Legal
Privacy and data handling
Last updated: October 2026 · Plain-language summary. The pilot agreement governs; review this with counsel before it goes public.
Strand is a job console for distributors. When your company uses it, two parties handle your data: your company decides what goes in, and we (the operator) host and maintain the system. This page says exactly what we store, why, and how it leaves.
What we store
Everything in Strand exists because a workflow step needs it. There are no hidden profiles, no tracking pixels, and no ad tech anywhere on this site or in the app.
| Data | What it is | Why it's there |
|---|---|---|
| Job records | Customer job data: job numbers, BOM lines, quotes, vendor POs, submittals, pick tickets, invoices, change orders, notes. | The product. Stored per company, visible only to that company's users. |
| Contacts | Names and email addresses of your customers, vendors and your own staff that you enter. | Routing quotes, RFQs, notifications and audit trails. We email your contacts only when your workflow triggers it (an RFQ you sent, an alert you configured). |
| Files | Documents you upload: BOMs, POs, submittals, closeout docs. | Attached to jobs, stored per company, served only to users your company's permissions allow. |
| Accounts & auth | Your staff's name, email, role(s), and either a salted password hash or an Entra (Azure AD) object id. Session tokens are stored as salted hashes. | Sign-in and role-based access. We never store your passwords in any readable form. |
| Audit trail | Who changed what, when, from which role. Sign-ins, lockouts, denied permission attempts. | Distributors asked for it; jobs with money attached need a paper trail. Append-only. |
| Operational logs | Request metadata (timestamp, which company, endpoint, status, duration) for slow or failed requests. | Finding bugs and slow queries. Not used for profiling anyone. |
Who can see it
Your data is separated by company on day one: every record carries a company scope, every query is bound to it, and an automated audit suite fails our builds if any database statement forgets the scope. Another customer's data is not reachable from your account, and our staff access production only for support and maintenance, logged as such.
Where it lives, who processes it
Strand is hosted on infrastructure we operate (not a hyperscaler console you see, but servers and storage under our accounts). As the operator we are the data processor for your company's data: we run the machines, take the backups, apply the fixes, and follow the security commitments below. Your company remains the data controller: you decide what enters, who at your company sees it, and when it's deleted.
Sub-processors
Keeping it short on purpose:
- Backups: scheduled, encrypted copies on storage we control, kept off the production box.
- Email: transactional mail (RFQs, alerts) goes out through either Microsoft Graph or an SMTP relay under our account. We send only what your workflow composes.
- Optional Entra SSO: if your company uses work-account sign-in, Microsoft's Entra ID authenticates your staff; we receive a token with their name/email and the fields listed above.
Security commitments
- Passwords: scrypt-hashed, never stored readably; repeated failures lock the account and raise an alert.
- Sessions: server-side tokens, revocable instantly (report a laptop lost and we kill the sessions).
- Transport: HTTPS everywhere; production refuses to boot in a half-configured auth mode.
- Backups: scheduled, off-box, with a restore drill we run on a schedule and can show you.
- Least privilege in the app itself: roles gate every screen and field; denied attempts are audited.
Retention and deletion
Jobs are retained through closeout plus your warranty window, then deleted; you can delete any job or contact sooner from the app, and offboarding a company is a documented hard delete of its rows and files (including pruning from future backups as they rotate out). On request we export your data (structured dumps or the reports you already run) before deletion. Ask for deletion by emailing us below; we confirm what was removed.
Children, payments, and what we don't do
Strand is a B2B work tool; it is not for children and collects no data knowingly from them. We do not process card payments in the app (invoices are records; settlement happens in your accounting system). We don't sell data, share it with advertisers, or use your business data to train anything.
Contact
Questions, deletion requests, export requests, or a request for our security checklist: [email protected]. For pilot customers, contract contacts override this address.