Last updated: August 26, 2026
This Privacy Policy describes how Flobuildr LLC (“FloBuildr,” “we,” “us,” or “our”), a South Carolina limited liability company, collects, uses, discloses, and otherwise processes personal information in connection with our websites, applications, APIs, customer portals, electronic signing experiences, mobile apps, and related services (collectively, the “Services”). By accessing or using the Services, you acknowledge this Policy. If you do not agree, do not use the Services.
This Policy should be read together with our Terms of Service. Capitalized terms not defined here have the meanings in the Terms.
Contact for privacy matters: contact@flobuildr.com.
Flobuildr LLC provides construction operations software used by remodeling and specialty contractors and their teams (“Customers”). Customers may invite employees, subcontractors, and other authorized users (“Authorized Users”), and may share job information with homeowners, property owners, and other end customers through portals, payment links, estimate/invoice links, and electronic signature links (together, “End Customers”).
We act as a business / data controller for personal information we collect for our own purposes, including: marketing website visitors; demo, contact, and waitlist inquiries; Customer account administration and billing; product analytics and security monitoring we operate; and FloBuildr staff operations.
When Customers enter, upload, import, or otherwise process information about their clients, jobs, properties, employees, vendors, or End Customers in the Services (“Customer Data”), the Customer is the controller / business and FloBuildr processes that Customer Data as a processor / service provider on the Customer’s instructions, subject to our Terms and applicable law. End Customers and other individuals whose information appears in Customer Data should contact the relevant Customer (the contractor) for most privacy requests about that data. We will assist Customers as required by law and our agreements.
This Policy covers information processed in connection with, without limitation:
The categories below describe information we may collect depending on how you interact with the Services. Not all categories apply to every person.
Where Customers enable field features, the Services may collect precise or approximate location information for clock-in/clock-out, geofence validation, progress updates, and related job-site workflows, including latitude, longitude, accuracy, distance from a job site, time zone, validation status, and override reasons. Mobile apps may also request camera, photo library, and microphone access (for example, for photos or speech-to-text used in punch lists or notes). Location and device permissions are controlled by the device OS and can be revoked; some features will not work without them.
Depending on Customer configuration, we may receive or exchange information with:
This list is not intended to be exhaustive and is subject to change by FloBuildr.
We do not intentionally collect government-issued identification numbers, biometric identifiers for authentication, health information, or information from children under 13. Customers should not upload special-category or highly sensitive data unless necessary for their business and lawful. Our observability tooling attempts to redact patterns resembling emails, phone numbers, SSNs, and certain secrets from diagnostic logs, but Customers remain responsible for minimizing sensitive data in free-text fields and uploads, including those made by End Customers.
We use personal information to:
Where required by applicable law, we rely on one or more of the following bases: performance of a contract; legitimate interests (such as securing and improving the Services); consent (where obtained); and legal obligation.
We do not sell personal information for money. We may share information as follows:
FloBuildr staff may access Customer accounts for support, billing, security, abuse investigation, or platform operations, including through audited administrative tools and, where necessary, impersonation/session assistance. Access is limited to personnel on a need to know basis.
Mobile / SMS opt-in information: We do not sell or share mobile opt-in information, phone numbers collected for SMS consent, or SMS consent status with third parties or affiliates for their marketing or promotional purposes. Phone numbers and consent records are used only to deliver the customer-requested job and schedule texts (and related delivery, compliance, and support functions) through our SMS service providers and carriers.
Customers may generate shareable tokens or links that allow End Customers (and anyone who receives the link) to view or interact with selected job information—such as progress, photos, daily logs, invoices, punch lists, messages, payments, or documents—without creating a FloBuildr login. Anyone with a valid link may access the enabled content until the link expires, is revoked, or is otherwise disabled. Customers are responsible for:
If you are an End Customer and have privacy questions about information shown in a portal or signing flow, contact the contractor who sent you the link. You may also contact us at contact@flobuildr.com and we will route or assist as appropriate.
Customer is solely responsible for the content, accuracy, legality, enforceability, delivery, timing, and use of all estimates, bids, proposals, contracts, change orders, invoices, payment requests, receipts, lien notices, lien waivers, refund communications, cancellation notices, tax charges, consumer disclosures, project communications, and other documents or materials created, stored, sent, signed, or processed through the Services.
Customer will ensure that such materials and transactions comply with all applicable laws, rules, regulations, licensing requirements, permit obligations, tax requirements, consumer-protection statutes, home-improvement and construction-contract laws, notice and cancellation requirements, lien and bond statutes, payment and refund obligations, e-signature laws, privacy laws, employment laws, and other legal obligations applicable to Customer’s business and transactions.
FloBuildr does not provide construction, design, engineering, legal, tax, accounting, insurance, licensing, permitting, consumer-compliance, lien, bond, or payment advice. The Services are tools; Customers are responsible for their own regulatory compliance and should consult qualified professionals as appropriate.
When documents are signed electronically through the Services, we process signer identity information, signature data, consent records, IP address, user agent, timestamps, and related audit materials to create an audit trail and to help Customers evidence agreement. Customers are responsible for the content of documents presented for signature and for ensuring e-sign use is appropriate for their transactions.
Electronic signature audit materials—including signer identity, signature images, consent records, IP addresses, user agents, timestamps, and related artifacts—may be retained for the longer of:
After all applicable retention periods have expired, signature audit materials will be deleted or de-identified in accordance with Section 11 (Data Retention) below.
Subscription fees for FloBuildr are processed through our payment processor. Separately, Customers may connect payment accounts (such as Stripe Connect) so End Customers can pay invoices. FloBuildr may receive transaction metadata, fee information, and limited card descriptors (for example, brand and last four digits). Full card numbers are collected by the payment processor’s secure fields and are not stored by FloBuildr. Payment processor terms and privacy policies apply to card processing.
If a Customer enables AI features, prompts and context—which may include job details, account names, property addresses, line items, pipeline summaries, and similar operational content—may be sent to AI models through FloBuildr’s Amazon Bedrock account (platform-managed). Customers control whether to enable AI and what content Authorized Users include in prompts. Do not include information in AI prompts that you are not authorized to process or disclose. We may log AI usage metadata such as model, token counts, latency, cost estimates, and errors. Separately, FloBuildr may compute anonymized aggregate regional price benchmarks across Customers (k-anonymized so no company identity appears in suggestions) to power estimate pricing assist.
We and our service providers use cookies, pixels, local storage, session storage, and similar technologies to operate the Services, maintain sessions, remember preferences, measure performance, and detect abuse. Our marketing site and applications may send first-party telemetry (page views, performance, and diagnostic events) to our own observability endpoints. Third-party resources (such as Google Fonts) may receive IP address and referrer information when loaded by your browser. You can control cookies and storage through browser settings; disabling certain storage may break login or core functionality.
We retain information for as long as needed to provide the Services, comply with legal obligations, resolve disputes, enforce agreements, and support legitimate business needs. Retention periods vary by data type. Without limiting the foregoing:
When a company tenant is deleted, associated tenant data is generally removed from primary systems subject to backups, legal holds, and residual copies in logs or archives that are deleted or anonymized over time according to our schedules.
Export window. Customers should export any needed data before termination. Following termination or account closure request, Customer will have thirty (30) days to request export of Customer Data, unless (a) the account was terminated for a material legal, security, or abuse violation, or (b) a separate Order or agreement provides a different period.
Deletion target. FloBuildr will target deletion or de-identification of Customer Data from active production systems within ninety (90) days after the later of account closure, termination, or the end of the export window described above.
Backup purge. Copies of Customer Data residing in backups, disaster-recovery archives, and log systems will be overwritten or purged in the ordinary backup lifecycle, targeted within one hundred eighty (180) days following deletion from production systems, unless preserved pursuant to a legal hold, security investigation, or disaster-recovery obligation.
Exceptions. Notwithstanding the foregoing, FloBuildr may retain information after termination to the extent reasonably necessary for: (i) compliance with legal, tax, or accounting obligations; (ii) fraud prevention and security monitoring; (iii) dispute resolution, enforcement of agreements, and defense of claims; (iv) electronic signature audit trails as described in Section 7.1; (v) payment and billing records required by payment-processor agreements or applicable law; (vi) legal holds, court orders, or regulatory requirements; and (vii) residual copies in logs or archives, which will be deleted or anonymized over time and will not be restored to production systems except for disaster recovery, legal, or security purposes.
We implement reasonable administrative, technical, and organizational measures designed to protect personal information, which may include encryption in transit, encryption at rest for primary datastores, access controls, authentication, logging, and vulnerability management. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Customers are responsible for safeguarding credentials, configuring permissions, protecting share links, and securing devices used to access the Services.
Definition. A “Security Incident” means an unauthorized access to, or unauthorized acquisition, disclosure, or use of, Customer Data that compromises the security, confidentiality, or integrity of such data. A Security Incident does not include (a) unsuccessful access attempts, port scans, denial-of-service attacks, or similar events that do not result in unauthorized access to or compromise of Customer Data; or (b) access authorized by the Customer or by this Policy or the Terms.
Notification. Where FloBuildr processes Customer Data as a processor or service provider, FloBuildr will notify the affected Customer without unreasonable delay after confirming that a Security Incident involving that Customer’s Customer Data has occurred. Notification will include, to the extent then reasonably available, the nature of the incident, the categories of data affected, and the measures taken or proposed to address the incident.
Cooperation. FloBuildr will provide information reasonably available and reasonably necessary to assist the Customer in fulfilling its own breach-assessment and legally required notification obligations. FloBuildr will cooperate reasonably with Customer’s investigation, provided that such cooperation does not unreasonably disrupt FloBuildr’s operations or compromise the security of other customers’ data.
Customer’s role. Customer, as controller or business with respect to Customer Data, is responsible for determining whether notice to affected individuals, employees, regulators, or other parties is required by applicable law and for providing such notices, unless applicable law or a separate written agreement (such as a Data Processing Addendum) expressly requires FloBuildr to provide direct notice.
Flobuildr LLC is organized under the laws of South Carolina and operates in the United States. We process information in the United States and in other locations where we or our service providers operate. If you access the Services from outside the United States, you understand that your information may be transferred to, stored, and processed in the United States and other jurisdictions that may have different data-protection laws than your country. Where required, we use appropriate transfer mechanisms.
Authorized Users may update certain profile information in-product. You can delete your login and the personal information you supplied from Settings → About Me → Delete account on the web app, or Settings → Delete account in FloBuildr Mobile. Deletion removes your password and profile fields (such as name, phone numbers, and photo). Your company keeps your email on work records so administrators can still identify who performed the work. Customers control much of the Customer Data in their tenant, including soft-deletion of certain records and revocation of portal or signing access.
You may opt out of marketing emails by following unsubscribe instructions or contacting us. Transactional and service messages are not marketing and may continue.
Subject to applicable law, you may request access to, correction of, deletion of, or information about our processing of personal information we control by emailing contact@flobuildr.com. We may need to verify your identity and the nature of your request. For Customer Data processed on behalf of a Customer, we will typically refer you to the Customer or coordinate with the Customer, except where law requires us to act directly.
Residents of certain U.S. states (including California under the CCPA/CPRA) may have rights to know/access, delete, correct, and opt out of certain sharing or targeted advertising, and to not be discriminated against for exercising rights. FloBuildr does not sell personal information as “sell” is commonly understood. We also do not knowingly sell or share the personal information of consumers under 16. To exercise rights, contact contact@flobuildr.com. You may use an authorized agent as permitted by law. We will respond within the timeframes required by applicable law.
Notice at collection (California): We collect the categories described in Section 3 for the purposes in Section 4, retain them as described in Section 11, and disclose them to the categories of recipients in Section 5. We do not use or disclose sensitive personal information for purposes that require a right to limit under the CPRA, except as permitted to provide the Services you request or as otherwise allowed by law.
If European or UK data-protection law applies to personal information we control, you may have rights of access, rectification, erasure, restriction, portability, and objection, and the right to lodge a complaint with a supervisory authority. Contact us to exercise these rights. Where we process Customer Data as a processor, please contact the relevant Customer first.
The Services are designed for business users and adult End Customers. They are not directed to children under 13 (or under 16 where a higher age applies), and we do not knowingly collect personal information from children. If you believe a child has provided personal information, contact us and we will take appropriate steps to delete it.
The Services may link to or integrate with third-party websites, apps, or services. Their privacy practices are governed by their own policies. We are not responsible for third-party practices. Enabling an integration constitutes Customer authorization for the related data exchanges.
We may update this Privacy Policy from time to time. The “Last updated” date at the top will change when we post revisions. Material changes will be indicated by updating this page and, where appropriate, by additional notice (such as email or in-product notice). Continued use of the Services after the effective date constitutes acceptance of the updated Policy, except where applicable law requires a different standard.
To the extent this Policy forms part of the agreement between FloBuildr and Customer (whether incorporated by reference in the Terms of Service or otherwise), the following limitations apply. Unless a separate Order, Data Processing Addendum, or written agreement expressly provides otherwise:
Except for claims subject to the Elevated Cap below, each party’s total aggregate liability arising out of or related to this Policy or the processing of personal information under this Policy will not exceed the greater of (a) the amounts paid by Customer to FloBuildr for the Services during the twelve (12) months immediately preceding the event giving rise to the claim, or (b) one hundred dollars ($100).
For claims arising from FloBuildr’s breach of its confidentiality obligations or from a confirmed Security Incident (as defined in Section 12.1) caused by FloBuildr’s material breach of its security obligations under Section 12, FloBuildr’s total aggregate liability will not exceed the greater of (a) two (2) times the amounts paid by Customer to FloBuildr for the Services during the twelve (12) months immediately preceding the event giving rise to the claim, or (b) ten thousand dollars ($10,000).
Nothing in this Section 18 limits liability that cannot be limited by applicable law. The following are not subject to the caps in Sections 18.1 or 18.2 and remain governed by the Terms, applicable Order, or law:
This Section 18 is subject to and does not modify any conflicting terms in a separately executed Order or Data Processing Addendum between the parties.
For privacy questions, requests, or complaints:
Flobuildr LLC
Email: contact@flobuildr.com
Business hours: Monday–Friday, 9:00 a.m.–5:00 p.m. Eastern Time.