Privacy Policy

Last updated April 28, 2026 · Effective April 22, 2026

This Privacy Policy describes how DigiDocs Technologies LLC, doing business as “DigiDocs” (“we”, “us”, “our”), collects, uses, and shares information when you use our services at digidocs.app (the “Service”). By using the Service, you agree to the collection and use of information as described in this policy.

1. Who We Are

DigiDocs Technologies LLC provides a software-as-a-service platform for digital equipment inspections, lift planning, bills of lading, job safety analyses, deficiency tracking, and compliance reporting for construction, trucking, and heavy-equipment businesses. The Service is operated from Texas, United States.

For privacy-related questions or to exercise any of the rights described below, contact us at support@digidocs.app.

2. Information We Collect

2.1 Information You Provide Directly

  • Account information: your name, email address, password (stored hashed, never in plain text), company name, role within your company, and optional phone number.
  • Billing information: payment card details are collected and stored by Stripe, Inc. We do not see or store full card numbers. From Stripe we receive: billing address, last four digits of card, card brand, expiration, and transaction history.
  • Equipment and inspection data: equipment records, inspection templates, inspection responses, deficiency records, repair notes, digital signatures, meter readings, and any other content you add to the Service.
  • Photos and signatures: photos uploaded during inspections or deficiency reports, and digital signatures captured within the Service.
  • Communications: messages you send us via email, support form, or any other channel, and our responses to them.

2.2 Information Collected Automatically

  • Usage data: pages viewed, features used, action timestamps, and system-level activity (for audit-log purposes).
  • Device and connection data: browser type and version, operating system, device type, screen size, IP address, approximate location derived from IP address, referring site.
  • Cookies and local storage: see Section 8.

2.3 Information from Third Parties

  • Google Sign-In (OAuth): if you choose to sign in with Google, we receive your email and name from Google.
  • Refgrow (affiliate tracking): if you arrived via a partner referral link, we receive attribution data from Refgrow indicating which partner referred you.
  • Google reCAPTCHA: a risk assessment score is provided to us by Google to help prevent automated abuse.
  • Stripe: subscription lifecycle events (payments, failed charges, cancellations).

3. How We Use Your Information

We use your information to:

  • Provide, operate, and maintain the Service.
  • Process subscription payments through Stripe.
  • Send transactional emails (account welcome, invitations to your teammates, password resets, monthly compliance reports, billing notifications).
  • Respond to your support requests.
  • Enforce our Terms of Service and detect, prevent, and address fraud, abuse, or security issues.
  • Comply with legal obligations, including tax, accounting, and audit requirements.
  • Improve the Service and develop new features based on aggregated and anonymized usage patterns.

We do not sell your personal information to third parties. We do not use your Customer Content to train artificial-intelligence models, our own or any third party's.

4. How We Share Your Information

4.1 Service Providers

We share information with trusted third-party service providers who help us operate the Service. Each is contractually obligated to protect your information and to use it only for the purposes for which we disclose it.

  • Stripe, Inc. — payment processing. Stripe Privacy Policy.
  • Refgrow— affiliate and referral tracking for the partner program. Refgrow Privacy Policy.
  • Google LLC— reCAPTCHA (bot protection) and Google Sign-In (optional OAuth login). Google Privacy Policy.
  • Email delivery providers— transactional email sending (welcome, invitations, password resets, compliance reports).
  • Hosting and infrastructure providers— servers, database hosting, backups, content delivery.

4.2 Within Your Organization

When your company uses the Service, Customer Content you or your teammates create is visible to other users in your company according to the role permissions configured by your Company Admin (Operator, Mechanic, Supervisor, Admin, Company Admin). Review our role hierarchy and permissions in the Help Center or with your Company Admin before uploading sensitive information.

4.3 Legal and Safety

We may disclose information if required by law, subpoena, court order, or valid governmental request. We may also share information to: enforce our agreements; investigate or respond to suspected fraud, security incidents, or violations of our Terms of Service; or protect the rights, property, or safety of DigiDocs Technologies LLC, our users, or the public.

4.4 Business Transfers

If DigiDocs Technologies LLC is involved in a merger, acquisition, financing, reorganization, bankruptcy, receivership, sale of assets, or transition of service to another provider, your information may be transferred as part of that transaction. We will notify you via email or a prominent notice on the Service before your information becomes subject to a different privacy policy.

4.5 With Your Consent

We may share information with other parties when you give us specific consent to do so.

5. Data Retention

  • Active accounts: we retain your data for as long as your account is active.
  • After account closure: we delete personal data within 30 days, except where we are required or permitted by law to retain it longer (e.g., tax records, accounting records, audit logs, pending legal matters).
  • Inspection records: given the compliance purpose of the Service, aggregated and anonymized inspection data may be retained indefinitely for analytics and service improvement.
  • Backups: data may persist in automated backup systems for up to 90 days after deletion from the active database.
  • Audit logs: we retain audit logs (who changed what, when) for at least seven years or longer where required for compliance evidence.

6. Your Rights and Choices

Depending on your state of residence or applicable law, you may have the following rights regarding your personal information:

  • Access: most of your data is accessible directly in the Service. For anything not exposed in the UI, contact us.
  • Correction: you can update profile, equipment, and inspection data directly. For other records, contact us.
  • Deletion: Company Admins can close the company account through Settings. Individual users should contact their Company Admin, or contact us if no Company Admin is reachable.
  • Data portability / export: you can export inspection data as CSV and PDF through the Admin dashboard. On request we will provide a broader export of your account data within a reasonable time.
  • Opt-out of marketing: we do not currently send marketing emails. If we introduce them, you will be able to opt out via an unsubscribe link in the email and in your account settings.
  • California residents (CCPA / CPRA):you have the right to know what personal information we collect and how we use it; the right to request deletion; the right to correct inaccurate information; and the right to opt out of the “sale” or “sharing” of personal information. We do not sell or share personal information as those terms are defined by the CCPA.
  • EU, UK, and other GDPR-equivalent residents: to the extent GDPR or similar legislation applies, you have the rights of access, rectification, erasure, restriction, portability, objection, and the right to lodge a complaint with your local supervisory authority. You can exercise these rights by contacting us.
  • Automated decision-making: we do not make decisions about your account that have legal or similarly significant effects based solely on automated processing.

To exercise any of the above, email us at support@digidocs.app and include enough information for us to verify your identity.

7. Security

We implement commercially reasonable administrative, technical, and physical safeguards designed to protect your information, including:

  • HTTPS / TLS encryption for all data in transit.
  • Password hashing with bcrypt (we never store passwords in plain text).
  • Role-based access controls within the application.
  • Encryption at rest for sensitive datastores where supported.
  • Regular automated backups.
  • Third-party processing of payment data by Stripe (we never see full card numbers).

No system is 100% secure. You are responsible for protecting your own account credentials and for notifying us at support@digidocs.app if you believe your account has been compromised.

8. Cookies and Similar Technologies

We use cookies and local browser storage for the following purposes:

  • Essential cookies: session authentication, CSRF protection, preference storage. These cannot be disabled without breaking core functionality.
  • Functional cookies: Refgrow referral attribution, if you arrived via a partner link; user-interface preferences you set.
  • Security cookies: Google reCAPTCHA cookies to prevent bot abuse.
  • Analytics: we do not currently run third-party analytics products. If we add them in the future, we will update this policy.

You can control cookies through your browser settings. Blocking essential cookies will prevent you from signing in to or using the Service.

9. Children's Privacy

The Service is intended for business use by adults, and is not directed to children under 16. We do not knowingly collect personal information from children under 16. If we become aware that we have collected personal information from a child under 16 without appropriate consent, we will delete it. Contact us at support@digidocs.app with any concerns.

10. International Transfers

The Service is hosted in the United States. If you access the Service from outside the United States, your information will be transferred to, stored, and processed in the United States, which may have data protection laws different from those of your jurisdiction. By using the Service you consent to this transfer.

11. Third-Party Links

The Service may contain links to third-party websites, services, or integrations (e.g., Stripe, Refgrow, Google). We are not responsible for the privacy practices of those third parties. We encourage you to read their privacy policies before providing any information.

12. Do Not Track

Some browsers transmit “Do Not Track” signals. Because there is no industry-standard interpretation of DNT signals, we do not respond to them. We describe all of our tracking practices in this Policy and provide the opt-out mechanisms described in Sections 6 and 8.

13. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the “Last updated” date at the top of the page. For material changes that reduce your rights, we will provide prominent notice — typically via email to your account email address and a banner in the Service — at least 30 days before the changes take effect. Your continued use of the Service after the effective date constitutes acceptance of the updated policy.

14. Contact Us

For questions, requests, or concerns about this Privacy Policy or your personal information: