Privacy Policy
Last updated 17 August 2026
CodeShop QC provides document control software for ASME code shops at codeshopqc.com. This policy explains what we collect, why, and who else touches it.
The short version
- Your project records belong to you. We access them to run the service, support you, and keep them secure — not for anything else.
- We do not sell your personal information, and we never have.
- We do not use your records to train AI models. No part of this application sends anything to an AI provider.
- There is no analytics or advertising of any kind here. No tracking cookies, no advertising pixels, no analytics provider, and no third-party trackers — which is why this site has no cookie banner.
- The application never asks your device for its location.
What we collect
Information you give us
- Account details — your name, email address, and password. Passwords are handled by our authentication provider and are never visible to us.
- Company profile — company name, address, phone number and logo, if you add them. These print on your documents.
- Project records — everything you enter: vessels and spools, heat numbers and material test reports, weld and NDE records, checklists, and the Manufacturer’s Data Reports built from them, plus any files you upload such as drawings, certificates and photographs.
- Workforce records — welder and inspector names, qualification and certification details and their expiry dates, where you use those features. This is information about your people rather than about you, and you are responsible for it. We store it, we do not use it for anything except showing it back to your account, and it is deleted with the rest of your data.
- Auditor assignments — when you grant an outside auditor access to a customer’s records, we store that relationship so the database can enforce it.
- Team information — the email addresses you use to invite colleagues, clients or inspectors.
- Contact details — if you write to us for support.
Information collected automatically
- Technical data — IP address and browser type, as any web service receives, used for security and diagnostics.
What we do not collect
- Card details. Payment pages are hosted by Stripe. Card numbers never reach our servers.
- Your device location. The application never calls the browser's location API.
- Anything from third-party trackers. There are no advertising pixels, no social media trackers, no analytics provider and no data brokers involved.
Why we use it
To operate your account and store your records; to provide support when you ask for it; to process payments; to send service messages such as invitations and notifications; and to keep the service secure and diagnose faults.
We do not use your project records for marketing, and we do not build advertising profiles.
Who else processes your data
We use the following providers. Each is bound to process data only on our instructions.
| Provider | What it does | What it sees |
|---|---|---|
| Supabase | Database, authentication, file storage | Account details and all project records and files |
| Netlify | Website and application hosting | IP address and request data |
| Stripe | Payment processing | Name, email, billing and card details |
| Resend | Transactional email | Recipient name and email address |
| Google Fonts | Typefaces on our web pages | IP address when a page loads |
| jsDelivr | The JavaScript library the application loads | IP address when a page loads |
Providers are located in the United States. If you are outside the United States, using CodeShop QC means your data is transferred there.
How long we keep it
- While your account is active — for as long as you have one.
- After you close it — your records may be permanently deleted. Export anything you need to keep first; every table exports and the application will not stop you taking a copy.
- Contact addresses — until you ask us to remove them.
- We may retain limited billing records for longer where tax or accounting law requires it.
Your rights
You can, at any time and without asking us, export your records, correct them in the application, and delete them.
Write to info@codeshopqc.com to request a copy of your personal data, correction, deletion of your account, or to object to how we use it. We aim to respond within 3 business days.
To delete your account, see Delete your account — it explains what is removed, what stays with your team, and how to ask.
Depending on where you live you may have additional rights — for example under the CCPA in California, or the GDPR in the UK and EU. We do not sell personal information as those laws define it, and we do not share it for cross-context behavioural advertising.
Cookies
We use no advertising or tracking cookies, and there is no analytics provider on this site.
We store a session token in your browser so you stay signed in. That is strictly necessary to operate the service — without it you would be logged out on every page.
Security
Access to your records is enforced by the database itself through row-level security, not merely hidden in the interface. A user with no relationship to a project cannot read or write to it even through the API. Data is encrypted in transit and at rest by our infrastructure providers.
No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you promptly and tell you what happened.
Children
CodeShop QC is a business tool and is not directed at anyone under 18. We do not knowingly collect data from children.
Changes
If we change this policy materially, we will email account holders and update the date at the top. Continuing to use CodeShop QC after a change means the updated policy applies.
Contact
info@codeshopqc.com — we aim to respond within 3 business days.
CodeShop QC — Texas, USA.