Privacy Policy
UNOFFICIAL DRAFT — LAWYER REVIEW PENDING. This document is a good-faith starting point drafted by the founder and an AI assistant. It has not been reviewed by a licensed attorney and does not constitute legal advice. Before TinyFleet PM accepts its first paying customer, this document must be reviewed by qualified legal counsel — especially the GDPR, UK-GDPR, and CCPA sections if we intend to accept EU/UK/California users.
Last updated: 2026-07-07 Effective date: upon lawyer review and republication
1. Who this policy is about
This Privacy Policy explains how TinyFleet PM ("we") collects, uses, stores, and shares information about you when you use tinyfleetpm.com, the TinyFleet PM Android app, or any related services.
The controller of your personal data is the individual owner of TinyFleet PM. Contact: sellecks1@yahoo.com.
2. Information we collect
2.1 Information you give us
- Account info: email address, display name, password (stored hashed by Supabase Auth — we never see the plaintext).
- Organization info: organization name, industry, member list, and roles you assign.
- Content: assets, tasks, parts orders, notes, photos, files, and any other data you enter into TinyFleet PM.
- Payment info: we do NOT store your card details. Stripe handles payment; we receive only the payment status, subscription state, last 4 digits, and card brand for display purposes.
- Support requests: if you email support or fill out a form, we keep the correspondence for follow-up.
2.2 Information collected automatically
- Auth session data: login timestamp, IP address, and user agent (kept in our audit log for security investigations).
- Audit log entries: for every user-editable table, we record the actor's user id and organization, the record affected, the action (create / update / delete), the JSON snapshot before and after, IP address, and user agent. This helps you (and us) reconstruct what happened if something goes wrong.
- Basic usage data: page views, feature usage, error events. We currently DO NOT use third-party analytics like Google Analytics or Mixpanel. If we add one, we will update this policy and give notice.
- Cookies and local storage: we use cookies and localStorage only for essential purposes: keeping you signed in, remembering your preferences, and CSRF protection. We do not use tracking cookies for advertising.
2.3 Information from third parties
- Stripe: billing status, subscription info, invoice history.
- Firebase Cloud Messaging (Android only): push notification delivery status and device token.
- Google Play Store: if you install via Play Store, Google may share install and crash data with us.
3. How we use your information
We use your information to:
- Operate the TinyFleet PM service (store your assets, sync between devices, deliver notifications).
- Authenticate you and keep your account secure.
- Process your payment and manage your subscription.
- Detect, investigate, and prevent fraud, abuse, and security incidents.
- Respond to your support requests.
- Comply with legal obligations.
- Communicate with you about your account, service changes, and (if you opt in) product news.
We do NOT:
- Sell your personal data to anyone.
- Share your data with advertisers or ad networks.
- Use your content to train AI models.
4. Who we share information with
We share only the minimum data needed with these categories of recipients:
- Service providers who operate the service on our behalf:
- Supabase (US-based, hosts our Postgres database and storage buckets)
- Vercel (US-based, serves the web app)
- Stripe (US-based, processes payments)
- Firebase / Google (US-based, delivers Android push notifications)
- Your Organization's other members — they can see the shared Organization data as their role permits.
- Anyone with a public Maintenance Passport link you enable — they can see the info on the linked passport page you chose to publish.
- Legal / safety: we may disclose information if required by law, subpoena, or court order, or if we believe in good faith it's necessary to protect our rights, users, or the public.
- Business transfers: if TinyFleet PM is acquired, merged, or sells assets, your info may transfer to the buyer, subject to this policy.
We do not currently transfer data outside the US. All primary storage is in US-hosted Supabase and Vercel infrastructure.
5. How long we keep your data
- Account data: for as long as your account is active.
- Content: until you delete it, or until 30 days after account/org deletion.
- Audit log entries: kept for the lifetime of the account, then deleted within 30 days of account deletion. Some entries may be retained longer if needed for fraud investigation or legal reasons.
- Payment records: as required by applicable tax and financial- reporting laws (typically 7 years in the US).
- Support emails: typically 2 years after last interaction.
You can request full account deletion at any time (see section 8).
6. Security
We take reasonable technical and organizational measures to protect your data:
- All connections use HTTPS/TLS.
- Passwords are hashed by Supabase Auth (bcrypt / Argon2 depending on Supabase's version); we never see plaintext.
- Row-Level Security (RLS) enforces that Organization data is only visible to authorized members of that Organization.
- Regular backups to a separate storage location.
- An immutable audit log records who changed what.
No system is perfectly secure. If we become aware of a breach affecting your data, we will notify you and applicable authorities as required by law, generally within 72 hours of discovery for jurisdictions where that is the legal standard.
7. Children's privacy
TinyFleet PM is not directed at children under 16 (or the equivalent minimum age in your jurisdiction). We do not knowingly collect data from children. If you believe a child has created an account, please contact us and we will delete it.
8. Your rights
Depending on where you live, you may have some or all of these rights:
- Access: get a copy of the personal data we hold about you.
- Correction: ask us to fix inaccurate data.
- Deletion: ask us to delete your data ("right to be forgotten"). We will do so unless we have a legal obligation to retain it.
- Portability: get your data in a machine-readable format.
- Restriction / objection: ask us to stop or limit certain processing.
- Withdraw consent: where processing is based on consent, withdraw it at any time.
- Complaint: lodge a complaint with your local data protection authority.
To exercise any of these, email sellecks1@yahoo.com with the subject line "Privacy request". We will respond within 30 days.
8.1 California residents (CCPA / CPRA)
If you're a California resident, you have the right to know what personal information we collect, sell, or share (we don't sell or share for cross-context behavioral advertising); the right to delete; and the right to non-discrimination for exercising your rights. We do not sell personal information as defined by the CCPA.
8.2 EU / UK residents (GDPR / UK-GDPR)
If you're in the EU, EEA, UK, or Switzerland, the legal bases for processing your personal data are:
- Contract: to deliver the service you signed up for.
- Legal obligation: to comply with tax and financial-reporting law.
- Legitimate interest: to secure the service, prevent fraud, and improve the product (balanced against your privacy).
- Consent: for optional communications you opt into.
You may lodge a complaint with your national supervisory authority.
(To be discussed with counsel: whether we need an EU representative under Article 27, and how to handle international data-transfer mechanisms if we accept EU users.)
9. Cookies
TinyFleet PM uses only essential cookies and localStorage:
- Session cookie: keeps you logged in.
- CSRF token: protects against cross-site request forgery.
- UI preferences: remembers your theme, view settings, and last- visited page.
We do not use tracking, advertising, or third-party analytics cookies. If we add any, we will update this policy and provide a cookie banner where required.
10. Changes to this policy
We may update this policy from time to time. Material changes will be announced by email and/or in-product notice at least 30 days before they take effect. The "Last updated" date at the top will reflect the latest version.
11. Contact us
Questions or requests about this Privacy Policy: sellecks1@yahoo.com
Postal address: (to be filled in after formal business address is set)