Privacy policy
Who we are
LifecycleDashboard.com ("we") provides an IT asset lifecycle management service to federal programs, lines of business, facilities and other organizations ("customers"). Contact: briefings@lifecycledashboard.com.
What data the service holds
- Account data: name, work email address, role, hashed password, sign-in and session records (time, browser user agent, IP address for rate limiting and security logs).
- Asset data entered by the customer: asset identifiers, serial numbers, models, locations, departments, purchase and warranty dates, costs, and the names of people or teams recorded as owners. The customer decides what to enter and is the controller of that data; we process it on the customer's behalf.
- Public label reports: free-text problem reports submitted from a scanned asset label are stored against the asset without any personal data unless the reporter types it in.
- Request logs: IP address, request path, user agent and timestamps, kept for security monitoring.
Why we process it
To provide the service to the customer, to keep accounts secure (authentication, rate limiting, audit logging), and to operate and improve the service. We do not sell data, use it for advertising, or train models on it.
Where it is stored
Each customer's data is stored in that customer's own dedicated PostgreSQL database, hosted by Neon in the United States (AWS US East, N. Virginia), and reached only through that customer's own application instance on Cloudflare's network. Per-customer region selection is on the roadmap. See Security & sub-processors.
Retention and deletion
Customer data is retained for the life of the engagement and deleted within 30 days of termination on request. Customers can export their data at any time, including before deletion, to meet their own records-retention requirements. Security and audit logs are retained for up to 90 days unless the customer's contract requires longer. Point-in-time database history, used for recovery, is retained for 7 days.
Cookies
The application sets one strictly necessary cookie (ld_session) that identifies your sign-in session. It is not used for tracking. The marketing site sets no cookies.
Your rights
Individuals whose data is held by a customer should contact that customer, who controls the data. For questions about our own processing, contact the address above.
Changes
We will post changes to this page and note the effective date.