Legal

Privacy Policy

This Policy explains what personal information Project Telemetry collects, how and why we use it, who we share it with, how long we keep it, how we protect it, and the rights you have — including under the GDPR and the CCPA/CPRA.

Last updated: January 1, 2026 Effective: January 1, 2026 Version: 2026-01-01

Project Telemetry (“Project Telemetry,” “we,” “us”) provides construction project- and workforce-management software. This Privacy Policy describes how we handle personal information across our websites and the Service.

Two different roles. When we handle information about our own customers, website visitors, and account holders, we act as a controller. When our customers upload personal information about their field employees, subcontractors, and project contacts, the customer is the controller and we act as a processor on their behalf — those activities are governed by our Data Processing Addendum. This Policy focuses on our controller activities but explains both.

1. Scope & Roles

This Policy applies to personal information we process as a controller: information about visitors to our marketing sites, people who create or hold accounts, billing contacts, and prospects. For personal information that a customer Organization submits to the Service about its workforce and third parties (“Customer Content”), the customer is the controller/“business,” and we process it under the customer's instructions and the DPA. If you are a field employee or subcontractor whose data was entered by an employer or contractor, please direct privacy requests to that organization; we will support them in responding.

2. Information We Collect

a. Account & identity data

Name, email address, username, hashed password, phone number, job title, employer/Organization, role, profile photo, and communication preferences.

b. Billing data

Plan and subscription details, billing contact, and transaction records. Card and bank details are collected and stored by our payment processor (Stripe); we receive limited tokens and metadata, not full card numbers.

c. Project & operational data

Projects, schedules, budgets and job-cost records, change orders, billings and pay applications, timecards, daily logs, RFIs, submittals, punch/safety/quality issues, meeting minutes, and correspondence that you create in the Service.

d. Jobsite media

Photographs and files you upload, which may include embedded metadata such as capture time and GPS coordinates, and may depict individuals on a jobsite.

e. Field-employee & workforce personal information (sensitive)

Where a customer uses onboarding and workforce features, the Service stores personnel records that can include full name, date of birth, contact details, emergency contacts, certifications and licenses, and government identifiers such as Social Security number and driver's-license number, as well as prevailing-wage/certified-payroll and classification records. This information is Customer Content processed on the customer's instructions; sensitive identifiers are encrypted at rest.

f. Usage & telemetry data

Log data, device and browser information, IP address, pages and features used, actions taken, timestamps, referring URLs, approximate location derived from IP, performance metrics, and diagnostic/error data.

g. Cookies & similar technologies

We and our providers use cookies, local storage, and similar technologies as described in our Cookie Notice — for authentication/session management, preferences (such as theme), security, and analytics.

h. Communications & support

Messages you send us, support tickets, and survey or feedback responses.

3. Where the Information Comes From

We collect information: (a) directly from you when you register, subscribe, upload content, or contact us; (b) automatically as you use the Service (usage/telemetry, cookies); (c) from your employer or an Organization Administrator who invites you or enters your record; and (d) from service providers such as our payment processor and analytics and infrastructure vendors. Jobsite media may carry metadata created by your device.

4. How We Use Information

  • Provide the Service — create and administer accounts and Organizations, deliver features, and process the data you instruct us to process.
  • Billing — process subscriptions, payments, renewals, and taxes.
  • Security & integrity — authenticate users, prevent fraud and abuse, enforce our policies, and protect the Service and its users.
  • Support & communication — respond to requests and send service, transactional, security, and legal notices (including changes to terms).
  • Improve & develop — understand usage, debug, and improve features, including through aggregated/de-identified analytics.
  • Marketing — send product news and offers where permitted; you can opt out of marketing at any time.
  • Legal & compliance — comply with law, respond to lawful requests, and establish, exercise, or defend legal claims.

We do not sell personal information for money, and we do not use sensitive workforce identifiers (such as SSNs) for advertising.

6. How We Share Information

We share personal information only as described here:

  • Within your Organization — according to the role-based permissions your Administrators configure.
  • Subprocessors & service providers — vendors that host and run the Service and perform functions on our behalf under contract, listed below and in the DPA.
  • Payment processing — Stripe, to process payments.
  • Professional advisors — auditors, lawyers, and insurers, as needed.
  • Corporate transactions — in connection with a merger, financing, acquisition, or asset sale, subject to this Policy.
  • Legal & safety — to comply with law or valid legal process, or to protect the rights, property, or safety of Project Telemetry, our users, or the public.

We do not disclose Customer Content except on the customer's instructions, as required by law, or as necessary to provide the Service.

7. Service Providers & Subprocessors

We engage a limited set of vendors to operate the Service. The categories are:

Provider categoryPurpose
Cloud hosting & storageApplication hosting, databases, and file/object storage for Customer Data.
Payment processing (Stripe)Subscription billing and payment processing.
Email deliveryTransactional and notification email (verification, invites, alerts).
Weather dataAutomatic jobsite weather for daily logs.
Analytics & error monitoringUsage analytics and diagnostics to maintain and improve the Service.

A current, itemized subprocessor list is maintained in the Data Processing Addendum. We require subprocessors to protect personal information consistent with this Policy and applicable law, and we remain responsible for their handling of it in connection with the Service.

8. Data Retention

We keep personal information for as long as needed to provide the Service and for the purposes described here, then delete or de-identify it. Account and Customer Data are retained for the life of the Organization; after account closure or termination, we retain data for a limited wind-down/export window and then delete it in the ordinary course, subject to (a) retention required by law (for example, tax and accounting records) and (b) residual backup copies that expire on a rolling schedule. Aggregated/de-identified data may be kept indefinitely. Where we act as processor, retention and deletion follow the customer's instructions and the DPA.

9. Security

We use technical and organizational measures designed to protect personal information, including: encryption in transit (HTTPS/TLS); encryption at rest for sensitive identifiers such as Social Security and driver's-license numbers; role-based access controls and Organization data isolation; hashed credentials; rate limiting and abuse protections; audit logging; least-privilege administrative access; and regular patching. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for safeguarding your credentials and for configuring role-based access appropriately within your Organization.

10. International Data Transfers

Project Telemetry is operated from the United States, and we and our subprocessors may process personal information in the United States and other countries. Where we transfer personal information from the EEA, UK, or Switzerland to a country without an adequacy decision, we use appropriate safeguards, including the European Commission's Standard Contractual Clauses (and the UK Addendum/IDTA), together with supplementary measures as needed. You may request information about these safeguards at privacy@projecttelemetry.com.

11. Your GDPR/UK Rights

If you are in the EEA, UK, or Switzerland, you have the right to: access your personal information; rectify inaccurate data; erase data (“right to be forgotten”); restrict or object to processing (including profiling and direct marketing); data portability; and to withdraw consent at any time without affecting prior processing. You may also lodge a complaint with your local supervisory authority.

To exercise these rights over data we control, contact privacy@projecttelemetry.com. If your data is Customer Content held by an employer or contractor, we will refer your request to that organization (the controller) and assist them in responding. We do not discriminate against you for exercising your rights.

12. Your California Rights (CCPA/CPRA)

If you are a California resident, subject to the CCPA/CPRA, you have the right to: know what personal information we collect, use, disclose, and (if applicable) share, and the categories of sources and recipients; access and receive a copy of your personal information; correct inaccurate personal information; delete personal information, subject to exceptions; and to opt out of the “sale” or “sharing” of personal information and to limit the use of sensitive personal information.

We do not sell personal information and do not “share” it for cross-context behavioral advertising. Sensitive personal information (such as SSN or driver's-license number entered for workforce onboarding) is processed only to provide the Service and related purposes permitted by law, not to infer characteristics. We will not discriminate against you for exercising your rights. To exercise them, contact privacy@projecttelemetry.com; you may use an authorized agent, and we will verify requests before responding. Where we act as a “service provider” for a business customer, we will route your request to that business.

13. Other U.S. State Rights

Residents of other U.S. states with comprehensive privacy laws (for example, Virginia, Colorado, Connecticut, Utah, Texas, and others as they take effect) have similar rights to access, correct, delete, and obtain a portable copy of their personal information, and to opt out of targeted advertising, sale, and certain profiling. You may exercise these rights, and appeal a denial, by contacting privacy@projecttelemetry.com.

14. Marketing Choices

You can opt out of marketing emails using the unsubscribe link in any such message or by contacting us; we will still send necessary service, transactional, and legal messages. You can control cookies as described in the Cookie Notice. Where we honor Global Privacy Control (GPC) or similar browser signals as opt-out preference signals, we will treat them as such.

15. Children

The Service is a business tool not directed to children and is not intended for anyone under 18. We do not knowingly collect personal information from children under 13 (or the minimum age in your jurisdiction). If you believe a child has provided us personal information, contact privacy@projecttelemetry.com and we will delete it.

16. Changes to This Policy

We may update this Policy from time to time. We will revise the “Last updated” date and, for material changes, provide additional notice (such as email or an in-product notice) and, where appropriate, request acknowledgment. Your continued use of the Service after the effective date constitutes acceptance of the updated Policy.

17. Contact Us & DPO

For privacy questions or to exercise your rights, contact our privacy team at privacy@projecttelemetry.com. For all other legal matters, contact legal@projecttelemetry.com. Where required, our Data Protection Officer and/or EU/UK representative can be reached at the same privacy address; we will identify a designated representative before offering the Service in jurisdictions that require one.

This document is provided by Project Telemetry and reflects our current practices. Governing law is the State of California, United States (a company deploying this software in another jurisdiction should update the governing-law, dispute-resolution, and statutory-rights sections accordingly). If you have questions, contact legal@projecttelemetry.com.