This Privacy Policy describes how Conduix (“we”, “us”) handles information in connection with the Conduix platform (the “Service”). The Service is business software operated for our business customers (each a “Customer”); we process most information on the Customer’s behalf to run their deployment.
1. Information we collect
- Account information — name, work email address, phone, job title, and an optional profile photo and email signature, provided when a Customer administrator invites you.
- Business records — the operational data users enter: jobs, quotes, companies, contacts, vendors, shipments, uploaded documents and photos. This data belongs to the Customer.
- Usage and session data — activity logs, an append-only audit trail of data changes, and session recordings (screen-interaction snapshots) used for support and quality. The sign-in screen discloses recording; recordings auto-purge after a configured retention window.
- Technical data — authentication events and server-side error logs necessary to operate and secure the Service.
2. How we use information
- To provide, support, and secure the Customer’s deployment.
- To send transactional email the Customer’s users initiate or that the Service requires (sign-in links, invitations, quotes, shipment notices).
- To diagnose problems and improve reliability.
We do not sell personal information, use it for advertising, or share it with third parties except the service providers below.
3. Service providers (subprocessors)
- Vercel — application hosting (United States).
- Supabase (on AWS) — database, file storage, and authentication (United States).
- Resend — transactional email delivery.
- Intuit (QuickBooks Online) — only when the Customer connects its own QuickBooks company; the Service exchanges the Customer’s accounting records with the Customer’s own QuickBooks account.
- 17TRACK — carrier tracking status; receives only shipment tracking numbers.
4. Cookies
The Service uses essential cookies only — session cookies that keep you signed in. There are no advertising or cross-site tracking cookies.
5. Security
Data is encrypted in transit (TLS) and at rest. Each Customer runs on a dedicated database with row-level security and role-based access control. Administrative changes are recorded in an append-only audit log. Access to production systems is limited to the operator.
6. Retention
Business records are retained for the life of the Customer’s account and handled per the Customer’s written agreement at termination. Session recordings purge automatically after the configured retention window. Audit log entries are retained as part of the Customer’s controlled records.
7. Your choices
Access requests, corrections, or deletion of personal information in a Customer deployment are handled through that Customer’s administrator, since the Customer controls its business records. You can update your own profile details in Settings at any time.
8. Changes
We may update this policy; the effective date above reflects the current version. Material changes will be communicated to Customer administrators.