Privacy Policy
1. Who we are
[Your company / legal entity name] (“we”) runs Amberchalk (the “Service”). This policy explains what information the Service handles, where it lives, who else touches it, and the choices you have. Contact us at [email protected].
2. What we handle, and where it lives
| Information | Where it is stored | Why |
|---|---|---|
| Your projects, logs, schedule, contacts, change orders, financial entries, plans and settings | On your device (browser storage). If you sign in and sync, also in our database (Supabase). | To run the app, work offline, and keep your devices in step. |
| Photos, plan files (PDF/images) and receipt photos | On your device. If you sync, also in private file storage (Supabase). Photos attached to an approval request are copied to a private area so your client can see them. | Progress records, takeoff, expense records, client approvals. |
| Account details: email address, company name, team members you invite | Our database (Supabase). | Sign-in, team access, support. |
| Subscription details: plan, status, billing interval, renewal dates, Stripe customer and subscription IDs | Our database; card and billing details are held by Stripe, not us. | To bill you and apply the right plan limits. |
| Email we send for you (sign-in codes, invitations, notices) | Sent through Resend; the recipient’s email address and message content pass through them. | To deliver the emails you ask the app to send. |
| Client approval responses: the decision, typed name, any question or comment, timestamp, and an audit trail | Our database, linked back to your change order or decision. | To give you a record of what your client approved. |
| Technical request data (such as IP address and browser type) | Normal server logs at our hosting (Cloudflare) and database (Supabase) providers. | Running and securing the Service. |
3. Data stored on your device
- The app stores your work in your browser’s storage (IndexedDB, local storage and the offline cache), so it works without a signal. We can’t see this data unless you sync it.
- This data is not encrypted by the app. It’s protected by your device’s lock and encryption. The optional in-app passcode only discourages casual access and is not strong security.
- Receipt scanning runs on your device. The text-recognition files download once to your device and then read receipt images locally; the receipt image is not sent to us for scanning. The receipt photo is stored like any other photo (on your device, and in your synced storage if you sync).
- Photos are resized in your browser before they’re stored. [Developer: confirm whether embedded metadata such as GPS location is removed by this step; update this sentence accordingly.]
- Clearing site data, or the browser clearing it for you, removes the local copy. Export a backup regularly.
4. Cloud sync, Supabase and your clients
- Cloud features are optional. If you don’t sign in, your project data stays on your device.
- If you sign in, your records and files are stored with Supabase, our database and storage provider, in [region]. Access is separated by company using row-level security so one company can’t read another’s data.
- Approval links: when you send an item for approval, we create a one-time link. We store only a hash of the link’s secret token, not the token itself. Your client opens the link without an account and sees a snapshot of that item (and any photos you attached). The app does not store the client’s IP address or browser details, though our infrastructure providers’ standard logs may contain request metadata.
- Owner’s View and guests: a client you invite can see only what you choose to share; internal items, subcontractor details, estimating, and (unless you turn it on) costs are not shown.
- Your clients’ and team’s information. You decide what personal information about your clients, employees and subcontractors goes into the Service. For that information we act on your behalf, and you are responsible for any notices and consents you owe them.
5. Payments (Stripe)
Paid plans are billed through Stripe. You enter card details on Stripe’s pages; we don’t receive or store the full card number. We receive and keep your plan, subscription status, billing dates and Stripe IDs. Stripe’s own privacy policy covers what it does with your information.
6. Email (Resend)
We use Resend to send sign-in codes, team and guest invitations, and other emails the Service sends. Resend processes the recipient address, the message and delivery information. We don’t use your client’s email address for our own marketing. [Add: any marketing email policy and unsubscribe handling if you plan to send product news.]
7. Text messages
Where the app opens a text-message draft on your phone, the message is sent by your own device and carrier, not by us. [If you add automated SMS notices (a Pro feature), name the SMS provider here and describe what it receives.]
8. How we use information
- To provide, secure and support the Service, including syncing, approvals, billing and plan limits.
- To send service messages (sign-in codes, invitations, receipts, important changes).
- To investigate abuse, fix bugs and comply with the law.
- We don’t sell personal information, we don’t share it for advertising, and we don’t use your project content to train advertising or AI models. [Confirm before publishing.]
9. Cookies, local storage and tracking
The app uses browser storage to work and to remember your sign-in and settings. We don’t currently use advertising cookies or third-party analytics trackers. [Confirm; if you add analytics, list the tool and what it collects here and add a consent mechanism where required.]
10. Who we share with
Only service providers that help us run the Service (currently Supabase, Stripe, Resend and Cloudflare), people you choose to share with (like your clients and team), professional advisers, and authorities when the law requires it. If we are involved in a merger or sale, information may transfer to the new owner under this policy. Providers may process data in the United States and other countries. [Attorney: add international transfer language if you serve customers outside the US.]
11. How long we keep it
- Data on your device stays until you delete it or your browser clears it.
- Synced data stays while your account is active. After you ask us to delete your account we will delete or anonymise it within [30] days, except what we must keep by law (for example, billing and tax records) and short-lived backups, which roll off within [90] days.
- Deleted items inside the app may be kept briefly as markers so that your other devices can remove them too.
12. Your choices: export and deletion
- Export: in the app, Backup & data lets you download everything as one file (photos included). Financials → Export gives QuickBooks Online CSV, QuickBooks Desktop IIF and Excel files. Reports and takeoffs can be printed or saved as PDF/CSV. Export is available on every plan.
- Delete on your device: the app can erase all data stored on a device.
- Delete your cloud account and synced data: [in the Account page / email [email protected] from your sign-in address]. We will confirm once it’s done. Cancel any subscription first, or tell us to do it.
- Access, correction and other rights: depending on where you live (for example, California or the EU/UK), you may have rights to access, correct, delete or port your information, to object to or restrict some processing, and to complain to a regulator. Contact us and we will respond within the time the law requires. [Attorney: add jurisdiction-specific disclosures.]
- If a client of yours wants their information removed, please ask the contractor who uses the Service, or contact us and we will point you in the right direction.
13. Security
We use reasonable measures to protect data in the cloud, including sign-in, encrypted connections, row-level access controls and private file storage. No system is perfectly secure. You are responsible for your device security, your sign-in email, and who you invite. If we learn of a breach that affects you, we will notify you as the law requires.
14. Children
The Service is for businesses and is not directed to children under 18. We don’t knowingly collect information from children.
15. Changes
We may update this policy. We will post the new version here and, for material changes, tell you through the app or by email before it applies to you.
16. Contact
[Your company / legal entity name]
[Postal address]
[email protected]