Back to EquipLoop

PRIVACY

Privacy Policy

This policy explains what information EquipLoop handles, why we use it, and the choices available to you—including when you sign in with Google.

Last updated: 25 September 2026

Overview and scope

This Privacy Policy explains how EquipLoop collects, uses, shares, stores, and protects personal information when you visit our website, create an account, use our equipment management service, or contact us.

EquipLoop acts as the responsible party or data controller for account, website, billing, and service-operation information. For personal information an organisation uploads about its people, that organisation generally decides why and how it is processed, and EquipLoop acts as its operator or processor.

Information we collect

Depending on how you use EquipLoop, we may collect:

  • Account information: name, email address, profile image, account identifiers, and authentication details.
  • Organisation information: company name, contact details, members, roles, settings, subscription, and billing records.
  • Equipment operations data: equipment, serial and asset identifiers, categories, custom fields, locations, assignments, condition, notes, photos, signatures, issue and return records, and activity history.
  • People records: names, work contact details, roles, departments, locations, and equipment assignment history entered by an organisation.
  • Technical data: IP address, browser, device, operating system, timestamps, authentication events, diagnostics, and security logs.
  • Communications: messages, support requests, feedback, and notification preferences.

Google sign-in and Google user data

If you choose Continue with Google, Google authenticates you and, through Supabase Auth, shares the basic account information needed to create or access your EquipLoop account. This typically includes your Google account identifier, name, email address, email verification status, and profile image.

  • We use this information only to authenticate you, maintain your profile, secure your account, and provide the Service.
  • We do not request access to Google Drive, Gmail, Contacts, Calendar, or other Google product data.
  • We do not receive or store your Google password.
  • We do not sell Google user data or use it for advertising.
  • We do not transfer Google user data except to service providers needed to provide or secure EquipLoop, when you direct us to, or where law requires it.

EquipLoop’s use and transfer of information received from Google APIs will comply with the Google API Services User Data Policy, including its Limited Use requirements. You can revoke access in your Google Account connections. Revoking access stops future Google sign-in authorisation but does not automatically delete your EquipLoop account; contact us to request deletion.

How we use information

We process information to:

  • create accounts, authenticate users, and manage organisation access;
  • provide equipment records, assignments, returns, locations, QR workflows, audit history, reports, and exports;
  • send service messages such as confirmations, security alerts, equipment reminders, and requested summaries;
  • process subscriptions, administer plans, and keep financial records;
  • provide support, troubleshoot errors, monitor reliability, and improve usability;
  • detect fraud, abuse, and security threats and enforce our Terms; and
  • comply with legal obligations and protect our users and rights.

Our legal grounds may include performing our contract with you, legitimate interests in operating and securing the Service, consent where requested, and compliance with legal obligations.

When we share information

We do not sell or rent personal information. We may share it with:

  • Your organisation: authorised owners, administrators, and members according to their permissions.
  • Service providers: hosting, database, authentication, storage, email, payments, analytics, monitoring, and support providers acting for us under appropriate obligations. Supabase currently provides core database, authentication, and storage infrastructure.
  • Professional advisers and authorities: where reasonably necessary for legal advice, compliance, court processes, fraud prevention, or protection of rights and safety.
  • Business transactions: in connection with a merger, financing, acquisition, reorganisation, or sale, subject to appropriate confidentiality and notice where required.

We may also share information at your direction or after obtaining your consent.

Cookies and similar technologies

EquipLoop uses essential cookies and browser storage to keep you signed in, protect authentication flows, remember necessary settings, and maintain security. We may use limited analytics to understand service performance and usage. Where law requires it, we will request consent before using non-essential cookies. You can control cookies through your browser, but blocking essential cookies may prevent sign-in or other core features.

Data retention and deletion

We retain information for as long as needed to provide the Service, maintain equipment audit history at the organisation’s direction, comply with law, resolve disputes, and protect security. Retention depends on the data, account status, contractual commitments, and legal requirements.

Organisation administrators may correct or remove many records in the Service and can request workspace closure. Account deletion requests can be submitted through our contact page. We may retain limited records where legally required or necessary for fraud prevention, and residual encrypted backups may remain until their scheduled deletion cycle completes.

Security and international transfers

We use reasonable administrative, technical, and organisational controls designed to protect information. These include managed authentication, access controls, tenant isolation policies, encryption provided by our infrastructure, backups, and operational monitoring. No method of storage or transmission is completely secure.

EquipLoop and its providers may process information in countries other than yours. Where required, we use recognised safeguards for cross-border transfers and require providers to protect information consistently with applicable data-protection law.

Your privacy rights

Depending on your location, including under South Africa’s Protection of Personal Information Act (POPIA), you may have rights to access, correct, delete, restrict, or object to processing; withdraw consent; request data portability; or complain to a regulator.

Where an organisation controls a people or equipment record, send your request to that organisation first. We will assist it as required. We may verify your identity and authority before completing a request. You may lodge a complaint with the Information Regulator of South Africa or your applicable local authority.

Children’s privacy

EquipLoop is a business service and is not directed to children. Individuals must be legally able to enter into these Terms, or use the Service through an organisation with appropriate authority and supervision. We do not knowingly collect personal information directly from children for independent consumer use.

Policy changes and contact

We may update this Policy as EquipLoop, our providers, or legal requirements change. We will post the revised version here, update the date above, and provide additional notice for material changes where appropriate.

For privacy questions, requests, account deletion, or complaints, use our contact page. Please do not include passwords, authentication codes, or unnecessary sensitive information in your message. Use of the Service is also governed by our Terms and Conditions.

Questions about these terms?

Contact us if you need clarification about this document or how EquipLoop handles your information.

Contact us