Privacy Policy
Last updated 17 August 2026
ROW QC provides daily field reporting software for pipeline construction at rowqc.com. This policy explains what we collect, why, and who else touches it.
The short version
- Your project records belong to you. We access them to run the service, support you, and keep them secure — not for anything else.
- We do not sell your personal information, and we never have.
- We do not use your records to train AI models. No part of this application sends anything to an AI provider.
- There is no analytics or advertising of any kind here. No tracking cookies, no advertising pixels, no analytics provider, and no third-party trackers — which is why this site has no cookie banner.
- The application never asks your device for its location.
What we collect
Information you give us
- Account details — your name, email address, and password. Passwords are handled by our authentication provider and are never visible to us.
- Company profile — company name, address, phone number and logo, if you add them. These print on your documents.
- Project records — everything you enter: daily inspection reports, controlled forms, quantities and progress, punch items and non-conformances, plus any files you upload such as photographs and drawings.
- Signatures — where a form is signed in the application, we store the drawn signature image as part of that record. It is personal data about the person who signed and is kept with the report it belongs to.
- Workforce records — inspector and crew names, employee numbers, qualifications and hours where you use those features. This is information about your people rather than about you, and you are responsible for it.
- Project locations — the coordinates you set for a project or a report.
- Team information — the email addresses you use to invite colleagues, clients or inspectors.
- Contact details — if you write to us for support.
Information collected automatically
- Technical data — IP address and browser type, as any web service receives, used for security and diagnostics.
What we do not collect
- Card details. Payment pages are hosted by Stripe. Card numbers never reach our servers.
- Your device location. The application never asks your browser or your device where you are. It does read the location your camera already wrote into a photograph you choose to upload — see Photographs.
- Anything from third-party trackers. There are no advertising pixels, no social media trackers, no analytics provider and no data brokers involved.
Why we use it
To operate your account and store your records; to provide support when you ask for it; to process payments; to send service messages such as invitations and notifications; and to keep the service secure and diagnose faults.
We do not use your project records for marketing, and we do not build advertising profiles.
Photographs
Photographs you upload are stored with the report they belong to. We read part of the EXIF metadata inside them, in your browser, before the file is uploaded — when the photograph was taken, and the latitude and longitude if the camera recorded them. Those three values are stored alongside the file, so a photograph of a defect is evidence about a place rather than a loose image.
Many photographs carry no location at all. iOS omits it unless the camera has been given permission, and messaging apps strip EXIF when a photo is sent, so one that arrived by text has none. Where there is nothing to read, nothing is stored and the upload carries on.
The rest of the metadata is neither read nor removed. It travels inside the file, so it is included when you export a project or hand a turnover book to your client.
Who else processes your data
We use the following providers. Each is bound to process data only on our instructions.
| Provider | What it does | What it sees |
|---|---|---|
| Supabase | Database, authentication, file storage | Account details and all project records and files |
| Netlify | Website and application hosting | IP address and request data |
| Stripe | Payment processing | Name, email, billing and card details |
| Resend | Transactional email — invitations, notifications and password resets | Recipient name and email address |
| OpenStreetMap | Map tiles behind the project map | IP address, and which map area you are looking at |
| National Weather Service (weather.gov) | Site weather conditions on a report | The project coordinates you set, and nothing else |
| Google Fonts | Typefaces on our web pages | IP address when a page loads |
| jsDelivr and Cloudflare (cdnjs) | JavaScript libraries the application loads | IP address when a page loads |
Providers are located in the United States. If you are outside the United States, using ROW QC means your data is transferred there.
How long we keep it
- While your account is active — for as long as you have one.
- After you close it — your records may be permanently deleted. Export anything you need to keep first; every table exports and the application will not stop you taking a copy.
- Contact addresses — until you ask us to remove them.
- We may retain limited billing records for longer where tax or accounting law requires it.
Your rights
You can, at any time and without asking us, export your records, correct them in the application, and delete them.
Write to support@rowqc.com to request a copy of your personal data, correction, deletion of your account, or to object to how we use it. We aim to respond within 3 business days.
To delete your account, see Delete your account — it explains what is removed, what stays with your team, and how to ask.
Depending on where you live you may have additional rights — for example under the CCPA in California, or the GDPR in the UK and EU. We do not sell personal information as those laws define it, and we do not share it for cross-context behavioural advertising.
Cookies
We use no advertising or tracking cookies, and there is no analytics provider on this site.
We store a session token in your browser so you stay signed in. That is strictly necessary to operate the service — without it you would be logged out on every page.
Security
Access to your records is enforced by the database itself through row-level security, not merely hidden in the interface. A user with no relationship to a project cannot read or write to it even through the API. Data is encrypted in transit and at rest by our infrastructure providers.
No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you promptly and tell you what happened.
Children
ROW QC is a business tool and is not directed at anyone under 18. We do not knowingly collect data from children.
Changes
If we change this policy materially, we will email account holders and update the date at the top. Continuing to use ROW QC after a change means the updated policy applies.
Contact
support@rowqc.com — we aim to respond within 3 business days.
ROW QC — Texas, USA.