PRIVACY
SOR FastTrack Privacy Policy
This Policy explains the main information flows in SOR FastTrack. The service is designed so ordinary job working data remains local to the user's device unless a feature explicitly sends information to a server or third-party service.
1. Account information
We store information needed to operate an account, such as name, email address, role, plan, Dataset entitlements, account status and billing status. Passwords are stored as salted password hashes, not as readable passwords.
2. Local job data and photos
Job details, selected SOR items, notes, photos, imported workbook baselines and autosaves are primarily stored in browser storage on the user's device. They are not automatically uploaded to a FastTrack job cloud service in this release.
3. AI photo analysis
If a user intentionally uses AI Photo Scope, the selected images and the minimum supporting context required for that request are sent through the FastTrack server to the configured OpenAI service. Do not submit images or information you are not authorised to process.
4. Billing
Stripe processes subscription checkout, payment methods, invoices and customer billing management. FastTrack stores limited Stripe-linked identifiers and subscription status needed to reconcile the account. FastTrack does not collect or store full payment-card numbers.
5. Transactional email
Resend is used for account verification and password-recovery email when production email delivery is configured. The recipient email address and message delivery information are provided to that service for this purpose.
6. Location lookups
If reverse geocoding is used, coordinates may be sent to the configured OpenStreetMap/Nominatim service to resolve a human-readable location. FastTrack caches successful lookups to reduce repeated requests.
7. Browser storage and PWA caches
FastTrack uses IndexedDB, local/session storage, Cache Storage and a Service Worker for autosave, offline operation, Dataset caching and PWA updates. Clearing site data can remove local jobs and photos.
8. Security and access
Authentication tokens, Dataset entitlements, server-side access checks, signed workflows, rate limits and private Dataset storage are used to reduce unauthorised access. No internet service can be guaranteed completely secure.
9. Retention and account requests
Account and billing metadata is retained while reasonably required to operate the service, meet contractual or legal obligations, resolve disputes and protect the service. You may contact us to request access, correction or deletion where applicable.
10. Disclosure and sale
We use service providers only where needed to operate features such as hosting, email, billing and AI. We do not sell personal information to advertisers.
11. Contact
Privacy enquiries can be sent to the privacy contact. General support is available at the support address.
