Legal

Privacy Policy

Effective date: September 17, 2026

This Privacy Policy explains what information IncidentLog ("we", "us") collects, how we use it, and the choices you have.

1. Information we collect

  • Account information: your name, work email, hashed password, and organization name.
  • Incident report content: descriptions, dates, locations, GPS coordinates, category/severity, names and contact details of people involved or witnesses, photos, and electronic signatures that you or your team submit.
  • Usage data: basic technical logs (e.g. request metadata) needed to operate and secure the Service.
  • Billing information: handled directly by our payment processor; we do not store your full card number.

2. How we use it

  • To provide the Service: create, store, and let you export incident reports.
  • To send transactional email (e.g. a copy of a submitted report) via our email provider.
  • To secure accounts and prevent abuse.
  • To improve the Service based on aggregate, non-identifying usage patterns.

We do not sell your personal information or Customer Content to third parties.

3. Where your data is stored

Report data is stored in a PostgreSQL database (hosted via Supabase) and the application runs on Vercel's infrastructure. Transactional emails are sent via Resend. These providers process data on our behalf under their own security and data-processing terms.

4. Photos and signatures

Photos and electronic signatures you capture in the app are stored securely and associated with the relevant incident report. They are retained according to your plan's archive policy and are only accessible to members of your organization.

5. Data retention

We retain incident report data for as long as your account is active, and, on paid plans, per the advertised legal-archive period. You can request deletion of your organization's data via our contact page, subject to any legal retention obligations that may apply to your industry.

6. Children's data submitted by customers

Some customers (e.g. daycare or school operators) may submit incident reports that include information about minors. We process this data only as instructed by that customer, who is responsible for having a lawful basis to collect and submit it. We do not knowingly collect personal information directly from children as end users of the Service.

7. Cookies and sessions

We use a session cookie to keep you signed in. We do not use third-party advertising trackers.

8. Your choices

You can update your account and organization details from your settings page, and request export or deletion of your data via our contact page.

9. Changes to this policy

We may update this Privacy Policy from time to time. We will post the updated version here with a new effective date.

10. Contact

Questions about this policy? Reach us through our contact page.