Privacy Policy
Effective June 2026
This Privacy Policy describes how Axis (“Axis”, “we”, “us”, or “our”) collects, uses, shares, and protects information in connection with the Axis manufacturing operations platform (the “Service”). By using the Service, you acknowledge that you have read and understood this policy.
1. Information We Collect
Account information
When you register, we collect your name, email address, company name, and a salted, hashed copy of your password. Passwords are never stored in plaintext.
Manufacturing data
The Service stores the operational data you enter — projects, tasks, inventory items, build plans, bills of materials, work orders, material requests, records, certifications, and uploaded files. This data is owned by you, our customer, and is treated as Customer Data under our Terms of Service.
Usage data
We log information about how you interact with the Service, including pages visited, features used, request timestamps, IP address, browser type, and operating system, for the purpose of operating, securing, and improving the Service.
Cookies
We use cookies to keep you signed in and to remember your preferences. See the Cookies section below for details.
2. How We Use Information
We use the information we collect to:
- provide, operate, maintain, and improve the Service;
- authenticate users and secure accounts;
- send transactional messages such as password resets, invitations, notifications, billing receipts, and security alerts;
- send product updates and announcements, which you may opt out of at any time;
- monitor usage, troubleshoot issues, and detect and prevent fraud, abuse, and security incidents;
- comply with legal obligations and enforce our agreements.
3. Information Sharing
We do not sell your personal information. We share information only as needed to operate the Service:
- Service providers: with the third-party sub-processors listed below, each of which handles information only as needed to provide its service to Axis and is contractually obligated to protect it;
- Law enforcement: if required to comply with a subpoena, court order, or other valid legal process, or to protect the rights, property, or safety of Axis, our users, or the public;
- Business transfers: in connection with a merger, acquisition, financing, or sale of assets, in which case we will continue to protect your information consistent with this policy.
4. Third-Party Providers
We rely on the following sub-processors to deliver the Service:
- Stripe — payment processing and subscription management;
- Amazon Web Services (AWS) — cloud hosting and storage infrastructure;
- Resend — transactional and product email delivery;
- Fly.io — application hosting and edge infrastructure.
5. Data Security
Axis maintains administrative, technical, and physical safeguards to protect your information. Data in transit is encrypted using TLS 1.3, and data at rest is encrypted using AES-256. Tenant data is isolated through row-level access controls, access by Axis personnel follows the principle of least privilege, and security-relevant activity is captured through audit logging. No method of electronic transmission or storage is one hundred percent secure, and absolute security cannot be guaranteed.
6. Data Retention
Account data and Customer Data are retained for as long as your account is active and for ninety (90) days after termination, after which Customer Data is purged from active systems and routine backups, except where longer retention is required by law. Audit logs are retained for seven (7) years to support security, compliance, and traceability. Aggregated, anonymized usage data that cannot reasonably identify any individual may be retained indefinitely.
7. Your Rights
Subject to applicable law, you may:
- Access the personal information we hold about you;
- Correct inaccurate or incomplete personal information;
- Delete your account and associated personal information;
- Port your Customer Data by exporting it in a standard, machine-readable format using the Service’s export functionality.
To exercise any of these rights, contact support@axiscrm.org. We will respond within forty-five (45) days.
8. California Privacy Rights
If you are a California resident, the California Consumer Privacy Act (CCPA) gives you the right to know what categories and specific pieces of personal information we have collected about you, the right to request deletion of that information (subject to certain exceptions), and the right to non-discrimination for exercising your rights. We do not sell your personal information. To submit a request, contact support@axiscrm.org.
9. Cookies
The Service uses cookies strictly for session authentication — keeping you signed in — and to remember a consent preference and display settings such as theme. We do not use third-party advertising or cross-site tracking cookies. You can control cookies through your browser settings, though disabling session cookies will prevent you from signing in.
10. Children’s Privacy
The Service is not directed to and is not intended for use by anyone under the age of sixteen (16). We do not knowingly collect personal information from children under 16. If we learn that we have collected such information without appropriate consent, we will take steps to delete it.
11. International Users
Axis is operated from, and your information is processed and stored in, the United States. If you access the Service from outside the United States, you understand that your information will be transferred to and processed in the United States, where data protection laws may differ from those in your jurisdiction.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will give you at least thirty (30) days’ notice of any material change, by email or in-Service notification. The “Effective” date at the top of this policy reflects the most recent revision. Continued use of the Service after the effective date constitutes acceptance of the updated policy.
13. Contact
Questions or requests regarding this Privacy Policy may be directed to support@axiscrm.org.