Legal
Privacy Policy
How DealQuip handles information across its public website, authenticated services, and mobile app.
Effective and last updated: September 19, 2026 Document version 2026-09-19-v3
1. Scope and our role
This Privacy Policy explains how DealQuip LLC (“DealQuip,” “we,” “us,” or “our”) handles personal information through dealquip.com, the DealQuip authenticated web application, the DealQuip mobile application, and related communications and services (collectively, the “Services”).
DealQuip provides business asset-management tools to organizations. For account, support, website, and billing administration information, DealQuip generally determines why and how the information is handled. For equipment records and other content submitted by a customer organization, DealQuip generally processes that information to provide the Services on the organization’s behalf. Your organization may have its own privacy obligations and policies.
2. Information we collect
Depending on how you use the Services, we collect the following categories:
- Account and contact information: name, business email, phone number, password-related authentication records, profile information, role, job title, invitation status, and organization membership.
- Organization and workspace information: organization name and contact details, sites, addresses, internal locations, business units, projects, team settings, and permissions.
- Asset and operational information: equipment descriptions, identifiers, serial and model information, photos, documents, notes, condition, custody, assignment, import, reconciliation, maintenance-related status, and history.
- Billing information: plan, subscription status, seat quantities, billing period, and identifiers linking an organization to its Stripe customer and subscription. DealQuip does not store complete payment-card numbers.
- Communications: account and organization signup choices, company and approximate Asset count, support messages, invitation and service-email delivery status, and marketing choices.
- Device and app information: app version, device name, operating-system platform, network availability, push-notification token, notification preferences, and delivery status when push notifications are enabled.
- Website activity: pages viewed, referral and campaign information, browser or device characteristics, interaction events, and approximate location inferred from an IP address when public-site analytics is configured.
The mobile app can access the camera, photo library, and files only after you choose the relevant workflow and, where iOS requires it, grant permission. It uses that access to capture or select Asset photos and documents. DealQuip does not currently request precise device location, contacts, microphone, Bluetooth, or App Tracking Transparency permission.
3. Sources of information
We receive information directly from you; from administrators and other authorized users in your organization; automatically from browsers, devices, and the Services; from service providers that support authentication, hosting, email, notifications, analytics, and billing; and from files or records that authorized users import or upload.
4. How we use information
We use information to:
- create and secure accounts, authenticate users, and recover access;
- provide organization workspaces, equipment inventory, projects, reconciliation, reports, imports, private media, notifications, and support;
- manage invitations, roles, seat allowances, subscriptions, and billing administration;
- send requested transactional communications and, only after the separate optional choice shown at signup, nonessential customer-success, product-tip, feedback-request, announcement, and marketing communications;
- operate, troubleshoot, protect, measure, and improve the Services;
- prevent fraud, abuse, and unauthorized access; and
- comply with law and establish, exercise, or defend legal claims.
Customer-success eligibility may use bounded account and organization milestones such as access state, Asset presence, team size, completed workflows, operational activity, support-risk state, and prior communication or feedback history. Complete email bodies and unnecessary operational detail are not stored in the customer-success outbox.
5. AI-assisted features
When an organization enables AI-assisted equipment identification and a user grants the required permission, DealQuip creates an AI-only derivative of one candidate equipment photo and sends it through a server-side evidence workflow. AWS Textract first checks for useful text from a data plate, label, decal, or equipment marking. If no useful identifying evidence is found, processing stops and the photo is not sent to OpenAI. If useful evidence exists, DealQuip may send the derivative, bounded OCR evidence, and limited Asset identification context to OpenAI to produce suggestions for human review. General appearance alone is not treated as reliable identity evidence.
DealQuip limits the identification request to the equipment task and excludes billing information, credentials, member rosters, Sites, Projects, custody or reconciliation history, unrelated documents, audit records, and support messages. Photos and free-form Asset fields can nevertheless contain incidental personal information—for example, a person, face, employee badge, name, license plate, address, phone number, email address, or customer label—and users should avoid capturing information that is not needed for the equipment task. DealQuip does not use this workflow for facial recognition, biometric identification, or identity verification.
For an authenticated support request, DealQuip may send OpenAI the ticket subject, description, selected category, current workflow area, and bounded excerpts from approved DealQuip Help content to classify and summarize the request and prepare a suggested response. Attachments, unrelated workspace or customer data, organization or account identifiers, credentials, tokens, payment details, and broad account exports are excluded. Common secrets and direct identifiers in the submitted text are removed before transmission. The minimum necessary context is used.
DealQuip sends requests from its servers and does not place provider credentials in the browser or Mobile app. OpenAI states that API inputs and outputs are not used to train its models by default unless a customer opts in. DealQuip sets these requests to store: false, but that setting is not a contractual zero-retention guarantee.
DealQuip stores suggestions, summaries, confidence or severity values, bounded evidence and routing metadata, review state, response delivery mode, and related processing history so authorized reviewers can evaluate the result. A narrowly whitelisted, high-confidence response to a documented low-risk product question or feature-request acknowledgment may be sent automatically. Billing, customer-data, permission, security, destructive, unresolved, and production actions remain approval-gated. AI suggestions never automatically change authoritative Asset fields or perform a production, billing, data, permission, security, or destructive action. DealQuip does not send user corrections to OpenAI for model training. A materially different AI purpose, provider, payload, or training use requires a new product and privacy review.
7. How we disclose information
We disclose information only as reasonably needed for the purposes described above, including to:
- Supabase for authentication, database, private file storage, Realtime, and related backend services;
- Vercel for website, web-application, and authenticated relay hosting;
- Resend for transactional account, invitation, billing, and support email. A founder support alert is limited to the ticket reference, organization and submitting-user names, category, severity, a concise redacted summary, and a founder-console link;
- Stripe for hosted checkout, customer portal, subscription, invoice, and payment processing;
- Expo, Apple, and platform notification services for app distribution, push-token issuance, and notification delivery when enabled;
- Google for public-site analytics when configured;
- AWS for bounded text detection on an AI-only photo derivative when AI identification is used; and
- OpenAI for limited, server-side AI-assisted Asset identification and the bounded support-triage processing described above.
We may also disclose information to professional advisers; to authorities or others when required by law or needed to protect rights, safety, and security; or in a merger, financing, acquisition, reorganization, or sale of assets subject to appropriate safeguards.
DealQuip does not sell personal information for money. Based on the audited configuration, DealQuip does not share personal information for cross-context behavioral advertising. Activating advertising technology would require a new review and appropriate notice and choice.
8. Organization access and responsibility
Authorized members of an organization may access information according to their assigned role. Owners and administrators can manage users and organization settings. An organization may remove a membership without deleting the person’s global DealQuip authentication account. Equipment records, audit history, and other organization content belong to the organization’s workspace and are not automatically deleted when one member leaves.
9. Retention and deletion
Active organization content is retained while needed to provide and secure the Services. Canceling a subscription does not currently trigger automatic organization deletion: organization content remains subject to administrator authority, the applicable agreement, operational requirements, and an approved deletion request. Capture drafts and their temporary media follow the shorter expiration and cleanup lifecycle built into Capture. Production database backups follow the hosting provider’s current backup cycle and ordinarily age out as newer backups replace them.
Billing and transaction records are retained as needed for accounting, tax, fraud prevention, disputes, and legal obligations. Consent, security, audit, and Asset-history records may be retained to preserve accountability and protect the organization and its users. Support records are retained while needed to resolve and document the request; the Help Assistant does not store raw conversations in DealQuip. Analytics and usage records are retained according to their operational purpose and provider settings.
Individual account deletion is available in DealQuip Mobile, but it does not automatically erase organization-owned records, shared history, billing records, or information we must retain. Organization or customer-content deletion requests are reviewed for requester authority, shared-record impact, backup lifecycle, security, and legal obligations. Retention periods may therefore vary by record type. DealQuip’s planned 30-day read-only post-subscription lifecycle is not yet active and is not a promise of automatic deletion.
10. Your privacy choices and requests
Depending on where you live and applicable law, you may request access to or confirmation of personal information, correction, deletion, a portable copy, or additional information about collection and disclosure. You may also object to or restrict certain processing, opt out of covered sale, sharing, targeted advertising, or profiling practices, and appeal a denied request where those rights apply. DealQuip does not currently sell personal information or share it for cross-context behavioral advertising.
Each nonessential DealQuip customer-success email includes an unsubscribe action. An opt-out is recorded server-side and suppresses later customer-success and marketing email; it does not suppress essential account, authentication, security, billing, invitation, or support communications. You may also email support@dealquip.com for assistance.
Submit a privacy request through Privacy Choices. We ordinarily verify a request through an authenticated account or the email associated with the account, and request additional information only when reasonably necessary. Organization-owned information may also require verification of your authority. We will explain a denial and available appeal method when applicable, and will not discriminate against you for exercising an applicable privacy right.
Account deletion is different from removing a membership or deleting organization content. A request involving a sole owner, active subscription, shared Asset history, or legally retained records may require additional steps.
11. Security
We use administrative, technical, and organizational safeguards designed for the nature of the information, including encrypted transport, private media storage, server-only credentials, role-based access, row-level database controls, and limited authenticated sessions. No system can be guaranteed completely secure. Please report suspected unauthorized access promptly.
12. Children
The Services are for business use and are not directed to children under 13. DealQuip does not knowingly collect personal information from children through the Services. Users must be at least 18 or the age of legal majority needed to enter an agreement for their organization.
13. International processing
DealQuip is based in the United States, and DealQuip and its providers may process information in the United States and other countries where they operate. Those locations may have different data-protection laws. DealQuip is not presently representing that it offers a standardized contractual-clause or international data-processing package. We will evaluate and implement transfer arrangements if required for a customer or jurisdiction before making that commitment.
14. Changes to this policy
We may update this policy as the Services and legal requirements change. We will post the revised policy with a new version and effective date. For a material change, we may also provide notice through the website, app, or email, highlight the change, and obtain renewed acceptance when appropriate or required. Updating a policy does not by itself expand DealQuip’s rights to use confidential customer content.
15. Contact
Send privacy questions or requests to support@dealquip.com. Please do not send passwords, payment-card details, or sensitive asset documents by email.
