Opsite Privacy Policy

Effective Date: September 10, 2026

Opsite Solutions LLC ("Opsite," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our construction project management platform at useopsite.com and related services (the "Service").

By using our Service, you consent to the data practices described in this Privacy Policy. If you do not agree with the practices described in this Privacy Policy, please do not use the Service.

1. Information We Collect

1.1 Information You Provide to Us

We collect information you provide directly, including:

  • Account Information: Name, email address, phone number, password, and profile information
  • Business Information: Company name, business address, contractor license numbers, tax ID/EIN
  • Financial Information: Bank account details for payment processing, credit card information (processed by our payment providers)
  • Project Data: Job details, client information, contracts, invoices, purchase orders, change orders, and financial records
  • Documents: Files you upload including photos, permits, contracts, plans, and other construction documents
  • Communications: Messages you send through the Service, support requests, and feedback
  • Biometric Information: If you use facial recognition or fingerprint authentication features on your device to access the Service, we may process biometric identifiers solely for authentication purposes. We do not store raw biometric data.
  • Audio/Visual Data: Voice recordings if you interact with voice-enabled features, and photographs or video you upload as project documentation
  • Referral Data: If you refer another contractor to Opsite, we collect the name and contact information you provide for the purpose of sending the referral invitation only

1.2 Information Collected Automatically

When you use the Service, we automatically collect:

  • Usage Data: Features used, pages viewed, actions taken, time spent on pages
  • Device Information: IP address, browser type and version, operating system, device identifiers
  • Location Data: General location based on IP address; precise location with your permission for map and address-autocomplete features; continuous precise location ("location pings") collected from employees while clocked in through the time-clock feature, when enabled by their employer — see § 1.5
  • Log Data: Access times, error logs, referring URLs
  • Cookies and Tracking Technologies: See our Cookie Policy for details

1.3 Information from Third Parties

We may receive information from third-party services you connect:

  • QuickBooks: Customer information, invoice status, payment information
  • Google: Account identifiers and email address; calendar event details; task lists, task details, and completion status when you enable the corresponding integration
  • Identity Providers: Authentication information when you sign in with Google or other providers

1.4 SMS and Messaging Data

If you opt in to SMS or WhatsApp communications, the contractor using Opsite sends messages through our integration with Twilio, Inc. We process the recipient phone number, message body, and delivery status to operate the messaging service and to honor opt-out requests. STOP, UNSUBSCRIBE, QUIT, and END are honored as opt-out keywords; HELP returns a help response identifying the sending contractor and our customer-support contact. To opt out of all Opsite-facilitated messages across every contractor, reply STOP ALL or email privacy@useopsite.com.

1.5 Employee Time-Clock and Location Data

When a contractor using Opsite enables the time-clock feature for its employees, Opsite collects the employee's device latitude, longitude, and accuracy at clock-in, at clock-out, and at periodic intervals during the shift while clocked in ("location pings"). This data is collected on behalf of and under the instruction of the contractor (the employer), who is the controller of the data for purposes of GDPR and the business for purposes of CCPA. Opsite acts as a service provider/processor. Contractors are responsible for providing the notices required by applicable law to their employees before enabling this feature, including (where applicable) under Cal. Penal Code § 637.7, Cal. Civ. Code § 1798.100(b), 820 ILCS 55, Conn. Gen. Stat. § 31-48d, and N.Y. Civ. Rights Law § 52-c. A model employee-monitoring notice is available at app.useopsite.com/legal/employee-monitoring-notice.

Google API Services User Data Policy

Opsite's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Your choice and account identity: Google integrations are optional. Each user connects their own Google account and grants the requested permissions. We use your Google account identifier and email address to identify the connected account; Google sign-in may also provide your name.

Google Calendar: With your permission, Opsite reads calendar event details, including titles, descriptions, dates and times, locations, and attendee details, to display and synchronize schedules. Opsite can create, update, and delete linked calendar events as you manage scheduling in Opsite.

Google Tasks: When you enable Tasks sync, you choose which Opsite projects to include. Opsite creates a Google task list for each selected project and sends tasks assigned to you, including their titles, descriptions, due dates, completion status, company and project names, and links back to Opsite. Opsite reads task-list identifiers and titles to find its project lists, and reads tasks in those lists to synchronize linked work and avoid duplicates. These responses can include task titles, notes, dates, status, and deletion indicators. Unrelated personal Google tasks are not imported as Opsite tasks.

Task changes and removal: Opsite creates and updates linked Google tasks and synchronizes completion and reopening in both directions. When a project is deselected, access is lost, or an assignment changes, Opsite removes the affected linked Google copies during a successful sync while the connection remains authorized. Deleting a Google copy stops that copy from syncing; it does not delete the original Opsite task. This functionality requires read and write access to Google Tasks; read-only access cannot create, update, or remove the linked copies.

Use and sharing: Google user data is used only to provide the connected account, calendar, and task-sync features you choose and that are visible in Opsite. Google user data includes information received from Google APIs and any data derived, aggregated, or anonymized from it. We do not sell this data or use or transfer it for advertising, marketing, unrelated analytics or research, creditworthiness or lending decisions, or to develop, train, fine-tune, or improve AI or machine-learning models. Anonymizing or aggregating Google user data does not remove these restrictions. These Google-specific restrictions take precedence over every other section of this policy, including the sections on service improvement, AI, sharing, business transfers, and retention.

Permitted transfers: We share Google user data with our hosting and database providers, Vercel and Supabase, only as necessary to operate the Google-connected features you authorize. Other transfers are limited to security needs, applicable legal requirements, or a merger, acquisition, or sale of assets after obtaining your explicit prior consent. We do not transfer Google user data to advertising platforms, data brokers, or information resellers. A general consent to this policy does not authorize otherwise prohibited uses or transfers.

Human access: Our personnel may access Google user data only with your affirmative agreement to access specific data, when necessary for security or legal compliance, or as otherwise permitted by the Limited Use requirements for aggregated internal operations. Employees, contractors, service providers, and successors must follow these restrictions.

Storage and protection: We store the connected Google account identifier and email, authorization scopes, access and refresh tokens, and the identifiers and synchronization records needed to link Google lists, tasks, and events to Opsite. Task-sync records include project and task links, due dates, status, sync timestamps, and errors; completion changes are recorded in Opsite's audit history. Google Tasks access and refresh tokens are encrypted before database storage. Connections to Google use HTTPS, and access to integration records is restricted to authorized application services.

Disconnecting and revoking access: In My Tasks → Google Tasks, select Disconnect to stop Tasks sync and remove the saved Tasks access and refresh tokens. Disconnecting does not delete existing Google copies or the original Opsite tasks. The connected account identifier, email, project selections, and sync links remain for reconnection; audit history remains with the project records. To remove linked Google copies through Opsite, deselect the projects and complete a successful sync before disconnecting, or delete the copies directly in Google Tasks. You may also revoke Opsite's Google permissions through your Google Account connections; revocation may affect other Google integrations connected to Opsite.

Retention and deletion requests: Integration records and project audit history follow the retention periods in Section 6. You may request deletion of stored Google account and sync records by emailing privacy@useopsite.com. Account deletion and any legally required retention follow Sections 6 and 7. Disconnecting or revoking Google access does not itself erase records already stored in Opsite or copies remaining in your Google account.

2. How We Use Your Information

We use your information for the following purposes, subject to the Google-specific restrictions above. These purposes do not authorize additional uses of Google user data or data derived from it:

2.1 Provide and Operate the Service

  • Create and manage your account
  • Process transactions and send related information
  • Enable project management, invoicing, and financial tracking features
  • Facilitate integrations with third-party services
  • Generate reports and analytics for your business

2.2 Improve and Develop the Service

  • Analyze usage patterns to improve functionality
  • Develop new features and services
  • Evaluate and improve feature quality without using Google user data or data derived from it to train or improve AI models
  • Conduct research and analytics

2.3 Communicate with You

  • Send service-related notices and updates
  • Respond to your inquiries and support requests
  • Send marketing communications (with your consent; Google user data and data derived from it are excluded)
  • Notify you of changes to our policies

2.4 Security and Legal Compliance

  • Detect and prevent fraud, abuse, and security incidents
  • Enforce our Terms of Service
  • Comply with legal obligations
  • Protect our rights and the rights of others

2.5 AI-Specific Processing

Our AI features (including the Lino assistant, document categorization, smart scheduling, and automated recommendations) process your data in real-time to provide personalized assistance. This section does not authorize using Google user data or data derived from it to train or improve AI models, or for any purpose outside the Google-specific restrictions above. Specifically:

  • Your project data, communications, and documents may be sent to our AI service provider (currently Anthropic) for real-time processing via API
  • We implement retrieval-augmented generation (RAG) using vector embeddings of your data to provide contextually relevant responses
  • AI-generated outputs (proposals, summaries, recommendations) are based on your data and our proprietary prompt engineering
  • We do not use your individual data to train or fine-tune general-purpose AI models
  • You may opt out of AI features at any time through your account settings, though this may limit certain Service functionality

2.6 Automated Communications

The Service includes scheduled and triggered features that send communications on a contractor's behalf, including overdue-invoice reminders, lead-nurture emails, scheduled social-media posts, and WhatsApp digests. The contractor selects the recipients, the templates, and the schedule; Opsite executes the contractor's instructions. The contractor is responsible for ensuring the recipient has provided any consent required under the Telephone Consumer Protection Act, the CAN-SPAM Act, or analogous law before the automation is enabled.

3. Legal Basis for Processing (GDPR)

If you are in the European Economic Area (EEA), UK, or Switzerland, we process your personal data based on:

  • Contract Performance: Processing necessary to provide the Service you requested
  • Legitimate Interests: Processing for our legitimate business interests (improving the Service, security, fraud prevention) where not overridden by your rights
  • Legal Obligation: Processing required to comply with applicable laws
  • Consent: Processing based on your explicit consent (e.g., marketing communications)

4. How We Share Your Information

We do not sell your personal information. We only share your information in the following circumstances:

4.1 Service Providers

We share information with third-party vendors who help us operate the Service, including those below. This list does not authorize every provider to receive Google user data; any transfer of Google user data must satisfy the Google-specific restrictions above:

  • Cloud infrastructure: Vercel (hosting, CDN, Vercel Analytics), Supabase (database, authentication, file storage)
  • Payment processing: Stripe
  • AI services: Anthropic (Claude API)
  • SMS and messaging: Twilio
  • Email: Resend
  • Vector storage and caching: Upstash
  • Analytics: Plausible (cookieless, EU-hosted)
  • Maps and address autocomplete: Google Maps Platform

4.2 Third-Party Integrations

When you connect integrations like QuickBooks or Google, we share data necessary to provide those features, as authorized by you.

4.3 With Your Consent

We may share information with your consent, such as when you share project access with clients or team members.

4.4 Legal Requirements

We may disclose information if required by law, subpoena, court order, or government request, or to protect our rights, safety, or property.

4.5 Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred. We will notify you of any such change. Google user data, including data derived from it, will be transferred in such a transaction only after obtaining your explicit prior consent.

4.6 Subprocessor List

We maintain a current list of subprocessors who process personal data on our behalf. As of 2026-09-10, our subprocessors include:

SubprocessorPurposeData categoriesRegion
VercelHosting, CDN, edge runtime, and Vercel AnalyticsAll Service data; aggregated traffic metricsUS (multi-region)
SupabasePrimary application database and authenticationAll Service data, account credentials, session tokensUS
StripePayment processing and subscription managementBilling identifiers, payment-card tokens, invoice metadataUS
AnthropicAI assistant (Lino), document categorization, and generative features via the Claude APIProject data and prompts submitted by you to AI features; not used to train general-purpose modelsUS
UpstashVector embedding storage for retrieval-augmented generationAnonymized vector representations of your dataUS
TwilioSMS and WhatsApp delivery and delivery-status webhooksRecipient phone numbers, message bodies, delivery statusUS
ResendTransactional and outbound email deliveryRecipient email addresses, message bodies, deliverability metadataUS
Plausible AnalyticsPrivacy-preserving website analytics (cookieless, no PII)Aggregated page-view counts, referrer, countryEU (Germany)
Intuit (QuickBooks)Optional accounting integration for invoice and payment syncInvoice and customer records you sync; OAuth identifiersUS
Google (Maps, Identity, Calendar, Tasks)Address autocomplete, map display, optional sign-in, optional calendar and assigned-task syncAddress strings, sign-in identifiers, calendar metadata, selected project names and assigned-task titles, descriptions, due dates, and status — only on user authorizationUS

We will provide at least thirty (30) days' advance notice of material changes to this list by updating this page and, where required by law, notifying account administrators by email. Users may object to a new subprocessor by emailing privacy@useopsite.com; if we are unable to accommodate the objection, the user may terminate the affected portion of the Service for a pro-rata refund of prepaid fees.

5. Data Security

We implement industry-standard security measures to protect your data:

  • Encryption: Data is encrypted in transit (TLS 1.2+) and at rest
  • Access Controls: Role-based access with multi-factor authentication
  • Regular Audits: Security assessments and vulnerability testing
  • Employee Training: Security awareness training for all employees
  • Incident Response: Procedures for detecting and responding to security incidents

While we strive to protect your data, no method of transmission over the Internet or electronic storage is 100% secure. See our Security page for more details.

Breach Notification

In the event of a data breach affecting your personal information, we will notify affected users via email and in-app notification without undue delay and no later than seventy-two (72) hours after confirmation. Where required by law, we will also notify relevant supervisory authorities. Breach notifications will include the nature of the breach, categories of data affected, our contact information, and steps taken to address the breach.

6. Data Retention

We retain your information for as long as necessary to provide the Service and fulfill the purposes described in this Privacy Policy:

  • Active Accounts: Data is retained while your account is active
  • After Termination: We retain data for 30 days to allow data export, then delete it
  • Legal Requirements: We may retain certain data longer if required by law (e.g., tax records for 7 years)
  • Anonymized Data: Aggregated, anonymized data may be retained indefinitely for analytics, excluding Google user data and data derived from it. Google data is retained only for the disclosed connected features and applicable legal obligations, not for unrelated analytics, research, or model training

7. Your Privacy Rights

7.1 All Users

You have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Export your data
  • Delete your account and data
  • Opt out of marketing communications

7.2 European Users (GDPR)

If you are in the EEA, UK, or Switzerland, you also have the right to:

  • Data portability (receive your data in a structured format)
  • Restrict processing in certain circumstances
  • Object to processing based on legitimate interests
  • Withdraw consent at any time
  • Lodge a complaint with a supervisory authority

7.3 California Residents (CCPA/CPRA)

If you are a California resident, you have the right to:

  • Know what personal information we collect and how it's used
  • Request deletion of your personal information
  • Opt out of the sale or sharing of personal information (we do not sell your data)
  • Non-discrimination for exercising your rights
  • Correct inaccurate personal information
  • Limit use of sensitive personal information

To exercise your rights, contact us:

Email: privacy@useopsite.com

We will respond within 30 days (or 45 days for complex requests).

8. International Data Transfers

We are based in the United States and process data in the U.S. If you are accessing the Service from outside the U.S., your information will be transferred to, stored, and processed in the U.S.

For transfers from the EEA, UK, or Switzerland, we rely on Standard Contractual Clauses approved by the European Commission and implement additional safeguards as necessary.

9. Children's Privacy

The Service is not intended for persons under 18 years of age. We do not knowingly collect personal information from anyone under 18. If we learn we have collected information from a person under 18, we will delete it within thirty (30) days of confirmation. If you believe we have collected information from a person under 18, please contact us at privacy@useopsite.com.

10. Third-Party Links

The Service may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies before providing any personal information.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the revised policy on this page and updating the "Last Updated" date. For significant changes, we may also send you a notification via email or through the Service. Your continued use of the Service after changes become effective constitutes acceptance of the revised policy.

12. Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us:

Opsite Solutions LLC

Privacy Inquiries: privacy@useopsite.com

General Support: support@useopsite.com

Website: https://useopsite.com

13. Additional Disclosures

13.1 Categories of Personal Information (CCPA)

In the past 12 months, we have collected the following categories of personal information:

CategoryExamplesCollected
IdentifiersName, email, IP address, device identifierYes
Commercial InformationTransaction history, invoices, subscription recordsYes
Internet ActivityPages viewed, features used, referrer URLsYes
Geolocation DataGeneral IP-based location; precise location for map and employee time-clock featuresYes
Professional InformationCompany name, contractor license info, tax ID/EINYes
Sensitive Personal InformationPrecise geolocation (employee time-clock); biometric authentication tokens (device-local only)Yes
InferencesUsage-based feature recommendationsYes

13.2 Do Not Track and Global Privacy Control

We do not respond to legacy "Do Not Track" (DNT) browser signals, which have been deprecated by most major browsers. However, we honor the Global Privacy Control (GPC) browser signal as a valid opt-out of any sale or sharing of personal information under the California Consumer Privacy Act, consistent with the California Attorney General's enforcement position in People v. Sephora USA (2022). When we detect a GPC signal, we automatically apply your opt-out preference for the current and future visits from the same browser.

14. AI Transparency and Automated Decision-Making

14.1 Automated Processing

We use AI and automated systems to provide features such as: document categorization, project recommendations, financial forecasting, automated communications, and the Lino AI assistant. These systems assist your decision-making but do not make legally significant decisions about you without human oversight.

14.2 Your Rights Regarding AI

You have the right to:

  • Know when you are interacting with an AI system
  • Request human review of any AI-generated recommendation or output
  • Opt out of AI-powered features through your account settings
  • Request an explanation of how AI features process your data

14.3 AI Accuracy

While we strive for accuracy, AI-generated outputs (including financial calculations, scheduling recommendations, and document analysis) may contain errors. You are responsible for reviewing and verifying all AI-generated outputs before acting on them. Opsite is not liable for decisions made based on AI-generated content.

14.4 State-Specific AI Disclosure Obligations

Where the Service is used to deploy AI features in a jurisdiction with applicable AI-specific consumer disclosure laws (including the Colorado AI Act, Texas HB 149, California AB 2013, and New York City Local Law 144 for automated employment tools), the contractor using Opsite is responsible for providing the required consumer disclosures. Opsite provides configurable AI-disclosure banners and document watermarks in Settings, with defaults aligned to the strictest applicable state for accounts in Colorado, Texas, and California.