Back to Home
Legal

Privacy Policy

How Giantronic collects, uses, and protects your data when you manage ESP32 devices through our platform.

Overview

Giantronic is built to give you full control over your IoT devices and your data. This policy explains what we collect, why we collect it, and how we keep it safe.

We believe privacy is a right, not a feature. Giantronic does not sell your data, does not inject advertising trackers, and does not share personal information with third parties except where required to operate the service (such as Firebase for authentication and cloud messaging).


Data We Collect

We only collect the minimum data necessary to run the platform and keep your devices secure.

Account Data

Username, email address, profile details, and authentication credentials managed through Firebase Auth.

Device Data

Device names, chip IDs, MAC addresses, firmware versions, online status, and pin configurations.

Operational Data

Flash job logs, OTA update history, energy readings, schedules, scenes, and automation rules.

Usage Data

IP addresses, browser type, session activity, and audit logs used for security and debugging.


How We Use Your Data

Your data is used solely to operate, secure, and improve the Giantronic platform.

  1. Authentication & Access

    Verify your identity, manage sessions, and enforce role-based access control across organizations.

  2. Device Management

    Pair ESP32 devices, push firmware, monitor online status, and execute remote pin controls and automations.

  3. Security & Auditing

    Detect suspicious activity, log security events, and protect against unauthorized access to your fleet.

  4. Service Improvement

    Analyze aggregated, anonymized usage patterns to improve reliability and fix bugs. No personal identifiers are used.


Data Sharing & Third Parties

Giantronic does not sell or rent your personal data. We only share data with trusted service providers necessary to operate the platform.

ServicePurposeData Shared
Firebase (Google)Authentication, cloud messaging, and real-time databaseEmail, UID, device tokens
Hosting ProviderApplication hosting and deliveryStandard server logs (IP, user agent)
Celery / RedisBackground job processingFlash job metadata, firmware URLs

No advertising partners. Giantronic has no ad networks, analytics trackers, or data brokers in our supply chain.


Cookies & Local Storage

Giantronic uses minimal session storage to keep you logged in and remember your preferences.

The platform uses Django session cookies for authentication and localStorage solely for theme preference (flashhub-theme). No third-party tracking cookies or advertising pixels are deployed.


Data Security

We implement industry-standard measures to protect your data.

Encryption in Transit

All API and dashboard traffic is served over HTTPS/TLS. Firebase connections are also encrypted.

Role-Based Access

Organization-level isolation, role checks, and audit logging ensure only authorized users access sensitive operations.

Audit Logging

Every login, firmware flash, user creation, and configuration change is logged with timestamp and IP address.

Two-Factor Auth

TOTP-based 2FA is available for all accounts to prevent unauthorized access even if a password is compromised.


Your Rights

You have full control over your data. Here is what you can do at any time.

  • Access Your Data

    View all account information, devices, jobs, and organization details directly from the dashboard.

  • Update or Correct Data

    Edit your profile, rename devices, update pin configurations, and modify automation rules as needed.

  • Delete Your Data

    Delete individual devices, remove organizations, or request full account deletion by contacting support.

  • Export Your Data

    Request a full export of your account data, device configurations, and operational logs at any time.


Data Retention

We retain data only as long as necessary for operational and legal purposes.

Account and device data is retained for the lifetime of your account. Flash job logs and audit trails are kept indefinitely for security and debugging purposes. When you delete your account, all personally identifiable data is removed within 30 days, while anonymized operational data may be retained for aggregate analytics.


Changes to This Policy

We may update this privacy policy from time to time. Material changes will be communicated through the dashboard or via email.

The version and last updated date will be shown at the top of this page. Continued use of Giantronic after changes are posted constitutes acceptance of the updated policy.


Contact Us

If you have questions about this privacy policy or how your data is handled, please reach out.

Email: privacy@giantronic.com  |  Support: support@giantronic.com

We aim to respond to all privacy inquiries within 5 business days.