1. Scope
This Privacy Policy applies to personal information we collect through the Arch Grid website and application (the "Service"), including from visitors, registered users, and members of Organizations that use the Service. It does not apply to Customer Content that firms upload about their own projects except where that content includes personal information, which is covered below.
2. Information We Collect
Account & Organization information
Name, work email address, password (stored hashed by our authentication provider), organization name, workspace URL, role, and profile details you provide.
Project content
Drawings, submittals, RFIs, site issue records, comments, and files you or your Organization upload or generate while using the Service. This may incidentally include personal information (for example, names in a comment or a photo of a job site) that you control as the uploader.
Billing information
When you subscribe, our payment processor Polar collects payment details (such as card information) directly — we do not receive or store full card numbers. We receive limited billing metadata (for example, subscription status and plan tier) needed to manage your account.
Usage & device data
Log data such as IP address, browser type, pages visited, timestamps, and actions taken in the product, collected automatically to operate and secure the Service and to diagnose errors (via our error-monitoring tool, Sentry, in production).
Marketing & website analytics
On our public marketing pages (not the logged-in workspace), we use website analytics tooling (Vercel Analytics) and an inbound visitor-identification tool (Apollo.io) that can associate a visit with a likely company or contact for sales follow-up. This tracking does not run on authenticated, in-app pages.
Communications
If you contact us for support or sales, we collect the information you provide in that correspondence.
3. How We Use Information
- To provide, maintain, and secure the Service, including authentication and tenant isolation between Organizations;
- To process payments and manage subscriptions and billing;
- To send transactional email (account verification, invitations, notifications about your projects) via our email provider, Zoho ZeptoMail;
- To respond to support requests and communicate about the Service, including updates to these terms;
- To monitor, debug, and improve the Service, including through error and performance monitoring;
- To market the Service to prospective customers who visit our public site; and
- To comply with legal obligations and enforce our Terms of Service and Acceptable Use Policy.
4. How We Share Information
We do not sell personal information. We share it only as follows:
| Recipient | Purpose |
|---|---|
| Supabase | Database, authentication, and file storage infrastructure underlying the Service |
| Vercel | Application hosting and website analytics |
| Polar | Payment processing (acting as merchant of record for subscriptions) |
| Zoho ZeptoMail | Delivery of transactional email (verification, invitations, notifications) |
| Sentry | Error and performance monitoring in production |
| Apollo.io | Inbound website-visitor identification for sales follow-up, on public marketing pages only |
These providers process information on our behalf and are contractually restricted from using it for their own purposes. We may also disclose information if required by law, to protect the rights and safety of Arch Grid or others, or in connection with a merger, acquisition, or sale of assets (with notice to affected users where required).
5. Cross-Organization Sharing
Arch Grid supports collaboration between firms on shared projects. When your Organization joins another firm's project (or invites another firm into your own), the project's content — and the names/roles of the people your Organization designates to that project — become visible to the other participating firm(s), consistent with the project's access model. This sharing happens only through deliberate connection actions (owner-controlled connection codes), never automatically or without your Organization's participation.
6. Data Retention
We retain account and project data for as long as your Organization has an active account, and for a reasonable period afterward to allow account recovery, satisfy legal obligations, resolve disputes, and enforce our agreements. On request following account closure, we will provide a reasonable window to export Customer Content before deletion, as described in our Terms of Service.
7. Data Security
We use tenant-isolated data access controls (row-level security) so that one Organization's data is not accessible to another absent an explicit cross-organization connection, encrypt data in transit, and rely on our infrastructure providers' security controls for data at rest. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
8. Your Rights & Choices
Depending on where you live, you may have rights to access, correct, delete, or export your personal information, or to opt out of certain processing. We aim to honor these requests regardless of your location, even where not strictly required by law. You can access and update much of your account information directly in the product; for anything else, or to exercise a deletion or export request, contact us at hello@arch-grid.com. We will verify your request and respond within a reasonable time, consistent with applicable law (for example, the California Consumer Privacy Act and similar state privacy laws, and the EU/UK GDPR where applicable). If you are acting on behalf of an Organization, note that project and Customer Content requests may need to go through your Organization's owner, since we act as a processor of that data on the Organization's behalf.
9. Cookies & Tracking Technologies
We use essential cookies to keep you signed in and remember preferences (such as light/dark theme). On public pages only — never inside the authenticated workspace — a cookie banner asks for your consent before we load the Apollo.io visitor-identification script described in Section 2; it only runs if you accept. We show this banner to every visitor, everywhere (including the EU/UK), rather than trying to detect your location and only ask some visitors. Vercel Analytics, which we also use on public pages, is cookieless and does not require this consent. See our Cookie Policy for the full list and how to change your choice. You can also control cookies through your browser settings, though disabling essential cookies may prevent sign-in from working correctly.
10. Children's Privacy
The Service is intended for business use by construction industry professionals and is not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us personal information, contact us and we will delete it.
11. International Data Transfers
Our infrastructure providers may process and store data in the United States and other countries. Where we transfer personal information internationally, we rely on the transfer mechanisms our providers make available (such as standard contractual clauses) to the extent applicable.
12. Changes to This Policy
We may update this Privacy Policy from time to time. If changes are material, we will provide notice (for example, by email or an in-product notice) before they take effect. The "Effective" date above reflects the most recent update.
13. Contact
Questions about this Policy or requests regarding your personal information can be sent to hello@arch-grid.com.