CabTracker is a web and iOS application operated by Rainier Woodworking
Company ("Rainier Woodworking", "we", "us", "our") that lets authorized
customers and staff view the status of proposals and orders in production
and request help on specific work orders. This policy explains what
information the service handles and why.
Information we collect
Account information. When you create an account or
sign in, we collect your name, email address, and username. If you sign
up with a username and password, your password is stored only as a salted
bcrypt hash — we never see or store the plaintext.
Sign-in identifiers. If you sign in with Apple or
Google, we receive a unique identifier from that provider (Apple's
sub claim or Google's account id) and, where you permit it,
your name and email, solely to create and authenticate your account. We
do not receive your provider password.
Customer association. An administrator may link your
account to one or more customer or company records in our manufacturing
platform (Innergy) so that the app shows only the proposals and orders
that belong to those customers.
Order and proposal data. The proposal, project,
work order, production-step, and shipment information shown in the app
originates from Rainier Woodworking's business systems and is displayed
only to accounts authorized to see it.
"Need Help?" reports (iOS). When you tap "Need
Help?" on a work order in the iOS app, you can include a description,
select a shipment item, and optionally attach photos. That report is
composed in the native iOS Mail composer and sent by you, from your
own email account, to Rainier Woodworking support. We do not store the
report or the photos on our servers; the content is delivered to our
support inbox and retained according to our normal email retention
practices.
Camera and photo library (iOS). The iOS app requests
access to your camera and photo library only when you choose to attach
images to a Need Help report. Images are kept in memory until the
composer is opened and then handed to the Mail composer. The app does
not upload, scan, or otherwise process the contents of your photo
library.
Authentication tokens and session cookies. The
iOS app stores a signed JSON Web Token in the iOS Keychain to keep you
signed in. The website uses a short-lived HTTP session cookie for the
same purpose. These are used only to authenticate your requests.
How we use information
We use this information only to:
Authenticate you and keep you signed in;
Show the proposals, orders, and production status that belong to
your account or associated customer;
Deliver Need Help reports to our support team and respond to them;
and
Maintain the security and integrity of the service.
We do not use your information for advertising, profiling, or any
purpose unrelated to operating CabTracker.
How information is shared
We do not sell your information. The service uses the following
third parties strictly to provide the features above:
Apple and Google — when you
choose to sign in with one of those providers, they authenticate you
and return the identifiers described above. Their use of your
information is governed by their own privacy policies.
Innergy — our manufacturing platform, the
source of the proposal, project, work order, and shipment data shown in
the app.
Hosting provider — we host the CabTracker
server on Railway. Account information and Innergy data pass through
that infrastructure to reach your device.
We disclose information only as described here, with your consent, or
as required by law.
Security
All traffic between the app or website and our servers is encrypted in
transit using HTTPS. Passwords are stored as bcrypt hashes. Authentication
tokens on iOS are kept in the iOS Keychain. Access to administrative
features is gated by role-based controls.
Tracking
The app does not track you across other companies' apps or websites and
contains no third-party advertising or analytics SDKs.
Children's privacy
CabTracker is intended for business use by authorized customers and
staff of Rainier Woodworking. It is not directed to children under 13,
and we do not knowingly collect information from children. If you
believe a child has provided us with information, please contact us so
we can delete it.
Data retention and your choices
We retain account information for as long as your account is active.
You may request access to, correction of, or deletion of your account and
associated data by contacting us using the details below. We will respond
within a reasonable time and may retain limited information as required by
law or for legitimate business records (for example, an order history
required for accounting purposes).
Changes to this policy
We may update this policy from time to time. When we do, we will revise
the "Last updated" date above. Material changes will be noted on the
service or by other reasonable means.