1. Who we are
AuditIt is a software service for template-based before/after condition records. For privacy questions, contact support@auditit.app.
2. What we collect
Depending on how you use the service, we may process:
- account data (name, email, authentication identifiers);
- organization and team membership data;
- asset and customer display information you enter;
- photos, videos, notes, and checklist values uploaded as audit evidence;
- signer name and contact details (or hashed contact data) where provided;
- server timestamps and audit/event metadata;
- optional location evidence when your organization enables it;
- device/browser metadata used for security and rate-limiting (often hashed);
- billing and subscription metadata when payment providers are connected;
- transactional email delivery metadata (e.g. invitation or signing notifications).
We design for data minimization: collect what is needed to produce and verify an audit record. We do not use your audit evidence to train third-party AI models for general purposes in the current product scope.
3. How we use data
- to provide templates, audits, signatures, reports, and verification;
- to secure the service (auth, rate limits, abuse prevention);
- to send transactional messages you or your organization trigger;
- to enforce plan limits and process billing events when configured;
- to respond to support, export, and deletion requests.
4. Sharing
We use infrastructure processors such as hosting, database/auth/storage (e.g. Supabase), email delivery (e.g. Resend), and payment providers (when you enable billing). We do not sell personal data. Public verification and share links only show what your organization and product privacy settings allow.
5. Retention
Default retention and holds are described in the Data Retention Policy. Signed/refused reports are not silently deleted. Billing failure does not delete evidence.
6. Export and deletion
Organization owners/admins may request export or deletion via support. We may need to preserve some audit history where legally or contractually required.
7. Security
We apply access controls, tenant isolation, hashed tokens for public links, and server-side hashing of media. No method of transmission or storage is perfectly secure; report issues to support@auditit.app.
8. Your choices
Depending on your location, you may have rights to access, correct, or request deletion of personal data. Contact support from the relevant account email. Staff of a customer organization should also contact that organization's admin for data they control.
9. Changes
We may update this policy; the date above will change when we do.