Not open for general onboarding yet. Join the list and we'll reach out when we're bringing on new teams.

Privacy Policy

Last updated 29 July 2026 · Site OS, a construction operations platform.

Plain summary. Your company's data belongs to your company. We use it to run the service you're paying for, we don't sell it, we don't train public AI models on it, and you can get a copy of it or have it deleted when you leave.

1. Who this covers

This policy applies to runsiteos.com and to the Site OS application at app.runsiteos.com ("the Service").

Two different relationships matter here:

  • Customer data: the records your organization puts into the Service: projects, vendor bills, invoices, timesheets, daily logs, photos, documents and personnel records. Your organization controls this data. We process it on your instructions.
  • Our own visitor and account data: what we collect when you browse this marketing site or request a demo. We control that, and this policy describes it directly.

2. What we collect

From the marketing site

  • What you type into the demo request form: name, company, work email, an approximate jobsite count, and optionally a note about what's taking your time.
  • Standard server and delivery logs, including IP address and browser user agent, retained for security and abuse prevention.

From the application

  • Account information: name, email address, role, organization, and authentication records.
  • Operational records you enter or upload: projects and addresses, vendors and their contacts, bills and invoices with amounts and cost coding, lien releases, contracts, purchase orders, timesheets and hours, daily logs, jobsite photos, plan sets, vehicle and asset records.
  • Personnel and HR records, where your organization uses those modules: compensation history, advances and repayments, benefits enrollment, time-off requests, employee documents and notes. These are sensitive by nature and are restricted to administrators within your organization.
  • Usage and security records: sign-in history, an append-only log of row-level changes (who changed what, and when), email delivery logs, and a log of questions asked of the in-app assistant.

What we don't collect

  • We do not process card numbers or bank credentials on our systems.
  • The optional desktop time-capture agent keeps raw activity (window titles and idle state) in local storage on that machine. Only time blocks a user has explicitly marked billable and assigned to a project are sent to the Service.

3. How we use it

  • To provide, secure, support and improve the Service.
  • To send transactional email you've asked the Service to send: approval notifications, release requests to your vendors, reminders, and owner portal links.
  • To detect and investigate fraud, unauthorized access, and unusual activity on your account.
  • To respond to a demo request and, if you become a customer, to administer your account and billing.

We do not sell personal information, and we do not share it for cross-context behavioral advertising.

4. Automated document reading and AI

The Service uses AI models to read documents you upload (invoices, receipts, timesheets) and to answer questions about your own records. Two commitments apply:

  • Document contents are sent to the AI provider configured for your organization solely to produce the extraction or answer you requested.
  • We do not use your customer data to train our own models, and we configure provider access so your content is not used to train theirs. Enterprise customers may supply their own provider and API keys, in which case that content goes to your provider under your agreement with them.

Extractions are suggestions for a person to confirm. The Service is designed to leave a field blank rather than record an uncertain guess.

5. Service providers

We use a small number of vendors to operate the Service, each with access limited to what their function requires:

  • Hosting and application delivery (Vercel).
  • Database, authentication and file storage (Supabase, on Amazon Web Services infrastructure in the United States).
  • Transactional email (SendGrid).
  • AI document processing (Anthropic, OpenAI or Google, per your organization's configuration).
  • Optional integrations you enable, such as QuickBooks Online, DocuSign and Google Maps address lookup.

We will also disclose information if legally required, and will tell you unless we're prohibited from doing so.

6. Where your data lives

The Service is hosted in the United States. If you access it from elsewhere, your data is transferred to and processed in the US.

7. Security

  • Every table in the database carries an organization identifier with row-level security policies enforced by the database itself, so one customer's records are not reachable from another customer's session.
  • Data is encrypted in transit, and at rest by our infrastructure providers.
  • Access within your organization is governed by the roles, access profiles and per-project permissions your administrators configure.
  • Row-level changes are captured in an append-only log to support investigation and reversal.

No system is perfectly secure. If a breach affects your data, we will notify you promptly and tell you what we know.

8. Retention

We keep customer data for as long as your organization has an active account. After termination we retain it for 90 days so it can be exported or an accidental cancellation reversed, then delete it from active systems, with backup copies aging out on our providers' backup schedule.

Some records are kept longer where we're required to: billing records for tax and accounting purposes, and security logs for abuse investigation.

Construction-specific note. Daily logs, jobsite photos and safety records can become evidence in a dispute, a claim, or a regulatory proceeding years after a job closes. Decide deliberately how long you need yours, and tell us. We will honor a longer retention period agreed in writing, and we will place a hold on deletion if you notify us of anticipated litigation.

9. Your choices and rights

  • Access and export. Ask us and we'll provide a copy of your organization's data in a machine-readable format.
  • Correction and deletion. Most records can be corrected in the application. For deletion, contact us. Note that removing a posted financial record may be restricted by your own audit obligations.
  • Marketing email. Unsubscribe from any of it. You'll still receive transactional messages the Service sends on your behalf.
  • California residents have rights under the CCPA/CPRA, including to know, delete, correct, and to opt out of sale or sharing, and we don't sell or share personal information as those terms are defined. We won't discriminate against you for exercising any of these rights.
  • Individuals in the EEA or UK may have rights of access, rectification, erasure, restriction, portability and objection under the GDPR.

If your data was entered by your employer, ask them first, and we'll route requests about customer data to the organization that controls it.

10. Cookies

This marketing site sets no advertising or third-party analytics cookies. The application uses cookies strictly necessary to keep you signed in and to remember interface preferences.

11. Children

The Service is a business tool and is not directed to anyone under 16. We don't knowingly collect their personal information.

12. Changes

We'll update the date at the top when this policy changes. For changes that materially affect how we handle customer data, we'll notify account administrators by email before they take effect.

13. Contact

Questions, requests, or a data processing agreement: get in touch.