Back to sign in

Privacy Policy

Last updated: September 9, 2026
This is a starter Privacy Policy for InspectoQMS's early pilot customers. It has not been reviewed by an attorney. Pinkney Technologies LLC intends to have this document reviewed by qualified legal counsel before onboarding customers beyond the initial pilot.

1. Who We Are

InspectoQMS is operated by Pinkney Technologies LLC ("Pinkney Technologies," "we," "us," or "our"). This Privacy Policy describes how we collect, use, and protect information in connection with the InspectoQMS Service.

2. Information We Collect

  • Account information — name, username, email address, role, and organization, provided when an account is created.
  • Customer Data — the quality records, documents, inspection results, nonconformance reports, and other business data your organization enters into or uploads to the Service.
  • Usage data — log data such as IP address, browser type, timestamps, and pages accessed, used for security, troubleshooting, and improving the Service.
  • Billing information — subscription and payment details are collected and processed directly by our payment processor, Stripe. We do not store full payment card numbers on our own servers.

3. How We Use Information

  • To provide, operate, and maintain the Service;
  • To authenticate users and enforce tenant-level data isolation;
  • To process subscription billing;
  • To monitor for security issues and troubleshoot problems;
  • To communicate with account administrators about the Service (e.g. maintenance, billing, security notices).

We do not sell Customer Data or account information to third parties.

4. Where Data Is Stored

The Service is hosted on Amazon Web Services (AWS) infrastructure located in the United States. Data at rest is stored in an encrypted database (Amazon RDS) and encrypted object storage (Amazon S3). Each customer's data is logically isolated from other customers' data (multi-tenant isolation enforced at both the application and database level).

5. Subprocessors

We rely on the following third-party subprocessors to operate the Service:

  • Amazon Web Services (AWS) — application hosting, database, and file storage.
  • Stripe — subscription billing and payment processing.

6. Data Retention and Deletion

Customer Data is retained for as long as the subscription is active. If a subscription is cancelled, Customer Data is retained for a limited retention window (currently 30 days) to allow for reactivation or export, after which it is permanently deleted from active systems. Encrypted backups are retained separately for a limited period for disaster-recovery purposes and are not used for any other purpose.

7. Export-Controlled Data

Some customers may use the Service to store technical data subject to U.S. export control laws (ITAR/EAR). We do not access or use Customer Data except as needed to operate, support, or troubleshoot the Service, and access by our personnel is limited to what is necessary for that purpose. Customer remains responsible for determining whether its use of the Service is consistent with its own export control obligations.

8. Your Choices and Rights

  • Account administrators can access, update, or request export of their organization's Customer Data at any time by contacting us.
  • You may request deletion of your account and associated data, subject to the retention practices described above and any legal obligation we may have to retain certain records.

9. Cookies

The Service uses a session cookie strictly necessary to keep you signed in. We do not use third-party advertising or tracking cookies.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will make reasonable efforts to notify active customers of material changes.

11. Contact

Questions about this Privacy Policy, or requests regarding your data, can be sent to chris@pinkneytechnologies.com.