Version 2.0 · Effective 2026-04-26 · Perkio Technology Group, LLC
# Privacy Policy
**Last updated: April 26, 2026**
This Privacy Policy explains how Perkio Technology Group, LLC ("we", "us", "our") collects, uses, and protects information when you use Tractornuity (the "Service"). The Service is operated from Montgomery County, Pennsylvania, USA.
This policy applies to visitors to our website and registered users of the Service, regardless of where you are located. We extend most of the rights described in this policy to all users worldwide, including the rights granted under the European Union's General Data Protection Regulation (GDPR), the United Kingdom's Data Protection Act 2018 / UK GDPR, and the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA).
## 1. Information we collect
### 1.1 Information you provide directly
- **Account information:** your email address, display name, and (for password-based accounts) a password hash. We do not store passwords in plain text.
- **Equipment information:** the machines, attachments, manufacturers, models, serial numbers, hour readings, and service records you record in the Service.
- **Service records:** photos, receipts, lab analyses, and any other attachments you upload as part of documenting maintenance.
- **Billing information:** if you subscribe to a paid plan, your billing address and tax information. Payment card details are collected and stored by our payment processor (Stripe) and are never seen by our servers.
- **Communications:** messages you send to support, feedback, and content you submit via forms.
### 1.2 Information we collect automatically
- **Authentication tokens:** stored in your browser's local storage to keep you signed in.
- **Session cookies:** small files stored on your device. See our [Cookies Policy](/legal/cookies) for the full list.
- **Diagnostic logs:** when our servers experience errors, we record technical details (timestamps, request paths, error codes) for debugging. These logs do not include the content of your equipment records.
### 1.3 Information from third parties
- **Single sign-on providers:** if you sign in with Google, Microsoft, or Apple, we receive your email address and a unique identifier from that provider. We do not receive your contacts, calendar, or other data from your account with that provider.
## 2. How we use information
We use the information we collect to:
- Operate the Service — sign you in, save your machines and service records, send you maintenance reminders.
- Process payments for paid subscriptions.
- Send transactional emails (account verification, password resets, maintenance reminders, security alerts).
- Display advertisements on the free tier (see Section 4).
- Investigate and prevent fraud, abuse, and security incidents.
- Improve the Service — diagnose bugs, understand which features are used, develop new functionality.
- Comply with legal obligations.
We do not sell your personal information. We do not share it with data brokers. We do not use it to train artificial intelligence models, ours or anyone else's.
## 3. Legal bases for processing (GDPR / UK GDPR)
If you are in the European Economic Area, the United Kingdom, or another jurisdiction with similar law, we rely on the following legal bases for processing your personal information:
- **Contractual necessity:** processing required to provide the Service you signed up for (your account, machines, service records, reminders, billing).
- **Legitimate interests:** diagnostic logs, fraud prevention, anonymized analytics, and direct sponsor-paid advertisements that fund the free tier. We balance these interests against your privacy and you can object at any time.
- **Consent:** personalized advertising and certain analytics. You provide consent through our cookie banner and may withdraw it at any time via the Cookie settings link.
- **Legal obligation:** retention required by tax, accounting, or other law.
## 4. Advertisements
The free tier of the Service is supported by advertisements. We display two kinds of ads:
- **Direct sponsor ads:** advertisements we sell directly to sponsors (typically equipment dealers, parts suppliers, and related businesses). These ads do not use cookies to track you between websites. We log the number of times each ad is displayed and clicked, but those logs do not contain your IP address, browser fingerprint, or any third-party identifier.
- **Google AdSense (when enabled):** Google may serve advertisements on our pages. AdSense uses cookies and similar technologies to measure performance and, when you have given advertising consent, to personalize ads to your interests. AdSense's data practices are governed by Google's privacy policy: https://policies.google.com/privacy.
Paid subscribers (Plus and Fleet tiers) do not see advertisements.
You can decline personalized advertising at any time using the Cookie settings link in the footer. When advertising consent is declined, AdSense ads are still shown but are not personalized.
## 5. How we share information
We share personal information only in these circumstances:
- **Service providers:** with vendors that operate parts of the Service on our behalf, under contractual obligations to protect the data and use it only for the agreed purpose. Current vendors include:
- Stripe (payment processing)
- Resend (transactional email delivery)
- Amazon Web Services (server and database hosting)
- Google AdSense (advertisement delivery, when enabled)
- **Legal requirements:** when we receive a valid subpoena, court order, or other legal process, and only to the extent required.
- **Safety:** when we believe in good faith that disclosure is necessary to prevent imminent harm, fraud, or a violation of our Terms of Service.
- **Business transfers:** if Perkio Technology Group, LLC is acquired or merges with another entity, your information may be transferred. You will be notified before any transfer and given the opportunity to delete your account.
We do not share information for advertising purposes beyond what AdSense may collect when you have consented to advertising cookies.
## 6. International transfers
Our servers are located in the United States. If you access the Service from outside the United States, your information will be transferred to and processed in the U.S. We rely on appropriate safeguards for international transfers, including Standard Contractual Clauses where applicable.
## 7. Data retention
- **Account data:** retained as long as your account is active.
- **Service records:** retained as long as the parent entity exists; you can delete individual records at any time via the Service.
- **Diagnostic logs:** retained for up to 90 days, then deleted.
- **Consent records:** retained for as long as required to demonstrate the legal basis for processing, typically the statutory limitation period in the relevant jurisdiction.
- **Billing records:** retained for the period required by tax law (typically 7 years in the United States).
When you delete your account, we delete or anonymize your personal information within 30 days, except where retention is required by law.
## 8. Your rights
You have the following rights with respect to your personal information. We honor these rights for all users worldwide regardless of location.
- **Access:** request a copy of the personal information we hold about you.
- **Rectification:** correct inaccurate or incomplete information.
- **Deletion:** request that we delete your personal information ("right to be forgotten" in GDPR / "right to delete" in CPRA).
- **Restriction:** request that we limit how we use your information.
- **Portability:** receive your information in a machine-readable format.
- **Objection:** object to processing based on legitimate interests, including direct marketing.
- **Withdrawal of consent:** for any processing that relies on consent (such as advertising cookies), withdraw consent at any time without affecting the lawfulness of prior processing.
- **Lodge a complaint:** contact your local data protection authority. EU residents can find theirs at https://edpb.europa.eu/about-edpb/about-edpb/members_en. UK residents can contact the Information Commissioner's Office at https://ico.org.uk.
To exercise any of these rights, email us at the address in Section 13. We will respond within 30 days (or 45 days for California residents per CPRA).
We do not discriminate against you for exercising any of these rights.
## 9. California-specific disclosures (CCPA / CPRA)
In the past 12 months, we have collected the following categories of personal information about California residents:
- Identifiers (name, email)
- Internet activity (interactions with the Service, advertising)
- Commercial information (subscription tier, billing details)
- Inferences (none — we do not build profiles)
We have not sold or shared personal information for cross-context behavioral advertising in the past 12 months, except as may occur through Google AdSense when you have consented to advertising cookies. You can opt out of advertising cookies at any time using the Cookie settings link.
You also have the right to limit our use of "sensitive personal information." We do not collect sensitive personal information as defined by CPRA.
## 10. Children's privacy
The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided personal information to us, please contact us and we will delete it.
## 11. Security
We use industry-standard measures to protect personal information, including encryption in transit (TLS) and at rest, hashed passwords, and access controls limiting who can view production data. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
If we discover a security incident affecting your personal information, we will notify you and the relevant authorities as required by law.
## 12. Changes to this policy
We may update this Privacy Policy. When we make material changes, we will:
- Post the updated policy at this URL with a new "Last updated" date.
- Bump the privacy_version, which causes the Service to prompt you to review and accept the new policy on your next visit.
- For significant changes, send a notice to your account email address.
Your continued use of the Service after the new policy takes effect constitutes acceptance of the changes.
## 13. Contact us
For questions, complaints, or to exercise your rights, contact:
**Perkio Technology Group, LLC**
Attn: Privacy
Montgomery County, Pennsylvania, USA
Email: privacy@madpretzel.com
For GDPR-related inquiries you may also contact our EU/UK representative if one is appointed; the current contact is the same address above.
Jurisdiction: Montgomery County, Pennsylvania, USA