Privacy Policy
What IMS collects, why we collect it, and the choices you have.
Last updated: 9 September 2026
1. Scope
This policy covers the IMS web application at ims-tech.io and the IMS mobile app for iOS and Android (together, the “Service”). IMS is a business operations platform for metals and alloys trading, sold to companies rather than to consumers. Accounts are created and administered by the customer organisation that subscribes to IMS; the Service is not intended for personal or household use.
Where a customer organisation loads its own business records into IMS, that organisation is the controller of those records and IMS acts as its processor. This policy describes our own handling in both roles.
2. Information we collect
Account information. The email address and password used to sign in, your display name, and the role assigned to you by your organisation’s administrator (for example standard, accounting or administrator). Passwords are handled by Google Firebase Authentication and are never stored by us in readable form.
Business records you enter. The operational data you or your colleagues create in the Service — contracts, purchase orders, invoices, shipments, stock and warehouse records, supplier and client details, expenses, cashflow entries, pricing formulas, and any documents or certificates you upload. This content is stored under your organisation’s own namespace and is not shared between customer organisations.
Technical and device information. Basic technical data needed to operate the Service, including authentication session tokens and, if you enable push notifications in the mobile app, a device push token used solely to deliver those notifications.
Stored on your device only. If you turn on biometric sign-in, your sign-in credentials are stored in the operating system’s secure keystore (iOS Keychain / Android Keystore) on that device so you can unlock the app with Face ID, Touch ID or a fingerprint. Those credentials are not transmitted to us, and we never receive your fingerprint or face data — the operating system performs the biometric check and only reports success or failure to the app.
We do not use advertising identifiers, we do not track you across other companies’ apps or websites, and we do not sell personal information.
3. How we use information
- To authenticate you and keep your session secure.
- To provide the Service — storing, retrieving, calculating and presenting your organisation’s business records.
- To send notifications you have enabled, such as reminders and operational alerts.
- To diagnose faults, maintain security, and prevent misuse.
- To meet legal, tax and accounting obligations.
4. AI-assisted features
Parts of the Service use large language models supplied by OpenAI to reduce manual data entry and to summarise information. These features include reading uploaded trade documents and certificates, categorising expenses, checking material certificates, producing cashflow forecasts and daily briefings, drafting reminders, flagging margin anomalies, and answering questions in the in-app assistant.
When you use one of these features, the relevant content — for example the text of a document you uploaded or the records needed to answer your question — is transmitted to OpenAI for processing, and the result is returned to the Service. We send only the content needed for the requested task. We do not permit this content to be used to train third-party models. If you would prefer that your organisation’s data is not processed this way, your administrator should contact us so these features can be discussed for your account.
6. Storage and security
Data is held on Google Cloud infrastructure. Traffic between the apps and our servers is encrypted in transit, and data is encrypted at rest by the underlying platform. Access to records inside the Service is limited by your organisation’s role assignments, and administrative access on our side is restricted to staff who need it to run and support the Service. No system can be guaranteed completely secure, but we work to protect your information using measures appropriate to its sensitivity.
7. Retention
We keep your organisation’s records for as long as its account is active, and afterwards only as long as needed for legitimate business or legal purposes. On written request from your organisation’s administrator we will delete or return its data within a reasonable period, subject to any retention we are legally required to observe.
8. Your choices and rights
Depending on where you live, you may have the right to access, correct, export or delete personal information we hold about you, to object to or restrict certain processing, and to complain to a data protection authority.
Because IMS accounts are issued and controlled by your employer, the quickest route for access, correction or deletion is usually your own administrator, who can change or remove your account directly. You can also write to us at info@ims-metals.com and we will respond, coordinating with your organisation where the request concerns its business records. You can turn off push notifications at any time in your device settings, and turn off biometric sign-in from within the app.
9. Children
The Service is a workplace tool intended for use by adults acting for a business. It is not directed to children, and we do not knowingly collect information from anyone under 16.
10. International transfers
Our providers may process information in countries other than your own, including the United States. Where required, we rely on appropriate safeguards — such as the European Commission’s standard contractual clauses — for those transfers.
11. Changes to this policy
We may update this policy as the Service develops. When we do, we will revise the date at the top of this page, and we will give notice of material changes through the Service.
12. Contact us
Questions about this policy or about how your information is handled can be sent to info@ims-metals.com.