Summit Fab logo Summit Fab
Privacy Terms Sign in
Privacy

Privacy Policy

Effective September 11, 2026 · Version 1

This policy explains what Summit Fab LLC collects when your company uses Summit Fab, why we collect it, who it is shared with, and how long we keep it. It works together with the Terms of Service.

On this page

Overview

This Privacy Policy describes how Summit Fab LLC ("Summit," "we," "us") handles personal information in connection with the Summit Fab platform at https://summit-fab.com, our iOS and iPad apps, our Revit plugin, our shop machine agent and related support (together, the Services).

Summit Fab is business software sold to companies, not to individuals. Our customer is the fabrication company that opens a workspace (the Customer). The people who sign in — shop admins, office staff, fitters, welders, QC — are that company's Authorized Users. The job, package, spool, drawing and production information a Customer puts into the platform is Customer Data.

Summit Fab is an early-access product, so the data we collect may change as the product does; when it does, we will update this policy (see Changes to This Policy). Your use of the Services is also governed by our Terms of Service.

Who We Are and Our Role

Customer Data — we act as a service provider

For everything a Customer puts into its workspace — jobs, packages, spools, drawings, photos, inventory, shipping documents, and production timer records showing which Authorized User worked which stage and for how long — the Customer is the controller (a "business" under California law) and Summit is the service provider (a "processor"). We handle that information under the Customer's instructions and our Terms of Service, and not for our own purposes beyond operating, securing and supporting the Services.

This matters for shop employees. If you scan into a cut, fit-up, weld or QC stage, the platform records that you did the work, on which spool, and how long it took. That is employee productivity data and it belongs to your employer, so questions about how it is used go to your employer — we cannot change, hide or delete it without their instruction.

The Customer is responsible for having a lawful basis to collect this information and for telling its Authorized Users that the company uses Summit Fab and tracks production activity through it. We do not send privacy notices to a Customer's employees on its behalf.

Account, waitlist and security data — we act as the controller

For information we collect directly to run our business — waitlist submissions, activation details, account records, sign-in and security logs, and support conversations — Summit is the controller, and this policy describes our own practices.

Information We Collect

Information you give us

  • Waitlist requests. Name, work email, phone number, company name, whatever you write in the free-text box, and whether you marked yourself interested in the beta.
  • License activation. The company name and the administrator's full name, email address and chosen password (stored only as a secure hash).
  • User accounts. For each Authorized User: name, work email (also the username), hashed password, role, job title or crew group, invited-by reference, theme preference and account timestamps.
  • Feedback and support. Bug reports, improvement requests, message threads and screenshots you attach. Please do not paste passwords or sensitive personal details into a bug report.

Customer Data your company puts in

Authorized Users create working content in the workspace: jobs, packages and spools; drawings and PDFs; job, location and category photos; the company logo; inventory and material records; bills of lading; Revit model data imported through the plugin; production timers; and a log of transactional emails the system sent (recipient, subject, delivery status). Most of this is fabrication data, but it can contain personal information — a name in a drawing title block, a person in a shop photo, or the user attached to a production timer.

Information collected automatically

  • Sign-in and session records. Login timestamps, IP address, browser user-agent and active session records.
  • Security records. Two-factor authentication data (a TOTP secret, backup codes, and "trusted browser" records if you trust a browser), password-reset tokens, and rate-limiting counters keyed to a hashed IP address or email address.
  • Audit log. An administrator audit trail of significant events — successful and failed sign-ins, license events and similar actions — with the associated user and IP address.

From our mobile apps, the Revit plugin and the machine agent

  • iOS / iPad apps. Device identifier and name, a hashed API token, trusted-device records, and — if you set one — a hashed four-digit PIN for quick re-entry on the shop floor. The apps collect no location data, contacts or advertising identifiers.
  • Revit plugin. The license key plus the registered device identifier, name, type and user-agent for the seat it is bound to.
  • Summit Control Box / machine agent. Heartbeat and command records for shop equipment such as a TigerStop, plus controller pairing details. This is equipment telemetry, though the operator who ran the job may appear in the related production record.

We collect no biometric data, precise geolocation, health data or government identifiers. There is no billing in the Services today, so we collect no payment card data at all.

How We Use Information

  • Provide the Services. Maintain workspaces and accounts, store and display Customer Data, run production tracking and package health, sync the mobile apps, authorize plugin seats and talk to registered shop machines.
  • Authenticate and secure. Verify sign-ins, enforce two-factor authentication where a workspace requires it, recognize registered devices, rate-limit abusive traffic, keep audit logs and investigate misuse.
  • Send transactional email. Password resets, order and receipt notifications and similar operational messages.
  • Support and improve. Answer questions, reproduce and fix reported bugs, monitor reliability and plan features. Where we look at Customer Data for this, it is to fix that Customer's problem or keep the platform running — never to study one Customer's shop for another's benefit.
  • Waitlist follow-up. Contact you about early access. We use waitlist details only for that; we do not sell or rent them or add you to unrelated marketing.
  • Comply with law. Meet legal obligations and enforce our Terms of Service.

We do not use Customer Data to train general-purpose machine learning models, and we do not profile Authorized Users for advertising.

Cookies and Local Storage

Summit Fab sets exactly two first-party cookies, both strictly necessary:

CookiePurposeType
sessionidKeeps you signed in between page loads.Strictly necessary
csrftokenProtects forms and API calls against cross-site request forgery.Strictly necessary

We also use your browser's localStorage to remember interface preferences on your own device: light or dark theme, sidebar collapsed state, dashboard widget layout and jobs list preferences. That stays in your browser and is not sent to us as a tracking signal.

We use no analytics platforms, advertising networks, social pixels, session replay tools or third-party tracking scripts. Because we set no cookies that require consent, we do not show a cookie consent banner. Sessions also time out after inactivity (30 minutes by default), which signs you out and clears the session cookie.

How We Share Information

Sub-processors

A small number of vendors help us operate the Services. Each is bound by contract to protect the information it handles and use it only to serve us.

Sub-processorWhat it does for usWhat it can reachLocation
Render (render.com) Application hosting, managed database, and the persistent disk holding uploaded drawings and photos. All account data and Customer Data, as the underlying infrastructure. United States
Microsoft 365 / Microsoft Graph Sends outbound transactional email from a Summit Fab no-reply mailbox. Recipient address, subject and message contents. United States
Autodesk Platform Services Powers the optional Model Viewer. Used only if a workspace enables the module and links its own Autodesk account; models are viewed from the Customer's own Autodesk storage. We keep those credentials encrypted. Model data the Customer already holds with Autodesk. United States
Apple App Store Distributes our iOS and iPad apps; Apple's own privacy practices apply to the download. Nothing from your workspace — Apple sees the download, not your data. United States

There is no payment processor, because there is no billing during early access. If that changes we will update this policy before collecting any payment details.

Other sharing

  • Within your workspace. Authorized Users see their workspace's data according to the roles their administrators configure. Workspaces are isolated from one another.
  • Legal and safety. We may disclose information where we reasonably believe it is required by law or legal process, or necessary to investigate fraud, protect people's safety or enforce our agreements. Where the request concerns Customer Data and we are legally permitted to, we will tell the Customer first.
  • Business transfer. In a merger, acquisition, financing or sale of assets, information may transfer as part of the transaction; the receiving party stays bound by this policy or gives notice before materially changing it.
  • At your direction. When you ask us to — for example an export, or a Customer-owned integration.

We do not sell personal information, and we do not share it for cross-context behavioral advertising, as those terms are used in California law. We never have.

Data Security

Measures currently in place include:

  • TLS encryption on all traffic, with HSTS enforced.
  • Passwords stored only as salted PBKDF2 hashes — we never store or see the plain text.
  • Mobile API tokens and shop-floor PINs stored as hashes, not readable values.
  • Two-factor authentication available to every user, which administrators can require for accounts in their workspace, with backup codes and optional trusted-browser records.
  • Device registration for plugin seats, and rate limiting on sign-in, activation and password-reset endpoints to slow credential-stuffing.
  • Workspace isolation checks on every view and API endpoint, so one company cannot read another company's records.
  • Uploaded drawings and photos served through an ownership-checked view rather than a public or guessable URL, so a file link alone grants no access.
  • Session idle timeout (30 minutes by default) — important on shared shop-floor terminals.
  • Audit logging of significant account and license events.
  • Upload validation and size budgets to limit malformed or abusive files.
  • Encrypted storage of third-party credentials such as a workspace's Autodesk connection.

No system is perfectly secure and we cannot guarantee the Services will never be compromised. If we become aware of a security breach affecting Customer Data or Authorized User accounts, we will notify the affected Customer without undue delay, describe what we know, and cooperate with the Customer's own notification obligations. If you believe an account is compromised or you have found a vulnerability, email landenowens@summit-fab.com immediately.

Data Retention

  • Customer Data and accounts. Kept for the life of the Customer's workspace. After the agreement ends we will delete or return Customer Data within 90 days of the Customer's written request.
  • Backups. Deleted records may persist in backups until those backups roll off on their normal schedule. Backups are not used to restore individually deleted records.
  • Security and audit logs. Kept for a limited period for fraud prevention and incident response, then removed.
  • Waitlist submissions. Kept while we are evaluating or contacting you about early access; removed on request.
  • Feedback and support threads. Kept while we work the issue and for a reasonable period afterward.

We may keep information longer where a law, a legal hold or the defense of a legal claim requires it.

Your Choices and Rights

Access, correction and deletion

Authorized Users can change their own password and interface preferences in the app. A workspace administrator can add, edit, deactivate and remove accounts and can correct or delete Customer Data directly. If something cannot be changed in the app, write to landenowens@summit-fab.com.

Requests from employees

If you are an Authorized User asking about information your employer put into or generated inside its workspace — including production timer records — we will forward the request to your employer and act on their instruction. That follows from our role as a service provider; we will not delete a Customer's production records at the request of one of its employees.

Email preferences

Email from Summit Fab is transactional: password resets, order and receipt notifications, and account or service notices. We do not run marketing campaigns. You cannot unsubscribe from security and account messages while your account is active, but you can ask us to stop contacting you about early access at any time.

California residents

Under the California Consumer Privacy Act as amended by the CPRA, California residents may request to know the categories and specific pieces of personal information we collected, why, and who it was disclosed to; request correction or deletion; and not be discriminated against for exercising those rights. The categories we collect are listed in Information We Collect — identifiers, professional and employment-related information, internet and device activity, and audio/visual information in the form of uploaded photos and drawings. We do not sell personal information and we do not share it for cross-context behavioral advertising, so there is nothing to opt out of. Email landenowens@summit-fab.com to make a request; we verify it through your workspace account, and an authorized agent may act for you with written permission. Where we hold the information as a service provider for an employer, we refer the request to that employer.

Outside the United States

Summit Fab is offered from the United States to United States customers, and all personal information is stored and processed in the United States. We do not currently target the Services to the European Economic Area, the United Kingdom or Switzerland, and we have not put the transfer mechanisms the GDPR requires in place. If you use the Services from outside the United States, your information will be handled here under United States law.

Children's Privacy

The Services are intended for businesses and their employees. They are not directed to children, and we do not knowingly collect personal information from anyone under 16. If you believe someone under 16 has an account, contact landenowens@summit-fab.com and we will delete it. Customers are responsible for ensuring every Authorized User they invite meets this requirement and any applicable minimum working age.

Changes to This Policy

This policy will evolve with the product. If we make a material change — new categories of information, a new sub-processor, or a new purpose a reasonable Customer would want to know about — we will post the updated policy with a new effective date and notify workspace administrators by email or in the app before it takes effect. Clarifying edits may be posted without notice. Continuing to use the Services after an update means you accept it.

Contact Us

Questions, requests or complaints about this document:

  • Summit Fab LLC
  • Email: landenowens@summit-fab.com
  • Web: https://summit-fab.com

See also our Privacy Policy and Terms of Service.

© 2026 Summit Fab LLC. All rights reserved.
Home Privacy Policy Terms of Service landenowens@summit-fab.com