Legal

Privacy Policy

What Alderworks holds when you use Alderworks Equipment Management Software or buy SpecRun, ShiftHandover, RetainLog, PullPlan, CoverPlan, EquipLog or the Alderworks Quality Suite, who else handles it, how long it is kept, and what is deliberately not collected.

1. Who controls what

Alderworks Equipment Management Software, SpecRun, ShiftHandover, RetainLog, PullPlan, CoverPlan, EquipLog, and the Alderworks Quality Suite are provided by Alderworks LLC, which is responsible for the data described here and is who you contact about it. Two different relationships run through Alderworks Equipment Management Software, and the difference decides who you should ask about what.

Records inside a workspace — equipment, calibrations, maintenance, work orders, certificates, uploaded files, and the people named on them — belong to the subscribing organization. They decide what goes in, who can see it, and what is published. We hold that data on their behalf and act on their instructions. If you are an employee of a subscribing organization, ask them first.

Account and billing information we hold in our own right, to provide the service, take payment, and support it.

SpecRun, ShiftHandover, RetainLog, PullPlan, CoverPlan, EquipLog and the Alderworks Quality Suite are different: they are files that run on your own computer, and nothing you do in them reaches us. What we hold for them is only what a purchase gives us, which we also hold in our own right, to take payment, deliver the download, and support it.

2. What we hold

Account information

Your email address, your name, your role, and your workspace memberships. If you signed up for a trial yourself, also the organization name you gave and the plan whose button you pressed. If you set up an electronic signature, the name, initials, title, and statement you enter for it. Passwords are handled by our authentication provider and we never see or store them.

Workspace records

Everything entered into the service. Some of it names people, and this is easy to overlook because much of it is typed as free text rather than chosen from a list: technician names on calibration records, the names and email addresses of whoever performed and reviewed a calibration, who a work order was assigned to and who completed it, who a piece of equipment belongs to, the name on a generated certificate, contact names and addresses for organizations, and the recipient addresses set for reminder email.

Uploaded files

Equipment photographs, nameplate images, documents, manuals, procedures, scanned certificates, work-order attachments, and a company logo, with the file name, type, size, and who uploaded it. Photographs of equipment sometimes include people.

Activity and audit records

Who changed what and when, including the values before and after a change. Because those snapshots are complete, a personal detail that was later corrected still exists in the history of the record.

Billing information

Your plan, subscription status, billing period, and the identifiers our payment provider gives us. We also keep a copy of each payment event the provider sends us, which includes the billing contact details entered on its pages. Card details are entered on the provider’s own pages and never reach us.

Purchase information for SpecRun, ShiftHandover, RetainLog, PullPlan, CoverPlan, EquipLog and the Alderworks Quality Suite

When you buy one, the payment provider collects your email address, name, the billing address details it needs, and the organization you name as the license holder. We receive those details in the payment event it sends us, keep a copy of that event, and use your email address and organization to email you the download link. The link identifies your purchase, so anyone you share it with can download the release. There is no account to create.

Reminder delivery records

The address each reminder was sent to, whether it was delivered, and any error returned.

Public certificate views

When someone opens a public verification link, we record the time, the browser’s user-agent string, and the page they came from, so a workspace can see that a certificate was checked.

3. What we deliberately do not collect

This list is as much a part of the policy as the one above, and it is short because the service was built this way rather than trimmed back later.

  • No IP addresses in our records. The application does not record the IP address of anyone using the service or opening a public link. Our authentication and hosting providers keep their own security and request logs, which include IP addresses, as any host must.
  • No analytics or product telemetry. There is no analytics service, no usage tracking, and no session recording.
  • No advertising or tracking identifiers, and no data is sold, rented, or shared for advertising.
  • No third-party fonts, scripts, or embeds. Fonts are served from our own domain, so loading a page does not announce your visit to anyone else.
  • No training. Your records are not used to train machine-learning models, ours or anyone else’s.

4. Who else handles it

Four companies process data on our behalf. There are no others, and we will update this list before adding one.

  • Supabase — Database, authentication, and file storage. All workspace records, user accounts and credentials, uploaded files, and a copy of each payment event Stripe sends us. Sign-up confirmation, invitation and password-reset email is composed by Supabase and handed to Resend to deliver.
  • Vercel — Application hosting. Processes all requests to the service as its host. No customer records are stored there by the application.
  • Stripe — Subscription payments and one-time purchases. Billing contact and payment details, entered on Stripe's own pages; for a SpecRun, ShiftHandover, RetainLog, PullPlan, CoverPlan, EquipLog or Alderworks Quality Suite purchase, also the organization named as the license holder. Card details never pass through our systems. We keep a copy of each payment event Stripe sends, which includes the billing contact but no card details.
  • Resend — Account email, reminder email and purchase download email. The address of anyone sent a sign-up confirmation, invitation or password-reset email, and the link in it; the recipient addresses configured in a workspace and the contents of the reminder digest sent to them; for a SpecRun, ShiftHandover, RetainLog, PullPlan, CoverPlan, EquipLog or Alderworks Quality Suite purchase, the buyer's email address, the organization named as the license holder, and the download link.

We will also disclose data where the law requires it. If we are ever compelled to, we will tell the affected customer unless we are prohibited from doing so.

The regions in which our infrastructure providers store data depend on how our accounts with them are configured. If you need that in writing for a procurement or data-transfer assessment, ask us and we will tell you what it is rather than guess here.

5. Records that can be made public

The service can publish two things to anyone holding a link, and both deserve to be understood before they are used.

Certificate verification links let a customer or auditor confirm a certificate without an account. The page shows the calibration date, due date, result, certificate number and version, the equipment’s name, asset ID, serial number, manufacturer and model, and the workspace’s company name, address, phone, and email. It does not show the technician, the notes on the record, or where the equipment is kept. Downloading the certificate as a PDF is off unless a workspace turns it on.

Equipment profile links, typically reached from a printed QR code, show the equipment’s name, asset ID, serial number, manufacturer and model, its calibration interval and due date, and recent calibrations with their dates, results and certificate numbers. They do not show its location, its owner, its notes, or the technician. Equipment profiles are enabled by default when equipment is created. They can be turned off per item, and they should be, for anything whose details should not be readable by whoever finds the label.

These links are addressed by a long random token and are not listed or indexed, but they are not secret: anyone holding the link can open them, and a label carrying one travels with the equipment. Some older links remain valid because they were printed on labels that cannot be reissued.

6. What is stored on your device

We use no tracking cookies, so there is no consent banner. What the application does store in your browser is:

  • Your sign-in session, held in browser local storage by our authentication provider. Signing out removes it. Because it is in local storage rather than a protected cookie, treat a shared or public computer accordingly and sign out when you finish.
  • Interface preferences: theme and appearance, workspace branding, notification settings, which commands you use most, filters, sorting, and paging.
  • Unsaved form drafts, so a half-entered equipment record survives a closed tab. These contain what you typed.
  • One cookie, holding your workspace’s display name so the page does not flash the wrong one while loading. It carries no identifier and does not track you.
  • A stored copy of your workspace logo, so it does not reload on every page.

All of it stays on your device. Clearing your browser storage removes it and costs you nothing but the preferences.

SpecRun, ShiftHandover, RetainLog, PullPlan, CoverPlan, EquipLog and the Alderworks Quality Suite keep what you enter in your browser’s storage on the computer running them: the run and its readings, the settings, the last order details, and the shared folder chosen in SpecRun; the summary being written, the standards lists, and the shared folder chosen in ShiftHandover; the staged queue, queued corrections and sign-offs, the checker’s initials, recent changes, and a copy of the last workbook opened in RetainLog; order details and settings in PullPlan; the name chosen, a copy of the team’s settings and the shared folder chosen in CoverPlan; the shared folder chosen, the light or dark and color setting, and whether admin mode is unlocked in EquipLog, which keeps the equipment register and its records only in the workbook in that folder; and in the Alderworks Quality Suite, the same for each app it holds, plus the team folder chosen, the light or dark and color setting, which admin is signed in, and a copy of the admins, what the staff see and the team lists. They make no network requests, so none of it reaches us or anyone else. Clearing that browser storage removes it, including anything in RetainLog not yet saved to a workbook, a ShiftHandover summary not yet saved as a handover file, and a SpecRun run not yet written to a workbook.

7. How long we keep it

Workspace records are kept for as long as the workspace is active, because that is what the service is for: a calibration history is evidence, and silently expiring it would destroy its value.

When a workspace is suspended, its data is retained for 30 days and then becomes eligible for permanent deletion. Deletion removes the workspace and everything belonging to it, including equipment, calibrations, certificates, maintenance, work orders, uploaded files, activity, and audit history. It is permanent and we cannot recover it.

Three things deliberately survive that deletion:

  • a record that the workspace existed and was deleted, with its name, plan, dates, and the stated reason, kept as evidence that the deletion was performed properly;
  • platform administration records of actions taken on the account;
  • payment-provider event history, which we are required to keep for financial records.

Purchase information for SpecRun, ShiftHandover, RetainLog, PullPlan, CoverPlan, EquipLog and the Alderworks Quality Suite is part of that payment-provider event history and is kept for the same reason. Your download link does not depend on it: each time the link is used, the purchase is checked with the payment provider.

Deleting a workspace does not delete the user accounts of its members, since a person may belong to more than one. Ask us to delete an account and we will.

Within an active workspace, activity and audit history is not automatically pruned, by design, so it accumulates. Nobody signed in to a workspace, whatever their role, can change or delete an entry in it, the approval history of a calibration, or an issued certificate: the database refuses. It is removed only when the whole workspace is deleted.

8. How it is protected

Each workspace is isolated, and access is enforced by the database itself rather than only by the application asking nicely. Roles separate administration from execution. Uploaded files are stored under their workspace and served through short-lived links that expire, except the company logo, which is public because it is printed on certificates.

Payment events, including purchase information for SpecRun, ShiftHandover, RetainLog, PullPlan, CoverPlan, EquipLog and the Alderworks Quality Suite, are stored in the same database and are readable only by the service itself and our staff, not by any workspace.

Our staff can be added to a workspace to provide support. That access is recorded, distinguishable from a customer account, and used only to help with a request or to investigate a fault.

No system is perfectly secure. If a breach affects your data, we will tell you what happened, what it affected, and what we are doing about it.

9. Your rights

Depending on where you live you may have rights to see, correct, export, or delete the personal data held about you, and to object to or restrict its handling.

For data inside a workspace, the subscribing organization decides, so start with your administrator; the service gives them the tools to correct records and export them. We will help them, and we will pass on any request that reaches us first.

For your own account information, or the purchase information we hold for SpecRun, ShiftHandover, RetainLog, PullPlan, CoverPlan, EquipLog or the Alderworks Quality Suite, write to us and we will act on it, except where we must keep a payment record for financial records. We will not charge you for it or treat you differently for asking.

One limit worth stating plainly: a completed calibration record is evidence about a piece of equipment at a moment in time, and the technician named on it is part of what makes it evidence. Removing that name may not be possible without destroying the record’s purpose, and an organization may be required to keep it. Where that is the case we will explain it rather than quietly decline.

10. Children

The service is for workplace use and is not directed at children. We do not knowingly collect data from them.

11. Changes

If we change this policy in a way that materially affects you, we will tell you before it takes effect. Adding a new company that handles your data always counts as material.

12. Contact

Privacy questions and requests go to support@alderworks.dev. Our security page describes how the service is built, and the terms of service govern the rest of the relationship.