Privacy Policy
Last updated 31 August 2026
Equipora (“we”, “us”) provides equipment maintenance tracking software. This policy explains what we collect when you use the site and the app, why, and what you can ask us to do about it. Questions: hello@equipora.app.
Who is responsible for your data
The data controller is Equipora Ltd, which trades as Equipora and operates from Lahore, Pakistan. Write to us at hello@equipora.app about anything in this policy, or see our contact page for the rest of our details. Payments are taken by Paddle.com as merchant of record, so Paddle is the controller of the billing and tax data you enter at checkout, under its own privacy notice.
What we collect
- Account details. Your name, email address and a hashed password. Passwords are stored only as salted hashes, we cannot read them.
- What you put in the app. Your organisation’s equipment, work orders, repair costs, meter readings, maintenance schedules, documents and any photos your team uploads. This is your data; we process it to run the service for you.
- Technical logs. IP address, browser user-agent and timestamps, kept for security, rate limiting and debugging.
- Anonymous product analytics. Which pages get visited and which key actions happen (an account is created, a work order is closed). These events carry only opaque internal IDs and coarse attributes such as role or business type, never names, emails, or anything your team typed into the app.
- Session recordings, on our public pages only, and only if you agree. If you accept the banner on our marketing and sign-up pages, we record how you move through those pages, clicks, scrolling, mouse movement and navigation, so we can see where the page confuses people. Everything typed into a form is masked before the recording leaves your browser, so we never see what you entered. This runs on the public pages only. It is never active inside your account, so no recording can ever contain your equipment, work orders or repair notes. Decline, or ignore the banner, and no recording is made.
- Billing records. If you subscribe, we keep your subscription status and plan, and a record of each payment, the amount, currency, dates, and the payment provider’s transaction reference. Payment is processed by Paddle (see below); your card number is entered with and held by Paddle, we never receive or store it.
We do not sell personal data, we do not share it for advertising, and we do not use your equipment data to train machine-learning models.
Cookies
We use no advertising cookies and no cross-site tracking, ever. What we do use is a short list:
- a session cookie that keeps you signed in, strictly necessary;
- an optional shop-PIN cookie on the public QR pages, so a tech who has entered your shop PIN isn’t asked again on every scan, strictly necessary; and
- an analytics cookie on our public marketing and sign-up pages, set only if you accept the banner. It holds a random identifier that lets us join a session recording together across page loads. It is not set inside your account, and it is not set at all if you decline.
We also store your answer to that banner on your device, so we can honour it and stop asking. That one is strictly necessary, it is the only way a “no” can be remembered, and it is kept whichever way you answer.
If you decline, or simply ignore the banner, we still count page visits anonymously, but nothing is written to your device: no cookie, no local storage, no session storage, and no recording. We are telling you this rather than hiding it, because it is the part most cookie notices are vague about. To change your mind later, clear this site’s data in your browser and the banner will ask again.
Who processes your data
We keep the list of third parties deliberately short. Each one processes data only to provide its service to us:
- Hetzner (Germany), hosting and database.
- Cloudflare R2, off-site storage of our database backups, in a private bucket.
- Paddle (United Kingdom), payment processing. Paddle is the merchant of record for subscriptions and handles checkout, card details, invoicing and tax. We receive only the billing records described above, never your full card number.
- Resend (United States), transactional email (verification, password reset, invites, renewal notices).
- PostHog (United States), anonymous product analytics and, with your consent, the public-page session recordings described above.
- Sentry (United States), error monitoring. Session replay is disabled, so no recording of your screen or page content is ever captured.
Where this involves transferring data outside the UK/EEA, we rely on the providers’ standard contractual clauses and equivalent safeguards.
How long we keep it
Your account and organisation data are kept for as long as your account is active. Ask us to close it and we delete your organisation’s live data within 30 days. Copies may survive for a while longer in our disaster-recovery backups, which are private, access-controlled, and used only to restore the service. Technical logs and anonymous analytics are kept on a rolling basis and cannot be tied back to an individual once the account is gone.
Your rights
You can ask us to give you a copy of your data, correct it, or delete it, and you can object to how we process it. Email support@equipora.app and we’ll respond within 30 days. If you are in the UK or EEA and you’re unhappy with our response, you can complain to your local data protection authority.
Security
Traffic is encrypted in transit (HTTPS). Passwords are hashed. Every query against your organisation’s records is scoped to your organisation in code, and that isolation is covered by automated tests that run on every change. No system is perfectly secure, but if we ever suffer a breach affecting your data we will tell you promptly.
Children
Equipora is a business tool. It is not directed at children and we don’t knowingly collect data from anyone under 16.
Changes
If we change this policy we’ll update the date at the top, and for material changes we’ll email account owners. Our Terms of Service cover the rest of the relationship.