EDI-ready in every applicable state 31 jurisdictions cataloged
support@smepro.app
Legal

Privacy Policy

Effective June 12, 2026 · SMEPro is a business-to-business service; we process data for operator organizations
The short version. We collect what the product needs to track and validate your regulatory filings — nothing else. No advertising, no sale of data, no third-party analytics or tracking scripts anywhere on this site or in the application.

1. What we collect

CategoryExamplesSource
Account data Name, work email, role, organization, hashed password, last sign-in time Provided at provisioning or by your workspace admin
Operational data Asset inventories (wells, leases, facilities), filing obligations, form payloads, validation findings, agency confirmation numbers, regulatory registrations (e.g., RRC P-5 operator number) Entered or imported by your users
Audit records Who created or changed an obligation or submission, and when — written by database triggers as part of the product's audit-trail feature Generated by the Service
Technical logs IP address, request path, status, timestamp from infrastructure request logging Generated by hosting infrastructure

We do not collect payment card data through the application (billing, where applicable, is invoiced), and the Service is not directed to or intended for children.

2. How we use it

We do not use your data for advertising, do not sell or rent it, and do not train machine-learning models on your filing contents.

3. Cookies and local storage

This website sets no cookies and loads no third-party scripts, fonts, pixels, or analytics. The application uses browser storage for exactly three values, all functional:

KeyStoragePurpose / lifetime
smepro_tokensession storage Your signed-in session token (12-hour expiry; cleared when the tab closes)
smepro_usersession storage Your display name and organization, to render the workspace header
smepro_org / smepro_apilocal storage Workspace selection and optional API endpoint override

4. Where your data lives

Production data is hosted on Google Cloud Platform in the us-central1 (Iowa, USA) region: the application runs on Cloud Run and data is stored in a managed Cloud SQL PostgreSQL instance with high availability and point-in-time-recovery backups. Secrets (database credentials, token-signing keys) are held in GCP Secret Manager, not in application code.

5. Sharing and subprocessors

We disclose data only:

6. Security

Highlights — the full picture is on the Security overview:

7. Retention and deletion

8. Your rights

Workspace admins can manage users and export Customer Data in-product or by request. Individual users may request access to, correction of, or deletion of their personal information by emailing support@smepro.app; we respond within 30 days. Because SMEPro processes most data on behalf of your employer (the workspace owner), we may route requests about operational data to your workspace admin, as B2B data -protection frameworks contemplate. We honor applicable rights under US state privacy laws for the personal information we control.

9. Changes and contact

We will post any changes to this policy here and, for material changes, notify workspace admins by email at least 30 days in advance. Questions and requests: support@smepro.app.