Privacy Policy

Important: This Privacy Policy describes how FloBuildr LLC ("FloBuildr," "we," "us," or "our"), a South Carolina limited liability company, collects, uses, discloses, and otherwise processes personal information in connection with our websites, applications, APIs, customer portals, electronic signing experiences, mobile apps, and related services (collectively, the "Services"). By accessing or using the Services, you acknowledge this Policy. If you do not agree, do not use the Services.

This Policy should be read together with our Terms of Service. Capitalized terms not defined here have the meanings in the Terms.

Legal entity: FloBuildr LLC (South Carolina Entity ID 01566009), registered agent: Registered Agents Inc, 6650 Rivers Ave STE 100, Charleston, SC 29406.

Contact for privacy matters: contact@flobuildr.com.

1. Who we are and our roles

FloBuildr LLC provides construction operations software used by remodeling and specialty contractors and their teams ("Customers"). Customers may invite employees, subcontractors, and other authorized users ("Authorized Users"), and may share job information with homeowners, property owners, and other end customers through portals, payment links, estimate/invoice links, and electronic signature links (together, "End Customers").

1.1 When FloBuildr is a controller

We act as a business / data controller for personal information we collect for our own purposes, including: marketing website visitors; demo, contact, and waitlist inquiries; Customer account administration and billing; product analytics and security monitoring we operate; and FloBuildr staff operations.

1.2 When FloBuildr is a processor / service provider

When Customers enter, upload, import, or otherwise process information about their clients, jobs, properties, employees, vendors, or End Customers in the Services ("Customer Data"), the Customer is the controller / business and FloBuildr processes that Customer Data as a processor / service provider on the Customer's instructions, subject to our Terms and applicable law. End Customers and other individuals whose information appears in Customer Data should contact the relevant Customer (the contractor) for most privacy requests about that data. We will assist Customers as required by law and our agreements.

2. Scope of the Services covered

This Policy covers information processed in connection with, without limitation:

  • Public marketing sites (including flobuildr.com)
  • The FloBuildr web application (including app.flobuildr.com)
  • Customer-facing job portals and share links (including portal.flobuildr.com)
  • Electronic signature experiences (including sign.flobuildr.com)
  • Public payment, estimate PDF, and invoice PDF links
  • Mobile crew / field applications
  • APIs, webhooks, background workers, email delivery, and realtime features
  • FloBuildr administrative systems used to operate and support the platform

3. Categories of information we collect

The categories below describe information we may collect depending on how you interact with the Services. Not all categories apply to every person.

3.1 Information you or your organization provide

  • Identity and contact data: name, display name, email address, phone numbers, profile photo, company affiliation, role, and similar account details.
  • Authentication data: passwords (stored as irreversible hashes), invite tokens, email-change tokens, session tokens, and related security metadata.
  • Business and company data: company name, domain, business address, phone/fax, logo, tax settings, margins, branding, subscription plan, and configuration metadata.
  • Customer / job / operations data (Customer Data): client and prospect records; property and job-site addresses; notes; pipeline and job status; estimates, contracts, change orders, line items, budgets; schedules and calendar events; tasks, checklists, workflows; daily logs; permits and inspections; punch lists; communications logs; purchase orders, receipts, vendors; invoices and payment records; and related files, photos, and documents.
  • Portal and messaging content: messages, sender names, read status, and content End Customers or Authorized Users submit through portals or related channels.
  • Electronic signature data: signer name, signature image or typed signature, consent acceptance, timestamps, IP address, user agent, document identifiers, and audit artifacts.
  • Payment-related data: invoice amounts, payment method type, card brand and last four digits (where provided by our payment processor), transaction identifiers, fee breakdowns, and billing history. We do not store full payment card numbers or CVV; card data is handled by our payment processor.
  • Support and feedback: messages you send us, bug reports, page URL, user agent, and release information associated with feedback.
  • Marketing and sales inquiries: name, work email, company, phone, and message content from contact, demo, or waitlist forms.

3.2 Information collected automatically

  • Device and network data: IP address, approximate location derived from network or CDN headers (such as country, region, city, or postal code), browser type, operating system, device identifiers, referrer, and user agent.
  • Usage and diagnostics: pages and routes viewed, feature usage events, performance metrics (including web vitals), error reports, stack traces (with automated redaction of certain sensitive patterns), request logs, session identifiers, and timestamps.
  • Local storage / session storage: authentication tokens and expiry, company selection, UI preferences, role-preview settings, geocode caches, and similar client-side state. We primarily use browser local/session storage rather than traditional first-party authentication cookies.
  • Email delivery events: send, delivery, bounce, complaint, and related telemetry for transactional messages we send on behalf of the platform or Customers.

3.3 Location and field data (mobile and job sites)

Where Customers enable field features, the Services may collect precise or approximate location information for clock-in/clock-out, geofence validation, progress updates, and related job-site workflows, including latitude, longitude, accuracy, distance from a job site, timezone, validation status, and override reasons. Mobile apps may also request camera, photo library, and microphone access (for example, for photos or speech-to-text used in punch lists or notes). Location and device permissions are controlled by the device OS and can be revoked; some features will not work without them.

3.4 Information from third parties and integrations

Depending on Customer configuration, we may receive or exchange information with:

  • Payment processors (for example, Stripe and Stripe Connect) for subscriptions and customer invoice payments.
  • Accounting systems (for example, QuickBooks Online) when a Customer connects an integration.
  • Maps, geocoding, and weather providers (for example, Google Maps Platform and OpenWeather) using addresses or coordinates.
  • Property data providers (for example, Realie) for property enrichment based on addresses Customers look up.
  • Supplier / materials systems (for example, SRS / RoofHub) for pricing, quotes, or orders when configured.
  • AI model providers (for example, OpenAI, Anthropic, or Google Gemini) when a Customer enables AI features and supplies or authorizes use of API credentials ("bring your own key" / BYOK).
  • Cloud infrastructure providers (for example, Amazon Web Services) that host databases, files, email, logs, and compute.
  • Customer-configured webhooks that receive outbound event payloads the Customer elects to send.

3.5 Information we do not intentionally collect

We do not intentionally collect government-issued identification numbers, biometric identifiers for authentication, health information, or information from children under 13. Customers should not upload special-category or highly sensitive data unless necessary for their business and lawful. Our observability tooling attempts to redact patterns resembling emails, phone numbers, SSNs, and certain secrets from diagnostic logs, but Customers remain responsible for minimizing sensitive data in free-text fields and uploads.

4. How we use information

We use personal information to:

  • Provide, operate, maintain, secure, and improve the Services
  • Create and administer accounts, invitations, roles, and permissions
  • Process Customer Data as instructed by Customers
  • Enable portals, messaging, document delivery, e-signatures, invoicing, and payments
  • Process SaaS subscription billing and Connected Account payment flows
  • Send transactional communications (invites, signing links, invoices, security notices, product-operational messages)
  • Send customer-facing SMS (job and schedule notifications) when a Customer records End Customer consent in the Services
  • Respond to inquiries, provide support (including limited account access/impersonation when needed to troubleshoot, subject to internal controls), and handle feedback
  • Monitor reliability, abuse, fraud, and security incidents
  • Analyze aggregated or de-identified usage to improve product design
  • Comply with law, enforce agreements, and protect rights, safety, and property
  • Send product or marketing communications where permitted (you may opt out of marketing emails; transactional messages may still be sent)

Where required by applicable law, we rely on one or more of the following bases: performance of a contract; legitimate interests (such as securing and improving the Services); consent (where obtained); and legal obligation.

5. How we share information

We do not sell personal information for money. We may share information as follows:

  • Service providers / subprocessors: hosting, databases, file storage, email delivery, SMS delivery (for example, AWS End User Messaging and mobile carriers), payment processing, maps, weather, property data, supplier integrations, observability infrastructure, and similar vendors who process data on our behalf under contractual obligations.
  • Payment processors: Stripe processes subscription and Connect payments. Their privacy practices apply to data they process as an independent controller or as described in their terms.
  • Customer-directed disclosures: when a Customer shares portal links, payment links, PDFs, signing envelopes, or enables integrations/webhooks/AI features, information is disclosed as directed by that Customer.
  • Within a Customer organization: Authorized Users of a company tenant may access Customer Data according to roles and permissions configured by the Customer.
  • Corporate transactions: in connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, subject to appropriate confidentiality protections.
  • Legal and safety: when we believe disclosure is required by law, legal process, or government request, or to protect the rights, safety, or security of FloBuildr, our users, or the public.
  • With consent or at your direction.

FloBuildr staff may access Customer accounts for support, billing, security, abuse investigation, or platform operations, including through audited administrative tools and, where necessary, impersonation/session assistance. Access is limited to personnel with a need to know.

Mobile / SMS opt-in information: We do not sell or share mobile opt-in information, phone numbers collected for SMS consent, or SMS consent status with third parties or affiliates for their marketing or promotional purposes. Phone numbers and consent records are used only to deliver the customer-requested job and schedule texts (and related delivery, compliance, and support functions) through our SMS service providers and carriers.

6. Customer portals, public links, and End Customers

Customers may generate shareable tokens or links that allow End Customers (and anyone who receives the link) to view or interact with selected job information—such as progress, photos, daily logs, invoices, punch lists, messages, payments, or documents—without creating a FloBuildr login. Anyone with a valid link may access the enabled content until the link expires, is revoked, or is otherwise disabled. Customers are responsible for:

  • Obtaining any required notices and consents from End Customers
  • Configuring which sections are visible
  • Safeguarding and distributing links appropriately
  • Revoking access when no longer needed

If you are an End Customer and have privacy questions about information shown in a portal or signing flow, contact the contractor who sent you the link. You may also contact us at contact@flobuildr.com and we will route or assist as appropriate.

7. Electronic signatures

When documents are signed electronically through the Services, we process signer identity information, signature data, consent records, IP address, user agent, timestamps, and related audit materials to create an audit trail and to help Customers evidence agreement. Customers are responsible for the content of documents presented for signature and for ensuring e-sign use is appropriate for their transactions.

8. Payments and billing

Subscription fees for FloBuildr are processed through our payment processor. Separately, Customers may connect payment accounts (such as Stripe Connect) so End Customers can pay invoices. FloBuildr may receive transaction metadata, fee information, and limited card descriptors (for example, brand and last four digits). Full card numbers are collected by the payment processor's secure fields and are not stored by FloBuildr. Payment processor terms and privacy policies apply to card processing.

9. Artificial intelligence features

If a Customer enables AI features, prompts and context—which may include job details, account names, property addresses, line items, pipeline summaries, and similar operational content—may be sent to third-party AI providers using Customer-supplied or Customer-authorized credentials. Customers control whether to enable AI, which provider/key to use, and what content Authorized Users include in prompts. Do not include information in AI prompts that you are not authorized to process or disclose. We may log AI usage metadata such as provider, model, token counts, latency, cost estimates, and errors.

10. Cookies, local storage, and similar technologies

We and our service providers use cookies, pixels, local storage, session storage, and similar technologies to operate the Services, maintain sessions, remember preferences, measure performance, and detect abuse. Our marketing site and applications may send first-party telemetry (page views, performance, and diagnostic events) to our own observability endpoints. Third-party resources (such as Google Fonts) may receive IP address and referrer information when loaded by your browser. You can control cookies and storage through browser settings; disabling certain storage may break login or core functionality.

11. Data retention

We retain information for as long as needed to provide the Services, comply with legal obligations, resolve disputes, enforce agreements, and support legitimate business needs. Retention periods vary by data type. Without limiting the foregoing:

  • Account and Customer Data generally persist for the life of the Customer relationship and for a reasonable period thereafter, unless deleted earlier pursuant to Customer action, our Terms, or law.
  • Certain soft-deleted Customer records may be retained for a recovery window (currently on the order of approximately 45 days) before permanent purge, subject to change.
  • Observability and diagnostic data are typically retained for limited periods (for example, on the order of months for detailed events), while aggregated metrics may be kept longer.
  • Database backups and logs may persist for shorter operational windows after deletion from primary systems.
  • Email delivery records, signature audit materials, payment records, and security logs may be retained longer where needed for compliance, fraud prevention, accounting, or dispute resolution.

When a company tenant is deleted, associated tenant data is generally removed from primary systems subject to backups, legal holds, and residual copies in logs or archives that are deleted or anonymized over time according to our schedules.

12. Security

We implement administrative, technical, and organizational measures designed to protect personal information, which may include encryption in transit, encryption at rest for primary datastores, access controls, authentication, logging, and vulnerability management. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Customers are responsible for safeguarding credentials, configuring permissions, protecting share links, and securing devices used to access the Services.

13. International transfers

FloBuildr LLC is organized under the laws of South Carolina and operates in the United States. We process information in the United States and in other locations where we or our service providers operate. If you access the Services from outside the United States, you understand that your information may be transferred to, stored, and processed in the United States and other jurisdictions that may have different data-protection laws than your country. Where required, we use appropriate transfer mechanisms.

14. Your privacy choices and rights

14.1 Account controls

Authorized Users may update certain profile information in-product. Customers control much of the Customer Data in their tenant, including soft-deletion of certain records and revocation of portal or signing access.

14.2 Marketing

You may opt out of marketing emails by following unsubscribe instructions or contacting us. Transactional and service messages are not marketing and may continue.

14.3 Access, correction, deletion, and other requests

Subject to applicable law, you may request access to, correction of, deletion of, or information about our processing of personal information we control by emailing contact@flobuildr.com. We may need to verify your identity and the nature of your request. For Customer Data processed on behalf of a Customer, we will typically refer you to the Customer or coordinate with the Customer, except where law requires us to act directly.

14.4 U.S. state privacy rights (including California)

Residents of certain U.S. states (including California under the CCPA/CPRA) may have rights to know/access, delete, correct, and opt out of certain sharing or targeted advertising, and to not be discriminated against for exercising rights. FloBuildr does not sell personal information as "sell" is commonly understood. We also do not knowingly sell or share the personal information of consumers under 16. To exercise rights, contact contact@flobuildr.com. You may use an authorized agent as permitted by law. We will respond within the timeframes required by applicable law.

Notice at collection (California): We collect the categories described in Section 3 for the purposes in Section 4, retain them as described in Section 11, and disclose them to the categories of recipients in Section 5. We do not use or disclose sensitive personal information for purposes that require a right to limit under the CPRA, except as permitted to provide the Services you request or as otherwise allowed by law.

14.5 EEA/UK individuals

If European or UK data-protection law applies to personal information we control, you may have rights of access, rectification, erasure, restriction, portability, and objection, and the right to lodge a complaint with a supervisory authority. Contact us to exercise these rights. Where we process Customer Data as a processor, please contact the relevant Customer first.

15. Children's privacy

The Services are designed for business users and adult End Customers. They are not directed to children under 13 (or under 16 where a higher age applies), and we do not knowingly collect personal information from children. If you believe a child has provided personal information, contact us and we will take appropriate steps to delete it.

16. Third-party sites and services

The Services may link to or integrate with third-party websites, apps, or services. Their privacy practices are governed by their own policies. We are not responsible for third-party practices. Enabling an integration constitutes Customer authorization for the related data exchanges.

17. Changes to this Policy

We may update this Privacy Policy from time to time. The "Last updated" date at the top will change when we post revisions. Material changes will be indicated by updating this page and, where appropriate, by additional notice (such as email or in-product notice). Continued use of the Services after the effective date constitutes acceptance of the updated Policy, except where applicable law requires a different standard.

18. Contact us

For privacy questions, requests, or complaints:

Business hours: Monday–Friday, 9:00 a.m.–5:00 p.m. Eastern Time.