Privacy Policy
Introduction
Thank you for choosing to be part of our community at ESP Hub ("Company", "we", "us", "our"). We are committed to protecting your personal information and your right to privacy. If you have any questions or concerns about our policy or our practices with regards to your personal information, please contact us at support@esphub.app.
This privacy policy applies to all information collected through our mobile application, ESP Hub, and any related services, sales, marketing, or events (collectively referred to in this privacy policy as the "Services").
Information We Collect
We collect limited information needed to operate, secure, and improve the Services. The types of information we collect include:
- Account and authentication data: Email, account identifiers, and authentication status. Passwords are handled by Firebase Authentication and are not stored by ESP Hub.
- Device and security data: A device identifier, device name, platform (Android/iOS/Web), manufacturer/model, operating system version, browser/user agent (web only), app version/build number, approximate location (region/country), and security events such as sign-ins, sign-outs, device status (active/lost/blocked/signed out), and timestamps (last sign-in/last active). We use this data to show your connected devices in the Devices screen so you can monitor account access and protect your account.
- Notification data: Push notification tokens and notification delivery data used to send security alerts (e.g., new device sign-in, device marked lost, sign out all devices).
The following permissions may be requested:
- Photo Gallery Access: Only used when the user chooses to pick an image to upload into the app. The app does not scan or access the gallery automatically or in the background.
- Camera Access: Only used when the user selects the option to take a new photo and upload it to the app. Camera access is never initiated without user interaction.
- Location Access (Well Sites): Only requested when the user wants to add or edit a well site location. Viewing or using previously saved locations does not require location permission.
- Approximate Location (Devices): We may use approximate location (region/country) to help secure your account and show device activity in the Devices screen. This does not require precise GPS location.
- File Access: Required only when the user chooses to upload scanned reports or save generated reports to device storage. We do not access or browse other files on the device.
- Contacts Access: Only requested when the user explicitly selects to import contacts from the device. Adding contacts manually or using contacts already stored in the app does not require permission to access the user’s device contacts.
Account Creation and Login
User accounts in ESP Hub are created by designated administrators only. End users cannot create an account themselves. Once created, users are able to set or reset their password through the app. Login credentials are managed securely via Firebase Authentication using email and password.
Account Deletion
End users cannot delete their accounts directly from the app. If an account needs to be deleted (e.g., when a user leaves their company), this action must be performed by an administrator through internal procedures. Users wishing to request account deletion should contact their administrator directly.
Information from Third Parties
For user authentication, data storage, and push notifications, we rely on Google Cloud services (including Firebase). These services process data on our behalf to provide the Services.
How We Use Your Information
We use the information described above to:
- Authenticate users and maintain account security.
- Register and manage devices associated with an account.
- Detect suspicious activity and enforce security controls (for example, device limits or sign out all devices).
- Send security notifications related to account/device activity, and app notifications based on user selections in the Notifications Setting screen.
- Provide, maintain, and improve the Services.
How We Share Your Information
We do not sell personal information. We may share information with trusted service providers (such as Firebase/Google) to operate the Services, deliver notifications, and maintain security. We may also disclose information if required by law or to protect the security of our users and Services.
Security of Your Information
We rely on Google Cloud services (including Firebase) with industry-leading security controls to protect your data and ensure it is 100% secure.
Data Retention
We retain account, device, and security data for as long as your account is active or as needed to provide the Services, comply with legal obligations, resolve disputes, and enforce our agreements.
Push Notifications
We use push notifications to deliver security alerts. You can control notifications through your device settings, but some security notifications are important for account safety.
International Data Transfers
Your information may be processed and stored in data centers operated by our service providers, which may be located outside your country of residence.
Changes to This Privacy Policy
We may update this privacy policy from time to time. The updated version will be indicated by an updated "Last updated" date and will be effective as soon as it is accessible.
Contact Us
If you have questions or comments about this policy, you may contact us at: support@esphub.app