Skip to content

Legal

Privacy Policy

How AuditIt collects, uses, and protects data when you and your organization run condition audits.

Last updated 2026-07-09

1. Who we are

AuditIt is a software service for template-based before/after condition records. For privacy questions, contact support@auditit.app.

2. What we collect

Depending on how you use the service, we may process:

  • account data (name, email, authentication identifiers);
  • organization and team membership data;
  • asset and customer display information you enter;
  • photos, videos, notes, and checklist values uploaded as audit evidence;
  • signer name and contact details (or hashed contact data) where provided;
  • server timestamps and audit/event metadata;
  • optional location evidence when your organization enables it;
  • device/browser metadata used for security and rate-limiting (often hashed);
  • billing and subscription metadata when payment providers are connected;
  • transactional email delivery metadata (e.g. invitation or signing notifications).

We design for data minimization: collect what is needed to produce and verify an audit record. We do not use your audit evidence to train third-party AI models for general purposes in the current product scope.

3. How we use data

  • to provide templates, audits, signatures, reports, and verification;
  • to secure the service (auth, rate limits, abuse prevention);
  • to send transactional messages you or your organization trigger;
  • to enforce plan limits and process billing events when configured;
  • to respond to support, export, and deletion requests.

4. Sharing

We use infrastructure processors such as hosting, database/auth/storage (e.g. Supabase), email delivery (e.g. Resend), and payment providers (when you enable billing). We do not sell personal data. Public verification and share links only show what your organization and product privacy settings allow.

5. Retention

Default retention and holds are described in the Data Retention Policy. Signed/refused reports are not silently deleted. Billing failure does not delete evidence.

6. Export and deletion

Organization owners/admins may request export or deletion via support. We may need to preserve some audit history where legally or contractually required.

7. Security

We apply access controls, tenant isolation, hashed tokens for public links, and server-side hashing of media. No method of transmission or storage is perfectly secure; report issues to support@auditit.app.

8. Your choices

Depending on your location, you may have rights to access, correct, or request deletion of personal data. Contact support from the relevant account email. Staff of a customer organization should also contact that organization's admin for data they control.

9. Changes

We may update this policy; the date above will change when we do.

Back to home