Privacy Policy
Last updated July 29, 2026
MachineSheets is operated by Caleb Buchta, a sole proprietorship trading as MachineSheets. This policy describes what we collect, why, who else sees it, and how to get it back or get rid of it.
What we collect
- Account details. Your name, work email, and a hash of your password. We never store the password itself.
- Shop details. The shop name and the short code phones use to join it.
- Your documents. The files you upload and the text extracted from them, plus the titles, tags, machine numbers, and revisions you enter.
- Enrolled devices. A label you choose for each phone, its browser user-agent string, and when it was last used. We do not collect location, contacts, photos, or anything else from the device.
- Minimal usage data. A per-document view count and the time of each sign-in. That is all.
- Billing details. Handled by Stripe. We store only your Stripe customer and subscription identifiers and your subscription status. We never see or store card numbers.
What we do not do
- No third-party analytics, advertising pixels, or tracking scripts. The product loads none.
- No selling or renting of personal information to anyone, ever.
- No using your documents to train machine-learning models.
- No reading your documents, except where you ask us to for support and we have your permission.
Cookies
We set two, both strictly necessary and neither used for tracking. One identifies a signed-in person and lasts 30 days. One identifies a phone that has joined a shop and lasts a year, so an operator does not have to sign in at the machine. Both are signed, and both can be ended by you — sign out, or revoke the device from settings.
Who else processes it
These providers hold data on our behalf so that the service can run:
- Vercel — hosting and file storage for your uploaded documents.
- Neon — the database holding accounts, shops, and document metadata.
- Stripe — payments. Card details go directly to Stripe and never touch our servers.
- Resend — sending password reset links and team invitations.
We disclose data to no one else, except where the law requires it. Data is stored in the United States.
How it is protected
- Passwords are hashed with scrypt. A copy of our database does not reveal anyone’s password.
- Password reset and invitation links are stored only as hashes, so a copy of the database is not a set of working links.
- Every shop’s data is separated at the database level. A request cannot name an organisation other than the one it belongs to, and automated tests cover that on every change.
- Everything travels over HTTPS.
No system is perfectly secure. If we discover a breach affecting your data, we will tell you promptly and tell you what we know.
How long we keep it
Account and document data is kept while your account is open. When an account closes we keep it for 30 days so you can ask for an export or change your mind, then delete it. Deleting a document removes its file too. Invoices are kept as long as tax law requires.
Your choices
Ask us at support@example.com and we will export your data, correct it, or delete it. We answer within 30 days and we do not charge for it. If you are in a place with statutory rights over your personal data — California, the EU, the UK and others — those rights apply and this is how you exercise them. We will not treat you differently for asking.
The people whose data appears here are usually employees of our customer rather than our customer. If you are one of them, contact your employer first — they control the account. We will help either way.
Children
The service is for business use and is not directed at anyone under 18. We do not knowingly collect data from children.
Changes
If we change this policy materially we will email account owners before it takes effect. The date at the top always reflects the last substantive change.
Contact
Caleb Buchta, trading as MachineSheets — support@example.com.