BAMF Apps

BAMF Tracker

Live

Field CRM for solar & electrical crews

  • Web
Business

BAMF Tracker is a self-hosted CRM and job tracker for solar and electrical services companies. It runs as an installable web app (PWA) and keeps contacts, jobs, quotes, e-signatures, payments, timesheets, inventory, and solar-inverter monitoring in one place, with real-time sync across the crew and full offline support.

Features

  • Contacts and customer management with geocoded service addresses
  • Jobs with workflow stages, auto-created checklist tasks, and activity history
  • Quotes, contracts, and in-house e-signature (no third-party signing service required)
  • Invoicing and payments (Stripe when configured; manual/offline methods otherwise)
  • Crew timesheets and availability
  • Inventory, products, purchase orders, and shopping lists
  • EG4/Luxpower solar-inverter monitoring, settings control, and one-click customer onboarding
  • Real-time multi-user sync via WebSockets and full offline mode (PWA + IndexedDB)
  • Optional Discord notifications and AI-generated job summaries
  • Public, login-free customer pages for viewing quotes, signing documents, and paying

Permissions

  • Camera: scan QR/barcodes on solar dataloggers and equipment during onboarding
  • File access (file picker): attach photos, PDFs, and documents to jobs; upload backups

Third-party services

  • Stripe: payment processing and invoicing (only when the operator configures Stripe keys)
  • Google Maps / Geocoding / Static Maps: convert service addresses to coordinates and render maps (operator-configured API key)
  • Google Sign-In (OAuth): optional alternative login for staff (operator-configured)
  • Gmail API: send transactional email such as welcome and notification emails (operator-configured)
  • OpenStreetMap Nominatim: fallback address geocoding
  • Discord: post job/task/payment notifications to a team channel (operator-configured webhook/bot)
  • EG4 Monitor (monitor.eg4electronics.com): read and control customer solar inverters (operator-configured EG4 credentials)
  • OpenSolar: import solar system designs and pricing (operator-configured)
  • Anthropic (Claude): generate optional AI summaries of job activity (operator-configured API key)
  • Weather & geo data (Open-Meteo, NWS api.weather.gov, USGS, ASCE, Hawaii GIS): wind/seismic/hazard lookups for permit packets
  • County property records (qPublic / Schneider): look up parcel data for permit packets

Data & privacy disclosures

Data Disclosures: BAMF Tracker

BAMF Tracker is a self-hosted web app (PWA) and is not currently distributed on the Apple App Store or Google Play. The tables below are provided for completeness, for the BAMF Apps website, and for any future store packaging. They are mapped from the App's actual data use.

Key framing: the App stores data on the Operator's own server. The publisher (BAMF Apps) does not collect or receive any of it. "Collected" below means "stored/processed by the App instance," and "shared" means "sent to a third party only when the Operator enables that integration." The App contains no analytics, advertising, or crash-reporting SDKs and does no tracking.


Apple "App Privacy" nutrition label

Used to Track You: None. The App does not track users across apps or websites.

Data Linked to You (stored within the Operator's instance, associated with records/accounts):

Data TypeSpecific DataPurposeLinkedTracking
Contact InfoName, email, phone, physical addressApp FunctionalityYesNo
User ContentNotes, photos/files, quotes, contracts, signatures, site surveysApp FunctionalityYesNo
Financial InfoInvoice/payment records, Stripe identifiers (no full card numbers)App FunctionalityYesNo
IdentifiersUser/account ID, login email, session token, optional Google IDApp FunctionalityYesNo

Data Not Linked to You: None.

Data Not Collected (by the App / its publisher):

  • Health & Fitness: Not collected
  • Location (device GPS / precise / coarse): Not collected (addresses are typed, not taken from device location)
  • Browsing History: Not collected
  • Search History: Not collected
  • Usage Data: Not collected (no analytics)
  • Diagnostics: Not collected (no crash/analytics SDKs)
  • Contacts (device address book): Not collected
  • Sensitive Info: Not collected
  • Purchases (advertising): Not collected

Note: when the Operator enables Stripe, Google, Gmail, Discord, EG4, OpenSolar, or Anthropic, the relevant subset of the "Linked to You" data above is transmitted to that provider to deliver the feature. Each provider maintains its own App Privacy disclosures.


Google Play "Data safety"

Does the app collect or share user data? Yes (stored on the Operator's server; shared with a third party only when the Operator enables that integration). Is data encrypted in transit? Yes, when the Operator serves the App over HTTPS (recommended). Can users request data deletion? Yes, handled by the Operator within the App (see account-deletion.md). Is there a way to delete an account? Yes, by the Operator/admin.

Data categoryData typeCollectedShared*Processed ephemerallyRequired / OptionalPurpose
Personal infoNameYesYes*NoRequiredApp functionality
Personal infoEmail addressYesYes*NoRequiredApp functionality, Account management
Personal infoPhone numberYesNoNoRequiredApp functionality
Personal infoPhysical addressYesYes*NoRequiredApp functionality (geocoding)
Personal infoUser IDsYesNoNoRequiredApp functionality, Account management
Financial infoPurchase/payment historyYesYes*NoOptionalApp functionality (invoicing/payments)
Photos & videosPhotosYesNoNoOptionalApp functionality (job attachments)
Files & docsFiles & documentsYesYes*NoOptionalApp functionality (attachments, AI summary text)
App activityOther user-generated contentYesYes*NoRequiredApp functionality

* Shared only when the Operator enables the relevant integration: Stripe (payments), Google Maps/Gmail (geocoding/email), Discord (notification content), Anthropic (text included in a requested AI summary), EG4/OpenSolar (solar identifiers). With no integrations enabled, no data is shared with third parties.

Not collected: location (device), health, contacts (device), calendar, SMS/call logs, browsing/search history, usage analytics, diagnostics/crash data, advertising identifiers.

Security practices: passwords stored hashed (one-way); role-based access control; sensitive hardware actions gated with confirmation. Transport security and host hardening are the Operator's responsibility.

Legal & support