Skip to content

Mobile application

Privacy Policy — ToolFlux app

Last updated: 16 August 2026

Translation for convenience

This English text is provided to help you understand the document. The Romanian version is the legally binding one; in the event of any discrepancy between the two, the Romanian text prevails.

This policy covers the ToolFlux mobile application for iOS and Android. The toolfluxapp.com website processes different data for different purposes — cookies, the contact form, the digital assistant — and has its own policy: toolfluxapp.com/privacy-policy.

1. Who is responsible

Data controller: MORNINGSTAR SOFTWARE S.R.L., registered in Romania, trade register no. J2026050102002, tax code (CUI) 55437739. The registered office is shown in the footer of every page. Data protection contact: support@toolfluxapp.com.

One distinction decides most of what follows. For the person who registers the account we are the controller. For the data a company enters about its own employees — who holds which tool, and the signatures — we are only the processor, acting on that company’s instructions under the Data Processing Agreement. An employee’s request therefore goes to their employer, and we assist them technically; we may not act on it ourselves.

2. What the app collects

CategoryDataPurpose
IdentityFirst name, surnameIdentifying the user within the company
ContactE-mail addressSign-in, notifications, password recovery
PhotographsImages attached to assets (tools, equipment)Visual documentation of the inventory
SignaturesThe signature image captured at handoverEvidence of the transfer of custody
CustodyWho holds which asset, since when, with what due dateA record of responsibility for equipment
Company dataName, locations, employeesMulti-tenant operation
Device tokenFirebase Messaging (FCM) tokenDelivering notifications
Audit logActions in the app (transfers, assignments, stocktakes)Logistical traceability and security
Technical dataDevice type, operating-system versionDiagnosing faults

If you sign in with Google, Facebook or Apple, we receive your e-mail address, profile name and the account identifier from them. We never receive or store your password.

The app has no analytics, no crash reporting and asks for no location permission. The camera is used only to scan labels and take photographs of assets, when you choose to.

Signatures are stored as an image only. We do not record pressure, timing or stroke dynamics, so they are not biometric data within the meaning of art. 9 GDPR.

3. Legal basis

  • Performance of a contract (art. 6(1)(b)) — everything the app needs to work: account, assets, locations, custody.
  • Consent (art. 6(1)(a)) — photographs and push notifications, which you can refuse and withdraw.
  • Legitimate interest (art. 6(1)(f)) — the audit log, for traceability and security.
  • Legal obligation (art. 6(1)(c)) — where the law requires it.

4. Where the data is, and where it is processed

The database is Google Firestore in europe-west4 (the Netherlands), and since 10 September 2026 the server functions that act on it — daily alerts, notifications, account deletion — run in the same region. So your data is both stored and processed in the European Union. Until that date those functions ran in us-central1 (United States); that processing relied on the safeguards the GDPR provides — standard contractual clauses and the EU–US Data Privacy Framework, to which Google LLC is certified.

Multi-tenant isolation. Each client company operates in its own data space. No user of one company can reach another company’s data.

Security measures. HTTPS/TLS throughout; Firebase App Check (Play Integrity on Android, App Attest on iOS); the FCM token is deleted on sign-out to prevent cross-tenant leakage; and an optional app lock with PIN or biometrics, which is verified on your device and never leaves it.

5. Who else sees the data

We do not sell personal data and we do not pass it to anyone for advertising. We use technical suppliers only:

  • Google LLC — Firebase Auth, Firestore, Storage, Cloud Functions, FCM, App Check.
  • Apple, Google — only where a subscription is bought through their store; the purchase is made from them, not from us.

6. How long we keep it

CategoryRetention
Active account dataFor as long as the app is used
Audit log12 months from the entry
FCM tokenDeleted automatically on sign-out
Offline copy (SQLite)Local to the device, removed on uninstall
Asset photographsFor as long as the asset exists in the system
Signed handover reports«period to be set» — see section 7

7. Deleting your account and data

You can delete your account from within the app, in Settings, or request it without installing anything at toolfluxapp.com/delete-account.

When a company is deleted, the deletion is complete. Every tenant collection, the company record, all files in storage — asset photographs, profile pictures, signed handover PDFs — and the sign-in accounts of every member. Nothing is retained as an orphan.

One thing is still being settled: whether signed handover reports must be retained for a period despite a deletion request, because they are evidential documents. Until that is resolved, they follow the deletion above.

8. Push notifications

Notifications tell you about overdue items, expiring vehicle documents and stock below its threshold. They require your permission, which you can withdraw at any time in your device settings. The token that addresses your device is deleted when you sign out.

9. Working offline

The app keeps a local copy (SQLite) so the field flow works without a signal. It lives on your device, is not readable by other apps, and is removed when you uninstall. It is a copy, not a separate collection: nothing is gathered offline that is not described above.

10. Is providing this data compulsory

Nothing is collected because the law requires it. Name and e-mail are needed to create an account — without them the app cannot work, and that is the only consequence. Photographs, notifications and the app lock are all optional.

11. Automated decisions

We make no automated decisions with legal or similarly significant effects, and we do not profile anyone. Reports such as the maintenance analysis rank equipment, never people, and a person always decides what to do about them.

12. Data protection officer

We have not appointed a data protection officer; our processing does not meet the thresholds in art. 37 GDPR that would require one. Data protection questions reach us at the address in section 1 and we answer them ourselves.

13. Minors

The app is a professional tool and is not directed at anyone under 18. We do not knowingly collect data from minors.

14. Your rights

Access, rectification, erasure, restriction, portability, objection, and withdrawal of consent at any time. Write to the address in section 1; we answer within 30 days.

If you are an employee of a client company, your request goes to your employer, who decides it — see section 1. We will help them act on it.

You may also complain to the Romanian supervisory authority, ANSPDCP: dataprotection.ro.

15. Changes

If we change this policy substantially we will announce it in the app before the change takes effect. The date at the top always shows the current version.