Privacy Policy: Your Data, Strictly Isolated.
At SHIFT7, we understand the critical nature of compliance, safety records, and operator client data. This Privacy Policy details how we handle, protect, and isolate your information across our LeadGen engine and API RP 1173 platform.
Last Updated: August 2026
Multi-Tenant Data Isolation
Your compliance data is never co-mingled. SHIFT7 enforces strict server-side multi-tenancy. Every request is verified against the requesting user's organization context before any record touches the database. Contractor gap assessments, policies, and evidence remain invisible to unauthorized third parties and competing vendors.
Information We Collect
We collect only the essential data required to manage your API RP 1173 compliance programs, LeadGen usage, and field operations:
- LeadGen & Product Subscriptions: Email addresses provided when signing up, requesting access, or using the LeadGen regulatory tracking tool.
- Account Information: Name, work email address, job title, phone number, and organization affiliation provided during onboarding.
- Compliance & Safety Records: User-uploaded policies, procedures, evidence documents, MOC forms, incident reports, photos, internal audits, and Operator Qualification (OQ) training records.
- Authentication Credentials: Passwordless magic links generated for mobile field logins to maintain fast, secure user authentication.
- System Audit Logs: Server-generated append-only audit trails capturing user actions, timestamps, and record edits for audit defense and security verification.
How We Use Your Information
We do not sell, rent, trade, or monetize your personal or compliance data. Period.
Information collected on SHIFT7 is used strictly to:
- LeadGen Communications: If you provide your email address while using or subscribing to LeadGen, we will strictly use it to send you future SHIFT7 product updates, feature releases, and relevant platform news. We will never sell your email address or share it with third-party advertisers, data brokers, or marketers under any circumstances.
- Calculate automated maturity scores across the 56 API RP 1173 requirements.
- Generate operator-defensible compliance exports, gap analyses, and corrective action roadmaps for your clients or pipeline operators.
- Notify users of upcoming audits, expiring training qualifications, and pending MOC reviews.
- Provide technical support and enforce platform security controls.
Security & Storage Controls
We employ enterprise-grade defense-in-depth measures to protect compliance assets against unauthorized access:
- Encryption in Transit: All web traffic is forced over HTTPS/TLS (TLS 1.2+) protected by Cloudflare infrastructure.
- Encryption at Rest: Platform databases and uploaded file attachments are encrypted at rest using industry-standard AES storage encryption.
- Role-Based Access Control (RBAC): Granular permissions restrict visibility based on 5 user roles (Admin, Consultant, Safety Manager, Manager, Field Hand).
Third-Party Data Sharing
SHIFT7 shares information solely with infrastructure providers necessary to operate the application (e.g., secure cloud hosting, transactional email delivery for magic links and product updates). We do not share contractor records with pipeline operators unless an authorized user explicitly initiates an export or report generation.
Questions About Your Privacy?
If you have questions regarding this Privacy Policy, your organization's data isolation, or email preference updates, please contact our compliance team directly.