Last updated: May 31, 2026
FactoryArt ("we", "us", "our") respects your privacy. This Privacy Policy explains what data we collect, how we use it, and the rights you have over your information when you use the FactoryArt multi-tenant inventory & operations platform (the "Service").
1.1 Account Information. When you (or your company admin) create an account, we collect your name, business email, role, hashed password, and the company identifier you belong to.
1.2 Business Data. Within your tenant, the Service stores the inventory, sales, purchases, customers, suppliers, expenditures, lab tests, batches, technical entries and other operational records that you choose to enter or upload. This data belongs to your company and is isolated by tenant from other companies.
1.3 Files. Bill images and company logos that you upload are stored on Cloudinary (a third-party content-delivery service) under a folder scoped to your company_id.
1.4 Authentication Data. If you sign in with Google, we receive your name, email address, profile picture, and Google account ID from Google. We do not receive your Google password.
1.5 Device & Usage Data. We log standard request metadata (IP address, user agent, timestamps, endpoints accessed) for security and debugging.
1.6 Push Notification Tokens. If you opt in to web push or app notifications, we store the browser/device push subscription token so we can deliver low-stock and approval alerts.
We do not sell your data. We share data only with the following categories of processors, and only to the extent needed to operate the Service:
We retain tenant business data for as long as your subscription is active. After cancellation, data is retained in a soft-deleted state for 30 days, then permanently removed unless legal obligations require longer retention. You can request earlier deletion via the contact below.
Passwords are stored as bcrypt hashes. Sessions use server-side tokens with expiry. Multi-tenant isolation is enforced at the database layer via per-request company_id scoping. All traffic is served over HTTPS. No system is 100% secure — please use a strong, unique password.
Depending on your jurisdiction, you may have the right to access, correct, delete, or export your personal data, withdraw consent, or lodge a complaint with a supervisory authority. To exercise any of these rights, contact privacy@factoryart.com.
The Service is intended for business use and is not directed at children under 16. We do not knowingly collect personal data from children.
Your data may be processed in countries other than your own. We use processors that provide appropriate safeguards consistent with applicable data-protection laws.
We use local storage to keep you signed in and to remember recent screens. We do not use third-party advertising cookies. You can clear local storage from your browser settings at any time (you will need to sign in again).
We may update this Policy from time to time. Material changes will be communicated within the Service or by email. The "Last updated" date above reflects the most recent revision.
Questions? Email privacy@factoryart.com.