Privacy Policy
Your privacy is important to us. Learn how we collect, use, and protect your information.
Last updated: October 2026
1. Information We Collect
ConstructStream collects information you provide directly to us, such as when you create an account, use our services, or contact us for support. This includes your name, email address, company information, and any content you upload to our platform.
2. Location Data
Our mobile application collects precise (GPS) and approximate location data from your device. We collect location data in both the foreground and the background (when the app is closed or not in use) for the following purposes:
Job site visit tracking — automatically detect when field workers arrive at or depart from construction job sites using geofencing
GPS-verified timesheets — provide accurate, location-verified time records without manual clock-in
Travel tracking — record travel time and routes between construction sites
Team location map — allow managers to view real-time positions of field crew members on a map for coordination and safety
Background location collection occurs continuously while you are actively clocked in for work, and passively via OS-level geofences to detect when you arrive at or leave assigned job sites. A prominent disclosure dialog is displayed before requesting background location permission. When continuous background GPS tracking is active, the app displays a persistent notification so you are always aware.
User control: You can disable background location tracking at any time through the app's Settings screen or through your device's system settings. Disabling location will not affect other features of the app.
Data retention: Location data (GPS breadcrumbs and visit records) is retained for as long as it is associated with active time entries and project records. You may request deletion of your location data at any time by contacting us.
3. Mobile App Data Collection
When you use the ConstructStream mobile application, we may also collect:
Device information — device model, operating system version, and unique device identifiers for push notifications and support diagnostics
Push notification tokens — to deliver real-time alerts about project updates, schedule changes, and time tracking reminders
Crash reports and usage analytics — to improve app stability and performance
4. Gmail Integration
You can connect your own Gmail account to ConstructStream, so that emails you send from ConstructStream go out from your Gmail address. Connecting is optional, and each person connects only their own account. When you connect it:
What it accesses. ConstructStream asks Google for three permissions: to send email on your behalf (gmail.send), and to see your Google account's email address and basic profile (userinfo.email and userinfo.profile). It does not read your inbox, drafts or other emails, and the send permission would not allow it. After sending an email, the only thing it asks Gmail for is the ID of the message it just sent and of that message's conversation thread. It never sees your Google password.
How it is used. ConstructStream sends an email through your Gmail only when you send it, or when you have set ConstructStream up to send it for you. That covers the bid, estimate, invoice and other emails you write or approve; follow-ups and reminders about unpaid invoices that your organization has switched on for automatic sending; and the signed copy of an estimate, which goes to the person who signed it from the connected Gmail account of the team member who has been writing to them. We use your Google account's email address to show which account is connected. Emails sent from a record such as a bid or invoice include open and link-click tracking, so you can see whether the recipient opened or clicked.
What we store. The email address of the Google account you connect, and a refresh token that lets ConstructStream send for you without asking you to sign in each time. The token is encrypted before it is stored, with a key kept in a separate secrets vault, and only ConstructStream's servers can decrypt it, when they send. We also keep a copy of each email we send, with its recipients, subject, text and attachments and the message ID Gmail gave it, in your organization's ConstructStream account, filed to the bid, project or client it was about. People in your organization can see these copies in ConstructStream, according to their role.
Replies. ConstructStream does not read replies from your Gmail inbox. Emails sent from a record, such as a bid, ask recipients to reply to a ConstructStream address, so those replies reach ConstructStream directly. Its automated features read a reply to decide whether someone on your team needs to act, and use the emails you sent and the replies you received when drafting follow-up emails. The service providers named in Section 5 process them for those features.
Sharing, and what we never do. We do not share this data with anyone for their own purposes, except where the law requires. Google receives the emails we send, to deliver them. Our service providers store and process it only to run ConstructStream: Supabase (database and sign-in), Wasabi (attachment storage) and Postmark (receiving replies). We do not sell it, use it for advertising, or use it to train general-purpose AI models. People at ConstructStream do not read it, except with your permission, for security, or where the law requires.
Disconnecting and keeping. To disconnect, open Profile → Connections in ConstructStream, select Disconnect Gmail Account (the unlink icon next to your connected account) and confirm. ConstructStream then deletes the stored token and email address, and can no longer send from your Gmail. Copies of emails already sent stay in your organization's account until someone with access deletes them, or your organization's account is deleted (see Data Retention below). To also withdraw the permission on Google's side, remove ConstructStream on your Google Account's permissions page.
Signing in with Google. If you sign in or sign up with Google, on the web or in our mobile app, ConstructStream asks Google only for your name, email address and profile picture, to create or open your ConstructStream account and show your name and picture. This does not give ConstructStream access to your Gmail.
Google's rules. ConstructStream's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
5. ConstructStream for Gmail (the Gmail add-on)
When you install ConstructStream for Gmail and log an email with it:
What it accesses. Only the email you have open in Gmail, and only to show its sender and subject on the add-on's card and, when you tap Log to ConstructStream, to send that email (its headers, text, formatting and attachments) to your ConstructStream account. It also reads your Google account's email address, to tell emails you sent from emails you received. It does not read any other email, and it never sees your Google password.
How it is used. A logged email is stored in your organization's ConstructStream account and filed to the bid, project or client it belongs to. Colleagues who can see that record can see the email. ConstructStream's automated features read it to decide whether someone on your team needs to act, and use it when drafting follow-up emails to the person who wrote it. Our service providers process it for those features: TypeSafe AI's classifier and Google's Gemini models on Google Cloud.
What we never do. We do not sell this data, use it for advertising, or use it to train general-purpose AI models. People at ConstructStream do not read it, except with your permission, for security, or where the law requires.
Keeping and deleting. A logged email stays in your organization's account until someone with access deletes it, or your organization's account is deleted (see Data Retention below). Disconnecting the add-on stops new logging and keeps what was already logged.
Google's rules. ConstructStream's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
6. How We Use Your Information
We use the information we collect to:
Provide, maintain, and improve our services
Process transactions and send related information
Send technical notices and support messages
Respond to your comments and questions
Provide location-based features such as job site tracking and GPS-verified timesheets
7. Information Sharing
We do not sell, trade, or otherwise transfer your personal information to third parties without your consent, except as described in this policy. We may share information in response to legal requests or to protect our rights. Location data may be shared with your organization's administrators for workforce management purposes.
8. Data Security
We implement appropriate security measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. This includes encryption, secure servers, and regular security audits.
9. Your Rights
You have the right to:
Access your personal information
Correct inaccurate information
Delete your account and associated data
Disconnect third-party integrations
Disable location tracking at any time through device settings or in-app controls
Request deletion of your location data
10. Data Retention
We retain your information for as long as your account is active or as needed to provide you services. We will retain and use your information as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements. Location data is retained for as long as the associated time entries and project records remain active.
In concrete terms: cancelling a subscription retains all of your data; closing an account retains it for 90 days, during which reactivation restores everything; and permanent deletion happens on a verified request from an organization owner, after an offered export of your legal records and a 30-day cooling-off period. After deletion we retain only billing and tax records and a minimal record of the deletion itself. Executed contracts are also delivered by email to the person who signed them, so a signer's copy is theirs regardless of any later account deletion. See our Terms of Service for the full policy.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date. We encourage you to review this Privacy Policy periodically.
12. Contact Us
If you have questions about this Privacy Policy, please contact us at: