Privacy policy
Effective date: August 23, 2026
Who we are
GearLedger is operated by Invytx. GearLedger helps authorized organizations manage equipment accountability, personnel assignment, checkout and check-in workflows, signatures, synchronization, audit history, and requested exports.
Information you provide
GearLedger collects and transmits only information deliberately provided by authorized users or administrators and required to operate the service. Account name, email address, user ID, organization membership, role, authentication state, and session state are required for authenticated GearLedger accounts. Organization records, inventory records, personnel or recipient records, equipment identifiers and barcodes, checkout and return history, signature images captured for accountable checkout records, audit events, and export settings or generated documents are required or optional depending on the workflow the organization chooses to use.
Beta inquiry forms may collect contact and organization information submitted by the requester, including name, work email address, organization name and type, estimated users or assets, current accountability process, testing goals, consent status, browser-provided request metadata, and submission timestamps.
Camera and barcode scanning
The Android app requests camera access only when a user starts a barcode-scanning workflow for equipment or personnel identifiers. Inspected app code processes camera frames in memory through the on-device barcode scanner and passes decoded barcode text to the active workflow. GearLedger does not store or transmit camera frames for barcode scanning.
Local storage and synchronization
The Android app stores operational data locally so authorized users can keep working with inventory, personnel, checkout, check-in, signatures, queued changes, and exports. Cloud synchronization transmits signed-in organization data to GearLedger's backend using authenticated HTTPS requests. Authentication/session data is stored separately using Android encrypted preferences where supported.
Automatically generated metadata
GearLedger creates limited infrastructure and security metadata needed to run the service, such as authentication records, session state, timestamps, role and membership status, synchronization summaries, audit events, IP/browser request metadata available to hosting and security providers, and error status needed to protect accounts. GearLedger does not add advertising analytics, behavioral tracking, location collection, contacts access, microphone access, advertising identifiers, persistent hardware identifiers, installed-app inventory, or unnecessary diagnostic telemetry.
How we use information
We use GearLedger data to provide authentication, organization administration, inventory accountability, personnel assignment, checkout and check-in, signatures, synchronization, audit history, requested exports, beta onboarding, support, security, abuse prevention, legal compliance, and service administration.
Service providers and recipients
We use service providers for hosting, authentication, database, storage, email delivery, security, and abuse prevention. Organization data is available to authorized users in the same organization according to their role and permissions. We do not sell personal data.
Security safeguards
GearLedger uses HTTPS in transit, role-based access controls, organization-scoped database policies, audit logging, private storage where required, encrypted local session storage, and protected administrative functions. Operational offline data remains in the app-private local database unless synchronized or exported by an authorized user.
Retention and deletion
We retain account, organization, inventory, checkout, signature, synchronization, audit, and export-related records for as long as needed to provide GearLedger, maintain equipment accountability history, protect the service, resolve disputes, and meet legal or business-record obligations. Some accountability and audit records may need to be retained after account closure; where appropriate, access is restricted or records are de-identified instead of deleted.
You may request account or data deletion at invytx.com/delete-account. A verified deletion request immediately disables normal account access and synchronization, provides a secure opportunity to export applicable data for seven days, and then executes automatically and irreversibly. There is no application-level recovery method after purge, and data removed from active systems is not intentionally restored.
Residual encrypted disaster-recovery backups may retain deleted information only until the infrastructure provider's normal backup-retention period expires. Deleted information in those backups is not restored to active service except if required for disaster recovery, and any restored environment must re-apply deletion state before normal service resumes.
Your choices
You may contact Invytx to request access, correction, export, restriction, or deletion of information you submitted, subject to identity verification and applicable operational, security, audit, or legal limitations. Organization users should also contact their organization owner or administrator for organization-controlled records.
Updates
We may update this policy as GearLedger changes. The effective date will be updated when material changes are made.
Contact
Privacy questions and requests may be sent to privacy@invytx.com.