Privacy notice

How RigCheck handles information

This notice explains RigCheck’s nationwide privacy practices. Departments control their operational records; RigCheck operates the service and handles limited account, support, and website information.

Effective September 2, 2026 · Version 2026-09-02-us-2

Scope and roles

This notice applies to rigcheckems.com, RigCheck accounts, transactional emails, walkthrough requests, and related support. For apparatus checks, inventory, personnel-access entries, and department reports, the department decides why and how the information is used and is generally the responsible organization. RigCheck processes those records to provide the service. RigCheck is responsible for its own account, security, billing, website, and support operations.

Information collected

RigCheck processes names, email addresses, authentication identifiers, department memberships and roles, optional profile photographs, apparatus and checklist configuration, equipment inventory and expiration details, inspection reports, administrative activity, records-governance settings, and communications submitted to RigCheck.

Technical information may include IP-address-derived security keys, request timestamps, browser or device details available in service logs, session cookies, and diagnostic events. Stripe handles payment-card details when billing is enabled; RigCheck receives limited customer, subscription, plan, status, and transaction references.

Sources and purposes

Information comes from users, department administrators, connected service providers, and normal use of the website. It is used to authenticate accounts, enforce department boundaries, operate inspections and inventory features, send account and department messages, provide support, administer subscriptions, prevent abuse, preserve records, investigate incidents, meet legal obligations, and improve reliability.

Service providers and disclosures

RigCheck uses Cloudflare for application delivery and operational storage, Supabase for authentication, Resend for transactional email, and Stripe when payments are enabled. These providers process information to perform contracted services. See the Subprocessors page for current functions and links.

Information may also be disclosed when required by law, to protect users or the service, in a business transaction subject to appropriate safeguards, or at the department’s direction. RigCheck does not sell personal information or use it for cross-context behavioral advertising.

Cookies and authentication

RigCheck uses necessary cookies and browser storage for secure sessions, account recovery, department selection, drafts, and appearance preferences. RigCheck does not currently use advertising cookies. Blocking necessary storage can prevent sign-in or application features from working.

Department control, public records, and retention

Departments manage access and determine their legal retention duties. Existing workspaces default to preserving reports indefinitely. Standard permanent report disposal requires recorded retention authority, an elapsed period, department-owner action, and no legal hold. The verified RigCheck app owner may use an explicitly confirmed, audited technical override for a false test report only while also serving as that department’s owner. The override cannot bypass a legal hold and does not determine whether deletion is lawful. Archiving does not destroy a report. Limited audit entries remain after authorized disposal to preserve accountability and prevent replay.

Public-records and litigation obligations vary by jurisdiction. A request for a department-created operational record may be referred to the department’s designated records contact. Learn more on the Records Governance page.

Retention of other information

Account and membership information is retained while needed to provide access and support legitimate security, contractual, tax, and legal needs. Security rate-limit entries expire automatically. Walkthrough and privacy communications are retained as reasonably necessary to respond and maintain business records. Backup and provider logs may persist for limited operational cycles after primary deletion.

Privacy choices and state rights

Depending on where you live, you may have rights to know or access personal information, correct it, delete it, obtain a portable copy, limit certain uses, or appeal a decision. RigCheck does not discriminate for exercising applicable privacy rights. Submit a privacy request. Identity and authority may need to be verified; authorized-agent requests may require proof of permission.

Because departments control operational records, RigCheck may coordinate with or refer your request to the relevant department. Some information may be retained where permitted or required for security, legal claims, contracts, public records, or other lawful exceptions.

Children and patient information

RigCheck is a workplace service and is not directed to children under 13. It is not intended for patient care reports, protected health information, dispatch narratives, or clinical documentation. Users must not enter patient-identifying or medical information into forms, checklist fields, notes, inventory records, or messages.

Security and location

RigCheck uses encrypted connections, verified accounts, server-side authorization, private photo storage, audit controls, and provider-managed infrastructure. No service can guarantee absolute security. Providers may process information in the United States and other locations under their applicable contractual safeguards.

Changes and contact

Material updates will be identified by a new effective date or policy version, and account users may be asked to accept revised terms. For privacy rights or questions, use the Privacy Request form. Do not submit passwords, patient information, or sensitive operational evidence through a public form.