Who and what this covers
This policy covers the DealBoard app and related account, subscription and support services. The separate Brewed Apps website policy covers general visits to the corporate website. DealBoard is a work tool for tracking vehicle sales and estimated compensation.
Information we process
- Account information: your email address, account identifier, authentication and verification information, account timestamps, and sign-in preferences. Password-based sign-in and password changes are handled by Supabase Auth. When you explicitly accept the Terms of Use and acknowledge the Privacy Policy during registration, we record the document versions and server-recorded date with your account. This is not marketing consent, and this acknowledgement record does not include your IP address or device details. We do not assign a registration acknowledgement retrospectively to an older account.
- Sales and compensation records: pay plans and their versions, commission rates and tiers, gross amounts, unit shares, deal status and dates, bonuses, month periods and related history. Optional fields include stock numbers, customer names, VINs and comments.
- Subscription information: account-linked access status, store and product identifiers, transaction references, trial or paid status, renewal or expiry information, cancellation or billing status, and offer eligibility or redemption records. Google Play handles checkout and payment credentials; DealBoard does not ask you to enter card details in the app.
- Support and email information: your email address, messages you send, and information needed to send and track delivery of transactional account or subscription emails.
- Technical information: limited error reports, app release and platform information, timestamps and filtered stack traces. Providers may also process IP addresses, network and device metadata, and service logs when delivering or securing their services.
Only enter customer information you are authorized to use. Customer names, VINs and comments are optional. Do not enter payment card or bank details, government identifiers, credit applications, passwords, or other unnecessary sensitive information.
How information is used
- Create and secure your account; confirm your email and help recover access.
- Save and synchronize your records, display history, and calculate compensation estimates.
- Verify subscriptions and access, display eligible offers, manage their redemption, and send transactional emails.
- Respond to support and privacy requests, investigate errors and protect against misuse.
- Meet applicable legal obligations and address disputes where necessary.
Providers and disclosures
We use the following services for the functions described here:
- Supabase: account authentication, the cloud database, synchronization and server-side account and access operations.
- RevenueCat and Google Play: purchase verification, subscription status and billing-related access. RevenueCat uses your DealBoard account identifier to associate a subscription with your account. Google processes purchases under its store terms and privacy practices.
- Resend: delivery of transactional emails, including account messages and subscription welcome messages.
- Sentry: limited app diagnostics. The app is configured without session replay, attached screenshots, view hierarchies or performance tracing. Its reporting filters exclude deal contents, account details and raw error messages.
- Cloudflare and our website hosting provider: delivery and protection of web pages and the authentication-link handoff. These services can process request and security metadata.
- Google Workspace: the support mailbox and messages you choose to send us.
Service providers process information needed for their roles and may have their own legal obligations. We may disclose information when legally required or necessary to protect users or address misuse. The current app does not include advertising or cross-app advertising tracking. This does not mean that service providers receive no technical information.
On your device & security
Native authentication credentials are persisted using SecureStore, backed by the device’s Keychain or Keystore. Sales records use an account-specific SQLite cache so you can view previously loaded information offline. The sales cache is separate from credential storage; it should not be treated as an encrypted backup.
Signing out or switching accounts clears the previous account’s local sales cache. An offline device cannot receive a remote deletion immediately. Sign out on other devices, or remove DealBoard’s local app data, when disposing of a device or completing deletion.
Optional biometric unlock uses the operating system’s authentication result. DealBoard does not receive your fingerprint or face templates. Network connections use HTTPS, and database access is restricted by account and access controls. No security measure can guarantee protection against every risk.
Retention & deletion
Account and sales records remain in the service while needed to provide your account and history. An expired or cancelled subscription does not itself delete that information. Deleting an individual deal or bonus removes it from normal views; a marked-deleted record can remain in the database for synchronization until the account is deleted.
Successful account deletion removes the authentication account and its ordinary application records: profile, pay plans and tiers, deals, bonuses, month history, access grants, subscription sync and email records, offer-redemption records, and registration acknowledgements. It also clears the current device’s session and account cache when completed in the app.
Before account deletion, a restricted administrative case is created to complete the deletion request across providers and respond to you. It temporarily retains your account identifier (also used by RevenueCat), contact email, authentication email references, and minimal email-delivery references such as Resend message identifiers, recipients and times. It does not retain sales records, email bodies, passwords or access tokens. The case remains after the app account is removed. Once provider outcomes and any necessary retention exceptions are verified and the case is closed, its personal identifiers, contact information and provider references are cleared; a minimal non-personal outcome record remains.
Deletion is not an automatic purge of every provider’s records. Store transaction records, provider logs or backups, previously delivered emails, and support correspondence can exist separately. Minimal webhook-processing records (event identifiers, type, environment and processing times) are not removed by the account deletion operation; they support duplicate-event handling. These records do not contain a deal payload or a direct DealBoard account identifier.
The administrative case is a follow-up record, not proof that provider-held data has been erased. An operator must complete the relevant provider deletion steps or verify a legitimate retention basis and period for an exception. We will explain relevant exceptions and the expected handling of your request rather than promise immediate removal from every system. See account deletion options or contact hello@brewedapps.com.
Your choices & requests
You can update supported account details and sales records in the app, disable optional biometric unlock, and request account deletion. To ask for access to or a copy of your information, correction, deletion, or information about its handling, email hello@brewedapps.com. You may also ask about withdrawing consent or restricting a use where applicable; some requests can affect the services we can provide.
We verify ownership before disclosing or deleting account information and request only what is reasonably needed for that verification. Never send a password, recovery link, verification code or payment credentials. Your rights and the applicable response requirements depend on your location and the law. You may raise a concern with the relevant privacy authority; nothing here limits mandatory rights.
International processing
DealBoard uses cloud providers whose infrastructure and support operations may be outside your province, state or country, including in the United States. Information processed there may be subject to different laws and lawful access by authorities. Contact us for information about the providers involved in your request. We do not represent that all processing stays in one country.
Policy updates & contact
Updates to this policy will identify their effective date and version. Where required, we will provide additional notice or obtain consent for a change in data use.
Contact First Market Equities LLC, operator of the Brewed Apps brand and DealBoard, at hello@brewedapps.com.