Privacy policy
Amp-Hour is shop software for plating and anodizing job shops. This policy says what we collect, why, who else touches it, how long we keep it, and how to get it out or have it deleted. It is written to match what the software actually does, and we change it when the software changes.
- Who we are
- What we collect
- Why we use it and our legal bases
- How shop data is used
- Subprocessors
- How long we keep it
- Security
- Your rights
- Cookies and local storage
- Children
- Where data is hosted
- Changes to this policy
- Contact
1. Who we are
Amp-Hour is operated by [Legal entity], doing business as Amp-Hour, from Wisconsin, United States. For the hosted service at amphour.io we are the controller of your account information and a processor of the data your shop enters. The shop that signs up is the controller of its own records, which is explained in section 4.
Questions about this policy go to support@amphour.io. Postal mail goes to [Mailing address].
2. What we collect
Account information
When you create a login we store your name, email address and a hash of your password (we never store the password itself). If you turn on two-factor authentication we store the shared secret for your authenticator app and hashes of your recovery codes. Each time you sign in we record the date, the IP address and the browser identification string (user agent), and we keep a list of your open sessions so you can see and end them.
We also keep a security event log for your account: successful and failed sign-ins, lockouts, password and two-factor changes, sessions you ended, exports you downloaded, invitations you sent or accepted, and deletion requests. Section 6 says how long.
Shop data
Your shop enters its own records: customers and their contacts, parts and specifications, quotes, jobs and travelers, tank chemistry readings and additions, certificates, inspection and nonconformance records, wastewater and hazardous-waste records, invoices and payments, purchase orders, inventory, customer-owned stock held at the shop, shared tank loads, maintenance work orders, and documents or photos attached to any of these (images, PDFs, text and office documents up to 10 MB each, within a 2 GB allowance per shop). Shop data also includes information about your employees: names, badge numbers, roles, time-clock punches and hours, training records, and for anyone with a login, their email address.
Each shop's data lives in its own database file. We do not combine shop data across shops.
Messages and notifications
Staff can message each other inside the application. Messages, the people in each conversation and any record a message links to are stored in the shop's database with the rest of its data; they are visible to the people in the conversation, to a manager who removes a message, and to administrators through the shop's export. We do not read them except as section 4 describes for every kind of shop data. Notifications (a task assigned to you, a tank reading out of limits, a message received) are stored per person and removed after 90 days or when you delete them. Customer-portal users do not take part in messaging.
Billing
Payments are handled by Stripe. Your card number goes from your browser to Stripe and never passes through our servers. We store the Stripe customer and subscription identifiers, your plan, the subscription status and the dates of trial and billing periods. Invoices and receipts are generated by Stripe.
If a promotion code is entered at sign-up or under Settings > Billing, we record the code, the shop, the account that entered it and the date, so the trial can be set to the length the code carries and so we can see which mailing a shop came from. A code is not personal information in itself, but one printed on a flyer addressed to your shop identifies that mailing.
Server logs
Our web server writes one log line per request with the time, the requesting IP address, the URL, the response code and the user agent. These logs are used for troubleshooting and security review and are deleted after 90 days.
We send transactional email only: address verification, password resets, invitations, a notice when your account signs in from a new device, security alerts when two-factor authentication or your password changes, deletion confirmations, and billing notices. We do not send marketing email unless you ask for it, and you can stop it at any time by replying or emailing support.
What we do not collect
We do not use analytics or advertising trackers, we do not fingerprint devices, and we do not buy or receive data about you from anyone else.
3. Why we use it and our legal bases
Where the law asks us to name a legal basis (for example for shops in the EEA or the United Kingdom), these are they:
- Performing our contract with you. Account information, shop data and billing records are processed because that is what the service is: storing and showing your shop's records to the people you authorize, and charging the subscription you chose.
- Our legitimate interests. Sign-in records, the security event log and server logs are kept to keep accounts secure, detect and investigate misuse, and keep the service running. We balance these against your interests by keeping only what section 2 lists, for the periods in section 6.
- Legal obligations. Billing records are kept as long as tax and accounting law requires.
- Consent. Any optional email beyond the transactional messages above is sent only if you ask for it, and you can withdraw that at any time.
4. How shop data is used
Shop data is used for one purpose: to provide the service to your shop. Specifically, we store it, show it to the people your shop has given access, back it up, and restore it if something goes wrong.
- We do not sell shop data or account information, and we do not share it with anyone for their own purposes.
- We do not show advertising, and there are no advertising or analytics trackers on amphour.io or in the application.
- We do not use shop data to train artificial intelligence or machine learning models, ours or anyone else's.
- Our staff look at a shop's data only to provide support you asked for, to investigate a security problem, or when the law requires it. Every time an Amp-Hour operator enters a shop, the event is written to that shop's security log where its administrators can see it.
Your shop decides what to enter and who at the shop can see it. For the people whose information a shop enters (its employees, its customers' contacts), the shop is the controller and we act on the shop's instructions. If you are one of those people and want to see, correct or delete your information, ask the shop; if you contact us instead, we will forward the request to the shop's administrator.
Customer portal. A shop may give its customers portal logins. The shop decides, under Settings > Customer portal, which customers have access and whether the portal shows invoices, quotes and certificates or accepts quote requests. A portal user sees only the records of the customer they belong to. Their login, sign-in records and security event log are account information under section 2, and they can request deletion of their account the same way as anyone else.
What each role can see. The server, not only the screens, decides what a login receives: prices, job costing, pay rates, invoices, purchasing and financial reports go only to administrators, managers and office logins; QC and operator logins do not receive them even by asking the server directly. Only administrators can grant the manager or administrator role.
5. Subprocessors
These companies process data on our behalf. We give shop owners at least 30 days' notice by email before adding one that would handle shop data.
| Company | What they do for us | Where |
|---|---|---|
| DigitalOcean, LLC | Hosting: the servers the application and its databases run on, block storage for the data volume, and object storage for backup copies | United States (New York or San Francisco data centers) |
| Stripe, Inc. | Payments: card processing, subscription billing, invoices and receipts | United States |
| Microsoft Corporation (Microsoft 365) or Resend, Inc. | Transactional email: delivering the messages listed in section 2 | United States |
| GoDaddy Operating Company, LLC | Domain registration and DNS for amphour.io | United States |
Email providers see the recipient address and the content of the message, which may include your name and your shop's name. DNS and domain services do not receive account or shop data.
6. How long we keep it
| Data | Kept |
|---|---|
| Account information | Until you request deletion. The request starts a 30-day grace period during which you can cancel it; after that the account is anonymized (name, email, login, password hash and two-factor data removed) and cannot be recovered. |
| Shop data | Until the shop owner deletes the shop, or until the owner's account is purged after a deletion request (shops with no other administrator go with it). A shop whose trial or subscription has ended stays read-only, so it can still be exported; we may delete a shop that has been read-only for 12 months after emailing its owner 30 days ahead. |
| Backups | 30 days. A daily copy of every database is made and deleted 30 days later; deleted data therefore leaves the last backup within 30 days. |
| Security event log | 400 days. |
| Notifications | 90 days, or until you delete them. |
| Messages between staff | Until the author or a manager deletes a message (a deleted message is replaced by a placeholder in the thread), or until the shop is deleted. |
| Promotion code redemptions | Life of the shop, with the platform's audit log. |
| Web server access logs | 90 days. |
| Sessions | Ended after 7 days without use and in any case after 14 days. |
| Email verification, password reset and invitation links | 72 hours, 2 hours and 7 days respectively, after which they stop working and are deleted. |
| Billing records | As long as tax and accounting law requires, at Stripe and in our own records. |
7. Security
Each shop has its own database, so a query for one shop cannot read another's. Connections use TLS 1.2 or later. Passwords must be at least 12 characters and not on a list of common passwords, and are stored as scrypt hashes. Two-factor authentication with an authenticator app is available to everyone and can be required by a shop for its administrators and managers; our own operators must use it, and the platform console is open only to a confirmed email address on our administrator list. Sign-in attempts are rate limited per address and per login and take the same time whether or not an address is registered, so the sign-in form cannot be used to find out who has an account. The server, not only the screens, decides what each role receives. The code was reviewed adversarially in October 2026 and every finding was fixed before this version of the policy. Sessions end after 7 days idle or 14 days total, and you can see and end your sessions from Settings > Security. Our security page describes all of this in detail, including backups, logging, how to report a vulnerability, and what we do if there is an incident.
8. Your rights
Whatever the law where you are says, we give every account holder these rights and most of them can be exercised without asking us:
- Access. Sign in; everything we hold about your account is on the Settings pages, and your shop's data is the application.
- Export and portability. A shop administrator can download every table as CSV, or the whole shop database as one SQLite file, from Settings > Data, at any time and as often as needed. Both are open formats that other software can read.
- Correction. Edit your name under Settings > Account and shop records in the application. To change the email address on your account, email us from the current address.
- Deletion. Request deletion of your account from Settings > Account. We confirm by email, and the deletion happens 30 days later. During those 30 days you can cancel from the link in the email or by signing in. If you own a shop that other people still use, you must first transfer ownership to another member (Settings > Team) or delete the shop. The shop's owner can delete the whole shop from Settings > Shop by typing its ID to confirm; that takes effect immediately and removes the shop's database.
- Objection and restriction. If you object to a particular use, or want processing paused while something is sorted out, email us and we will do that where the law provides for it.
- Complaint. If you are in the EEA or the United Kingdom you can complain to your data protection authority; elsewhere, to your state attorney general or consumer protection office. We would like the chance to fix it first.
To ask for anything not available in the application, email support@amphour.io from the address on your account, or sign in and write to us from there, so we know the request is yours. We answer within 30 days. We do not charge for these requests and we do not treat anyone differently for making one.
9. Cookies and local storage
The application sets one cookie, named sid. It identifies your session after you sign in and is strictly necessary to use the service. It is marked HttpOnly (scripts cannot read it), SameSite (other sites cannot send it), and Secure (sent only over HTTPS). It expires 14 days after sign-in, or after 7 days without use, or when you sign out.
The application also uses your browser's local storage and session storage for display preferences and page state: the theme, collapsed sidebar groups, whether you have taken or declined the guided tour, remembered tabs and filters, unsent drafts, and on the shop-floor terminal the load being built. This information stays in your browser, is never sent to us, and is cleared when you clear your browser's site data.
There are no third-party cookies, no analytics cookies and no advertising cookies on amphour.io. When you pay, Stripe's checkout page is served by Stripe and uses Stripe's own cookies under Stripe's privacy policy.
10. Children
Amp-Hour is business software and is not directed to anyone under 16. We do not knowingly collect information from children. If you believe a child has created an account or has been given a login, tell us and we will remove it.
11. Where data is hosted
The service is hosted in the United States and our staff are in the United States. If your shop is somewhere else, your data is transferred to and stored in the United States, and by using the service you agree to that. Shops in the EEA or the United Kingdom that need a data processing agreement or standard contractual clauses can ask us at support@amphour.io.
12. Changes to this policy
When we change this policy we change the version and effective date at the top. For a change that affects what we collect, how we use it or who processes it, we email the owner of every shop at least 30 days before it takes effect. Smaller corrections take effect when posted. Earlier versions are available on request.
13. Contact
support@amphour.io
[Legal entity], [Mailing address], Wisconsin, United States