Privacy Policy
Effective date: upon publication · Last updated July 2026.
GaugeRoute ("GaugeRoute," "we," "us") is operated by ARDEO LABS LLC, a Florida limited liability company. This policy explains what we collect, why, and what your rights are. It covers the GaugeRoute mobile and web apps, the GaugeRoute website — including customer compliance pages, quote and contract portals, invoice shares, and calculators — and support channels. It applies both to operators (the fire-equipment service companies who hold GaugeRoute accounts, and the office staff and technicians they invite) and to their customers who open a compliance page or portal link.
The short version: your data is yours. We don't sell it, we don't run ads, we don't use your content to train AI models, and you can export or delete everything at any time.
1. What we collect
Account information. Email address, name, and authentication credentials (managed by our authentication provider).
Team and technician accounts. You invite office staff and technicians under your organization and set their role. Technician accounts are restricted, money-blind accounts you issue to your own personnel. You are responsible for having the authority to create them, for telling your technicians that the app records photos, device timestamps, and — where device permissions allow — location at the moment of photo capture in the course of their work, and for obtaining any consent your jurisdiction or employment relationship requires. The app never tracks any user's location continuously or in the background.
Your business content. What you enter to run your service business: your customers, their sites (address, map pin, access notes such as gate codes, and any authority-having-jurisdiction contact note you record), your customers' serialized assets (serial, barcode, manufacturer, model, manufacture date, agent type, size, and location label), cadences and per-asset overrides, checklist templates, route days and stops, inspections, deficiencies, tag records, quotes, contracts, work orders, invoices, payments, notes, business branding, and the operator license and certification numbers you enter for your records.
Your customers' contact details. You may enter names, emails, and phone numbers of your customers and their site contacts so you can schedule work, send quotes, and deliver records. You are responsible for having the right to share that information with us; we use it only to provide the service to you (e.g., rendering a compliance page you share or delivering an invoice you send) and never for our own marketing.
Inspection photos and capture metadata. Photos your technicians capture against an asset serial, with the device-clock time at capture (not upload) so the record is honest when the day ran offline. A photo carries location coordinates only when your device permission allows it; when location is unavailable, the record says so — we never fabricate a location.
Nameplate photos you submit for AI import. Photos of equipment nameplates and labels you submit so the service can draft asset rows for your review.
E-signature records. When your customer accepts a quote or signs a service agreement on a portal link, we record the typed signer name, the date and time, and the originating IP address, so you have evidence the document was accepted.
Payment information. Subscription payments — what you pay us — are processed by Stripe. We receive your subscription status only — we never receive or store card numbers, card brands, or billing card details of any kind (billing happens on Stripe's own pages). Payments your customers make to you happen entirely outside GaugeRoute on your own payment rails, and we never see or hold those funds.
Usage and device data. Product analytics events (screens used, features triggered), device type, OS version, and approximate region, collected via PostHog. Crash and error diagnostics collected via Sentry.
Support communications. Emails you send to our support address.
2. How we use it
- Provide, maintain, and improve the service (including offline sync of the route day and backups).
- AI nameplate import: nameplate photos you submit are sent to Anthropic's API to be transcribed into draft asset rows (manufacturer, model, serial, manufacture date, agent type, size, location). Results always land in a review queue for your approval — nothing becomes an asset without your confirmation, and the model is instructed to transcribe only what is legible and never to invent a serial, date, or agent type. Under Anthropic's commercial API terms, your inputs and outputs are not used to train their models.
- Compose the records and documents you ask for: inspection reports, tag records, quotes, invoices, renewal letters, and the customer compliance page.
- Send push notifications you enable (due work, deficiencies raised on sync, renewals, invoices ready, route-day reminders) and transactional email you initiate or that the service requires (record and portal shares, quote and invoice sends, renewal reminders, receipts, security notices) via Resend.
- Send a short onboarding email sequence after signup and, if you leave it on, a weekly operations digest (both carry one-click unsubscribe; unsubscribing is honored in-product too).
- Measure aggregate product usage, diagnose crashes, prevent fraud and abuse, and comply with law.
We do not sell or rent personal information, and we do not share it with third parties for their own advertising.
3. Compliance pages, portals, and share links
Several surfaces you share live at unguessable links that are not password-protected, and anyone who has such a link can view that page:
- Customer compliance pages show that customer's sites, their asset register, inspection history, tag records, and downloadable report PDFs. They render your business branding and the standing notice that the records reflect your inspections and do not certify code compliance.
- Quote and contract portals show the document, its lines and totals, and collect the acceptance or signature.
- Invoice shares show the invoice you sent.
Treat these links like the documents themselves. You can revoke a compliance link at any time by rotating it in the app, and portal links stop accepting action once the document is accepted or voided.
4. If you're a customer of a GaugeRoute operator
Your fire-equipment service company uses GaugeRoute to schedule, record, and bill the inspections it performs for you. They are responsible for the relationship with you and for the work itself; we process your details (contact information, site address and access notes, and the acceptance record when you sign) on their behalf to provide the service to them. To access, correct, or delete information about you, contact your service company — or email us and we'll help route the request. The records on a compliance page are your service company's records of the work it performed; they are not a compliance determination by us (see the Terms of Service, §5).
5. Where your data lives
Data is stored with Supabase (PostgreSQL and file storage) in the United States, encrypted in transit (TLS) and at rest. Access in our systems is enforced by row-level security scoped to your organization, and technician accounts are additionally denied every money surface at the database level. Public pages read only a narrow whitelist of fields for their link — never the underlying tables. The website and public page renders are served from our site infrastructure (Fly.io, US region).
6. How long we keep it
- While your account is active: we keep your content so the service works; export is available anytime (Settings → Export, CSV/JSON), on every plan, including after you cancel a subscription.
- If you delete your account: deletion is available in the app. Your organization enters a short grace window (currently 7 days) during which the deletion can be reversed by contacting us; after it closes, your content — including inspection and nameplate photos in file storage — is permanently purged. In all cases we complete deletion within 30 days, except minimal records we must keep for legal, tax, or security purposes (e.g., invoices we issued to you).
- Backups age out on a rolling schedule of no more than 30 additional days.
7. Service providers (subprocessors)
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, file storage, server functions | US |
| Stripe | Subscription billing (what you pay us) | US |
| Anthropic | AI transcription of the nameplate photos you submit | US |
| Resend | Transactional and lifecycle email | US |
| PostHog | Product analytics | US |
| Sentry | Error and crash diagnostics | US |
| Fly.io | Hosting for this website and public page renders | US |
| Expo (EAS) | App builds and push-notification delivery | US |
| Cloudflare | DNS and email routing | US |
Each provider processes data only as needed to provide its service to us, under its own contractual data-protection commitments.
8. Your rights and choices
- Access & portability: export everything from Settings → Export, free on every plan.
- Correction: edit your content in the app. Tag records are append-only by design — a correction is a new record, and the original stays in the history so the register can be relied on.
- Deletion: delete your account in Settings, or email us and we'll do it.
- Marketing opt-out: unsubscribe links in every non-transactional email, including the weekly digest.
- State privacy rights: depending on where you live (e.g., California, Colorado, Virginia, Florida), you may have statutory rights to access, delete, correct, or obtain a copy of your personal information, and to non-discrimination for exercising them. We honor these requests for everyone, resident or not. We do not "sell" or "share" personal information as those terms are defined in the CCPA/CPRA.
To exercise any right: [email protected]. We verify requests via your account email and respond within the time required by applicable law (generally 45 days).
9. Children
GaugeRoute is a business tool for adults; accounts require you to be 18+. It is not directed at children, and we do not knowingly collect information from them. If you believe a child has provided us information, contact us and we will delete it.
10. Security
Row-level security on every table, a money-blind technician role enforced in the database, TLS everywhere, encryption at rest, scoped credentials, unguessable and revocable share links, and no card data in our systems. No method of transmission or storage is 100% secure; if we learn of a breach affecting your personal information, we will notify you as required by law.
11. Changes
We'll post changes here and update the date above. For material changes, we'll notify you in the app or by email before they take effect.
12. Contact
Questions about your data, or a request to export or delete it? Email [email protected].
Ardeo Labs LLC5944 Coral Ridge Dr # 1017
Coral Springs, FL 33076
United States