MRO Tracker
Last updated: [DATE]
This Privacy Policy describes what information MRO Tracker ("we," "our," "the Service") collects, how it's used, and who it's shared with.
| Category | What's collected |
|---|---|
| Account information | Email address and password (password is not visible to us — it's managed by our authentication provider). |
| Task data | Task descriptions, timestamps, and due dates that you or your organization enter into the Service. |
| Login activity | Login timestamps, IP address, and browser/device information, used for account security and audit history. |
| Organization data | Organization name, uploaded logo image, and admin/member assignments. |
| Billing information | Subscription plan, seat count, and billing status. Payment card details are handled entirely by our payment processor (Stripe) — we never receive or store your full card number. |
We do not run advertising, third-party ad trackers, or analytics pixels in the Service.
We use the following third-party service providers to operate the Service. Each processes a limited set of data as necessary to perform its function:
| Provider | Purpose |
|---|---|
| Netlify | Application hosting and account authentication. |
| Supabase | Database storage for task, organization, and login-history data. |
| Stripe | Payment processing and subscription billing. |
| Resend | Delivery of report and notification emails. |
We do not sell personal information to third parties.
We retain account and task data for as long as your account or organization remains active, plus a reasonable period afterward for backup and legal purposes. Login history is retained to support security auditing. You can request deletion as described below.
You can ask your organization's administrator, or contact us directly, to access, correct, or delete your account information. Organization administrators can manage and remove members directly within the Service.
We rely on our infrastructure providers' security practices (encryption in transit, access controls) and apply role-based permissions within the Service so that organization data is only accessible to that organization's administrators and authorized super administrators.
The Service is intended for business use and is not directed at children. We do not knowingly collect information from children.
We may update this policy from time to time. We'll update the "Last updated" date above when we do.
Questions about this policy? Contact us.