Toolbox — Maintenance Reporting
Privacy Policy
Last updated: 28 July 2026
This policy explains what information the Toolbox maintenance-reporting service collects, why, and who processes it. Toolbox is operated by Craftly Apps (contact: [email protected]). Toolbox is a workplace tool: most personal information in it is entered by the subscribing property's own staff in the course of their work.
What we collect
- Names — the first/last name staff enter to report issues or sign in as crew, and manager names/emails for dashboard accounts.
- Report content — issue descriptions, notes, and photos staff choose to attach. Photos are stripped of location (GPS/EXIF) data before upload.
- Operational records — job status history, time logged, and which account performed each action (the activity log).
- Device/technical data — a random per-install device identifier, push-notification tokens, and standard server logs (IP addresses, timestamps) used for security and rate limiting.
- Billing data — subscription status and invoices are handled by Stripe; we do not see or store card numbers.
How we use it
- To run the service: syncing reports between devices, notifying the right people, and showing managers their property's maintenance state.
- AI-assisted filing: the text of a report or note is processed by an AI service (Anthropic's Claude API) to tidy wording and file the job by type and location. Only the report text and the property's location list are sent — no names beyond what staff typed into the report itself, no photos.
- Nightly off-site backups of records (not photos) are emailed to the property's nominated backup address.
- We do not sell personal information, use it for advertising, or share it with anyone except the processors below.
Who processes it (subprocessors)
| Provider | Purpose |
| Railway | Application hosting and database |
| Stripe | Subscription payments and invoices |
| Anthropic | AI processing of report/note text for filing |
| Brevo | Transactional email (password resets, backups, alerts) |
| Expo / Google (FCM) / Apple (APNs) | Push-notification delivery |
Retention and deletion
- Job records are retained while the subscription is active, so the property has a maintenance history.
- Photos are automatically deleted from our storage after 2 years (the property can configure a shorter period).
- When a subscription ends, data is available for export for at least 60 days and may then be deleted.
- Staff can ask their property's manager to correct or remove content about them; managers or individuals can also contact us directly at [email protected].
Security
- All traffic is encrypted in transit (HTTPS).
- Passwords for manager accounts are stored hashed (never in plain text); access is tiered (reporter / crew / manager / admin with two-factor authentication).
- Authentication endpoints are rate-limited, and removed accounts lose access immediately.
Your rights
Depending on where you are, you may have rights to access, correct, or delete your personal information (for example under the Australian Privacy Act, Canada's PIPEDA, or the GDPR). Because Toolbox holds data on behalf of the subscribing property, the fastest route is usually your property's manager; you can also contact us and we will assist within a reasonable time.
Changes
We will post any changes to this policy here and, for material changes, notify subscribing properties via the dashboard or email.