Privacy Policy
Version: v2.3 · Effective Date: August 26, 2026
1. Introduction
Andon Tool ("we," "us," "our") is committed to protecting the privacy of our customers and their users. This Privacy Policy describes how we collect, use, store, and protect information in connection with the Andon Tool platform.
2. Information We Collect
Account Information: When a Company Admin registers, we collect the company name, administrator name, email address, billing email, and subscription plan selection.
Company Information: We store the company name, customer join code, plant locations, departments, work areas, and configuration settings provided by Company Admins.
User Information: We collect names and email addresses for users invited to the platform by the Company Admin. Users may also be assigned roles and associated with plant locations and departments.
Usage Data: We collect information about how users interact with the platform, including request activity (requests submitted, claimed, completed), timestamps, and status changes. This data is used to power reporting and metrics features.
Employee Records: Customers may create records for their employees, including employees who do not have a platform login. These records hold the employee's name, job title, hire date, the date their skills were last reviewed with them, their department, shift and work-center assignment, and free-text notes entered by a supervisor.
Skill Certifications and Evidence: For customers using the Skill Matrix, we store each employee's status for each defined skill (not started, in training, or certified), the certification and expiry dates, who certified them, and any evidence note or evidence link entered to support the certification.
Certification Audit Trail: Every change to an employee's skill status is recorded, including the employee's name, the skill, the previous and new status, and the name and role of the person who made the change.
Conversation Records: For customers using the Skill Matrix, we store a supervisor's written account of a discussion with a named individual: the date it happened, the type of entry (conversation, one-on-one, recognition, concern, or follow-up), a subject line, free-text notes of what was discussed, the actions agreed, any follow-up date, and the name and role of the person who wrote it. An entry can be edited only within 24 hours of being written, and each edit stores the previous subject, notes, and actions as a separate record, so earlier versions are kept as well as the current one. After 24 hours the entry cannot be changed by anyone, including us. There is no delete: an entry can be archived, which hides it from active views, and archived entries still appear in exported reports marked as archived.
Performance Reviews: We store written assessments of a named individual covering a stated period: an overall summary, strengths, development areas, goals for the next period, and optional per-section ratings recorded as a position on a four-level scale together with a copy of the scale and section labels as they read when the review was written. A review may also hold the individual's own written comments and whether they acknowledged reading it. Once finalized, the assessment is permanently locked and cannot be edited or returned to draft by anyone, including us; only the individual's comments and acknowledgement can change after that. There is no delete, only archiving.
Development Plans: We store the role or direction a named individual could grow into, a readiness level, the steps recorded to get there, a target date, and when the plan was last reviewed with them.
Training Records: We store which named individuals completed which training activity and on what date, together with the name of the person who recorded it and any note they added.
Who these records are about. The employee records, skill certifications, conversation records, performance reviews, development plans, and training records described above are, in most cases, about a customer's employees. Those individuals are not our customer, did not agree to these terms, and in most cases have no login to the platform and no way to see what has been recorded about them here. Whether they are told about these records, and whether they can see or correct them, is decided by their employer, not by us.
C.I.B. Conversation Content: For customers using C.I.B., we store the full text of every message sent to and received from the assistant, together with the sender's user ID and email and the tone setting in force at the time. This content is free text written by your supervisors and managers and may describe individual employees by name.
Meeting Recordings and Transcripts: A user of C.I.B. can choose to record a meeting. When they do, we store the captured audio of that meeting as a file in your company's private storage, and the text transcript produced from it. The audio is transmitted to Deepgram, a third-party transcription provider, for processing. The transcript is returned with each distinct voice labelled by number ("Speaker 1", "Speaker 2"); nothing in the platform maps those labels to a person. A meeting recording and its transcript cannot be deleted. Our file storage provides no delete capability, so once a recording is uploaded, neither you nor we can remove it — not through the interface, not on request, and not by contacting support. A recording captures whoever was audible in the room. That may include people who are not users of this platform, who have no account here, who did not agree to these terms, and who have no way to see or remove what was captured. We do not control or inspect what a recording contains.
Meeting Notes: Notes about a meeting — typed, pasted, or dictated by a user, or arriving as a transcript as described above — are sent to the AI provider as C.I.B. message content in order to be structured into a summary, and are stored with the rest of that conversation. These notes are free text and routinely name individual employees and describe what they said, agreed to, or were asked to do. They are the same category of record as the conversation records described above, and are subject to the same retention: there is no automatic deletion.
Commitments and Follow-Ups: We store items recorded as agreed or deferred, including a title and description, the reason something was deferred, an owner recorded as free text exactly as the user wrote it, a due date, the item's status, and the name of whoever closed it and when.
C.I.B. Conversations Removed by a User: A user can remove a past C.I.B. conversation from their own list. This hides the conversation; it does not delete it. Every message in it remains stored in full, and remains visible to a Platform Admin. The interface describes this as removing the conversation from your list, and that is all it does.
Production Travelers and Inspection Records: For customers using the Production Traveler module, we store the route a job took through the plant and a record of each inspection performed: the questions as they were asked, the answers given, notes, any photograph taken as evidence, the controlled-document number and revision the inspection was performed against, the name of the roster employee who performed and attested to it, and the account under which it was signed. Once signed, an inspection record is permanently locked and cannot be edited or deleted by anyone, including us; a correction is recorded as a new record alongside the original. We also store who released a job that was placed on hold, when, and the reason they gave.
Plant Documents: For customers using the document library, we store documents entered in the platform — headings, text, images, and links — together with the document number, revision and effective date typed in by whoever maintains the library, and any original file uploaded alongside them. We do not control the document, do not verify these identity fields, and do not enforce any approval or revision process. An uploaded original may contain anything the customer put in it.
Skill Levels: Where a skill is defined as having several levels, we also store which level an individual reached, the label of that level as it read when they were certified, and the history of each level they were previously certified at, including the date and who certified them. That history is never removed, including if the individual is later no longer certified.
Unsent Dictation Drafts: While a user is dictating or typing into certain fields, the in-progress text is saved to our servers so it survives a refresh or a device going to sleep. This text is stored before the user has chosen to submit it. It is readable only by the user who wrote it, is offered back to them on their next visit, and is deleted when they submit it.
Uploaded Images and Files: We store images and files uploaded to the platform, including KPI board images and announcements, images attached to C.I.B. messages, inspection evidence photographs, document files and images, company logos, and meeting audio, along with the file size and any title or expiry date entered. We do not control or inspect what these files contain.
Support Ticket Information: If a Company Admin submits a support ticket, we collect the information included in that ticket, including the subject, description, and any related account or operational details.
Payment and Billing Data: Payment transactions are processed by a third-party payment processor (Stripe). We do not store full credit card numbers or sensitive payment credentials on our systems. We may store subscription status, billing cycle, recurring amounts, and Stripe customer or subscription IDs for billing management purposes.
3. How Information Is Used
We use the information we collect to:
- Provide, maintain, and improve the platform and its features.
- Process subscription payments and manage billing.
- Send account setup emails, billing confirmations, and subscription notifications.
- Respond to support tickets and customer inquiries.
- Generate in-app reports and metrics for Company Admins, Plant Managers, and Supervisors.
- Maintain audit logs for administrative and compliance purposes.
- Protect the platform from fraud, unauthorized access, or misuse.
4. Data Separation by Company
Customer data is separated by Company ID within the platform. Each company's data — including users, plant locations, departments, work areas, and requests — is logically isolated from other companies. Company Admins can only access data belonging to their own organization.
5. How Information Is Shared
We do not sell your data to third parties. We may share information with:
- Payment Processors: Stripe processes payment transactions on our behalf and is subject to their own privacy and security policies.
- Email Service Providers: We use email delivery services to send setup emails, billing notifications, and support responses.
- AI Provider (C.I.B. only): When a user sends a message to C.I.B., the following is transmitted to our platform's third-party AI provider in order to generate the reply: the message text; the most recent messages in that user's own conversation history; operational data for the departments that user is permitted to see, comprising downtime events, reasons, work centers and minutes lost, KPI metric names, goals and recent daily statuses, and skill-coverage data including the names of employees certified on each skill; the work-center and downtime-reason names in use; and any image attached to the message. A web-search context path is enabled by default, which routes the request through a search-capable model. A Platform Admin can disable that path.
- AI Provider — employee records (C.I.B. with the Skill Matrix): Where a company has both C.I.B. and the Skill Matrix, the data sent to the AI provider on every message also includes records about named individuals in the departments that user is permitted to see. This is a broader category than operational metrics, and it is sent whether or not the message is about a person. Specifically: conversation records — the date, the individual's name, the entry type, the author's name, the subject, an extract of the notes and of the actions agreed, and any follow-up date and whether it is outstanding; performance reviews — the individual's name, the period, the review's status, the reviewer's name, and extracts of the overall summary, strengths, development areas, and goals; development plans — the individual's name, target role, readiness, an extract of the steps, and the target and last-reviewed dates; and training records — which named individuals are overdue, never completed, or due soon on each activity. Records about the person sending the message, and records about any other supervisor or lead account, are excluded before anything is sent, except for training records, which may include the sender's own.
- Browser Speech Services: When a user uses the dictation (microphone) feature — available in C.I.B., in conversation records, in performance reviews, and in document authoring — the browser transmits the captured microphone audio to the speech service operated by the browser's vendor, as described in Section 10.
- Transcription Provider (meeting recording only): When a user records a meeting, the recorded audio is stored in your company's private storage and a temporary link to that stored audio is sent to Deepgram, which downloads the audio and returns a transcript with each distinct voice labelled by number. The audio of the entire recorded meeting, including the voices and words of anyone audible in the room, is processed by Deepgram. How Deepgram handles and retains what it receives is governed by its own practices, not ours.
- Legal and Compliance: We may disclose information when required by law, legal process, or to protect the rights and safety of users or the platform.
6. Data Security
We implement reasonable technical and organizational measures to protect customer data against unauthorized access, loss, or disclosure. However, no online service is completely secure, and we cannot guarantee absolute security.
Customers are responsible for maintaining the security of their own accounts, including managing user access and passwords within their organization.
7. Data Retention
We retain customer data for the duration of the active subscription and after it ends. This section describes how retention actually works today.
There is no automatic deletion. No automated process removes request history, operational data, employee records, skill certifications and level history, audit logs, conversation records and their edit trail, performance reviews, development plans, training records, C.I.B. conversations, meeting notes and transcripts, recorded commitments, inspection records and traveler history, plant documents, KPI entries, downtime records, or uploaded files. Data is retained indefinitely until it is removed manually.
Meeting recordings and their transcripts cannot be deleted at all. Our file storage provides no delete capability, so once a meeting recording is uploaded it is retained permanently: neither you nor we can remove it, through the interface or on request. Audio already transmitted to Deepgram is subject to its retention practices, not ours.
Some records cannot be changed or removed from within the platform at all. A conversation record is locked 24 hours after it is written and has no delete function; a finalized performance review is permanently locked; a signed inspection record is permanently locked, and a correction is added as a new record rather than replacing it. Archiving hides these records from active views but does not remove them, and archived conversation records still appear in exported reports. A plant document is retired rather than deleted, and every link to it keeps resolving.
Removing a C.I.B. conversation from a list does not delete it. The conversation stops appearing in that user's own list. Every message in it remains stored and remains visible to a Platform Admin.
History retention is not enforced. Our plans reference a history-retention period. That period is not applied by the software: request history and operational data are not trimmed or aged out when it elapses.
Deactivated records are not deleted. Organizational records such as plant locations, departments, and work areas that are deactivated, archived, or marked as removed remain stored. The same is true of records the interface describes as archived or deleted, including archived KPI board images and soft-deleted employee records.
Cancellation does not delete data. Suspending or cancelling an account removes access to it. It does not remove the data.
Requesting deletion. You may contact support@andontool.com to request deletion of your data. Deletion is performed manually, record by record. We cannot honour a request to delete everything: images and other uploaded files cannot currently be deleted from our file storage, and data already transmitted to the third-party providers listed below is subject to their retention practices, not ours.
8. Customer Responsibilities
Customers are responsible for the personal data of their employees and users that is submitted to the platform. Customers should ensure they have appropriate authority and legal basis to submit employee data to the platform and to use the platform for operational tracking and communication purposes.
9. Cookies and Tracking
Andon Tool uses Google Analytics 4 (GA4) to collect anonymous usage data including page views and navigation patterns. This data helps us understand how the product is used and improve the experience. Google Analytics may use cookies to distinguish users. We do not deliberately send names, email addresses, or other directly identifying fields to Google Analytics. Analytics does, however, run on signed-in pages inside the application as well as on our public marketing pages, and the page path it records can contain a record identifier — for example the address of an individual request. We do not treat that as anonymous, and you should not assume analytics data is free of anything that could be linked back to activity in your account. You can opt out of Google Analytics tracking by using the Google Analytics Opt-out Browser Add-on available at tools.google.com/dlpage/gaoptout.
10. Third-Party Service Providers
The platform depends on the following third parties. Each receives only the categories of data listed against it.
- Base44 — hosting, database, and file storage. Holds all customer data stored in the platform, including every category listed in Section 2 and every uploaded file.
- Our platform's AI provider — receives C.I.B. message content, recent conversation history, department-scoped downtime, KPI and skill-coverage data including certified employee names, attached images, and — where a company has both C.I.B. and the Skill Matrix — conversation records, performance review text, development plans, and training status about named individuals, all as described in Section 5. The provider is engaged through our hosting platform's AI integration; we name it as our platform's AI provider because the specific provider is selected by that integration rather than by us.
- Resend — email delivery. Receives recipient names and email addresses and the contents of the messages we send, including account setup and activation links, invitations, invoices, support replies, shift reports, and marketing enquiry details.
- Stripe — payment processing. Receives billing email, company name, billing address details, and transaction and subscription information.
- Google Analytics 4 — usage analytics. Receives page paths, page titles, and interaction events, as described in Section 9.
- Browser speech services — speech-to-text transcription. When a user uses the dictation (microphone) feature, the browser transmits the captured microphone audio to the speech service operated by the browser's vendor — for example Google for the Chrome browser and Apple for the Safari browser — which returns the transcribed text. This applies to dictation wherever it appears in the platform, including employee conversation records, performance reviews, document authoring, and microphone input in C.I.B. The service used, and how that vendor handles the audio, are determined by the browser vendor rather than by us.
- Deepgram — meeting transcription. Receives a temporary link to a stored meeting recording and downloads that recording, and returns a transcript with each distinct voice labelled by number. What it receives is the audio of the recorded meeting in full, which may include the voices and words of people who are not users of this platform. We send no message content, employee records, or account data to Deepgram. Its handling and retention of the audio it receives are governed by its own practices, not ours.
11. Uploaded Files
Some uploaded files — KPI board images and announcements, images attached to C.I.B. messages, and display background images — are stored at web addresses that are not access-controlled. Anyone who has the address of one of these files can open it without signing in to Andon Tool.
Other files — meeting recordings, inspection evidence photographs, plant document files and section images, and company logos — are stored privately and are reached through temporary links generated when the file is displayed or downloaded. A temporary link expires, but while it is valid it works for anyone who has it, and it can be copied out of the platform.
Files in both categories cannot be deleted. Archiving, retiring or removing a file in the interface hides it and removes the reference to it; the file itself remains stored. This applies to meeting recordings, which cannot be removed by anyone once uploaded.
Because of these facts, do not upload material you may later need removed, and do not place material in the non-access-controlled category above that you would not want readable by someone outside your organization. This includes photographs of boards, notices, or documents containing employee names, personnel or disciplinary information, medical information, or identifiable faces.
12. Data When an Add-On Is Switched Off
When a module such as the Skill Matrix, C.I.B., the Production Traveler, or the document library is switched off — including automatically at the end of the initial 30-day period, where that applies — the data created in that module is retained, not deleted. Skills, certifications and level history, certification audit records, C.I.B. conversations, meeting recordings and transcripts, inspection records, and plant documents remain stored and become inaccessible through the interface. Switching the module back on makes the existing data visible again.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify customers of material changes via email or in-app notification. Continued use of the platform after changes take effect constitutes acceptance of the updated policy.
14. Contact Information
For privacy questions or data requests, please contact:
Andon Tool Support
Email: support@andontool.com