Privacy Policy
Last updated: March 18, 2026
Introduction
Sandcreek AI ("we," "our," or "us") operates the Shopfloor mobile application (the "App"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our App.
By using Shopfloor, you agree to the collection and use of information in accordance with this policy. If you do not agree with the terms of this policy, please do not use the App.
Information We Collect
We collect the following types of information:
- Account Information: When you create an account, we collect your email address and password. Passwords are securely hashed and never stored in plain text.
- Profile Information: Your name and company affiliation as provided during account setup.
- Equipment Data: Information about tools and equipment you add to the App, including names, descriptions, serial numbers, asset tags, categories, and photographs.
- Location Data: Names and addresses of job sites, warehouses, and other locations you create within the App. We may also collect device GPS coordinates when you use location-based features, with your permission.
- Camera & Photos: When you use the AI scanning feature, images captured by your device camera are sent to a third-party AI service for equipment identification. These images are processed in real time and are not permanently stored by us after processing.
- Usage Data: Activity logs such as equipment check-ins, check-outs, transfers between locations, and other interactions within the App.
- Payment Information: If you subscribe to a paid plan, payment processing is handled by Stripe. We do not store your credit card number or banking details. Stripe's privacy policy governs how your payment information is handled.
How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain the App
- Enable equipment tracking, inventory management, and team collaboration features
- Process AI-powered equipment scans and image recognition
- Manage your account and subscription
- Communicate with you about your account, updates, or support requests
- Enforce our terms of service and protect against misuse
- Comply with legal obligations
How We Share Your Information
We do not sell your personal information. We may share your data in the following circumstances:
- Within Your Company: Equipment data, locations, and activity logs are shared with other members of your company within the App, based on their assigned roles.
- Service Providers: We use third-party services including Supabase (database and authentication), OpenAI (AI image analysis), and Stripe (payment processing). These providers only access data necessary to perform their services.
- Legal Requirements: We may disclose your information if required by law, court order, or government regulation.
Data Storage and Security
Your data is stored on secure servers provided by Supabase, which uses PostgreSQL databases with row-level security to ensure your company's data is isolated from other users. All data is transmitted over encrypted HTTPS connections.
Authentication tokens are stored securely on your device using encrypted storage (Keychain on iOS, encrypted SharedPreferences on Android).
While we take reasonable measures to protect your information, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.
Your Rights and Choices
You have the right to:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate personal data.
- Deletion: Request deletion of your account and associated data.
- Camera Permission: You can revoke camera access at any time through your device settings. The AI scanning feature will be unavailable without camera permission.
- Location Permission: You can revoke location access at any time through your device settings. Some location-based features may be limited.
To exercise these rights, contact us at the email address listed below.
Data Retention
We retain your personal data for as long as your account is active or as needed to provide you services. If you delete your account, we will delete or anonymize your personal data within 30 days, except where we are required to retain it for legal or legitimate business purposes.
Children's Privacy
Shopfloor is not intended for use by children under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected personal data from a child under 13, we will take steps to delete that information.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy within the App or on our website. Your continued use of the App after changes are posted constitutes acceptance of the updated policy.
Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us at:
Sandcreek AI
Email: privacy@sandcreekai.com