Legal
Privacy Policy
Last updated 28 July 2026
Turnaround QC (“Turnaround QC”, “we”) provides QA/QC document control software for refinery and petrochemical turnarounds at turnaroundqc.com. This policy explains what we collect, why, and who else touches it.
The short version
- Your project records belong to you. We access them to run the service, support you, and keep them secure — not for anything else.
- We do not sell your personal information, and we never have.
- We do not use your records to train AI models, and our AI provider is contractually barred from doing so.
- We use no advertising or tracking cookies. Our analytics do not use cookies at all.
What we collect
Information you give us
- Account details — your name, email address, and password. Passwords are handled by our authentication provider and are never visible to us.
- Company profile — company name, address, phone number, and logo, if you add them. These print on your job books.
- Project records — everything you enter: the systems and work list, isometrics, the weld log and its fit-up and repair records, NDE results, heat treatment, PMI, flange joints, the blind list, hold and witness points, the static equipment register, vessel entries and internals, exchanger bundles, thickness readings, relief valves, test packages and pressure tests, nonconformances, punch items, and so on. Plus any files you upload, such as drawings and isometrics, radiographs and NDE reports, heat treatment charts, material test reports, bench reports, calibration certificates, and photographs.
- Workforce records — if you use the qualification, certification, daily report or crew timesheet features, these hold information about your employees: names, employee numbers, licence and certification details, job classifications, and hours worked by day. This is information about your people rather than about you, and you are responsible for it. We store it, we do not use it for anything except showing it back to your account, and it is deleted with the rest of your data. Crew timesheets are deliberately excluded from the turnover job book, so they are not handed to your client with the rest of the project record.
- Team information — the email addresses you use to invite colleagues, clients, or inspectors.
- Contact details — if you email support, or leave your address for our free resources.
Information collected automatically
- Usage analytics — pages visited and features used, in aggregate. Our analytics provider is cookieless and does not build a profile of you or follow you across other sites.
- Technical data — IP address and browser type, as any web service receives, used for security and diagnostics.
What we do not collect
- Card details. Payment pages are hosted by Stripe. Card numbers never reach our servers.
- Anything from third-party trackers. There are no advertising pixels, no social media trackers, and no data brokers involved.
Why we use it
To operate your account and store your records; to provide support when you ask for it; to process payments; to send service messages such as invitations, notifications, and your data export at cancellation; to keep the service secure and diagnose faults; and to understand in aggregate which parts of the product are used.
We do not use your project records for marketing, and we do not build advertising profiles.
AI document reading — read this part
When you choose Read from document, that document is sent to Anthropic to extract the values on it. This only happens when you explicitly select a file and press the button. It never happens in the background, and no record is sent to any AI provider unless you initiate it.
- The document is processed to fill in that one form, and the result is returned to you to check before anything is saved.
- Anthropic does not train models on data submitted through its commercial API. That is a contractual commitment we rely on, not an assumption.
- If you would rather no document ever left our infrastructure, do not use the feature. Every field it fills can be typed by hand, and nothing else in Turnaround QC sends your data to an AI provider.
Who else processes your data
We use the following providers. Each is bound to process data only on our instructions.
| Provider | What it does | What it sees |
| Supabase | Database, authentication, file storage | Account details and all project records and files |
| Netlify | Website and application hosting | IP address and request data |
| Stripe | Payment processing | Name, email, billing and card details |
| Anthropic | AI document reading, only when you use it | The specific document you submit |
| Resend | Transactional email | Recipient name and email address |
| Umami | Cookieless website analytics | Aggregate page views; no personal profile |
| Google Fonts | Typefaces on our web pages | IP address when a page loads |
| Cloudflare (cdnjs) and jsDelivr | JavaScript libraries the app uses | IP address when a page loads |
| National Weather Service (weather.gov) | Site weather conditions | The project coordinates you set, and nothing else |
Providers are located in the United States. If you are outside the United States, using Turnaround QC means your data is transferred there.
How long we keep it
- While your subscription is active — for as long as you have an account.
- After you cancel — your records stay available for 90 days, read-only. You can sign in, read, print, export, and download attachments for that whole period, and we email you a complete export automatically when your subscription ends.
- After 90 days — your data may be permanently deleted.
- Contact and marketing addresses — until you ask us to remove them.
- We may retain limited billing records for longer where tax or accounting law requires it.
Your rights
You can, at any time and without asking us:
- Export everything. Every table exports to CSV, and Save Snapshot on the Project Turnover tab downloads a complete copy of a project that is yours outright.
- Correct anything. Records are editable in the application.
- Delete records, which go to a recoverable Trash first.
Write to info@turnaroundqc.com to request a copy of your personal data, correction, deletion of your account, or to object to how we use it. We aim to respond within 3 business days.
To delete your account, see Delete your account — it explains what is removed, what stays with your team, and how to ask.
Depending on where you live you may have additional rights — for example under the CCPA in California, or the GDPR in the UK and EU. We do not sell personal information as those laws define it, and we do not share it for cross-context behavioural advertising.
Cookies
We use no advertising or tracking cookies.
We store a session token in your browser so you stay signed in. That is strictly necessary to operate the service — without it you would be logged out on every page. Our analytics provider is cookieless by design, which is why this site has no cookie banner.
Security
Access to your records is enforced by the database itself through row-level security, not merely hidden in the interface. A user with no relationship to a project cannot read or write to it even through the API. Data is encrypted in transit and at rest by our infrastructure providers.
No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you promptly and tell you what happened.
Children
Turnaround QC is a business tool and is not directed at anyone under 18. We do not knowingly collect data from children.
Changes
If we change this policy materially, we will email account holders and update the date at the top. Continuing to use Turnaround QC after a change means the updated policy applies.
Contact
info@turnaroundqc.com — we aim to respond within 3 business days.
Turnaround QC — Texas, USA. Company registration in progress; full business details will be published here once filed.