LEGAL
Privacy Policy
Effective July 14, 2026 · Last updated July 17, 2026
MachineSOS is a customer-service platform for vending and micro-market operators: QR codes on machines let a customer submit a ticket (refund, outage, or suggestion) without creating an account, and operators manage those tickets on a dashboard. This policy explains what personal data we collect through that platform, why, who we share it with, and the choices you have.
This is a plain-English summary of a real legal document — it isn't a substitute for reading the sections below if a decision depends on the details.
1Scope of this policy
This policy covers personal data processed through the MachineSOS website, dashboard, public ticket-submission pages (the pages a customer reaches by scanning a QR code on a machine), and related emails and text messages. It applies to three groups of people:
- Operators and Employees — the vending/micro-market businesses and their staff who create an account and use the dashboard.
- Customers — end users of a vending or micro-market machine who scan a QR code and submit a ticket. Customers never create an account; MachineSOS only ever holds what they submit on that one ticket.
- Site visitors — anyone browsing machinesos.com without logging in or submitting a ticket.
2Who we are
MachineSOS is operated by Cody Brookes, doing business as “MachineSOS”(referred to in this policy as “MachineSOS,” “we,” “us,” or “our”). For the purposes of privacy law, MachineSOS is the data controller for personal data described in this policy, except where a sub-processor listed in Section 7 acts as an independent controller for its own purposes (for example, Stripe as the payment processor).
You can reach us about anything in this policy at helpmachinesos@gmail.com.
3Definitions
- “Company” account— one operator business's MachineSOS subscription, containing its own locations, machines, tickets, and staff. MachineSOS supports one company per account; there is no shared or franchise-style account structure.
- “Owner” — the person who created the Company account and has full administrative control over it.
- “Employee” — a staff member invited by an Owner, scoped to tickets assigned to them.
- “Ticket”— a Refund, Outage, or Suggestion report a Customer submits through a machine's QR code.
- “Personal Data” — any information that identifies or could reasonably be used to identify a person, such as a name, email address, phone number, or IP address.
4Data we collect
4.1 Information Owners and Employees provide
When you create or join a Company account: your name, email address, and password (which we never see or store in plain text — it's hashed by our authentication provider, Supabase Auth); your company name and business details; and, if you invite staff, the names and email addresses of the Employees you invite.
4.2 Information Customers provide through the public ticket form
Submitting a ticket doesn't require an account, but does require some contact information so an operator can follow up. Depending on the ticket category, this can include: a name; a phone number and/or email address; photos of the machine or product; and a free-text description of the issue. The specific machine and location are identified automatically from the QR code scanned, not typed in by the customer.
We also use the phone number and/or email submitted on refund tickets to detect repeat submissions across different tickets — this is a fraud-prevention measure described further in Section 5, and it surfaces as a flag to the operator, not a public record.
Refund payout information (added since this policy's effective date): a refund ticket also asks how you'd like to be paid back — Venmo, PayPal, Cash App, or cash — and, if you choose Venmo, PayPal, or Cash App, the username or handle to send it to. We collect this only to pass along to the operator so they can send your refund themselves, directly, outside MachineSOS. MachineSOS never processes the payment and never receives any money — we're not affiliated with Venmo, PayPal, or Cash App, and clicking a payment link in the operator's dashboard takes them to that company's own site or app, governed by that company's own privacy policy, not ours.
4.3 Billing information
Subscription payments are processed entirely by Stripe, Inc. MachineSOS never receives or stores your full card number, CVC, or bank account details — Stripe passes us only what we need to manage your subscription (for example, a subscription status and the last four digits of a card, for your own reference on your billing page).
4.4 Information collected automatically
Like most web services, our servers and infrastructure automatically log IP addresses, browser and device information, timestamps, and pages requested, for security, fraud-prevention, and rate-limiting purposes (for example, detecting when the same IP address is submitting an abnormal number of tickets). Our bot-protection provider, Cloudflare Turnstile, also collects signals needed to distinguish a human submitter from an automated script; we don't receive or see the raw signals it uses, only a pass/fail result.
4.5 Cookies
MachineSOS uses one strictly-necessary cookie to keep an Owner or Employee logged in between page loads (set by our authentication provider, Supabase). Cloudflare Turnstile may set its own cookie or use local storage solely to verify you're not a bot on the public ticket form. We do not use advertising cookies, third-party analytics cookies, or any cross-site tracking technology — there is currently no Google Analytics, ad pixel, or similar tool anywhere on MachineSOS.
4.6 Error and diagnostic data
We use Sentry to catch and diagnose software errors. When something breaks, Sentry captures a stack trace and technical request details (like the route and a truncated error message) so we can fix it quickly. Session-replay (recording what your screen looked like) is explicitly turned off, and our Sentry configuration is set to not forward default personal data.
4.7 Sticker order & shipping information
If you order physical QR stickers through the dashboard's sticker store, we collect the recipient name and shipping address you enter for that order — this is your own business information as the Owner placing the order, not a Customer's. We use it only to have the order printed and shipped, by sharing it with Prodigi, our print-on-demand fulfillment partner (see Section 7), together with the sticker artwork (your machines' QR codes and, if you're on the Main Hustle plan, your chosen border and logo).
5How we use data
- To operate the Service — routing a ticket to the right operator, displaying it on the Kanban and Machine Repair dashboards, and tracking its status.
- To relay refund payout information (your chosen method and handle) to the operator so they can send your refund directly — MachineSOS itself never touches or processes that payment.
- To fulfill physical sticker orders — sending the shipping address and sticker artwork you provide to our print-on-demand partner, Prodigi, so it can print and ship the order.
- To prevent fraud and abuse — flagging repeat refund submitters, rate-limiting the public ticket form, and verifying submitters aren't automated bots.
- To bill for subscriptions and manage your plan (via Stripe).
- To send transactional notifications — ticket-status emails to customers, new-ticket and billing alerts to operators, and (once launched) SMS alerts to Pro-tier operators.
- To respond to support requests you send us directly.
- To monitor for and fix errors, and to investigate security incidents.
- To comply with legal obligations, such as tax recordkeeping or responding to a valid legal request.
- To produce aggregated, company-level analytics and KPI reporting inside the dashboard and our internal admin tools — this never involves selling data or building advertising profiles.
We do not sell personal data, and we do not use ticket or account data for advertising — ours or anyone else's.
6Legal bases for processing
For visitors in regions where a specific legal basis is required (for example, under the EU/UK GDPR), we rely on: performance of a contract (providing the Service you or your operator signed up for); our legitimate interests (fraud prevention, security, and improving the Service); and legal obligation (tax and recordkeeping). Where we ever rely on consent — for example, an optional marketing email — we'll ask for it separately and let you withdraw it at any time.
7Data sharing & sub-processors
We share personal data only with service providers who need it to help us run MachineSOS (“sub-processors”), and only for the purposes described in this policy:
- Supabase — our database, authentication, and file storage provider. Hosts nearly all Company, Employee, and ticket data.
- Vercel — hosts and serves the MachineSOS website and application.
- Stripe, Inc. — processes subscription payments and stores payment card details on our behalf; Stripe is itself a data controller for that information under its own privacy policy.
- Resend — delivers transactional emails (ticket confirmations, status updates, billing notices).
- Cloudflare (Turnstile) — verifies that public ticket-form submissions come from a human, not a bot.
- Sentry — captures error and diagnostic data so we can fix bugs.
- Twilio — will deliver SMS alerts to Pro-tier operators once that feature launches; not in use today.
- Prodigi — our print-on-demand fulfillment partner; prints and ships physical QR stickers ordered through the dashboard, using the shipping address and sticker artwork submitted with that order.
Beyond our sub-processors, we may share personal data:
- With the relevant Operator — a ticket you submit is, by design, shared with the business that owns the machine you scanned. That's the entire point of the Service. This includes any refund payout method/handle you provide, so the operator knows how to pay you back.
- If required by law — to comply with a subpoena, court order, or other valid legal process, or to protect the rights, property, or safety of MachineSOS, our users, or the public.
- In a business transfer — if MachineSOS is ever involved in a merger, acquisition, or sale of assets, personal data may transfer as part of that deal; we'll provide notice before your data becomes subject to a different privacy policy.
We never sell personal data, and we never share it with third parties for their own advertising or marketing purposes.
8Data retention
- Ticket data (a customer's name, contact info, photos, and description) is retained for 24 months after the ticket is resolved, after which it is deleted or anonymized — long enough to be useful for repeat-submitter fraud detection and historical reporting, short enough not to become an indefinite record.
- Owner and Employee account data is retained for as long as the Company account is active, and is deleted or anonymized within 180 days of account closure — except for billing and tax records, which we retain as long as required by law (typically up to 7 years).
- Deleted data may briefly persist in encrypted backups for a limited rolling period after it's removed from our primary systems, before being permanently purged.
9Your rights & choices
If you're an Owner or Employee
You can review and update most of your account information directly in the dashboard. To request a full export or deletion of your account data, email helpmachinesos@gmail.com.
If you're a Customer who submitted a ticket
Since ticket submission never creates an account, we can't offer a self-service login to manage your data. To request access to, correction of, or deletion of information you submitted, email helpmachinesos@gmail.com with the phone number or email you used and roughly when and where you submitted the ticket, so we can locate it. We'll respond within 30 days. We may decline or delay a deletion request if the ticket is part of an active refund-fraud investigation or an operator's legal or accounting record.
Regional privacy rights
Depending on where you live, you may have additional rights — for example, the right to know what personal data we hold about you, to correct it, to delete it, to receive a portable copy of it, to object to certain processing, or (where applicable, like California's CCPA) to opt out of the sale of personal data. We don't sell personal data, so that last right is already satisfied by default. You can exercise any of these rights by emailing us at the address above, and, where applicable, you have the right to lodge a complaint with your local data protection authority.
10Children's privacy
MachineSOS is not directed to children, and we don't knowingly collect personal data from anyone under 13. If we learn that a child under 13 has submitted personal data through the ticket form, we'll delete it promptly. If you believe a child has submitted data to us, please email helpmachinesos@gmail.com.
11Data security
We take reasonable technical and organizational measures to protect personal data, including:
- Encryption in transit (HTTPS/TLS) for all traffic to and from MachineSOS.
- Database-level Row-Level Security policies that enforce tenant isolation — an Employee's or Owner's database session is restricted to their own company's data by the database itself, not just hidden by the interface.
- Private file storage for ticket photos, served only through short-lived signed URLs rather than public links.
- Passwords that are hashed by our authentication provider and never stored or visible to us in plain text.
- Automated error monitoring so failures in sensitive flows (like the public ticket form or billing webhooks) surface quickly rather than silently.
No method of electronic storage or transmission is 100% secure, and we can't guarantee absolute security — but we design and review the system with these protections as a baseline, not an afterthought.
12International users & data location
MachineSOS is designed for vending and micro-market operators in the United States, and our infrastructure (Supabase, Vercel) is hosted in the United States. If you access or use the Service from outside the U.S., your information will still be processed and stored in the United States.
13Do Not Track
Some browsers offer a “Do Not Track” signal. Because MachineSOS doesn't use cross-site advertising trackers in the first place, there's currently no tracking for that signal to disable, and we don't respond to it differently.
14Changes to this policy
We may update this policy as MachineSOS changes — for example, if we add a new integration or feature that changes what data we collect. The “Last updated” date at the top always reflects the current version. If a change is material, we'll notify Owners by email and post a notice in the dashboard before it takes effect. Continuing to use MachineSOS after a change takes effect means you accept the updated policy.
15Contact us
Questions, requests, or concerns about this policy or your data can go to helpmachinesos@gmail.com. See also our Terms of Service.