Privacy Policy

Last updated: July 14, 2026

What we collect

Account data. Your email address (used for magic-link sign-in), your name if you provide it, and the workspace and role you belong to. We also record sign-in timestamps, IP address, and browser user-agent as a security trail.

Project data. Whatever your workspace puts into the service: projects, units, schedules, budgets, payments, draws, punch items, daily logs, photos, and documents. This can include personal information about the owners, subcontractors, and team members your workspace invites or references — your workspace controls that content.

Billing data. Subscription plan, status, and invoices are handled by Stripe. Your card number goes directly to Stripe and never touches our servers; we store only Stripe’s customer and subscription identifiers.

How we use it

To run the product: authenticate you, scope what you can see to your role and workspace, bill subscriptions, send the emails you trigger (sign-in links, team invites, e-signature requests), and keep the service secure. We do not sell your data or use it for advertising.

Who can see what

Access is scoped in the database itself with row-level security: workspace members see their workspace’s projects, an owner sees only their own unit’s rows, and invited subcontractors see schedule and field data but not project financials. Our staff access customer data only to operate and support the service.

Service providers

We rely on a small set of processors to run the service: Supabase (database, authentication, and file storage), Vercel (application hosting), Stripe (payments), and an e-signature provider (SignWell) when you send documents for signature. Each receives only what it needs to perform its function.

Retention & deletion

Your project data is kept for as long as your workspace exists — including through a lapsed subscription, so nothing is lost if a card fails. You can export your data at any time, and you can request deletion of your account or your entire workspace by emailing us; we delete it within 30 days, except records we must keep for legal or accounting reasons.

Security

All traffic is encrypted in transit (TLS) and data is encrypted at rest by our hosting providers. Sign-in is passwordless (magic links), so there is no password database to breach. Authorization is enforced by database row-level security, not just in the interface. If we ever discover a breach affecting your data, we will notify your workspace administrator without undue delay.

Cookies

We use only the cookies needed to keep you signed in. No third-party advertising or cross-site tracking cookies.

Your rights & contact

You can ask us to access, correct, export, or delete your personal information at epextechnology@gmail.com. If your workspace entered your information (for example, you are an owner on a builder’s project), we may route the request through that workspace’s administrator, who controls that content. See also our Terms of Service.