1
Introduction
This Privacy Policy describes how CivCore Inc., a Delaware corporation with its principal place of business at 2261 Market Street STE 85261, San Francisco, CA 94114, United States (“CivCore,” “we,” “us,” or “our”), collects, uses, and discloses personal information in connection with our websites, our AI-enabled construction intelligence platform, and related services (collectively, the “Services”).
The Services are business-to-business tools intended for use by architecture, engineering, and construction firms and their authorized personnel. The Services are hosted and offered in the United States.
2
Our Two Roles
We handle personal information in two distinct capacities, and different sections of this Policy apply to each:
As a business (controller): information we collect and control directly - such as account registration details, billing information, website visits, marketing interactions, and product usage data. This Policy applies fully to this information.
As a service provider (processor): the documents, files, and data that our customers upload to the Services or connect through integrations (“Customer Data”) may contain personal information - for example, names and contact details of project personnel or subcontractors. We process Customer Data on behalf of and at the direction of our customers under our agreements with them, including our Data Processing Addendum. If your personal information is contained in Customer Data, the customer that uploaded it is responsible for it, and you should direct privacy requests to that customer. We will support our customers in responding to such requests.
3
Information We Collect
3.1
Information You Provide.
Account information: name, business email address, profile photograph (optional), employer/organization, and role.
Payment information: billing contact and invoicing details. We do not collect payment card information through the Services; payments are handled through invoicing and our banking and payment providers (currently Mercury; we may add Stripe or similar processors, which will be reflected in this Policy).
Communications: messages you send to support or sales, and feedback you provide.
3.2
Information Collected Automatically.
Usage data: pages viewed, features used, actions taken, session information, and interaction data, collected through PostHog (product analytics).
Diagnostics: error logs, crash reports, device/browser type, operating system, and IP address, collected through Sentry (error monitoring).
Cookies: we and our analytics providers use cookies and similar technologies to operate the Services and understand usage. See Section 9.
3.3
Customer Data. Customers upload documents and connect data sources (such as SharePoint, Procore, and OneDrive) to the Services. We process this Customer Data to provide the Services as described in Section 4 and in our agreements with the customer. We do not control what personal information customers include in Customer Data.
4
How We Use Information
to provide, maintain, secure, and support the Services, including processing Customer Data to generate analyses, summaries, and other outputs requested by the customer;
to set up and administer accounts, process payments, and communicate with customers about the Services;
to monitor, debug, and improve the Services, including through aggregated and de-identified usage analytics;
to detect, investigate, and prevent security incidents, fraud, and abuse;
to comply with legal obligations and enforce our agreements; and
with consent or at the customer’s direction, for other purposes described at the time of collection.
We do not use personal information for automated decision-making that produces legal or similarly significant effects about individuals. We do not sell personal information, and we do not share personal information for cross-context behavioral advertising.
5
Artificial Intelligence and Your Data
The Services use large language models operated by third-party providers, currently Amazon Web Services (including Bedrock), Anthropic, Google Cloud, and OpenAI, to analyze Customer Data and generate outputs. When a customer uses AI features, relevant Customer Data (which may include personal information contained in uploaded documents) is transmitted to one or more of these providers to generate the requested output.
No model training: we have configured our accounts with these providers so that data submitted through our Services is not used to train the providers’ models.
Limited retention by providers: these providers may temporarily retain submitted data in accordance with their standard API terms (for example, for abuse monitoring), after which it is deleted under those terms.
Our own use: we do not use Customer Data to train artificial intelligence models, except as expressly agreed with the customer. We may use aggregated, de-identified data as described in our customer agreements.
6
How We Disclose Information
Service providers and subprocessors: we use vendors that process information to help us deliver the Services, including cloud hosting and infrastructure (Amazon Web Services, Google Cloud Platform, Temporal, Upstash, Railway & Supabase), AI model providers (Section 5), analytics and diagnostics (PostHog and Sentry, which receive usage and diagnostic telemetry but not the content of customer documents), and banking/payment providers (currently Mercury). Our current subprocessor list for Customer Data is available at civcore.com/legal/subprocessors.
Your organization: personnel of the customer organization that controls an account may see account and usage information for users within that organization.
Legal and safety: we may disclose information to comply with law, legal process, or governmental requests, or to protect the rights, safety, and property of CivCore, our customers, or others.
Corporate transactions: in connection with a merger, acquisition, financing, or sale of assets, information may be transferred, subject to this Policy’s commitments.
With consent: we may disclose information with consent or at the direction of the customer or individual.
7
Data Location
The Services are hosted in the United States, and information we collect is stored and processed in the United States. If you access the Services from outside the United States, you understand that your information will be transferred to and processed in the United States, where privacy laws may differ from those of your jurisdiction. For customers subject to non-U.S. privacy laws, our Data Processing Addendum sets out the contractual protections that apply to Customer Data.
8
Retention
We retain account and billing information for as long as the account is active and as needed for legitimate business purposes, legal compliance, and dispute resolution. Customer Data is retained for the duration of the customer’s subscription and, after termination, is retained to allow the customer to reactivate its account unless the customer requests deletion. Deletion requests are honored within 90 days, subject to routine backup cycles (up to 90 additional days) and legal holds, as described in our customer agreements. Diagnostic and analytics data is retained for the periods needed for the purposes described in this Policy; session recordings and error logs are deleted within 90 days.
9
Cookies and Analytics
We use strictly necessary cookies to operate the Services (such as authentication and session cookies) and analytics tools (PostHog) and error monitoring (Sentry) to understand and improve the Services.; session recording are configured to mask document content and tax inputs are deleted within 90 days. You can control cookies through your browser settings; disabling necessary cookies may impair the Services.
10
Security
We maintain administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit, access controls, and monitoring. No system is completely secure; we cannot guarantee absolute security. Our SOC 2 Type II examination is in progress, and additional security information is available at our trust center, security.civcore.com.
11
Your Privacy Rights
11.1
California Residents. If you are a California resident, the California Consumer Privacy Act as amended (“CCPA”) gives you the right to: (a) know and access the personal information we collect about you, including the categories of information, sources, purposes, and third parties to whom it is disclosed; (b) correct inaccurate personal information; (c) delete personal information, subject to exceptions; (d) opt out of “sale” or “sharing” of personal information (we do not sell or share personal information as those terms are defined in the CCPA); (e) limit use of sensitive personal information (we do not use sensitive personal information beyond permitted purposes); and (f) not receive discriminatory treatment for exercising these rights.
In the preceding 12 months, we have collected the following categories of personal information: identifiers (name, email, IP address); commercial information (subscription and billing records); internet or network activity (usage and diagnostic data); professional information (employer, role); and audio/visual information (optional profile photo). We collect these from you directly, automatically through the Services, and from your organization. We disclose them to service providers for business purposes described in Section 6. We do not sell or share personal information and have not done so in the preceding 12 months. Retention criteria are described in Section 8.
To exercise these rights, contact us at support@civcore.com. We will verify requests using account information and respond within the timeframes required by law. You may designate an authorized agent to submit requests on your behalf.
11.2
Other Jurisdictions. Depending on where you live, you may have rights to access, correct, or delete personal information under the laws of your jurisdiction (including, for example, Canada’s PIPEDA). We will honor valid requests as required by applicable law. If your personal information was uploaded to the Services by one of our customers as part of Customer Data, we will refer your request to that customer and support their response.
12
Children
The Services are business tools not directed to individuals under 18, and we do not knowingly collect personal information from children. If you believe a child has provided personal information to us, contact support@civcore.com and we will delete it.
13
Changes to This Policy
We may update this Policy from time to time. We will post the updated Policy with a revised “Last Updated” date and, for material changes, provide notice by email or through the Services before the changes take effect. Prior versions archived internally and available under NDA for review upon request.
14
Contact Us
CivCore Inc.
2261 Market Street STE 85261, San Francisco, CA 94114, United States
support@civcore.com