Effective Date: July 31, 2026 · Last Updated: July 31, 2026
This policy explains how Good Software Co (“we”, “us”) handles personal information in Equipment Maintenance Log, available at equipmentmaintenancelog.com. We are based in Australia and are the entity responsible for the information described here.
It covers both our public website and the signed-in application, including the equipment records and service logs our customers store with us. Questions, requests, and complaints go to support@equipmentmaintenancelog.com.
Equipment Maintenance Log is a business product, so our role depends on the data:
We are the controller for account data (your name, email address, sign-in records), billing data, website analytics, error diagnostics, and support conversations. This policy is our notice to you for that data.
We are a processor for Customer Content. The organisation whose workspace you belong to is the controller: it decides what equipment and service records are entered, who is invited, and how long they are kept. We process that content on the organisation's instructions in order to run the service. If you are a member of someone else's workspace and want content corrected or removed, contact that organisation first. Where we cannot act without their instruction, we will forward your request to them.
Business customers who need a Data Processing Agreement, or a current list of our sub-processors, can request one at support@equipmentmaintenancelog.com.
1. Account and sign-in
We do not use passwords. You sign in either with Google or with a one-time link sent to your email address.
2. Organisation and team data
3. Customer Content
4. Billing
5. Collected automatically
6. Support conversations
We process personal data for the purposes below. The legal basis column applies to users covered by the GDPR or UK GDPR.
| Purpose | Examples | Legal Basis |
|---|---|---|
| Service Delivery | Authenticating you; storing and displaying equipment and service records; sending invitations | Contract |
| Transactional Email | Sign-in links, invitations, account deletion confirmations | Contract |
| Customer Support | Answering live chat and email enquiries | Contract / Legitimate Interests |
| Billing | Subscriptions, seat counts, renewals, refunds | Contract |
| Analytics & Improvement | Understanding usage patterns; prioritising features | Consent |
| Error Diagnostics & Session Replay | Diagnosing crashes and reproducing faults | Consent |
| Security & Abuse Prevention | Rate limiting, detecting suspicious sign-ins, server logs | Legitimate Interests |
| Legal Compliance | Tax records, regulatory and court-ordered obligations | Legal Obligation |
We do not send marketing or newsletter emails, and we do not run a mailing list. Every email we send is transactional, triggered by you or by someone in your organisation.
We use the providers below. They may access personal data only as needed to perform their service for us, under contract. We do not sell personal information to anyone.
| Provider | Purpose | Data involved |
|---|---|---|
| Vercel | Application hosting and content delivery | All request traffic, IP addresses, server logs |
| Managed PostgreSQL hosting | Primary database | Account data, organisation data, Customer Content, billing references |
| Sign-in (OAuth) | Name, email address, profile picture, account identifier | |
| Stripe | Payments and subscription billing | Billing contact, payment method, transaction records |
| Resend | Transactional email delivery | Recipient email address, message content |
| PostHog | Product analytics (only after you accept cookies) | Usage events, user ID, email, name, organisation |
| Sentry | Error monitoring; session replay only after you accept cookies | Error reports, request context, replayed page content |
| Axiom | Server log storage | Application and request logs |
| Tawk.to | Live chat support | Chat messages; name and email when signed in |
Analytics requests are routed through our own domain (equipmentmaintenancelog.com/ingest) before reaching PostHog. This is a technical proxy. PostHog still receives the data.
We use cookies and browser storage (localStorage and sessionStorage). On your first visit you are shown a banner with Accept and Decline. Your choice is stored in your browser and applied on later visits.
| Category | Set by | Purpose | Duration |
|---|---|---|---|
| Strictly necessary | Us | Session and CSRF cookies that keep you signed in. Cannot be disabled. | Session, up to 30 days |
| Preferences | Us | Light/dark theme and your cookie choice, held in localStorage rather than cookies. | Until you clear browser storage |
| Analytics | PostHog | Usage measurement. Set only after you accept. | Up to 1 year |
| Diagnostics | Sentry | Session replay identifiers in browser storage. Active only after you accept. | Session |
| Live chat | Tawk.to | Chat widget identifiers. Loaded after you accept, or when you open the chat yourself. | Up to 6 months |
What Decline does: no analytics events are collected, no session replay is recorded, and the live chat widget is not loaded. Only the strictly necessary and preference items above remain. Nothing in the analytics, diagnostics, or live chat rows loads before you choose.
Changing your mind: clear your browser storage for this site to be shown the banner again, or email us and we will action it. You can also block or delete cookies in your browser settings; disabling strictly necessary cookies will stop you from signing in.
Opening the chat: if you declined cookies but then click a “chat with us” button, the chat widget loads at that point because you asked for it, and it sets its own cookies.
Payments are processed by Stripe, a PCI-DSS Level 1 certified provider. Card details are collected in Stripe's own payment interface and are never transmitted to, stored on, or accessible from our servers. We store only a Stripe customer identifier, your subscription status, and seat count.
Because card data never reaches our systems, our own PCI obligations are limited to the lowest tier (SAQ A). We do not operate a cardholder data environment and do not claim to.
Transaction records that exclude card numbers are retained for up to 7 years for accounting and tax purposes.
We do not sell or share personal information for cross-context behavioural advertising, and we run no advertising on the service. Data is disclosed only in these circumstances:
We operate from Australia, and the providers listed above process data in the United States and other countries where they operate. Using the service therefore involves a cross-border disclosure of your personal information.
For transfers out of the EEA or the UK, we rely on the European Commission's Standard Contractual Clauses (Decision 2021/914) and the UK International Data Transfer Addendum, or on an adequacy decision where one applies.
For Australian Privacy Principle 8, we take reasonable steps to ensure overseas recipients handle your information consistently with the APPs, principally through our contracts with them.
We take the following measures. We describe them plainly rather than claiming certifications we do not hold:
We do not currently commission third-party penetration tests. If that changes, we will update this section.
No system is perfectly secure. If a data breach occurs that is likely to result in serious harm or risk to your rights, we will notify the relevant regulator, within 72 hours under the GDPR and UK GDPR, and as required by the Australian Notifiable Data Breaches scheme, and notify affected individuals without undue delay.
When you delete your account, or an organisation is closed, we mark the records as deleted so they are no longer accessible in the application, then remove them on the schedule below.
| Data Type | Retention Period | Reason |
|---|---|---|
| Account and organisation data | Life of the account, then deleted within 12 months | Recovery of accidental deletions and dispute resolution |
| Customer Content | Kept until the organisation deletes it; then deleted within 12 months of workspace closure | Controlled by the customer organisation |
| Sign-in sessions | Deleted immediately on account deletion; otherwise on expiry | Security |
| Pending invitations | Until accepted or expired, then up to 12 months | Audit of who was invited |
| Server and application logs | 90 days | Security monitoring and debugging |
| Analytics data | Up to 14 months | Trend analysis; expires at the analytics provider |
| Error reports and session replays | 90 days | Fault diagnosis; expires at the diagnostics provider |
| Support chat and email correspondence | 3 years | Records of what we told you and dispute resolution |
| Transaction and billing records | 7 years | Tax and accounting obligations |
Encrypted backups may retain deleted records for a short period after removal, until the backup rotates out.
Wherever you live, you can ask us to access, correct, or delete your personal information, and we will not charge you for it or treat you differently for asking.
We are an Australian entity and handle personal information in line with the Australian Privacy Principles under the Privacy Act 1988 (Cth). This document is our APP 1 privacy policy.
You may request access to the personal information we hold about you (APP 12) and ask us to correct it (APP 13) by emailing support@equipmentmaintenancelog.com. We will respond within 30 days. You may deal with us anonymously or by pseudonym for general enquiries, though not for an account, since an account requires a verified email address.
We do not collect sensitive information as defined in the Privacy Act, we do not use government-related identifiers, and we do not use your information for direct marketing.
If you are unhappy with our response, you can complain to the Office of the Australian Information Commissioner: oaic.gov.au.
If you are in the EU or EEA, the General Data Protection Regulation (EU) 2016/679 grants you these rights:
We will respond within 30 days, extendable by two months for complex requests. You may also lodge a complaint with the supervisory authority in your EU Member State.
Article 27 representative: we have not appointed an EU representative. Our processing of EU residents' data is occasional, limited to the account and usage data described above, does not include special category data, and is unlikely to result in risk to your rights, which are the conditions of the Art. 27(2)(a) exemption. If that changes we will appoint a representative and name them here. In the meantime, EU users can reach us directly at support@equipmentmaintenancelog.com.
If you are in the UK, your rights under the UK GDPR and Data Protection Act 2018 mirror those under the EU GDPR listed above. The Information Commissioner's Office (ICO) is the UK supervisory authority: ico.org.uk.
The categories of personal information we have collected in the preceding 12 months, using the statutory categories in Civil Code § 1798.140(v):
| Category | Collected | Source | Disclosed to |
|---|---|---|---|
| Identifiers (name, email, IP, account ID) | Yes | You; Google sign-in; your colleagues who invite you | Hosting, database, email, analytics, chat providers |
| Customer records (billing contact) | Yes | You; Stripe | Payment processor |
| Commercial information (subscription, plan) | Yes | You; Stripe | Payment processor |
| Internet activity (pages viewed, feature usage) | Yes, after consent | Automatically from your browser | Analytics and diagnostics providers |
| Professional information (your role, work performed) | Yes | You; your organisation | Hosting and database providers |
| Geolocation (approximate, from IP) | Yes | Automatically from your browser | Hosting, analytics, diagnostics providers |
| Sensitive personal information | No | — | — |
| Biometric, education, or inference data | No | — | — |
We collect this for the business purposes described in “How We Use Your Information”. We have not sold or shared personal information in the preceding 12 months, and we do not sell or share the personal information of consumers under 16.
Submit requests to support@equipmentmaintenancelog.com. We verify identity by confirming control of the account email address and respond within 45 days, extendable by a further 45 days. An authorised agent may submit a request on your behalf with written permission signed by you, and we may still ask you to verify your own identity directly.
Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other states with comparable privacy laws may exercise equivalent rights, including the right to appeal a refused request, at the same address.
We do not use automated decision-making or profiling that produces legal or similarly significant effects. Equipment is flagged as overdue by a fixed date calculation against the interval you set, which is arithmetic on your own data rather than a decision about a person.
Equipment Maintenance Log is a workplace tool and is not directed to children. We do not knowingly collect personal information from anyone under 16. If we learn we have collected such information, we will delete it. Parents or guardians can contact us at support@equipmentmaintenancelog.com.
We may update this Privacy Policy. When we make material changes, for example adding a new provider that receives your data, we will update the “Last Updated” date above and post a notice on the site. Where the change requires your consent, we will ask for it before it takes effect.
For questions, data requests, or privacy complaints, contact us:
We aim to respond to all enquiries within 5 business days, and within the legal deadline for formal data requests. If we cannot resolve your complaint, you may escalate to the OAIC (Australia), the ICO (UK), or your EU supervisory authority.