Arch Grid
Terms of ServicePrivacy PolicyCookie PolicyAcceptable UseData Processing Addendum

Privacy Policy

Effective July 1, 2026

This Policy explains what personal information Arch Grid LLC collects, how we use and share it, and the choices you have.

1. Scope

This Privacy Policy applies to personal information we collect through the Arch Grid website and application (the "Service"), including from visitors, registered users, and members of Organizations that use the Service. It does not apply to Customer Content that firms upload about their own projects except where that content includes personal information, which is covered below.

2. Information We Collect

Account & Organization information

Name, work email address, password (stored hashed by our authentication provider), organization name, workspace URL, role, and profile details you provide.

Project content

Drawings, submittals, RFIs, site issue records, comments, and files you or your Organization upload or generate while using the Service. This may incidentally include personal information (for example, names in a comment or a photo of a job site) that you control as the uploader.

Billing information

When you subscribe, our payment processor Polar collects payment details (such as card information) directly — we do not receive or store full card numbers. We receive limited billing metadata (for example, subscription status and plan tier) needed to manage your account.

Usage & device data

Log data such as IP address, browser type, pages visited, timestamps, and actions taken in the product, collected automatically to operate and secure the Service and to diagnose errors (via our error-monitoring tool, Sentry, in production).

Marketing & website analytics

On our public marketing pages (not the logged-in workspace), we use website analytics tooling (Vercel Analytics) and an inbound visitor-identification tool (Apollo.io) that can associate a visit with a likely company or contact for sales follow-up. This tracking does not run on authenticated, in-app pages.

Communications

If you contact us for support or sales, we collect the information you provide in that correspondence.

3. How We Use Information

  • To provide, maintain, and secure the Service, including authentication and tenant isolation between Organizations;
  • To process payments and manage subscriptions and billing;
  • To send transactional email (account verification, invitations, notifications about your projects) via our email provider, Zoho ZeptoMail;
  • To respond to support requests and communicate about the Service, including updates to these terms;
  • To monitor, debug, and improve the Service, including through error and performance monitoring;
  • To market the Service to prospective customers who visit our public site; and
  • To comply with legal obligations and enforce our Terms of Service and Acceptable Use Policy.

4. How We Share Information

We do not sell personal information. We share it only as follows:

RecipientPurpose
SupabaseDatabase, authentication, and file storage infrastructure underlying the Service
VercelApplication hosting and website analytics
PolarPayment processing (acting as merchant of record for subscriptions)
Zoho ZeptoMailDelivery of transactional email (verification, invitations, notifications)
SentryError and performance monitoring in production
Apollo.ioInbound website-visitor identification for sales follow-up, on public marketing pages only

These providers process information on our behalf and are contractually restricted from using it for their own purposes. We may also disclose information if required by law, to protect the rights and safety of Arch Grid or others, or in connection with a merger, acquisition, or sale of assets (with notice to affected users where required).

5. Cross-Organization Sharing

Arch Grid supports collaboration between firms on shared projects. When your Organization joins another firm's project (or invites another firm into your own), the project's content — and the names/roles of the people your Organization designates to that project — become visible to the other participating firm(s), consistent with the project's access model. This sharing happens only through deliberate connection actions (owner-controlled connection codes), never automatically or without your Organization's participation.

6. Data Retention

We retain account and project data for as long as your Organization has an active account, and for a reasonable period afterward to allow account recovery, satisfy legal obligations, resolve disputes, and enforce our agreements. On request following account closure, we will provide a reasonable window to export Customer Content before deletion, as described in our Terms of Service.

7. Data Security

We use tenant-isolated data access controls (row-level security) so that one Organization's data is not accessible to another absent an explicit cross-organization connection, encrypt data in transit, and rely on our infrastructure providers' security controls for data at rest. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

8. Your Rights & Choices

Depending on where you live, you may have rights to access, correct, delete, or export your personal information, or to opt out of certain processing. We aim to honor these requests regardless of your location, even where not strictly required by law. You can access and update much of your account information directly in the product; for anything else, or to exercise a deletion or export request, contact us at hello@arch-grid.com. We will verify your request and respond within a reasonable time, consistent with applicable law (for example, the California Consumer Privacy Act and similar state privacy laws, and the EU/UK GDPR where applicable). If you are acting on behalf of an Organization, note that project and Customer Content requests may need to go through your Organization's owner, since we act as a processor of that data on the Organization's behalf.

9. Cookies & Tracking Technologies

We use essential cookies to keep you signed in and remember preferences (such as light/dark theme). On public pages only — never inside the authenticated workspace — a cookie banner asks for your consent before we load the Apollo.io visitor-identification script described in Section 2; it only runs if you accept. We show this banner to every visitor, everywhere (including the EU/UK), rather than trying to detect your location and only ask some visitors. Vercel Analytics, which we also use on public pages, is cookieless and does not require this consent. See our Cookie Policy for the full list and how to change your choice. You can also control cookies through your browser settings, though disabling essential cookies may prevent sign-in from working correctly.

10. Children's Privacy

The Service is intended for business use by construction industry professionals and is not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us personal information, contact us and we will delete it.

11. International Data Transfers

Our infrastructure providers may process and store data in the United States and other countries. Where we transfer personal information internationally, we rely on the transfer mechanisms our providers make available (such as standard contractual clauses) to the extent applicable.

12. Changes to This Policy

We may update this Privacy Policy from time to time. If changes are material, we will provide notice (for example, by email or an in-product notice) before they take effect. The "Effective" date above reflects the most recent update.

13. Contact

Questions about this Policy or requests regarding your personal information can be sent to hello@arch-grid.com.

Questions about this document? Contact hello@arch-grid.com.
© 2026 Arch Grid LLC
Terms of ServicePrivacy PolicyCookie PolicyAcceptable UseData Processing AddendumHome