Legal
Privacy policy
Last updated July 2, 2026
1. What this covers
This policy explains what data DeviceChart collects and stores when your organization uses the app, and what we do with it. DeviceChart tracks IT hardware and software assets for businesses — it does not sell data, run ads, or build profiles of individuals for marketing.
2. Data we store
The data your organization stores in DeviceChart typically includes:
- Account and people data: names, work email addresses, and roles for people your admins invite into the account.
- Asset data: device makes/models, serial numbers, asset tags, status, location, assigned owner, and warranty dates.
- Software data: application names, seat counts, renewal dates, and (where entered) contract cost — no browser extensions, SSO/OAuth discovery, bank feeds, or stored passwords are involved in collecting this.
- Sensitive fields: disk recovery keys and similar secrets, where an admin chooses to record them. These render masked by default; every reveal is logged (see our security page).
- Billing data: handled by Stripe. We store subscription status, not full card numbers.
- Usage and audit data: an append-only log of who created, changed, deleted, revealed, or exported records, plus basic sign-in activity.
We don’t require or store deeply sensitive personal data (health, government ID numbers, financial account numbers) as part of normal use of the product.
3. How we use it
Data is used only to run the service for your organization: displaying your inventory, enforcing role-based access, sending the emails you’d expect (warranty and renewal reminders, account notices), and billing through Stripe. We don’t use your organization’s data to train models or share it with other customers.
4. Who can see it
Access is isolated per organization at the database level (Postgres row-level security), not just hidden in the UI — a bug in a screen can’t leak another organization’s rows. Within your organization, what a person can see depends on their role: viewers and auditors never see costs or recovery-key values, for example.
5. Subprocessors
We rely on the following subprocessors to run DeviceChart:
- Supabase — database, authentication, and row-level security.
- Vercel — application hosting.
- Stripe — subscription billing and payment processing.
- Resend — transactional email (warranty/renewal alerts, account notices).
We’ll update this list if that changes materially.
6. Data retention and deletion
Your data is retained for as long as your account is active, including during read-only grace after a lapsed subscription — a lapsed payment never triggers deletion. If you close your account, we’ll provide a final export on request and delete your organization’s data within a reasonable period afterward, except where retention is required by law (for example, billing records).
7. Your export rights
You can export your asset inventory, software register, and audit log as CSV at any time. Export access is never gated behind a plan tier or feature — it’s available to every paying account, including in read-only grace.
8. Security
See /security for details on isolation, encryption posture, and audit logging.
9. Changes to this policy
We may update this policy as the product evolves. We’ll update the date at the top of this page and, for material changes, notify account admins by email.
10. Contact
Questions about this policy, or a request to export or delete your data: support@devicechart.com.