Privacy Policy: BAMF Tracker
Effective date: June 21, 2026 Last updated: September 30, 2026
BAMF Tracker ("the App") is a self-hosted customer-relationship and job-management application published by BAMF Apps LLC ("we," "us") and operated by the business that installs and runs it ("the Operator"). This policy explains how the App handles information.
The most important thing to understand: who controls your data
BAMF Tracker is self-hosted. Each Operator runs its own private instance of the App on its own server (for example, an on-site NAS), and all operational data is stored in a local database on that server. BAMF Apps does not host, receive, collect, or have access to the data inside an Operator's instance.
- If you are a business using BAMF Tracker, you are the data controller for the information you put into it (your customers, jobs, employees, etc.). This policy describes how the software behaves; your own obligations to your customers and staff are yours to meet.
- If you are a customer or employee of a business that uses BAMF Tracker, the business (not BAMF Apps) is responsible for your data. Please direct privacy requests to that business. We can help with how the software works, but we cannot access their instance.
What information the App handles
The App stores the following on the Operator's server (and caches some of it in the browser for offline use):
- Contact information: names, email addresses, phone numbers, and physical service/billing addresses for customers, leads, and crew members.
- Account information: staff login email and a one-way hashed password (SHA-256), role (admin/crew), and session tokens. Optionally, a Google account identifier if the Operator enables Google Sign-In.
- Job and business content: jobs, workflow stages, tasks, notes, site surveys, quotes, contracts, signatures, and uploaded files (photos, PDFs). Attachments are stored in the database.
- Financial information: invoice and payment records and amounts. When Stripe is enabled, Stripe invoice and payment-intent identifiers are stored. Card/bank numbers are entered on and handled by Stripe; the App does not store full payment-card numbers.
- Solar system data: for the Operator's solar customers: inverter/battery telemetry, plant and station IDs, and equipment serials read from the EG4/Luxpower monitoring service.
- Operational logs: the server writes technical logs (e.g., connection and error messages) to its own console/log output. These stay on the Operator's server.
What the App does not do
- No third-party analytics, advertising, or crash-reporting SDKs are included (no Google Analytics, Firebase, Crashlytics, Sentry, Mixpanel, Amplitude, ad networks, etc.).
- No tracking across other apps or websites, and no sale of personal information.
- The App does not access your device's GPS location, microphone, contacts, or photo library. (Service addresses are typed in and geocoded; they are not collected from device location.)
On-device vs. transmitted
- On the Operator's server: the master database (SQLite), including everything listed above, plus file attachments and backups.
- On your device (browser): a cached copy of the data you work with is stored in IndexedDB so the App works offline, and a session token is stored in the browser's session storage. This local cache clears when you sign out or clear site data.
- Transmitted to third parties: only for the specific integrations the Operator enables (see below). With no integrations configured, the App's data stays entirely within the Operator's instance.
Third-party services (only when the Operator enables them)
Each integration below is optional and off until the Operator configures it. When enabled, only the data needed for that feature is sent to that provider:
| Service | What is sent | Purpose |
|---|---|---|
| Stripe | Invoice amounts, customer name/email, payment identifiers | Process card payments and invoicing |
| Google Maps / Geocoding / Static Maps | Service addresses | Convert addresses to coordinates; render maps |
| Google Sign-In (OAuth) | Google account sign-in token | Optional staff login |
| Gmail API | Recipient email and message content | Send transactional/notification emails |
| OpenStreetMap Nominatim | Service addresses | Fallback geocoding |
| Discord | Notification text (e.g., job/payment events) | Team notifications |
| EG4 Monitor | EG4 account credentials, plant/station/serial IDs, setting values | Read & control customer solar inverters |
| OpenSolar | Project/design identifiers | Import solar designs and pricing |
| Anthropic (Claude) | Only the activity text included in a requested summary | Generate optional AI job summaries |
| Weather/geo/permit data (Open-Meteo, NWS, USGS, ASCE, Hawaii GIS, county qPublic) | Site coordinates / parcel lookups | Wind, seismic, and hazard data for permit packets |
These providers process the data under their own privacy policies and terms. The Operator is responsible for choosing which to enable and for honoring the terms of each.
Data retention
Operational data persists on the Operator's server until the Operator deletes the relevant records or decommissions the instance. Session tokens expire automatically. Backups created by the Operator may retain data until those backups are rotated or deleted. Payment and invoice records may be retained longer where required for accounting or legal reasons. Because the App is self-hosted, retention is ultimately controlled by the Operator.
Security
- Passwords are stored as one-way hashes, not plain text.
- Access requires an authenticated session; roles (admin/crew) limit what each user can do.
- Higher-risk actions (such as writing settings to live solar hardware) are gated behind explicit controls and confirmation steps.
- Network access to the App and the security of the host server, backups, and any enabled integration keys are the Operator's responsibility. We recommend HTTPS, strong admin credentials, and restricted network exposure.
No system is perfectly secure, and we cannot guarantee absolute security.
Children's privacy
BAMF Tracker is a business tool and is not directed to children under 13 (or the equivalent minimum age in your jurisdiction). We do not knowingly enable the collection of personal information from children. If a child's information has been entered into an Operator's instance, contact that Operator to have it removed.
Your privacy rights
Depending on where you live, you may have rights over your personal information, including the right to access, correct, delete, port, or restrict/object to processing, and (under U.S. state laws such as the CCPA/CPRA) the right to know what is collected and to opt out of "sale" or "sharing." BAMF Tracker does not sell or share personal information for advertising and uses no cross-app tracking.
Because the data lives in the Operator's instance:
- Customers/employees of an Operator: send rights requests to the business that runs the instance; they can fulfill them directly in the App.
- Operators: you can exercise these rights for any record directly within the App (view, edit, export, delete). For questions about the software, contact us at the address below.
We (BAMF Apps) will not discriminate against you for exercising these rights.
GDPR/UK note
Where the EU/UK GDPR applies, the Operator is the controller and the App is the tool the controller uses to process data. Lawful bases (e.g., contract, legitimate interests, consent for optional integrations) are determined by the Operator. BAMF Apps does not act as a processor of Operator data because it has no access to it.
International data transfers
The App itself runs wherever the Operator hosts it. If the Operator enables an integration, data sent to that provider may be processed in other countries (for example, the United States) under that provider's safeguards. Enabling those integrations is the Operator's choice.
Changes to this policy
We may update this policy as the App evolves. The current version is always posted at
https://bamfapps.com/apps/bamf-tracker/privacy with an updated "Last updated" date. Material
changes will be reflected there.
Contact
Questions about this policy or the App: Email: support@bamfapps.com Support: https://bamfapps.com/apps/bamf-tracker/support
This document is a plain-English template provided for transparency and is not legal advice. Operators should confirm it fits their jurisdiction and practices.