PRIVACY & DATA SECURITY

Privacy Policy

This policy explains how Chapter collects, uses, stores, and protects data when you use our application and services.

Effective and last updated: August 20, 2026

01

Overview and scope

Chapter is an operational platform that helps organizations manage checklists, tickets, follow-ups, and outlet activities. This policy applies to the Chapter mobile application and the related services we provide.

Your organization's role

Your Chapter account is generally created or managed by the organization where you work. For operational data, your organization determines how and why the data is used, while Chapter processes it to provide the service according to the organization's instructions.

02

Data we process

We may process the following categories of data:

  • Account and organization data — your name, username, role, and assigned company, brand, outlet, or section.
  • Operational data — checklist responses and statuses, tickets, comments, mentions, activity timestamps, and follow-up history.
  • Photos and attachments — checklist evidence or ticket attachments that you capture with the camera or select from your photo library.
  • Device and technical data — platform type, notification token, IP address, application logs, and diagnostic information required for service security and reliability.
  • Support data — information you submit when contacting an administrator or our support team.

Chapter does not use user data for targeted advertising and does not sell personal data.

03

How we use data

We use data to:

  • authenticate users and enforce access permissions;
  • display relevant tasks, checklists, tickets, and notifications;
  • store work evidence and support operational collaboration;
  • maintain security, prevent misuse, and resolve service disruptions;
  • respond to support requests and comply with applicable legal obligations; and
  • improve the functionality, stability, and performance of the service.

04

Device permissions

Camera & photo library

Used only when you capture or select checklist evidence and ticket attachments.

Notifications

Used to deliver relevant task, ticket, mention, and activity updates.

You can change these permissions through your device settings. Some features may not work when a required permission is disabled.

05

Data sharing

We may share data on a limited basis with:

  • your organization, including administrators and authorized users according to their role and access scope;
  • service providers supporting infrastructure, storage, security, and notification delivery, including Firebase Cloud Messaging; and
  • competent authorities when required by law or necessary to protect the rights and safety of users.

Service providers are permitted to process data only to provide services to Chapter and are subject to data protection obligations.

06

Storage, security, and retention

We implement reasonable technical and organizational safeguards, including role-based access controls, protected connections, secure storage of authentication tokens on devices, activity logging, and restricted internal access.

Data is retained while an account or organizational service is active and for as long as needed for operational purposes, dispute resolution, security, backups, or legal obligations. When it is no longer required, data is deleted or anonymized in accordance with our retention procedures and customer instructions.

No system is entirely risk-free. If you become aware of a suspected security incident, contact your organization's administrator or the Chapter team immediately.

07

Your rights and data deletion

Subject to applicable law, you may request access, correction, restriction, or deletion of your personal data. Because your account is managed in an organizational context, the fastest route is usually to contact your organization's administrator.

Account or data deletion requests

Include your username and organization name. Do not send a password, token, or other credentials by email.

Submit a request

We may request additional information to verify the identity and authority of the requester. Some data may be retained when required by law or necessary for security and dispute resolution.

08

Children's privacy

Chapter is intended for professional use by organizations and is not directed to children. We do not knowingly collect personal data from children through the service.

09

Changes to this policy

We may update this policy to reflect changes to our services, practices, or legal requirements. The latest revision date will always appear at the top of this page. We may communicate material changes through the application or your organization.

10

Contact

For privacy questions, data rights requests, or security reports, contact:

Include your organization name so we can direct the request to the appropriate administrator.