Legal

Privacy Policy

InDate Systems LLC
Effective date: July 18, 2026 · Last updated: September 5, 2026

This Privacy Policy explains how InDate Systems LLC ("InDate," "we," "us," or "our") collects, uses, and protects information in connection with the InDate inventory management platform and related services (the "Service"). It applies to the organizations that subscribe to the Service and to the individual users those organizations authorize. It also covers visitors to the indatesystems.com website and users of the public barcode scan tool at indatesystems.com/scan.

InDate provides a business-to-business tool. Most of the information we handle relates to workplace accounts and supply inventory, not to consumers in their personal capacity.


1. Information We Collect

Account and contact information. When an organization signs up and when users are added, we collect information such as names, work email addresses, job roles or titles, the organization name, and the station or location a user is assigned to. We also collect authentication information used to secure accounts.

Customer Data you enter. The Service stores the supply and inventory information that you and your users enter, import, or scan, including item descriptions, quantities, locations, lot and batch numbers, expiration dates, par levels, and related activity such as who recorded a change and when. This also includes photographs, videos, and electronic signatures that your users capture in the course of their work, such as equipment images, evidence attached to a spot check, and the crew and witness signatures recorded on controlled-substance custody entries.

Usage and device information. When you use the Service, we automatically collect basic technical information such as log data, IP address, browser or device type, and actions taken within the Service. We use this to operate, secure, and improve the platform.

Device location. With your permission, the Service uses your device's approximate location to suggest the station nearest to you and to guard against recording activity at the wrong station. Location is used at the moment of that check and is not stored as a location history. You can decline the permission or turn it off in your browser or device settings; the Service remains usable, and you select your station manually instead.

Communications. If you contact us for support or otherwise, we keep records of that correspondence.

Website visitors and the public scan tool. The indatesystems.com website sets no cookies and runs no analytics. Its pages load web fonts from Google Fonts and rsms.me, which receive your IP address and browser details in order to serve the font files. The public barcode scan tool at indatesystems.com/scan decodes barcodes in your browser, and camera video never leaves your device. To describe a scanned product it may look the code up in public U.S. FDA and NIH databases, which receive the code and your IP address and nothing else. Your scan history is stored only in your browser.

The core Service is not designed to hold patient health information. One optional feature — the digital dose record in the Controlled Substances module — does, and is enabled for a customer only under a signed Business Associate Agreement. See Section 8.

2. How We Use Information

We use the information we collect to:

We may create aggregated or de-identified information that does not identify you, your organization, or any individual, and use it to operate and improve the Service.

3. We Do Not Sell Your Data

InDate does not sell your personal information or your Customer Data, and we do not share it with third parties for their own advertising or marketing purposes. We use the information solely to provide and improve the Service as described in this Policy.

4. Service Providers and Sub-Processors

We rely on a small number of trusted third-party providers to host and operate the Service. These providers process information only on our behalf and under obligations of confidentiality and security. They currently include:

Web push notifications are delivered through the push service operated by your browser or device vendor (Google, Apple, or Mozilla), which receives the delivery endpoint and the message payload needed to deliver the message to your device. We configure notifications, by email and by push, so that they do not contain patient-identifiable information; they direct you to sign in to view details.

Where your data is processed. The Service and its data are hosted in the United States.

We may add or change sub-processors as the Service evolves and will update this Policy accordingly.

5. Data Security

We take reasonable technical and organizational measures designed to protect information against unauthorized access, loss, or misuse. These measures include encryption in transit and at rest, access controls, and role-based permissions within the Service. No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your account credentials and for managing which of your users have access.

6. Data Retention

We retain account information and Customer Data for as long as your organization maintains an active subscription and as needed to provide the Service. Following termination, we make Customer Data available for export for a limited period (as described in our Terms of Service) and then delete it from our production systems, subject to any legal retention obligations. Copies remaining in routine backups are deleted as those backups age out of our normal cycle, within ninety (90) days. Aggregated and de-identified information created under Section 2, which does not identify you, your organization, or any individual, is not Customer Data and may be retained.

If your organization has a signed subscription agreement with us, the retention, export, and deletion terms of that agreement govern.

7. Your Rights and Choices

Depending on your location and applicable law, you may have rights to access, correct, update, or request deletion of certain personal information we hold about you. Because much of the information in the Service is controlled by the subscribing organization, we will generally direct individual requests to the relevant organization, which acts as the controller of that data. To make a request or ask a question, contact us using the details in Section 12.

8. Protected Health Information (HIPAA)

The core Service is designed for supply and inventory data, not for patient information, and the Controlled Substances module in its paper-log mode stores no patient data. We ask that customers not enter Protected Health Information (PHI) into the Service unless InDate has entered into a written Business Associate Agreement (BAA) with the customer.

The Controlled Substances module also provides for an optional digital dose record, which is not enabled by default. Where a customer has enabled it under a signed BAA, the Service stores a limited set of PHI for each administration: the incident or patient-care-report number, the patient's last name, and date of birth (or age and sex), and optionally first name. We enable the digital dose record for a customer only after a BAA has been signed; for those customers InDate acts as a HIPAA business associate and handles that PHI in accordance with the BAA, including encryption at rest, restricted access, and access logging. Absent a signed BAA, InDate does not act as a business associate, and the customer is responsible for ensuring that no PHI is introduced into the Service. If you have a need to process PHI through the Service, contact us to discuss a BAA before doing so.

9. Cookies and Similar Technologies

The Service uses cookies and similar technologies that are necessary to keep you signed in, to remember your preferences, and to keep the Service secure and functioning. We do not use advertising or cross-site tracking cookies.

10. Children's Privacy

The Service is intended for use by organizations and their authorized personnel in a professional capacity. It is not directed to children and is not intended for anyone under the age of 18. We do not knowingly collect personal information from children.

11. Changes to This Policy

We review this Privacy Policy at least once a year, and whenever we make a material change to the Service or to how we handle information. That review checks that our actual practices still match what this Policy describes, and where the two have drifted apart we correct the Policy or the practice.

We may update this Privacy Policy from time to time. If we make material changes, we will provide reasonable notice, such as by email or through the Service, and update the "Last Updated" date above. Your continued use of the Service after the changes take effect constitutes acceptance of the updated Policy.

12. Contact Us

If you have questions or requests regarding this Privacy Policy or your information, contact:

InDate Systems LLC
8593 State Highway 7 W
Jewett, TX 75846
Email: privacy@indatesystems.com