Privacy Policy
Effective June 6, 2026
Operated by Qualityiris LLC, Wylie, Texas, USA. Effective June 6, 2026.
Welcome to QualityIris, an end-to-end garment quality assurance and inspection management platform operated via qualityiris.com. We are committed to protecting the privacy and security of the data collected from our users, including QA inspectors, buyers, and factory representatives.
This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our SaaS application.
See also: Terms of Service · Data Processing Agreement.
Processor obligations are governed by our Data Processing Agreement.
1. Data Controller
The data controller responsible for your personal data is Qualityiris LLC, Wylie, Texas, USA. For privacy questions, GDPR/CCPA requests, or to exercise your rights, contact privacy@qualityiris.com. For general inquiries, contact info@qualityiris.com.
Qualityiris acts in two distinct roles under GDPR (and equivalent laws): we are a processor for personal data contained in customer-submitted inspection content (e.g. inspector, factory representative, and buyer names, signatures, email recipients, and any personal data recorded in inspection notes, photos, or order data) — the customer organization is the controller for that data. We are a controller for operational data we collect to run, secure, bill, and improve the Service, including tenant administrator account details, billing contact information, authentication and audit logs, support correspondence, and product-analytics telemetry. This Privacy Policy covers both roles; the Data Processing Addendum in our Terms of Service §8 governs the processor role.
2. Information We Collect
We collect information that is necessary to provide our quality assurance services and to manage user accounts.
Personal Data
- Contact Information: Name, email address, and phone number.
- Professional Information: Company name and job role.
- Authentication Data: Email and password. Accounts are created either via self-service sign-up that begins a 14-day free trial (tenant administrator) or by an existing administrator inviting teammates into an existing workspace.
Inspection and Operational Data
- Inspection Records: Detailed garment inspection data, measurement logs, and production data.
- Visual Evidence: Defect photos uploaded during the inspection process.
- Digital Signatures: Hand-drawn signatures captured via a digital canvas to verify inspection reports.
- Factory Information: Names, locations, and contact details of manufacturing facilities.
Technical Data
- Local Storage: For offline functionality, inspection data is stored locally on your device (IndexedDB) and synchronized with our servers once an internet connection is established. The local queue is cleared on successful sync or logout.
- Product Analytics: With your consent, we use PostHog to capture aggregated, first-party product usage events (page views, feature interactions). No cross-site tracking or advertising identifiers are collected.
- Error Monitoring: We use Sentry to capture application error reports (stack traces, browser metadata) so we can fix bugs.
Manage cookie preferences
Reopen the cookie banner to change your Accept / Reject choice.
3. How We Use Your Information
We use the collected data for the following purposes:
- Service Provision: To facilitate garment inspections and manage quality assurance workflows.
- Reporting: To generate PDF inspection reports and schedule summaries.
- Communications: To send automated email notifications regarding inspection status, report completions, and schedule updates.
- Account Management: To authenticate users and maintain secure access to the platform.
- Synchronization: To ensure data integrity between local offline storage and cloud databases.
We do not sell your personal data to third parties, and we do not use your data to train third-party AI models without your express opt-in.
Lawful Basis (GDPR)
Where GDPR applies, we process personal data on the basis of (a) performance of our contract with your organization, (b) our legitimate interest in operating, securing, and improving the service, and (c) compliance with legal obligations.
Staff Access to Account Metadata
Qualityiris staff may access account-level metadata (company name, administrator contact, usage counts, storage totals, sign-in events) for support, security, billing, and operation of the Service. Staff do not access tenant inspection content, photos, purchase orders, or measurement data through these tools.
4. Iris AI Features
QualityIris includes optional AI-powered features (collectively, "Iris AI") such as Iris Summary, Iris Draft, Iris Insights, and AI defect analysis. When these features are used:
- Inspection text, structured fields, and (for vision features) defect photos are sent to large-language-model and vision providers via our AI gateway strictly to generate the requested output.
- Our AI providers are contractually prohibited from using your data to train their models.
- AI outputs are advisory and reviewed by a qualified human inspector or manager before being saved to the report.
- An organization administrator may disable Iris AI features for their tenant at any time.
5. Data Storage & Security
We prioritize the security of your data:
- Cloud Infrastructure: Data is hosted on secure cloud infrastructure with strict tenant isolation enforced via row-level security.
- Photos & Media: Inspection photos and signatures are stored in private cloud storage buckets and served via short-lived signed URLs.
- Encryption: We use industry-standard encryption protocols (SSL/TLS) for data in transit and encryption for data at rest.
- Access Control: User accounts are created by administrators, and role-based access control ensures buyers, factories, inspectors, and admins only see data scoped to their organization.
E-Signature Evidence
When a user signs an inspection report (inspector, QA manager, factory representative, or buyer), we record signature attestation evidence alongside the signed record: the typed name, the authenticated user account and display name, a UTC timestamp, the browser/device user-agent string, and the public IP address of the signing device. This is collected for the sole purpose of evidencing the signature under the US ESIGN Act and eIDAS Article 25(1), is retained for the same period as the inspection record it belongs to, and is never used for tracking, profiling, or marketing. We do not collect device fingerprints. If the IP lookup fails, the signature is still recorded without it.
6. Data Retention
We retain your information only for as long as needed to provide the service and meet legal obligations:
- Inspection Records: Retained for the active subscription term plus 90 days after termination (export window), then permanently deleted unless a longer retention is required by law.
- Account Data: Profiles are deleted within 30 days of an administrator request, except where retention is required for billing, security, or legal compliance.
- Local Data: Offline IndexedDB data is cleared on successful sync or logout.
- Website Chat (Ask Iris): Sales-chat transcripts from our public marketing site are retained for up to 180 days and then automatically deleted. Transcripts attached to an open support or contact request are kept until that request is closed. If you choose to give a first name at the start of a chat (optional — you can skip it), we store it with the transcript, together with a coarse region derived from your browser's timezone and language setting. We do not store your IP address with the transcript, and both the name and the region are deleted with the transcript.
- Backups: Encrypted backups may persist for up to 14 days after deletion before being overwritten.
7. Sub-processors
To deliver the service, Qualityiris LLC engages a limited set of third-party sub-processors. Each is bound by a written data-processing agreement and is permitted to use your data only to provide its specific service to us:
- Supabase — managed Postgres database, authentication, object storage (defect photos, signatures, PDF reports), and edge functions (AWS, US regions).
- Resend — transactional email delivery for inspection reports, schedule notifications, and account emails from
notify.qualityiris.com. - Lovable AI Gateway, with downstream models from Google (Gemini) and OpenAI (GPT) — large-language-model and vision inference for Iris AI features. No customer data is used for model training.
- Sentry — error monitoring and diagnostics.
- PostHog — first-party product analytics.
- Stripe — subscription billing, checkout, customer portal, and tax calculation. Stripe processes your billing contact, payment method, and tax data on our behalf.
- Cloudflare — Turnstile bot-protection challenge on sign-up. Cloudflare sees the requesting IP address and challenge token for the purpose of distinguishing humans from automated abuse.
The current sub-processor list is available on request from privacy@qualityiris.com.
8. Your Rights (GDPR & CCPA)
Depending on your location, you may have the following rights regarding your data:
- Access: The right to request copies of your personal data.
- Correction: The right to request that we correct inaccurate information.
- Deletion: The right to request that we erase your personal data (under certain conditions).
- Data Portability: The right to request that we transfer your data to another organization.
- Objection / Restriction: The right to object to or restrict certain processing.
- Withdraw Consent: Where processing is based on consent, the right to withdraw it at any time.
- Lodge a Complaint: The right to complain to your local data protection authority.
- Non-Discrimination: We will not discriminate against you for exercising any of these rights.
To exercise these rights, contact your organization administrator or email privacy@qualityiris.com. We will respond within the timelines required by applicable law.
9. Children's Privacy
QualityIris is a professional B2B platform and is not intended for use by children under the age of 16. We do not knowingly collect personal data from children.
10. International Data Transfers
Qualityiris LLC is established in the United States, and personal data is processed in the United States and other jurisdictions where our sub-processors operate. Where personal data is transferred from the European Economic Area, the United Kingdom, or Switzerland to the United States, we rely on the Standard Contractual Clauses approved by the European Commission (and the UK Addendum, where applicable) as the lawful transfer mechanism.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated by email to organization administrators and by updating the "Effective Date" above. Your continued use of the service after the effective date constitutes acceptance of the updated policy.
12. Contact
If you have questions or concerns about this Privacy Policy or our data practices, please contact us at:
Qualityiris LLC
Wylie, Texas, USA
Privacy: privacy@qualityiris.com
General: info@qualityiris.com
Website: qualityiris.com