Legal
Privacy Policy
Effective date: 27 August 2026
Bucket 6 Inc., a registered trade name of Orange Chair Corporation, 117 Logan Avenue, Geneva, Illinois 60134, is the controller of the personal information described here.
This policy covers assetlink.us and the AssetLink application at app.assetlink.us.
1. What we collect
Account information. When someone in your organisation creates an account we collect their name, email address, and the organisation they belong to. Authentication is handled by Clerk; if a user signs in with Google, we receive their name and email address from Google, and never their Google password.
Organisation records you enter. The assets, inspections, work orders, photographs, personnel records and notes your organisation puts into AssetLink. This can include the names, employee identifiers, email addresses and telephone numbers of your staff, because work is assigned to people. We treat that as your data, held on your behalf.
Billing information. Handled by Stripe. We receive a customer identifier, the subscription status, and the last four digits and brand of a card. We never receive or store full card numbers.
Support correspondence. What you send us, so we can answer it.
Technical information. IP address, browser type and pages visited, in server logs and analytics.
2. Why we process it
- To provide the service and keep your organisation's data separated from every other organisation's — the basis is performance of our contract with you.
- To take payment — performance of contract.
- To send transactional email such as trial and billing notices — performance of contract.
- To secure the service, investigate abuse, and keep backups — our legitimate interest in running a service safely.
- To understand aggregate usage so we can improve the product — legitimate interest, and we do not use asset data for it.
We do not sell personal information, and we do not use your data to train machine-learning models.
3. Sub-processors
| Processor | What it handles | Where |
|---|---|---|
| Google Cloud Platform | Application hosting, database, file storage for photographs | United States (us-central1) |
| Clerk | Authentication and account management | United States |
| Stripe | Payment processing and billing | United States |
| Resend, with Amazon SES | Transactional and notification email | United States |
| Formspree | The contact form on assetlink.us | United States |
| Google Analytics | Aggregate website and application usage | United States |
All customer data is stored in the United States. If your organisation has a data residency requirement that this does not satisfy, tell us before purchasing.
We will update this list before adding a processor that handles customer data.
4. Analytics, and what we deliberately do not send
We use Google Analytics to understand aggregate usage.
Page paths are recorded without query strings, on purpose. The application puts asset identifiers and record numbers into URLs, and those describe what a particular department is working on. Automatic page-view collection is switched off and replaced with an explicit call that sends the path only, so the query string never leaves the browser.
We do not send your asset data, your personnel records, or the contents of any record to any analytics provider.
5. Cookies
The application sets cookies that are necessary to keep you signed in and to keep your session secure. Analytics sets cookies to distinguish repeat visits in aggregate. We do not use advertising or cross-site tracking cookies.
6. Retention
Account and organisation data is retained while your account exists, and after it closes, until you ask us to delete it. As explained in Terms §12, this is deliberate: public bodies often have statutory retention schedules, and a vendor that quietly destroyed municipal records could put you in breach of one.
Deletion is on request. Ask us and we will permanently delete your organisation's data and confirm when it is done.
Server logs are retained for 30 days.
Billing records are retained as long as tax and accounting law requires.
7. Security
Data is encrypted in transit. Database credentials and API keys are held in a managed secrets service rather than in configuration. Every request to the application is scoped to a single organisation, and that separation is enforced by the server rather than by the interface.
Photographs and file attachments are stored in cloud object storage at unguessable addresses. Anyone holding such an address can open the file, so do not use AssetLink to store documents that require access control — it is built for infrastructure records, not personnel files or anything else sensitive.
No system is perfectly secure. If you find a vulnerability, please tell us through assetlink.us/contact rather than disclosing it publicly, and we will work with you.
8. Your rights
Depending on where you live you may have rights to access, correct, delete, export or object to the processing of your personal information. Ask through assetlink.us/contact and we will action it within the time your law requires.
Where the request concerns records held on behalf of a public body, we will refer it to that organisation, which is the records custodian — and we will help them respond.
We will not discriminate against anyone for exercising these rights.
9. Children
AssetLink is a tool for public agencies and is not directed at children. We do not knowingly collect information from anyone under 16.
10. Changes
We may update this policy. Material changes will be notified by email or in the product before taking effect.
11. Contact
Privacy questions: assetlink.us/contact
Questions about this document: assetlink.us/contact