Privacy policy
Last updated 25 August 2026
TrackReserve provides asset tracking software to companies. This policy explains what we hold, why, and what we will not do with it. It is written to be read, not to be survived.
Who the data belongs to
Equipment records, locations, people and history entered into the portal belong to the customer company that entered them. TrackReserve stores and processes that information on their behalf. We do not sell it, we do not use it to train models, and we do not share it between customers.
What we hold about people who use the portal
- Name, work email, phone number and job title, as entered by their employer
- Which company they belong to and what role they hold in it
- A record of the actions they take on equipment — check-outs, returns, moves, reports
- Sign-in timestamps
Action history is deliberately durable: the value of an asset register is that it can tell you who had a thing and when. Records keep a person's name after they leave a company.
If you scanned a tag and are not a customer
Pointing a phone at a TrackReserve tag shows you a sign-in screen and an option to tell the owner you found their property. That page shows you nothing about the item, its owner, its value or its location.
When you scan, we record:
- Which tag was scanned and at what time
- A truncated form of your IP address — the first three groups for IPv4, so
203.0.113.45is stored as203.0.113.0/24 - A coarse device family, such as “ios” or “android”
That is enough to spot someone hammering the endpoint and not enough to build a picture of where you have been. If you fill in the found-item form, whatever you write there — including any contact details you choose to give — is passed to the company that owns the item.
Who at TrackReserve can see customer data
Not our staff, by default. Support access requires a session that names the customer, carries a written reason, expires after sixty minutes, and is written to an audit log the customer can read in their own settings. Read-only unless the customer grants more.
Where it lives
Data is held in Supabase (PostgreSQL and object storage) and served through Vercel. Separation between customers is enforced by database row-level security, not by application code alone.
How long we keep it
- Equipment records and history: for as long as the customer's account is active
- Scan logs: 24 months
- Audit logs: 24 months
- After an account closes: 90 days, then 30 days' written notice, then deletion
Your rights
If you are an employee of a customer company, your employer controls your record — ask them first. If you cannot resolve something with them, or you are a member of the public who submitted a found-item report, write to privacy@trackreserve.com and we will respond within 30 days.
Export
A customer can export everything they hold, at any time, in CSV. Export is never blocked — not for a late payment and not for a suspended account.
This document is a working draft prepared alongside the software. Have a lawyer in your jurisdiction review it before you rely on it.