Pitbook

Your information

Privacy policy

How Pitbook handles accounts, company records and the information you choose to share.

Last updated October 9, 2026 · Operator: Jeff Kreidler

Who operates Pitbook

Pitbook is operated by Jeff Kreidler (“we,” “us,” or “our”). It is an iPhone app for elevator companies to organize location details, access information, elevator records, photos and field notes. This policy describes the current app and its support website.

For support or privacy requests, email jmkreidler@yahoo.com. Your employer or company controls the business information it places in its Pitbook workspace and decides who can access it.

Information we process

  • Account information: email address, account identifier, email-verification status and authentication records. Passwords are submitted securely to Supabase Auth; we do not maintain a readable password list. The deletion service also verifies the password you enter through Supabase Auth.
  • Company information: company name, approved email domains, membership, role, invitations, plan allowance and administrative activity.
  • Workspace content: location names, addresses and map coordinates; entrances, codes, combinations, parking and contact information; elevator details, notes, photos and photo labels.
  • Change records: saved versions, timestamps and editor email attribution, plus company membership and role events.
  • Support information: the messages and attachments you choose to send us and information needed to handle your request. Company billing arrangements may include business contact and invoice records.
  • Service records: our infrastructure and email providers may process IP addresses, request times, security or error logs, and email delivery records to operate and protect the service.

Information comes from you, your company's authorized users, support correspondence and the services used to run Pitbook.

How information is used

We use information to authenticate users; apply company permissions and user limits; store and synchronize workspace content; display maps; record and restore changes; send verification and password-reset emails; provide support; administer company billing; and investigate technical problems or misuse.

The current Pitbook app does not include advertising or an advertising-tracking SDK. We do not sell personal information or use workspace content for targeted advertising.

Photos, screenshots and maps

Photo selection uses Apple's system picker, which gives Pitbook the items you select. Photos you attach and save to a location are uploaded to company storage and shared with authorized company users. You may revoke applicable permissions in iPhone Settings; doing so does not remove already saved content.

For ticket-screenshot imports, text recognition runs on the iPhone. The import feature submits the location name and address you approve, plus the resulting map coordinates. It does not upload the original ticket screenshot or import service-call details through that feature. Attaching that same image as a location photo is a separate action that does upload it.

Pitbook uses Apple map and address lookup services. Address lookups send the entered address to Apple to find map coordinates. The current app does not request your iPhone's GPS location or track your movements in the background. Apple's services are governed by Apple's privacy policy.

Who can access information

Workspace content is available to users authorized for that company. Company Owners, Executives and Admins have management abilities according to their assigned roles. Creating an account alone does not grant company access.

Jeff Kreidler and service administration may access information when needed to operate the service, answer support requests or investigate security issues. Pitbook uses Supabase for authentication, database storage, file storage and server functions; Resend for transactional email delivery; and Apple for maps and address lookup. Hosting services process website requests and technical logs.

We share information with providers as needed to deliver these functions, under their applicable service and data-processing terms. We may also disclose information when required by law, to protect rights or safety, or at your direction. Providers may process information in countries other than your own.

Retention and account deletion

We retain account information while the account is active and company information while needed to provide the company workspace. The current app has no automatic permanent purge schedule for workspace content. Recently Deleted locations and stored revisions can remain available for recovery; showing the latest 50 changes in the interface is not a promise that older database records have been purged.

You can initiate account deletion in Settings → Account → Delete account, including from the Welcome screen when you have no company access. The current password and a final confirmation are required. If you own a company, transfer ownership before deletion. If you cannot access the app, contact us for assistance.

Successful deletion removes the sign-in account, associated active authentication records and company memberships, revokes affected invitations and replaces automatic account-email attribution in the app's change and team records with “Deleted account.” It does not delete the company's locations, elevator details, shared notes or photos.

Manually entered names, contacts, notes, photo labels and image contents may still contain personal information after account deletion. To request removal or redaction of that information, email us; we will review the request with the relevant company and distinguish personal information from retained business records. Retained company content is not an exception to applicable personal-data deletion requirements.

Provider logs, email delivery records and any configured backups may remain for their applicable retention periods. Deletion from active systems does not instantly erase those copies. Information required for legal obligations, disputes or security may be retained where permitted. Contact us for the retention applicable to a specific request.

Device storage and security

Pitbook uses HTTPS for service requests, protected authentication tokens, company access checks and encrypted local caching for offline use. The app can require Face ID or the iPhone passcode when returning to the app. Biometric verification is handled by iOS; Pitbook does not receive your biometric templates.

Signing out clears the current real-account cache on that device. Removing access or deleting an account blocks future authorized service access, but cannot remotely erase information another device already downloaded or a person copied or photographed. Other devices must reconnect or sign out to update or clear their local state.

Security measures reduce risk but do not guarantee that every device or transmission is secure. Limit workspace membership and avoid including information your company is not authorized to store or share.

Your choices and requests

You may ask for access, correction, deletion or a copy of your personal information, or raise a privacy concern, by emailing jmkreidler@yahoo.com. Rights and permitted exceptions depend on applicable law. We may verify your identity before acting. We do not penalize people for exercising applicable privacy rights.

For business-record changes or company exports, contact your company Owner as well. Requests about another person's information require appropriate authorization. Where processing relies on consent, you may withdraw that consent; necessary account processing may still be required to provide the service.

Include your account email and company name, but do not send your password, access codes, combinations or unredacted customer records. We will provide instructions if further information is needed.

Children and policy changes

Pitbook is intended for adult workplace use and is not directed to children under 13. If you believe a child has provided personal information, contact us so we can investigate and arrange appropriate removal.

We will update this page when our practices change and update the date below. Material changes may also be communicated through the app or email. New analytics, payment processing or other services require an updated disclosure before use.