Review note
The product owner or counsel should confirm the contact inbox, processor descriptions, retention periods, and any jurisdiction-specific rights before this policy is treated as final.
1. Information collected
We collect information you provide to create an InspectWarden account, operate your workspace, complete inspections, communicate with your team, and support the service. The categories below describe the information that may be present in a workspace.
Account and team information
Names, email addresses, organization details, roles, login and account settings, invitations, and other details that administrators or team members provide.
Sites and property contacts
Site names, addresses, building details, and property-contact names, phone numbers, email addresses, and related notes entered for an inspection customer.
Inspection records, checklists, and notes
Asset identifiers, inspection dates and due dates, checklist selections, readings, pass or fail results, deficiencies, corrective-work notes, assignments, activity history, and report content.
Photos, documents, and reports
Photos of equipment or conditions, uploaded documents, generated PDFs, report identifiers, verification details, and the metadata needed to keep those files attached to the right record.
Portal links
The portal and report links your team creates to share selected records, including access tokens, expiration or revocation settings, and basic link access events. Anyone who receives a deliberately shared public link may be able to view the information that link exposes.
Billing information
We may receive plan, subscription, transaction, invoice, and payment-status details when billing is used. Payment-card details are handled by the configured payment processor rather than stored as full card numbers in InspectWarden.
Technical, usage, and visitor-beacon data
We may collect IP address, browser and device characteristics, timestamps, authentication and error logs, pages or features used, and similar diagnostics. The public website may also use a Polsia visitor beacon that reports basic visit and usage signals; its final configuration should be confirmed before launch.
2. Use of information
We use information to:
- provide, maintain, and secure InspectWarden, including inspections, checklists, reports, verification pages, portals, and account access;
- keep records connected to the right organization, site, asset, crew member, and customer contact;
- send transactional messages such as invitations, account notices, report sharing notices, and service or security updates;
- process billing, answer support requests, investigate abuse or failures, and improve product reliability; and
- meet legal obligations, enforce our agreements, and protect InspectWarden, our customers, and other people from harm.
We do not sell customer inspection records or use them for advertising. If we use aggregated or de-identified information to understand service performance, we take reasonable steps to keep it from identifying a customer or individual.
3. Tenant isolation and authorized sharing
InspectWarden is organized around customer workspaces. A workspace is intended to keep its sites, contacts, inspection records, files, and billing context separate from other customer workspaces. We use account identity, workspace membership, permissions, and server-side checks to limit access to the workspace a person is authorized to use.
Your organization controls who it invites and what it shares. Team members may access records based on their workspace permissions. An administrator may share a portal or report link with a property owner, customer, or other recipient; that recipient can see the information included in the shared surface. We may disclose information to service providers working on our instructions, when you direct us to share it, or when disclosure is required by law or necessary to protect rights and safety.
Please avoid entering information that your organization is not authorized to collect or share, and use portal-link controls carefully because possession of a link may provide access to its intended report or record.
4. Retention and deletion
We retain account, workspace, and inspection information for as long as needed to provide the service, follow your organization's instructions, maintain auditability, resolve disputes, meet legal or contractual requirements, and enforce our agreements. Your organization is responsible for choosing how long it needs to keep inspection records for its customers and regulatory work.
An organization administrator can request account or workspace deletion, and an individual can ask about access, correction, or deletion of information associated with them. We will review the request, verify authority where appropriate, and explain any information that must remain for legal, security, fraud-prevention, or accounting reasons. Deleted information may remain in limited, protected backups until those backups are rotated out.
Specific retention windows, deletion workflows, and any customer contractual commitments must be confirmed by the owner or counsel before this draft is finalized.
5. Service providers and processors
We use a limited set of infrastructure and service providers to run InspectWarden. They process information only as needed to provide their services, under their applicable terms and our instructions.
Polsia hosting, proxies, and visitor beacon
Polsia-provided hosting and proxy services support the application, email or other platform requests, and operational telemetry. A Polsia visitor beacon may support basic website analytics and should be confirmed in the final launch configuration.
Configured R2/S3-compatible photo store
Photos and related file objects may be stored in the R2/S3-compatible object storage configured for the application. The exact provider, region, and retention settings should be documented and confirmed before launch.
Stripe when billing is used
When a customer uses paid plans or other billing features, Stripe processes payment details and returns billing or payment-status information needed by InspectWarden. Stripe's own privacy terms also apply to its processing.
We may add or change processors as the service evolves. The final policy should include any required processor list, transfer disclosures, and customer notice or objection process.
6. Security
We use reasonable administrative, technical, and organizational safeguards to protect information, including access controls, authenticated workspace checks, secure application connections, logging, and operational monitoring. We design the product so that inspection history and workspace boundaries are treated as important records.
No internet service can promise absolute security. Keep account credentials private, invite only people who need access, review shared portal links, and notify us promptly if you believe an account or link has been compromised.
7. Changes and choices
Workspace administrators can manage team access, revoke or update shared links where the product supports it, and request changes to workspace information. Individuals may contact us about information associated with them. You can opt out of non-essential marketing messages when offered; transactional, security, and account messages may still be sent.
We may update this policy when the service, processors, or legal requirements change. We will post the current version at this URL, update the date above, and provide additional notice when required. The owner or counsel should confirm the final rights, notice, and jurisdiction language before publication.
8. Contact
For privacy questions, access or deletion requests, security concerns, or processor inquiries, contact InspectWarden at the address below. This contact inbox is proposed for this draft and must be confirmed by the owner or legal counsel before launch.
inspectwarden@polsia.app