This policy explains what Astrolabe collects, how we use it, and your choices. It covers the Astrolabe website and application. Astrolabe is a business-to-business service; most data we handle is business data you upload about installed equipment and service history.
We do not sell your data. Your Customer Data is isolated per tenant. Cross-company pooling is opt-in: if you consent, your experience contributes to shared, credibility-weighted aggregates — never in a form that identifies your company to another. We share data with service providers only as needed to run the service (see Sub-processors), and when required by law.
We use Amazon Web Services (hosting and database) and, for payments when enabled, Stripe. These providers process data on our behalf under their own security and privacy commitments. We never send your card details to our servers — payment entry is handled by the payment provider.
Traffic is encrypted in transit (HTTPS). Passwords are stored as salted, memory-hard hashes; session and reset tokens are stored only as hashes. Access is tenant-scoped and authenticated. No method is perfectly secure, but we apply reasonable, layered controls.
We keep Customer Data while your account is active and as needed to provide the service. On termination you may request an export within a reasonable window before deletion. We retain limited records as required for legal, security, and accounting purposes.
You control what you upload and whether you consent to pooling (and can revoke it). You may request access to, correction of, or deletion of your data, subject to legal limits, by contacting us.
We may update this policy; material changes will be posted here with a new "last updated" date.
Privacy questions or requests: hello@astrolabesolutions.com.