Privacy

Privacy Policy

This page is maintained by Wrap-IT Inc. to explain how we handle your data when you use the Wrap-IT helpdesk, asset, inventory, procurement, and monitoring platform. It describes our current practices in plain language — it is not an independent audit or certification.

Last updated: 31 July 2026

Who we are

Wrap-IT Inc. ("Wrap-IT", "we", "us") provides the Wrap-IT platform available at wrap-it.app. For personal data you give us directly as an account holder, Wrap-IT Inc. acts as the data controller.

Where your employer or IT provider uses Wrap-IT to manage its own helpdesk tickets, assets, and devices, that organization decides what data is entered and who may see it. In those cases we process the data on the organization's behalf, and you should also review your organization's own internal policies.

Privacy contact: Wrapituoh@gmail.com

What data we collect

  • Account details — your name, email address, profile picture, and password (stored only as a salted hash; we never see the plain value).
  • Organization and role — which workspaces you belong to and whether you are an owner, admin, technician, finance user, or employee.
  • Helpdesk tickets and attachments — subjects, descriptions, error messages, comments, and any files or screenshots you upload.
  • Asset and inventory records — devices, serial numbers, purchase and warranty details, assignments to employees, and lifecycle history.
  • Procurement records — purchase requests, RFQs, vendor quotes, purchase orders, goods receipts, invoices, and approval decisions.
  • Device monitoring data — when your organization connects its Microsoft Intune tenant, we read device inventory, compliance state, health metrics, installed software, and security alerts for the managed endpoints.
  • Notification preferences — email and push notification settings, and the push subscription token issued by your browser or device.
  • Feedback you send — messages and any screenshot you choose to capture and attach through the in-app feedback widget.
  • Technical logs — basic request, error, and audit records used to keep the service running securely.

Sign-in and Google SSO

You can sign in to Wrap-IT with an email and password, with Google, or with Apple. Sign-in is brokered through our authentication provider, and the consent screen you see is issued by Google or Apple, not by us.

Signing in with Google

When you choose "Continue with Google", Google asks for your permission and then shares a limited set of information with us:

  • Your Google account email address
  • Your name as it appears on your Google profile
  • Your Google profile picture
  • A unique account identifier that lets us recognise you on your next sign-in

We request only the openid, email, and profile scopes — nothing more. We never receive your Google password, and we do not request or read your Gmail, Drive, Calendar, Photos, or Contacts.

We use what Google shares to create or match your Wrap-IT account, populate your display name and email so colleagues can identify you, and keep you signed in. We do not sell this data or use it for advertising.

You can revoke Wrap-IT's access at any time from your Google Account permissions page. Revoking access stops future Google sign-ins but does not delete your Wrap-IT account — email Wrapituoh@gmail.com to have the account and its data removed.

Signing in with Apple

Apple sign-in shares your name and email address along with a unique identifier. If you choose Apple's "Hide My Email" option, we only ever receive a private relay address, and messages we send are forwarded to you by Apple. You can manage or revoke this from your Apple ID account settings under "Sign in with Apple".

How we use your data

  • Running the features you use — helpdesk, assets, inventory, preventive maintenance, procurement, monitoring, and reporting.
  • Identifying you to colleagues in your organization, such as showing who raised a ticket and who is working on it.
  • Sending service messages: ticket updates, SLA warnings, maintenance reminders, approval requests, and vendor emails you trigger.
  • Generating dashboards, exports, and reports for your organization.
  • Keeping the service secure — authentication, role checks, audit trails, rate limiting, and abuse prevention.
  • Responding to your support requests and feedback.

We do not sell your personal data, and we do not use it for advertising or behavioural profiling.

AI features

Wrap-IT includes AI assistance: ticket summaries and suggested next steps, the in-app copilot, remediation guidance for monitored devices, procurement suggestions, and executive insights in reports.

When you use one of these features, the relevant record content — for example the ticket text you are viewing or the aggregated figures in a report — is sent to our AI model provider so it can generate a response. Requests are processed to return your result only. This content is not used to train third-party models, and AI features are subject to the same role and organization access rules as the rest of the app.

AI output is a suggestion, not a decision. Actions the copilot proposes — such as creating a ticket or a procurement request — are only carried out after you confirm them.

Service providers we rely on

We share data with a small set of providers strictly so they can deliver part of the service:

  • Cloud hosting and database — stores your account, records, and file attachments.
  • Email delivery — transactional and notification emails sent from notify.wrap-it.app.
  • Push notification delivery — your browser or device vendor's push service, used to deliver alerts to your phone or desktop.
  • AI model provider — processes the content described in the AI section above.
  • Microsoft Graph / Intune — only where your organization connects its own tenant for device monitoring.
  • Google and Apple identity services — only when you choose to sign in with them.

We may also disclose data if we are legally required to, or to protect the rights and safety of our users and the service.

Cookies and local storage

Wrap-IT uses only what it needs to work. We store your session token so you stay signed in, plus a few preferences on your device: selected workspace, display currency, and whether you have completed the product tour.

We do not use advertising cookies, cross-site trackers, or third-party marketing pixels. Clearing your browser storage signs you out and resets these preferences.

How long we keep data

  • Account and profile data — kept while your account is active, and deleted within 90 days of account closure or a deletion request.
  • Tickets, assets, inventory, and procurement records — retained for the life of the organization's account, then deleted within 90 days.
  • Device health snapshots — 30 days.
  • Threat and alert events — 180 days.
  • Audit logs — 12 months, for security and accountability.
  • Backups — purged within 35 days.

We may keep limited records for longer where the law requires it, for example financial documents tied to procurement.

Your rights

We align our practices with the principles of the EU/UK General Data Protection Regulation, and we honour these rights for all users regardless of where you live:

  • Access — request a copy of the personal data we hold about you.
  • Correction — ask us to fix data that is wrong or incomplete.
  • Deletion — ask us to erase your account and personal data.
  • Portability — receive your data in a portable format.
  • Objection and restriction — object to, or ask us to limit, certain processing.
  • Withdraw consent — where processing relies on consent, such as push notifications, you can turn it off at any time.

To exercise any of these, email Wrapituoh@gmail.com. We respond within 30 days. If your data was entered by your employer through their Wrap-IT workspace, we may need to route your request through that organization's administrator.

International data transfers

Wrap-IT and the providers listed above operate across multiple regions, so your data may be processed outside the country where you live. When data moves across borders we rely on appropriate safeguards, such as standard contractual clauses with our providers, and we transfer only what is needed to run the service.

How we protect your data

  • Role-based access control — owners, admins, technicians, finance users, and employees each see only what their role allows.
  • Row-level isolation — records are scoped to your organization at the database layer, so one workspace cannot read another's data.
  • Encrypted transport — all traffic to and from Wrap-IT uses HTTPS.
  • Private file storage — ticket attachments are stored privately and served only to the requester and assigned staff.
  • Audit logging — sensitive changes are recorded so administrators can review activity.
  • Secret management — integration credentials such as Intune client secrets are held in a secure vault, never in application code.

No online service can promise perfect security, but we work to keep these controls current. If you believe you have found a vulnerability, please report it to Wrapituoh@gmail.com.

Children

Wrap-IT is a workplace tool intended for business use. It is not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact us and we will delete it.

Changes to this policy

We may update this policy as the product changes. When we do, we revise the "last updated" date at the top of this page, and for significant changes we notify account owners by email or with an in-app notice before the change takes effect.

Questions about your privacy?

Contact Wrap-IT Inc. about this policy, a data request, or anything else on this page and we'll get back to you.