ShareTrack Logo ShareTrack
  • Features
  • Use Cases
  • Pricing
Login Get Started

Privacy Policy

Effective Date: September 27, 2026

Doin, LLC ("Doin," "ShareTrack," "we," "our," or "us"), the publisher of ShareTrack, is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use ShareTrack: the web application at app.sharetrack.org, its public pages for shareholders (shareholder lookup, transfer and replacement-certificate requests, and irrigation schedules), the ShareTrack Water mobile app for iPhone and Android, and this website.

Companies, districts, and trusts ("organizations") use ShareTrack to keep their shareholder records. Each organization decides what it records about its shareholders and who in the organization can see it, and we process those records on its behalf. If you are a shareholder with a question about your records, you can contact the organization that keeps them or contact us.

1. Information We Collect

1.1 Account Information

  • Accounts: Your name, email address, organization, and role. Accounts are created by your organization's administrator, who sends you an email to set your password.
  • Passwords: Handled by our authentication provider and stored only as a one-way hash; we never see or store your password in readable form.
  • Account requests: The name, work email, organization, and plan you send us when you ask for an account or a demo.

1.2 Shareholder and Organization Records

Information your organization's staff enter, or bring in from QuickBooks Online:

  • Shareholder names, mailing addresses, email addresses, and phone numbers
  • Share certificates, ownership and transfer history, and the chain of prior owners
  • Assessments, invoices, balances, and payment status
  • Irrigation schedules (each shareholder's turns, times, and ditch) and water status updates
  • Expense reimbursements: the person being reimbursed, their optional email address, expense details, and receipt files
  • Board meeting records: agendas, attendees, attachments, audio recordings, transcripts, and minutes

1.3 Requests from Shareholders and the Public

Some pages can be used without an account. When you use them, we collect what you enter:

  • Shareholder lookup: Your name as registered, plus a certificate or invoice number.
  • Transfer requests: The certificate and shares being transferred, the new owner's name, address, email address, and phone number, notes, and any document you attach.
  • Replacement certificate requests: The certificate, notes, and the notarized affidavit of loss you attach.
  • Water problem reports: Whether there is no water or low water, and, if you choose to give them, a location note and your name.

Attached documents are kept in private storage that only authorized staff of that organization can open.

1.4 Mobile App Information

  • Push notifications: If you turn on alerts, your phone's push notification token, its platform (iOS or Android), and your alert choices, linked to your account and organization.
  • App version: Each request to our servers includes the app version and platform, so we can keep older versions working and tell you when an update is needed.
  • Permissions: The app asks only for permission to send notifications. It does not access your location, contacts, camera, photos, or microphone.

1.5 Information Collected Automatically

  • Server logs: Our web servers record requests, including IP address, browser or app type, the page requested, and the time.
  • Error reports: When the web app hits an error for a signed-in user, it sends us the error message, technical details, the page (without its query), the browser type, the app release, and the account, so administrators can fix the problem.
  • Activity history: Changes to records such as shareholders, certificates, invoices, transfers, expenses, meetings, and user profiles are logged with who made the change, when, and the values before and after.
  • Abuse protection: To limit repeated requests to public pages, we count them using salted, one-way hashes of IP addresses and the values entered, never the addresses or values themselves.

We do not use analytics, advertising, or tracking tools in the app or on this website.

2. How We Use Your Information

We use information only to:

  • Provide the service: Keep your organization's records, generate certificates and invoices, show schedules and water status, and sync with integrations your organization connects
  • Send notifications: Account invitations, password resets, expense updates by email, and water status and problem-report alerts by push notification
  • Handle requests: Route transfer, replacement-certificate, and water problem requests to the organization's staff
  • Support: Respond to your questions and troubleshoot issues
  • Security: Detect, prevent, and address fraud, abuse, and security issues
  • Compliance: Comply with legal obligations and enforce our terms

We do not sell your personal information and do not use it for advertising.

3. What Others Can See

  • Within your organization: Each person sees only what their role allows.
  • Irrigation schedules: An organization's schedule shows each turn with the shareholder's name as last name and first initial (for example, "SMITH, J"), or the organization or trust name, or a display name the organization chooses. Unless the organization sets a company code, its schedule is public. People with the code, and signed-in members, also see the first name and role of the person who last changed the water status.
  • Shareholder lookup: Someone who enters a shareholder's registered name together with one of their certificate or invoice numbers sees that shareholder's certificates, certificate history, latest invoice, and the organization's mailing address.
  • Transfer requests: Public transfer pages show shareholder names as last name and first initial and hide all but the last two characters of certificate numbers.
  • Meeting share links: Anyone with a meeting's share link can see the meeting's name, date, time, location, attendee list, agenda, and minutes (not recordings, transcripts, or attachments) until the link expires, after at most one year, or the organization turns it off.

4. Service Providers

We share information with these providers only as needed to run ShareTrack:

  • Supabase: Database, sign-in, file storage, and server functions, hosted in the United States.
  • Deepgram: Transcription of board meeting audio (see Section 6).
  • OpenAI: Drafting meeting minutes from transcripts (see Section 7).
  • Intuit QuickBooks Online: Invoices, customers, and financial reports, when your organization connects it (see Section 5).
  • Expo, Apple, and Google: Delivery of push notifications to the mobile app (the notification's title and text, and your device's push token), and app updates.
  • Cloudflare: Storage of off-site backup copies in Western North America.
  • Email delivery providers: Sending account and expense emails.
  • Google Fonts: The web app and this website load fonts from Google, which receives your IP address and browser type when a page loads.
  • Hosting providers: The servers that deliver the web app and this website.

The App Store and Google Play distribute the mobile app under their own privacy policies.

5. QuickBooks Online Data Handling

We take special care with data accessed through the QuickBooks Online integration.

5.1 Data We Access

When your organization authorizes the integration, we access:

  • Company profile information
  • Customer records (names, addresses, email addresses, and phone numbers)
  • Invoices we create, their balances, and the payments applied to them
  • Financial reports: profit and loss, balance sheet, receivables aging, general ledger, and open invoices

5.2 How We Use QuickBooks Data

  • We use QuickBooks data solely to provide the integration features your organization has authorized
  • We do not sell, rent, or share QuickBooks data with third parties for their own purposes
  • We do not use QuickBooks data for advertising or marketing purposes
  • We do not provide API access to QuickBooks data to any third parties

5.3 How the Integration Works

  • Invoices created in ShareTrack are sent to QuickBooks.
  • Customer contact details move in the direction your organization chooses: from ShareTrack to QuickBooks, or from QuickBooks to ShareTrack.
  • When QuickBooks tells us that one of our invoices or a payment on it changed, we fetch that invoice and update its balance and paid status in ShareTrack automatically.
  • Financial reports are fetched when someone with financial permission opens or refreshes the financial dashboard, and summaries are stored for display to those users.

5.4 Data Storage and Security

  • QuickBooks access and refresh tokens are stored only on our servers, in our database, and are never sent to browsers or apps
  • Tokens are never written to logs, URLs, or error messages
  • The database is encrypted at rest, and access is restricted by row-level security and permissions
  • Each authorization request carries a single-use state value, so an authorization cannot be forged or replayed
  • Notifications from QuickBooks are accepted only with a valid Intuit signature

5.5 Disconnection and Data Deletion

Your organization may disconnect QuickBooks at any time in ShareTrack. When it does:

  • We delete the stored access and refresh tokens and stop accessing your QuickBooks company
  • Invoices and customer details already in ShareTrack stay part of your organization's records
  • Copies of earlier data in backups are kept as described in Section 9
  • You may request deletion of all QuickBooks-related data by contacting privacy@sharetrack.org

6. Deepgram Audio Transcription

Board meetings can be recorded in the browser or uploaded as audio files. If staff ask for a transcript:

  • We give Deepgram a private link to the audio that expires after 6 hours. Deepgram fetches the audio, transcribes it with numbered speaker labels (not names), and sends the transcript back to us.
  • Deepgram's handling and retention of audio are governed by its own terms and privacy policy.
  • We delete meeting audio from ShareTrack 30 days after it is transcribed, and unfinished uploads after 30 days. The transcript stays with the meeting until your organization deletes it.
  • Transcription is optional; minutes can always be written by hand.

7. OpenAI Meeting Minutes Generation

If staff ask ShareTrack to draft minutes, we send OpenAI the transcript or notes, the meeting's name, date, time, location, attendee names, and objective, and the chosen level of detail.

  • OpenAI processes this data under its API data usage policies, which state that API data is not used to train its models and may be retained for up to 30 days for abuse monitoring.
  • Draft minutes can be edited or replaced before saving, and deleted at any time.
  • Generating minutes is optional.

8. Data Security

  • Encryption: Data is encrypted in transit with TLS and at rest by our hosting providers.
  • Separation: Each organization's data is kept separate with database row-level security, and role-based permissions limit what each person can see and change.
  • Private files: Attachments, receipts, recordings, and backups are kept in private storage and opened only through short-lived links for authorized users.
  • Web protections: HTTPS on every page, security headers, and a content security policy.
  • Backups: Backups are read back and checked after they are made, and copied off-site to storage that prevents deletion for their first 30 days.
  • Logging: We do not log passwords, access tokens, or QuickBooks data.

9. Data Retention

  • Organization records: Kept while your organization uses ShareTrack. If an organization closes its account, we delete or anonymize its data within 90 days, unless the law requires us to keep it.
  • Meeting audio: Deleted 30 days after transcription; transcripts and minutes stay with the meeting.
  • Error reports: Deleted after about 90 days.
  • Abuse-protection counters: Deleted within about a day.
  • Push notification registrations: Removed when you sign out of the app or your phone stops accepting notifications from it.
  • Backups: Backup copies can include records that were later changed or deleted. Off-site copies are deleted after one year, and copies in our main backup storage are removed periodically by our administrators.
  • Legal holds: Data subject to legal holds or regulatory requirements may be kept longer as required.

10. Your Rights and Choices

Depending on where you live, you may have the right to:

  • Access: Request a copy of your personal data
  • Correction: Request correction of inaccurate or incomplete information
  • Deletion: Request deletion of your personal data, including your account (subject to legal retention requirements)
  • Portability: Receive your data in a structured, machine-readable format
  • Restriction and objection: Ask us to limit or stop certain processing
  • Withdraw consent: Withdraw consent where consent is the legal basis

To exercise these rights, contact us at privacy@sharetrack.org. We will respond within 30 days. If your information is kept by an organization that uses ShareTrack, we may work with that organization to answer your request. You can turn off push notifications at any time in the app or in your phone's settings.

11. California Privacy Rights (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act:

  • Right to know what personal information we collect, use, and disclose
  • Right to request deletion of your personal information
  • Right to opt out of the sale of personal information (we do not sell personal information)
  • Right to non-discrimination for exercising your privacy rights

12. International Data Transfers

ShareTrack is based in the United States, and our service providers store data in the United States and North America. If you use ShareTrack from outside the United States, your information will be transferred to and processed in the United States.

13. Cookies and Device Storage

We do not use advertising or analytics cookies. ShareTrack stores a few things on your device so it works:

  • Sign-in: The web app keeps your sign-in session in your browser's local storage, and the mobile app keeps it on your phone.
  • Preferences: Your selected organization and screen layout.
  • Schedules: Company codes you enter, and a copy of the irrigation schedule and water status so they show when you're offline.
  • Recordings: A meeting recording is saved in the browser as it is made, and removed once it has uploaded.

You can clear this data in your browser or by removing the app. Clearing it signs you out.

14. Children's Privacy

ShareTrack is not intended for users under 18 years of age. We do not knowingly collect personal information from children. If we become aware that we have collected information from a child, we will delete it promptly.

15. Changes to This Policy

We may update this Privacy Policy periodically. We will post the updated policy on this page with a new effective date, and email account holders about significant changes. Your continued use of ShareTrack after changes take effect constitutes acceptance of the updated policy.

16. Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us:

  • Email: privacy@sharetrack.org
  • Address: Doin, LLC, Salt Lake City, Utah, USA

For QuickBooks-related privacy inquiries, you may also contact Intuit directly at their privacy portal.

ShareTrack ShareTrack
  • Login
  • Support
  • Privacy Policy
  • Terms of Service
  • EULA

"Clarity for every share."

© 2026 Doin, LLC. All rights reserved.