v1.2.0

Privacy Policy

Last updated: 2026-09-18

1. Scope.

This Privacy Policy describes how SiteProof, Inc. ("SiteProof") collects,
uses, and shares personal information of Property Owners and their
Property Managers, contracting companies and their staff, and Operators
("Users") who use the SiteProof platform.

2. What we collect.

Account information: name, email (or username for username-only
operators), phone (optional), role, organization affiliation.

Operational data: job records, geofence coordinates, GPS pings during
active jobs, photo captures (with embedded timestamp, lat/lng, and
accuracy), service event status changes.

Device/session data: IP address, user agent, sign-in events.

Billing data: none. SiteProof does not collect, process or store
payment details of any kind. Contractors are invoiced outside the app.

Operator location: recorded only while an Operator has a job open in
the app — at job start, at job completion, and periodically in between.
The app cannot record location when it is closed, and does not record
location outside an active job. See "Using SiteProof on Your Own Phone".

3. How we use it.

Service delivery: render the app, generate service event records, send
invitation + notification emails.

Compliance + safety: detect and prevent fraud, abuse, security
incidents; produce audit logs for the actor of every write.

Product improvement: aggregate behavioral analytics through the Hofund
Mirror SDK under the product_analytics consent layer.

4. Who we share with.

A Property Owner receives full operational data on jobs run at their
own sites by the contracting company they work with — including
operator identity, GPS, and photos. Operators consent to this share
when they first sign in, via the "Share-with-Owner Grant".

Hofund Labs (Mirror data platform) receives event-level operational
data under the consent each user gives when they first sign in.
Operators are told directly what this covers, in point 5b of "Using
SiteProof on Your Own Phone", rather than through their employer. Your
name, email address, phone number and the photographs themselves are
never sent to Hofund; an operator's identity in that data is a
scrambled code, and a different code is used for each employer.

Service providers (Supabase, Mapbox, Resend, Vercel) receive data
necessary to operate the platform.

We do not sell personal information.

5. Retention.

Different data has different horizons, and these are the horizons the
system actually enforces on a daily schedule:

Job records, photos and service history: retained for the lifetime of
the account, and then for as long as needed for accounting and
regulatory purposes. These are the proof-of-service records the
platform exists to produce.

GPS breadcrumbs recorded during a job: the individual position fixes
are deleted after 90 days. Before they are deleted, they are reduced to
a per-job summary — how many fixes, first and last, distance covered,
maximum speed, typical accuracy. That summary is kept with the job. It
records no path and no geometry, so the route cannot be reconstructed
from it.

Audit logs: retained 400 days.

Device sync records (that a phone held a given day's job list, and when
it last connected): retained 90 days. These carry no location.

You may request export or deletion at contact@siteproof.co.

6. Security.

Row-Level Security enforced at the database layer; per-tenant isolation
verified by automated probe tests. Service role keys are kept server-
side only. We use industry-standard encryption in transit and at rest
via Supabase and Vercel infrastructure.

7. Contact.

contact@siteproof.co.