Account data: name, email address, and password (stored as a salted hash, never in plain text). Project data: project details, tasks, budgets, change orders, RFIs, punch list items, and site log entries you or your team enter. Uploaded files: documents and photos you upload to a project.
To provide and operate the Service, to send account-related email (confirmation, password reset, team invitations), and to maintain security and prevent abuse. We do not sell your data.
Project data is visible only to people with a role on that specific project: the developer who owns it, the general contractor(s) assigned to it, and subcontractors (limited to their own assigned tasks and general project information). Access is enforced at the database level, not just hidden in the interface.
We use the following subprocessors to operate the Service: Supabase (database, authentication, and file storage), Vercel (application hosting). [Add any additional processor here, e.g. a payment processor or email-delivery provider, once configured.]
We retain your data for as long as your account is active. You may request deletion of your account and associated data by contacting jpaneyko6@gmail.com; some information may be retained where required by law or for legitimate business records (e.g., financial/billing history).
Uploaded files are stored in a private bucket and are never publicly accessible; downloads use short-lived signed links generated only for authorized users. Database access is protected by row-level security policies scoped to project membership.
Depending on where you live, you may have rights to access, correct, export, or delete your personal data. Contact jpaneyko6@gmail.com to make a request.
We may update this policy from time to time. Continued use of the Service after changes take effect constitutes acceptance of the revised policy.
Questions about this policy can be sent to jpaneyko6@gmail.com.