GearDomain Privacy Policy
Effective date: <effective date>
Who we are
GearDomain, at <address>, operates GearDomain for film crews, including the iOS and Android apps and the web app at app.geardomain.app. Contact support@geardomain.app about this policy or your information. Our home jurisdiction is <jurisdiction>.
Organizations decide what inventory and crew information they enter and who may access it. If an organization entered your information, you may contact it or ask us for help.
Account and inventory information
We store your email, display name, account credentials, organization and membership role. We store the inventory information your organization enters, including equipment names, models, serial numbers, purchase details, notes, photos, kits and label identifiers. Checkout records can include borrower names, projects, dates, returns and condition notes, as well as signatures and condition photos taken at check-out and check-in. Signatures and condition photos are visible to members of the organization and can be redacted on request.
We use these records to run accounts, share inventory within an organization, track checkouts, associate labels with equipment and generate label sheets and inventory reports. Borrowers named in these records may not have GearDomain accounts. Enter only information you have authority to use.
GearDomain's operator can see account and usage information for every organization: the organization's name, its members' names, email addresses and roles, sign-up dates, the date of the organization's latest activity, and counts of its members, items and photos. We use this to run and support the service. The administrative page we use for this does not display the inventory an organization enters, its photos, its checkout records or its signatures.
The apps also keep local information needed for sign-in, preferences and offline inventory work. Changes made offline reach the server when synchronization succeeds.
Finders without accounts
You do not need an account to submit a report through an enabled found-item page. The current form requires a phone number or email address. Your name, message and typed location are optional. We save the submitted details with the item, organization, label code, submission identifier and time so the organization can handle the report. Contact details are unverified and are not displayed on the public page.
For abuse prevention and rate limiting, we derive a salted hash from your IP address using the server's FINDER_IP_HASH_SALT. Finder reports store that hash rather than the raw IP address. A hash is still an identifier; it is not a promise of anonymity. Hosting services receive network information when handling a request. The form does not request GPS location.
Submitting a report does not change an item's checkout or confirm that the organization has read or answered it.
Requesters without accounts
When you submit through a request link, we collect your name and phone number or email, the project name and note you choose to provide, selected gear, requested dates and submission information. Salted IP hashes help limit abuse.
Phone numbers and email addresses are kept separately in request_contacts. Only the organization's owners and admins can read that contact field through the staff service; it is not included in ordinary sync data or request events. Other authorized members can see request information such as your name, project, dates and gear to arrange handover. Your name and project may become part of the checkout record.
The request status link lets its holder view request progress and, when permitted, cancel the request. Keep it private. GearDomain does not process rental payments through request links.
Intake text and image processing
Talk to Inventory is a text box. You can type into it or use your phone keyboard's own dictation. The GearDomain app does not record audio and does not request microphone access. Keyboard dictation is a feature of the keyboard provider, not of GearDomain; it follows the device provider's settings and processing practices and does not necessarily keep all processing on the device.
The text you submit is read by GearDomain's own server with rule-based parsing and a match against your organization's own gear catalog, to suggest equipment details for your review. We do not send this text, audio or inventory information to any AI text provider. Items you import become inventory records. This feature is optional.
Public pages and private downloads
For a recognized, available label, the found page shows the organization name even when public contact is disabled. When contact is enabled, it also shows the item name, category and, if applicable, that it is on a job. The current page uses a placeholder instead of an item photo. It does not publish serial numbers, prices, borrower details, project names or finder submissions.
Request links expose the gear selected for sharing and the availability information the organization enables. A shared link is intended to be accessible to anyone who has it.
Photos, label PDFs and generated reports use private storage and temporary signed download URLs. Anyone who obtains a valid signed URL may be able to download its file until the URL expires. Treat these URLs and downloaded reports as private; expiry does not remove copies already downloaded or printed.
Providers and data location
The deployment runbook specifies the following hosting arrangement. It is a deployment plan, not evidence that production has been provisioned:
| Provider | Role and information handled |
|---|---|
| Supabase | Postgres account, organization, inventory, checkout, signature, finder and request records; private storage for equipment and condition photos, label PDFs and generated reports |
| Render | The application server, which processes authenticated operations, public forms, reports and intake text parsing |
| Vercel | Web app delivery and forwarding of API and public-page requests to Render |
| Apple and Google | App distribution and device/platform services, under their own applicable privacy terms |
The runbook selects US West for the primary Supabase database and storage, preferably Oregon, and Oregon for Render. It does not establish that all processing, delivery networks, backups or other providers remain in US West. Apple and Google are platform providers and are not necessarily our sub-processors for all their activities.
Cookies and browser storage
The reviewed application code does not set advertising, tracking or session cookies. It does use browser storage: the web app keeps its sign-in token in localStorage, which can survive closing the browser, and removes it on sign-out. The found page uses sessionStorage for a submission-receipt timestamp, not the submitted form contents. Unsent finder form contents stay in page memory.
This is therefore not a session-storage-only web app. Browser storage is distinct from cookies. The request-link design proposes remembering requester details, but the reviewed request-page implementation does not implement that behavior.
Retention
Inventory records, checkout history, labels and photos remain while retained by the account or organization. Signatures and condition photos are retained with the checkout record and can be redacted on request. Deleting an item can mark records as deleted for synchronization rather than immediately erase every database row. Photos marked deleted are scheduled for permanent cleanup after 30 days; abandoned photo uploads after 24 hours.
Generated label PDFs and inventory reports are scheduled for deletion after 24 hours by the hourly cleanup process. Their download URLs also expire. Actual removal occurs on a successful cleanup run. This rule covers generated report files, not finder reports or the underlying inventory records.
Requester phone or email records are purged after 90 days from request closure. If a request never closes, cleanup uses 90 days after its requested end time. This deletes the separate contact record, not the requester name, project, note, IP hash, request history or resulting checkout records. Those require separate retention and deletion handling.
Finder-report IP hashes are scheduled for erasure 24 hours after submission. [pending: cleanup rule not yet deployed] Complete finder reports, including contact details, messages, typed locations and record metadata, are scheduled for deletion 90 days after submission. [pending: cleanup rule not yet deployed] Hourly cleanup normally completes each action within one further hour; failures or backlog can delay completion. [pending: cleanup rule not yet deployed] A specific legal preservation requirement may delay deletion of the affected data. [pending: cleanup rule not yet deployed] Request earlier deletion at support@geardomain.app. [pending: cleanup rule not yet deployed] The same review is needed for remaining request records, operational logs and support correspondence; no fixed deletion deadline for them is represented here. Deleted photos normally disappear from our backups within nine days, although a failed cleanup can delay their removal. [pending: backup job not yet deployed]
Access, export, correction and deletion
an account can be deleted in the app under Profile > Delete account; organizations the user alone owned are deleted with their gear, photos and records; organizations shared with others keep their custody records, signatures, checkout names and maintenance history as the organization's business records, with the user's reservation requester name replaced by Former member; the user's email and login are removed at once.
Authorized organization members can export inventory through the inventory/insurance report in PDF or CSV. It contains the report's equipment fields; it is not an export of every account, finder, request or checkout record. Contact support@geardomain.app for access to other personal information, corrections or deletion, including if you are a finder, requester or borrower without an account.
We may need to verify your identity and coordinate with the organization responsible for a shared record. Removing a member or uninstalling the app does not by itself erase the organization's inventory. Applicable privacy rights and lawful exceptions still apply. Ask us about any information that cannot be deleted and why.
Children
GearDomain is intended for people aged 13 and over, including people submitting finder reports or gear requests without an account. In countries where the digital consent age is higher than 13, a person under that age needs a parent's or guardian's permission to use GearDomain. If you believe someone under 13 has provided personal information, contact support@geardomain.app so we can investigate and arrange deletion where appropriate.
Changes and contact
We will update the effective date when this policy changes and provide notice of material changes before they take effect. Privacy questions and requests go to support@geardomain.app, or GearDomain, <address>.