1
Introduction
CivCore Inc. is a Delaware corporation with its principal place of business at 2261 Market Street STE 85261, San Francisco, CA, United States. The Services are business-to-business tools intended for use by architecture, engineering, and construction firms and their authorized personnel. The Services are hosted and offered in the United States.
2
Our Two Roles
We handle personal information in two distinct capacities. As a business, we collect and control account registration details, billing information, website visits, marketing interactions, and product usage data. As a service provider, we process Customer Data on behalf of and at the direction of our customers under our agreements with them, including our Data Processing Addendum. If your information is contained in Customer Data, direct privacy requests to the customer that uploaded it; we will support our customers in responding.
3
Information We Collect
3.1
Information You Provide. Account information: name, business email address, profile photograph (optional), employer/organization, and role. Payment information: billing contact and invoicing details. We do not collect payment card information through the Services; payments are handled through invoicing and our banking and payment providers (currently Mercury; we may add Stripe or similar processors, which will be reflected in this Policy). Communications: messages you send to support or sales, and feedback you provide.
3.2
Information Collected Automatically. Usage data: pages viewed, features used, actions taken, session information, and interaction data, collected through PostHog (product analytics). Diagnostics: error logs, crash reports, device/browser type, operating system, and IP address, collected through Sentry (error monitoring). Cookies: we and our analytics providers use cookies and similar technologies to operate the Services and understand usage. See Section 9.
3.3
Customer Data. Customers upload documents and connect data sources (such as SharePoint, Procore, and OneDrive) to the Services. We process this Customer Data to provide the Services as described in Section 4 and in our agreements with the customer. We do not control what personal information customers include in Customer Data.
4
How We Use Information
We use information to provide, maintain, secure, and support the Services; administer accounts, process payments, and communicate with customers; monitor, debug, and improve the Services through aggregated and de-identified analytics; detect security incidents, fraud, and abuse; comply with legal obligations; and carry out other purposes described at collection with consent or at the customer’s direction. We do not use personal information for automated decision-making that produces legal or similarly significant effects, and we do not sell or share personal information for cross-context behavioral advertising.
5
Artificial Intelligence and Your Data
The Services use large language models operated by Amazon Web Services, Anthropic, Google Cloud, and OpenAI to analyze Customer Data and generate outputs. Relevant Customer Data may be transmitted to these providers to generate requested output. Our accounts are configured so that submitted data is not used to train provider models; providers may temporarily retain data under their standard API terms. CivCore does not use Customer Data to train artificial intelligence models except as expressly agreed with the customer.
6
How We Disclose Information
We disclose information to service providers and subprocessors that help deliver the Services, including cloud hosting, AI model providers, analytics and diagnostics, and banking or payment providers. We may also disclose information within your organization, to comply with law or protect rights and safety, in connection with corporate transactions, or with consent or at the direction of a customer or individual.
7
Data Location
The Services are hosted in the United States, and information we collect is stored and processed in the United States. If you access the Services from outside the United States, you understand that your information will be transferred to and processed in the United States. For customers subject to non-U.S. privacy laws, our Data Processing Addendum sets out the contractual protections that apply to Customer Data.
8
Retention
We retain account and billing information while an account is active and as needed for legitimate business purposes, legal compliance, and dispute resolution. Customer Data is retained for the subscription term and may be retained after termination to allow reactivation unless deletion is requested. Deletion requests are honored within 90 days, subject to backup cycles and legal holds, as described in our customer agreements.
9
Cookies and Analytics
We use strictly necessary cookies to operate the Services, as well as PostHog for analytics and Sentry for error monitoring. You can control cookies through your browser settings, though disabling necessary cookies may impair the Services.
10
Security
We maintain administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit, access controls, and monitoring. No system is completely secure, and we cannot guarantee absolute security. Our SOC 2 Type II examination is in progress; additional information is available at security.civcore.com.
11
Your Privacy Rights
11.1
California Residents. If you are a California resident, the California Consumer Privacy Act as amended (“CCPA”) gives you the right to: (a) know and access the personal information we collect about you, including the categories of information, sources, purposes, and third parties to whom it is disclosed; (b) correct inaccurate personal information; (c) delete personal information, subject to exceptions; (d) opt out of “sale” or “sharing” of personal information (we do not sell or share personal information as those terms are defined in the CCPA); (e) limit use of sensitive personal information (we do not use sensitive personal information beyond permitted purposes); and (f) not receive discriminatory treatment for exercising these rights. In the preceding 12 months, we have collected the following categories of personal information: identifiers (name, email, IP address); commercial information (subscription and billing records); internet or network activity (usage and diagnostic data); professional information (employer, role); and audio/visual information (optional profile photo). We collect these from you directly, automatically through the Services, and from your organization. We disclose them to service providers for business purposes described in Section 6. We do not sell or share personal information and have not done so in the preceding 12 months. Retention criteria are described in Section 8. To exercise these rights, contact us at support@civcore.com. We will verify requests using account information and respond within the timeframes required by law. You may designate an authorized agent to submit requests on your behalf.
11.2
Other Jurisdictions. Depending on where you live, you may have rights to access, correct, or delete personal information under the laws of your jurisdiction (including, for example, Canada’s PIPEDA). We will honor valid requests as required by applicable law. If your personal information was uploaded to the Services by one of our customers as part of Customer Data, we will refer your request to that customer and support their response.
12
Children
The Services are business tools not directed to individuals under 18, and we do not knowingly collect personal information from children. If you believe a child has provided personal information to us, contact support@civcore.com and we will delete it.
13
Changes to This Policy
We may update this Policy from time to time. We will post the updated Policy with a revised Last Updated date and, for material changes, provide notice by email or through the Services before the changes take effect.
14
Contact Us
CivCore Inc. 2261 Market Street STE 85261, San Francisco, CA 94114, United States. support@civcore.com.