LEGAL / DATA HANDLING
Privacy policy
How the Netlabs portfolio collects, uses, retains, and deletes account, support, and connected-platform data.
Published pre-release policy — the contracting legal entity, registered address, and production subprocessor schedule must be approved before marketplace submission or payment acceptance.
Scope and roles
This policy covers BoardDrift, ReplenishIQ, GuestPreflight, CosmeticLedger, RebillLens, EvidencePass, this website, and associated support services. Every product and publisher name remains a working candidate until legal-name clearance is complete.
For customer-controlled platform records, the customer is generally the controller and the publisher acts as processor or service provider. For account administration, security logs, billing records, and support requests, the publisher acts as controller.
Data we process
- Account and organization data: name, work email, authentication identifiers, role, plan, and organization membership.
- Connected-platform data selected by the customer: configuration snapshots, inventory and sales aggregates, external-collaborator metadata, order and product references, renewal records, supplier evidence metadata, and diagnostic results.
- Support and pilot data: contact details, product selection, messages, attachments supplied through an approved channel, and resolution history.
- Security and usage data: audit events, request identifiers, coarse device and browser information, timestamps, rate-limit keys, and error telemetry. The preview tools do not save the JSON sample submitted on a public product page.
- Optional public-site analytics: after a visitor accepts analytics, Google Analytics 4 may receive the page URL and title, referrer, event time, browser and device information, coarse location derived from the network address, and analytics identifiers. We do not intentionally send support-form contents, preview JSON, account user IDs, or connected-platform records to GA4.
Why we use data
- Provide requested diagnostics, evidence workflows, account administration, support, and contracted services.
- Secure the service, prevent abuse, investigate incidents, maintain tenant isolation, and produce auditable records.
- Measure activation and reliability using minimized event data, improve rules with de-identified or aggregated evidence, and meet legal obligations.
- We do not sell personal information, use customer content for advertising, or train general-purpose AI models on customer content.
Optional analytics and your choice
Google Analytics 4 is disabled by default on the public website. The Google tag is not downloaded and no GA4 page view is sent unless the visitor selects “Accept analytics.” Advertising storage, advertising user data, ad personalization, and Google Signals are disabled in the site configuration.
The browser stores “analytics accepted” or “analytics declined” in local storage so the site can respect the choice on later visits. The Analytics preferences control in the footer can reopen the choice at any time. Declining or revoking consent prevents future Netlabs GA4 collection in that browser; it does not automatically erase data already received, so an eligible deletion request can be sent to privacy@netlabs.app.
If accepted, Google acts as an analytics service provider and may set or read analytics identifiers and process analytics data on infrastructure in more than one country under its own service and data-protection terms. The GA4 property retains user-level and event-level data for 14 months and resets that period on new activity; standard aggregated reporting may be retained differently. The production subprocessor schedule remains a launch disclosure.
Permissions and first-release limits
The first connected releases request the narrowest feasible read permissions. They do not automatically change boards, inventory, guest accounts, orders, subscriptions, payments, regulatory filings, or registry records. Product-specific permission scopes are shown during installation and in the applicable marketplace listing.
Third-party platforms process data under their own terms. Removing an app revokes future access but may not immediately erase records already retained under a customer contract; use the deletion process below.
Retention and deletion
- Public preview payloads: processed in memory and not intentionally persisted; standard infrastructure logs may retain request metadata without the submitted JSON.
- Diagnostic runs: retained for the customer-selected workspace period, with a launch default no longer than 90 days unless contract, legal hold, or an explicit evidence-retention setting requires otherwise.
- Security and audit logs: retained according to the production retention schedule, targeted at 90–365 days depending on event sensitivity.
- Support requests: targeted for deletion or de-identification within 90 days after closure unless needed for an active contract, dispute, or legal requirement.
Sharing, transfers, and rights
Data may be shared with vetted hosting, database, email, error-monitoring, authentication, billing, and support providers only to operate the service. A named subprocessor list and transfer mechanism will be published before production launch.
Depending on location, people may request access, correction, deletion, restriction, portability, or objection, and may complain to a regulator. Submit a request through the support page or email privacy@netlabs.app. Identity and authority over the relevant organization will be verified before disclosure or deletion.