Privacy Policy

Last updated: June 18, 2026

Introduction

CoopTrack ("we," "us," or "our") is a construction project management platform. This Privacy Policy explains how we collect, use, store, and protect information when you use our web application and related services. By using CoopTrack, you agree to the practices described in this policy.

Information We Collect

Account information: When you create an account, we collect your name, email address, and password (stored in hashed form). If you provide a company name, address, or phone number for your workspace profile, we store that too.

Project data: We store the construction project information you enter, including project names, addresses, stages, notes, schedules, financial records, change orders, and safety checklist data.

Photos and documents: Photos, PDFs, and other files you upload to projects are stored in our cloud storage infrastructure. We do not scan, analyze, or use this content for any purpose other than displaying it to authorized users in your workspace.

Team and customer data: When you invite team members or share customer portal links, we store the email addresses and names you provide for those individuals. Customers viewing shared projects do not need accounts — they access data via time-limited, tokenized links.

Usage data: We collect basic analytics about how you interact with the app (page views, feature usage) to improve performance and user experience. We do not track you across other websites.

Payment information: We do not store credit card numbers. All payment processing is handled securely by Stripe. We retain subscription status, billing history, and invoice records associated with your workspace.

How We Use Your Information

  • To provide and maintain the CoopTrack service for your workspace.
  • To display project data, photos, and documents to authorized team members and customers.
  • To send email notifications you configure (stage changes, new photos, weekly digests).
  • To process subscription payments and manage billing through Stripe.
  • To respond to support requests and troubleshoot technical issues.
  • To send important service announcements (billing, security, feature changes).

Data Sharing

Within your workspace: All project data, photos, and documents are visible to team members with appropriate permissions within your workspace. Admins and Project Managers can access all projects; Field Techs access only assigned projects.

Customer portals: When you generate a shareable customer link, the recipient can view the specific project data you choose to share. These links are tokenized and can be revoked at any time.

Service providers: We use Stripe for payment processing and Supabase for data hosting. These providers have access only to the data necessary to perform their services and are bound by strict confidentiality and security obligations.

Legal compliance: We may disclose information if required by law, subpoena, or court order, or to protect our rights, property, or safety.

No advertising: We do not sell, rent, or share your data with advertisers or data brokers.

Data Storage and Security

Your data is hosted on Supabase infrastructure with encryption at rest and in transit. All file uploads (photos, documents) are stored in encrypted object storage.

We implement Row-Level Security (RLS) policies so users can only access data belonging to their own workspace. Each workspace is logically isolated from others.

We regularly review access controls and follow industry-standard practices to protect against unauthorized access, disclosure, or destruction of data.

Data Retention

We retain your data for as long as your workspace account is active or as needed to provide you services. If you delete a project, photo, or document, it is removed immediately from active storage and becomes inaccessible to all users.

When a workspace admin deletes the entire workspace, all associated projects, photos, documents, and member data are permanently erased from our systems within 30 days.

Backups are retained for up to 30 days for disaster recovery purposes, after which they are automatically purged.

Your Rights and Choices

  • Access and export: Workspace admins can export project data and financial records at any time.
  • Update: You can update your profile information, workspace details, and notification preferences in Settings.
  • Delete: Workspace admins can delete individual projects or the entire workspace, which permanently removes all associated data.
  • Revoke sharing: You can disable customer portal links at any time to revoke access to shared project views.
  • Email preferences: You can opt out of non-essential notification emails in your Settings panel. Essential service emails (billing, security) cannot be disabled.

Contact Us

If you have questions about this Privacy Policy or how we handle your data, contact us at support@cooptrack.app.