Privacy Policy
Effective Date: 2 October 2026 | Last Updated: 2 October 2026
1. Who We Are
SubCompliance is a software tool built to help general contractors track subcontractor compliance documents — certificates of insurance, trade licenses, W-9s, and safety certifications — across their construction projects, so they always know who's cleared to work.
This Privacy Policy explains what information we collect from both general contractors who use SubCompliance directly, and from subcontractors who upload documents through the links we send on a contractor's behalf, how we use that information, and how we protect it.
If you have questions about this policy or how your information is handled, you can reach us at ghoshgeetika2@gmail.com.
India, West Bengal — 734001Email: ghoshgeetika2@gmail.com
2. Scope
This Privacy Policy applies to personal data collected through the SubCompliance website and platform. It covers data about:
- General Contractors ("GCs") who create and manage accounts.
- Subcontractors whose data GCs upload or who interact with the platform via upload links.
- Visitors to the SubCompliance website.
Note on GC and subcontractor data: When a GC uploads or enters data about their subcontractors, the GC acts as a data controller/fiduciary in respect of that subcontractor data. SubCompliance acts as a data processor on the GC's behalf. GCs are responsible for ensuring they have a lawful basis to share subcontractor personal data with SubCompliance.
3. Data We Collect
3.1 Account and Profile Data
- Full name and company name
- Email address
- Password (stored as a secure hash; never in plain text)
- Subscription plan and billing status
3.2 Project and Compliance Data
- Project names, addresses, and start dates
- Required document types per project
- Subcontractor names, company names, email addresses, phone numbers, and trade
- Uploaded compliance documents (PDFs, images)
- Document expiry dates and compliance statuses
- Invitation and reminder timestamps
3.3 Billing Data
Payment card details and billing information are processed directly by Dodo Payments (our payment processor and merchant of record). SubCompliance does not store raw payment card numbers. We receive and store subscription identifiers, plan tier, and payment status from Dodo Payments.
3.4 Technical and Usage Data
- IP address and browser/device information
- Pages visited and features used
- Error logs and performance data
- Cookies and similar technologies (see Section 11)
4. How We Use Your Data
- To create and manage your account.
- To provide the compliance management features of the platform.
- To send transactional emails: upload invitations, expiry reminders, and escalation alerts.
- To process payments and manage subscriptions.
- To enforce plan limits and prevent abuse.
- To improve the platform and fix technical issues.
- To comply with legal obligations.
5. Legal Bases for Processing (GDPR)
For users in the European Economic Area (EEA) and United Kingdom, we rely on the following legal bases:
- Contract: Processing necessary to provide the Service you have subscribed to.
- Legitimate interests: Security, fraud prevention, product improvement, and service communications.
- Legal obligation: Retaining billing and transaction records as required by law.
- Consent: Where we ask for your consent for specific optional processing (e.g., marketing communications).
6. DPDP Act 2023 — India
For users in India, we process personal data in accordance with the Digital Personal Data Protection Act, 2023. As a data fiduciary:
- We collect only data that is necessary for the purposes described in this policy.
- We provide clear notice of data processing at the point of collection.
- You have the right to access, correct, and erase your personal data (see Section 10).
- You have the right to withdraw consent for optional processing at any time.
- You have the right to nominate a representative for data requests.
- You have the right to raise grievances with us (see Section 13).
7. Data Sharing and Subprocessors
We share data only with trusted subprocessors required to operate the Service:
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, file storage | USA (AWS) |
| Vercel | Application hosting and deployment | USA |
| Resend | Transactional email delivery | USA |
| Dodo Payments | Payment processing and subscriptions | USA / Global |
We do not sell your personal data to third parties. We do not share your data with advertisers.
8. International Data Transfers
Our infrastructure and third-party subprocessors—specifically Supabase (database and storage), Vercel (hosting), Resend (email delivery), and Dodo Payments (payment processing)—process and store data primarily in the United States.
By using the Service, you acknowledge and consent that your data may be transferred to and processed in the United States and other jurisdictions outside your home country, which may have different data protection laws. Where applicable, we rely on legally approved mechanisms, such as Standard Contractual Clauses, to safeguard international data transfers.
9. Data Retention
- Account and profile data: Retained while your account is active.
- Project and compliance data: Retained while the project or account remains active.
- Uploaded documents: Retained while the associated project is active. Deleted documents are removed from active systems within 30 days.
- Billing and transaction records: Retained for 7 years as required by accounting and tax law.
- Security and access logs: Retained for up to 12 months.
- After account termination: Customer data is retained for up to 30 days to allow export, then permanently deleted, except where longer retention is required by law.
10. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete data.
- Erasure: Request deletion of your personal data.
- Portability: Request your data in a machine-readable format.
- Restriction: Request that we limit how we use your data.
- Objection: Object to processing based on legitimate interests.
- Withdraw consent: Where processing is based on consent, withdraw it at any time.
To exercise any of these rights, contact us at ghoshgeetika2@gmail.com. We will respond within 30 days.
11. Cookies
SubCompliance uses strictly necessary cookies and session tokens to authenticate users and maintain sessions. We do not currently use advertising or tracking cookies. If this changes, we will update this policy and seek consent where required.
12. Security
We implement industry-standard security measures including encrypted data transmission (TLS), hashed passwords, role-based access controls, and private cloud storage. However, no system is completely secure and we cannot guarantee absolute security.
13. Grievance Officer (DPDP Act / India)
In accordance with the Digital Personal Data Protection Act, 2023, you may raise grievances regarding the processing of your personal data by contacting our Grievance Officer:
Geetika Ghosh
India, West Bengal — 734001
Email: ghoshgeetika2@gmail.com
We will acknowledge your grievance within 48 hours and resolve it within 30 days.
14. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or a notice on the platform at least 14 days before they take effect.