Legal
Privacy Policy
Effective date: 2026-08-02. Company Asset Tracker ("we", "us", "our") operates the website at companyassettracker.com and the asset-tracking service hosted at app.companyassettracker.com (together, the "Service"). This policy explains what data we collect, how we use it, and the choices you have.
We try to keep this readable. If anything is unclear, email privacy@companyassettracker.com and a human will respond.
1. Information we collect
We collect three categories of information:
- Account data — name, work email, company name, and authentication credentials (or SSO subject ID) for the people who sign up to administer your workspace.
- Asset data — the records you choose to add to the Service: serial numbers, license keys, assignee identifiers, photos, and notes. This data belongs to you and is processed on your behalf.
- Operational data — request logs, error reports, and aggregated usage analytics. We use these to keep the Service fast and reliable, and to investigate bugs.
2. How we use information
We use the data above to:
- Authenticate users and authorize access to workspaces.
- Provide, maintain, and improve the Service.
- Send transactional emails (account verification, password resets, security alerts). Marketing emails are opt-in and can be unsubscribed in any email footer.
- Respond to support requests and troubleshoot issues you report.
- Detect and prevent abuse, fraud, and security incidents.
We do not sell personal data. We do not share data with advertising networks.
3. Cookies & tracking
We use a small number of strictly-necessary cookies to keep you signed in and to remember workspace context. We do not set advertising cookies. If we add analytics (we use PostHog in some workspaces), we ask for opt-in consent first via a banner at the bottom of the screen.
You can clear cookies at any time through your browser. The Service will continue to function; you'll just need to sign in again on your next visit.
4. Third-party services
To run the Service, we share limited data with a small set of vetted processors. The current list:
- Cloud hosting — Amazon Web Services (us-east-1, eu-west-1) for application compute and database storage.
- Email delivery — Postmark for transactional email; emails contain only the data you provide.
- Authentication — Google or Microsoft identity providers when you sign in via SSO.
- Error monitoring — Sentry for crash reports and stack traces; personally identifying data is scrubbed before transmission.
- Payments — Stripe for billing; we never see your card number, and Stripe stores it under their own privacy and security controls.
Each of these vendors signs a data processing agreement with us. We publish an up-to-date list at /legal/sub-processors.
5. Data security
We encrypt data in transit (TLS 1.3) and at rest (AES-256). Access to production systems is gated by hardware-backed MFA and reviewed quarterly. Audit logs are append-only.
Despite our efforts, no system can guarantee perfect security. If we ever experience a breach that affects your data, we'll notify you without undue delay and at most within 72 hours of confirmation.
6. Your rights & choices
You can:
- Access a copy of your personal data.
- Correct inaccurate records.
- Delete your account and all associated data.
- Export your workspace data to CSV at any time.
- Object to processing for direct marketing.
To exercise any of these, email privacy@companyassettracker.com from the address on file. We respond within 30 days.
7. Children's privacy
The Service is not directed at children under 16, and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, email us and we'll delete it.
8. International transfers
We operate in the United States and the European Union. Data may be transferred between regions to provide the Service; we rely on Standard Contractual Clauses for cross-border transfers where required. By using the Service, you understand your data may be processed in the United States.
9. Changes to this policy
We may update this policy as the Service evolves. We'll post the new version at this URL with a revised "Effective date" at the top, and for material changes we'll email workspace administrators at least 30 days before they take effect.
10. Contact us
Questions, comments, or complaints? Reach out:
- Email:privacy@companyassettracker.com
- Mail: Company Asset Tracker, Inc., Attn: Privacy, 123 Market St., Suite 400, San Francisco, CA 94105, USA
If you're in the EU or UK and believe we haven't addressed your concern, you have the right to lodge a complaint with your local data protection authority.