Back to sign in
Privacy Policy
Last updated: September 9, 2026
This is a starter Privacy Policy for InspectoQMS's early pilot customers. It has not been
reviewed by an attorney. Pinkney Technologies LLC intends to have this document reviewed by
qualified legal counsel before onboarding customers beyond the initial pilot.
1. Who We Are
InspectoQMS is operated by Pinkney Technologies LLC ("Pinkney Technologies," "we," "us," or
"our"). This Privacy Policy describes how we collect, use, and protect information in
connection with the InspectoQMS Service.
2. Information We Collect
- Account information — name, username, email address, role, and
organization, provided when an account is created.
- Customer Data — the quality records, documents, inspection results,
nonconformance reports, and other business data your organization enters into or uploads
to the Service.
- Usage data — log data such as IP address, browser type, timestamps, and
pages accessed, used for security, troubleshooting, and improving the Service.
- Billing information — subscription and payment details are collected and
processed directly by our payment processor, Stripe. We do not store full payment card
numbers on our own servers.
3. How We Use Information
- To provide, operate, and maintain the Service;
- To authenticate users and enforce tenant-level data isolation;
- To process subscription billing;
- To monitor for security issues and troubleshoot problems;
- To communicate with account administrators about the Service (e.g. maintenance,
billing, security notices).
We do not sell Customer Data or account information to third parties.
4. Where Data Is Stored
The Service is hosted on Amazon Web Services (AWS) infrastructure located in the United
States. Data at rest is stored in an encrypted database (Amazon RDS) and encrypted object
storage (Amazon S3). Each customer's data is logically isolated from other customers'
data (multi-tenant isolation enforced at both the application and database level).
5. Subprocessors
We rely on the following third-party subprocessors to operate the Service:
- Amazon Web Services (AWS) — application hosting, database, and file
storage.
- Stripe — subscription billing and payment processing.
6. Data Retention and Deletion
Customer Data is retained for as long as the subscription is active. If a subscription is
cancelled, Customer Data is retained for a limited retention window (currently 30 days) to
allow for reactivation or export, after which it is permanently deleted from active systems.
Encrypted backups are retained separately for a limited period for disaster-recovery purposes
and are not used for any other purpose.
7. Export-Controlled Data
Some customers may use the Service to store technical data subject to U.S. export control
laws (ITAR/EAR). We do not access or use Customer Data except as needed to operate, support,
or troubleshoot the Service, and access by our personnel is limited to what is necessary for
that purpose. Customer remains responsible for determining whether its use of the Service is
consistent with its own export control obligations.
8. Your Choices and Rights
- Account administrators can access, update, or request export of their organization's
Customer Data at any time by contacting us.
- You may request deletion of your account and associated data, subject to the retention
practices described above and any legal obligation we may have to retain certain records.
9. Cookies
The Service uses a session cookie strictly necessary to keep you signed in. We do not use
third-party advertising or tracking cookies.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will make reasonable efforts to
notify active customers of material changes.
11. Contact
Questions about this Privacy Policy, or requests regarding your data, can be sent to
chris@pinkneytechnologies.com.