Privacy Policy
Last updated: 29 August 2026
UNUMIS LTD, a company registered in the Republic of Uzbekistan, operates Gidlist. This policy explains what we collect, why, how long we keep it, and what you can ask us to do about it.
For anything in this policy, write to gidlist.operations@gmail.com. Our registered address is available on request to that address.
Two different relationships
Gidlist is used by organisations, and that changes who decides what happens to your data.
For your account — your email address and name — we decide, and this policy applies directly.
For the work recorded inside a space — checklists, submissions, photographs, locations — the organisation that owns the space decides, and we act on its instructions. If you fill in checklists for your employer and want that content changed or removed, ask your employer first. We will pass such requests on to them rather than acting alone, because the record belongs to them.
What we collect
Account details: your email address and name, and your profile picture if you choose to sign in with Google.
Membership: which spaces and boards you belong to, and your role in each.
Checklist content: the templates and schedules your organisation creates.
Submissions: which items were ticked, the time each one was ticked, who submitted the result, and any notes added.
Attachments: photographs and files, but only for items where your organisation has asked for them.
Location: GPS coordinates, only for items where your organisation has turned location on, and only at the moment you tick that item. We do not track your location in the background, and the app cannot read your position when it is closed.
Technical records: server logs, including IP address and browser, kept so we can secure the service and investigate faults.
Why we use it
To provide the service: to show your organisation what was done, by whom, and when.
To keep the record trustworthy, which is the point of the product.
To send necessary email, such as invitations and alerts about your account.
To keep the service secure and to investigate misuse.
We do not sell your data, and we do not use it for advertising or profiling.
How long we keep it
The record of a submission is kept for as long as the organisation’s account exists. An operational record that quietly disappeared after a year would be worth nothing, so we do not delete it on a timer.
Attachments are treated differently, because they are large and their usefulness fades. Photographs and files are removed automatically once the organisation’s plan retention window passes: 90 days on the free plan, 365 days on Starter, 730 days on Team, and indefinitely on Business.
When an attachment expires, the record still shows that one was provided and the date it was removed. Nothing about the submission itself is erased.
If you close your account we delete your account details. Content belonging to an organisation’s space remains that organisation’s record.
Who else handles your data
We use a small number of providers to run the service, and they process data only on our instructions:
Supabase — database, file storage, and sign-in.
Vercel — hosting for the website and application.
Resend — sending transactional email such as invitations.
Google — only if you choose to sign in with a Google account.
These providers operate infrastructure outside Uzbekistan, which means your data may be stored and processed abroad. If your organisation has obligations about where data is held, contact us before storing regulated records in Gidlist.
Your rights
You can ask us for a copy of your data, ask us to correct it, ask us to delete it, or object to how we use it.
Write to gidlist.operations@gmail.com and we will answer within 30 days.
Where the data forms part of an organisation’s operational record, we will forward your request to that organisation, as explained above.
Security
Access to data is enforced by the database itself rather than only by the application, so a fault in one screen cannot expose another organisation’s records. Traffic is encrypted in transit, and attachments are held in private storage reachable only through short-lived links.
No service can promise perfect security. If we ever discover a breach affecting your data, we will tell you.
Children
Gidlist is a workplace tool and is not intended for anyone under 16. We do not knowingly collect data from children.
Changes to this policy
When this policy changes we update the date at the top. If a change materially affects your rights, we will email account holders rather than relying on you to notice.