Privacy policy
Last updated: September 20, 2026. This policy explains how Indmaksoft ("we", "us") collects, uses, and protects personal information when you visit indmak.com, create an account, purchase a license, or use the FieldLedger desktop application.
1. Who we are (data controller)
Indmaksoft, Flat 226, Chun Tip House, Fu Tip Estate, Tai Po, Hong Kong, is the data controller for the processing described below. For privacy inquiries, data requests, or complaints, contact legal@indmak.com. We respond to verified requests within 30 days.
This policy is written to meet our obligations under applicable privacy laws, including the EU/UK General Data Protection Regulation (GDPR) and the California Consumer Privacy Act as amended (CCPA/CPRA), to the extent they apply to you.
2. Our design principle: the desktop app is local-first
FieldLedger stores your farm records — logs, harvests, costs, compliance documents, photos — as a database and files on your own computer. We do not receive, host, access, or process that content.
The desktop application contains no analytics SDK, no advertising identifier, and no third-party tracking. We cannot read your records, and we cannot recover them for you; backups are your responsibility and are made easy in-app.
The app works fully offline, but it connects to our licensing service (indmak.com) for a few things: starting the free trial and activating a license; a periodic license check (about every 24 hours, when online); an optional add-on entitlement check; and when you check for updates. Each request sends only what is listed in §3 — never your farm records, costs, photos or documents. If you never start a trial, activate a license or check for updates, the app makes no network connections at all.
3. Information we collect
We keep collection to the minimum required to sell, license, and support the software.
- Account data (website): email address, display name (optional), password hash (PBKDF2-SHA256 with a per-user salt; we never store plaintext passwords), account creation date, and email verification status where applicable.
- License & activation data: license key, product, license status, entitlement dates, and the device fingerprint and device name you submit when activating a license. Fingerprints are one-way SHA-256 hashes of a machine identifier — we never receive your raw machine ID, hardware serial numbers, or file contents. The device name is a hostname used for display and anti-abuse only.
- Trial data: when you start the free trial we receive the same hashed device fingerprint and the device name, and we store the trial start and expiry time against that fingerprint so a trial cannot be restarted on the same device. We keep this record to prevent repeat trials (see §7).
- Purchase & billing data: transaction identifiers, product, amount, currency, tax country, and the email used at checkout. Card and bank details are handled exclusively by our merchant of record (Creem) and never reach our servers.
- Support communications: messages you send to support@indmak.com, sales@indmak.com, or legal@indmak.com, and any files you choose to attach (for example a CSV export when troubleshooting).
- Update checks: when the app checks for updates we receive your app version, operating system platform and CPU architecture. No identifier is included.
- Technical logs: when a request reaches our servers we process IP address, timestamp, requested path, user agent, and outcome for security, abuse prevention, rate limiting, and debugging. Logs are retained short-term (see §7).
- Session cookies: strictly necessary cookies used to keep you signed in to your account. We do not use advertising cookies, cross-site trackers, or third-party analytics cookies.
4. What we do not collect
- No farm records, field data, financial records, photos, or documents created in the desktop app.
- No analytics or usage telemetry from the desktop application.
- No precise geolocation. We do not use GPS, Wi-Fi positioning, or location history.
- No advertising identifiers, and no sale or sharing of personal information for advertising purposes — ever (see §6).
5. How we use information, and our legal bases
Under the GDPR we rely on the following legal bases; for other jurisdictions we rely on equivalent grounds.
- Contract performance — creating your account, issuing and validating license keys, processing payments, delivering downloads, providing support you request.
- Legitimate interests — securing the service against fraud, key sharing, and abuse; rate limiting; maintaining reliability; understanding aggregate sales so we can keep the business running. We balance these interests against your rights and do not use them to profile you for advertising.
- Legal obligation — retaining tax-relevant purchase records, responding to lawful requests, and enforcing our Terms.
- Consent — only where required (for example, if you opt in to a product-updates email list). You can withdraw consent at any time; withdrawal does not affect prior lawful processing.
6. Sharing and disclosure
We do not sell your personal information. We share it only with service providers that help us operate, under contract and only for the purposes below.
- Creem (merchant of record) — checkout, payment processing, tax calculation and remittance, invoices, refunds. Creem processes your payment and identity data as an independent controller for its own compliance obligations (KYC/AML, tax).
- Cloudflare — hosting, content delivery, database, object storage, and security for this website and our licensing service. Data is processed on their global network under their data processing terms.
- Resend — transactional email delivery (order receipts, license keys, support replies).
- Professional advisers and authorities — when required by law, to respond to valid legal process, to enforce our agreements, or to protect the rights, safety, and property of our users or ourselves. Where permitted, we will notify you of such requests.
Distribution via the Microsoft Store: if you install FieldLedger from the Microsoft Store, Microsoft may collect installation and usage data under the Microsoft Privacy Statement. That processing is controlled by Microsoft, not by us.
7. Retention
- Account and license data: kept while your account is active and for as long as needed to honor your license. After account deletion we retain a minimal record of purchases required for tax and accounting (typically 7 years) and to prevent license abuse.
- Activation records (device fingerprints and device names): kept while the license is active so you can deactivate and move machines.
- Trial records (hashed fingerprint, device name, trial start/expiry): kept to enforce the one-trial-per-device rule, and removed or aggregated when no longer needed for that purpose.
- Technical logs: retained for a short period (generally up to 30 days) and then deleted or aggregated.
- Support correspondence: kept up to 24 months so we can help consistently across tickets, then deleted.
8. International transfers
Our service providers operate globally, so your information may be processed outside your country (including in the United States). Where personal data of EEA/UK/Swiss residents is transferred, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework, together with additional technical measures. You may request a copy of the relevant safeguards via legal@indmak.com.
9. Security
- Passwords are stored only as salted PBKDF2-SHA256 hashes; sessions use signed, short-lived tokens in HttpOnly, Secure, SameSite cookies with server-side revocation.
- Administrative access requires individual accounts with time-based one-time-password (TOTP) two-factor authentication and optional network restrictions.
- License entitlement files are signed with Ed25519 keys; private signing keys never leave our server environment.
- All traffic is encrypted in transit with TLS 1.2+. Data at rest is encrypted by our infrastructure providers.
- No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and the relevant authorities as required by law.
10. Your rights
Subject to your jurisdiction and to legal exemptions, you have the right to:
- Access a copy of the personal information we hold about you, and receive it in a portable, machine-readable format.
- Correct inaccurate information (email and display name can be edited in your account).
- Delete your account and associated personal data (subject to records we must retain by law, such as tax records and minimal anti-abuse records).
- Object to or restrict certain processing based on legitimate interests, and withdraw consent where processing is based on consent.
- Opt out of any "sale" or "sharing" and of targeted advertising — note that we simply do not engage in these practices, so there is nothing to opt out of.
- Non-discrimination: we will not deny you service or charge you more for exercising your privacy rights.
- Lodge a complaint with your local supervisory authority. We ask that you contact us first so we can resolve the issue quickly.
11. Cookies
We use only strictly necessary cookies: a session token (kept while you remain signed in) and a CSRF/anti-abuse value. No analytics, advertising, or social media cookies are set by this site, so no cookie banner is required. Clearing cookies signs you out but does not affect the desktop application or your license.
12. Children
Our services are intended for business use by adults. We do not knowingly collect personal information from children under 16 (or the applicable age of digital consent in your jurisdiction). If you believe a child has provided us information, contact legal@indmak.com and we will delete it.
13. Do Not Track
Because we do not track users across sites, we do not respond differently to browser Do Not Track or Global Privacy Control signals; we treat all users as opted out of cross-site tracking by default.
14. Changes to this policy
If we make material changes, we will update the date at the top of this page and, where the change significantly affects you, notify account holders by email before the change takes effect. Continued use of the website after changes constitutes acceptance.
This revision (September 20, 2026) adds details about trial records, the device name, update checks, and the network connections the desktop app makes to our licensing service.
15. Contact
Privacy questions, data subject requests, or complaints: legal@indmak.com. Not sure whether something is a privacy matter? support@indmak.com will route it correctly.