QR-based tool-tracking service for construction crews. The final data controller or business operator will be identified before production launch. Until then, this page should not be treated as an operative privacy notice.
2. Information the service may handle
Depending on the workspace features that are enabled, the service may handle:
- Account and authentication details such as an email address and sign-in events.
- Company workspace details, memberships, roles, workers, locations, and tool records.
- TAKE, MOVE, RETURN, damage, maintenance, import, and correction history.
- Support messages, billing references, and files that a workspace intentionally uploads.
3. How information is used
The intended uses are to provide the workspace, authenticate members, enforce company scope and plan limits, keep tool history reliable, support imports and exports, respond to support requests, protect the service, and meet legal obligations. The product is not designed to sell personal information or provide advertising profiles.
4. Sharing and service providers
Workspace information may be processed by infrastructure and service providers required to run the product, such as authentication, database, storage, email, billing, and hosting providers. The final notice will name the relevant providers or link to the approved subprocessor list. Information may also be disclosed when required by law or when a workspace owner requests an export.
5. Retention and deletion
Records should be retained only for the period needed to provide the service, preserve an auditable tool history, resolve disputes, meet legal obligations, or complete a deletion request. The production workflow must define retention windows, storage cleanup, backups, and audit-log handling before this policy becomes effective.
6. Security
The planned security boundary includes authenticated access, company-scoped authorization, row-level policies, signed file access, server-side validation, session expiration, and audit logging. A preview state must not be read as a guarantee that every production control is already enabled.
7. Cookies and local storage
The product may use cookies or browser storage that are necessary for authentication, session continuity, security, and user-selected preferences. Any optional analytics or marketing technologies must be reviewed and disclosed before they are enabled.
8. Rights and contact
Depending on the user’s location, people may have rights to access, correct, export, restrict, object to, or delete personal information. The final operator and privacy contact must be published before requests can be processed through the product.
9. Changes to this notice
The published notice should include an effective date and explain how material changes will be communicated. Draft changes made during product development do not change the rights or obligations of a production user until the approved notice is published.