Privacy policy
Projlog is a tool that service companies use to communicate with their customers. Companies own the data they put in. We don't sell anyone's personal information, we don't show ads, and we only use your data to run the service. When a contractor invites you to a project portal, that contractor controls your project data; we process it on their behalf.
- 01Who we are
- 02Our two roles
- 03Information we collect
- 04How we use information
- 05When we share information
- 06Service providers
- 07Artificial intelligence
- 08Text messages
- 09Cookies & tracking
- 10Data retention
- 11Security
- 12Your rights & choices
- 13Children
- 14International users
- 15Changes to this policy
- 16Contact us
Who we are
Projlog is operated by Project Log LLC ("Projlog," "we," "us"). We provide a customer communication platform for service companies: project portals, messaging, photo sharing, estimates, invoicing, scheduling, and related tools, available at projlog.app and through our applications (together, the "Service").
This policy explains what personal information we collect, how we use it, and the choices you have. It applies to visitors of our website, the companies that subscribe to Projlog ("Companies"), their staff and crews ("Users"), and the customers those companies invite into project portals ("Customers").
Our two roles
We handle personal information in two distinct capacities, and your rights differ depending on which applies:
- Projlog as a controller. For information about website visitors, demo requests, and Company account holders, we decide how and why the data is used. This policy governs that data directly.
- Projlog as a processor.For project data inside the platform (Customer names, addresses, messages, photos, estimates, payment records), the Company you hired is the controller. We process that data on the Company's instructions under our agreement with them. If you are a Customer and want your project data corrected or deleted, the fastest path is to ask your contractor; we support them in honoring those requests.
Information we collect
Information you provide
- Account information. Name, email address, phone number, company name, and password (stored as a salted hash) when a Company creates an account or a User is added to one.
- Project data. Content that Companies and Customers put into the Service: messages, project details, property addresses, access notes, photos and documents, estimates, invoices, and payment records.
- Customer onboarding data. Information Customers provide during their guided first visit: contact details, property information, and notification preferences.
- Voice recordings. If a User records a voice note or uses dictation, we store the audio and a text transcript of it. Where a Company enables call recording, recorded calls are stored as well. Section 07 explains how transcription works.
- Demo and support requests. Name, company, trade, email, phone, and anything you include in a message to us.
Information collected automatically
- Usage data. Log data such as IP address, browser and device type, pages viewed, and actions taken in the Service, used for security, debugging, and improving the product.
- Device data for notifications. Push subscription tokens and delivery status, so we know whether a notification reached you and when to fall back to a text message.
- Location, only if the Company turns it on.Crew location capture is off by default. When a Company enables it in Settings, the crew app records the device's coordinates at the moment a crew member clocks in or out, marks themselves en route or on site, or completes a quality checklist. It is a point in time, not a continuous track: there is no background location, no route history, and no live map of anyone's position. When the setting is off, the app does not ask the device for a position and no coordinates are stored. A crew member can also decline the permission on their own device, which does not prevent them from clocking in.
- Error and performance monitoring. When something breaks, we receive an error report with technical details about the request. For a sample of sessions in which an error occurs, we also receive a replay of what happened on the page. Text in those replays is masked before it leaves your browser, and images, video, and uploaded files are not captured at all, so the replay shows the shape of the page and the sequence of actions rather than the content on screen.
Information from third parties
- Sign-in providers. If you sign in with Google or Microsoft, we receive your name, email address, and profile identifier from that provider. We do not receive your password or your files.
- Payment processor. Stripe provides us with payment status and the last four digits of a card. Full card numbers never touch our servers.
- Property and owner information (prospecting tools). For Companies that use our prospecting tools, we obtain property records, owner names, business contact details, and property imagery from county assessor and GIS systems, parcel-data and contact-lookup vendors, and street-level imagery providers. This information is about property owners who are not our users. Section 07 explains what we do with it, and how an owner can have it removed.
How we use information
- To provide, maintain, and improve the Service.
- To deliver messages and notifications you or your contractor send through the platform.
- To process payments and maintain billing records.
- To respond to support requests and demo inquiries.
- To secure the Service: detecting fraud, abuse, and unauthorized access.
- To comply with legal obligations.
- To send Companies service announcements and, with consent, product news. We do not send marketing to Customers.
We do not sell personal information, and we do not share it for cross-context behavioral advertising.
When we share information
- Within a project. Project data is visible to the Company that owns the project and the Customers invited to it. That's the point of the product.
- Service providers. The vendors described in Section 06 and named in full on our subprocessor list, bound by contracts that limit their use of your data to providing services to us.
- Legal requirements. When required by law, subpoena, or court order, or to protect the rights, safety, and property of Projlog, our users, or the public.
- Business transfers. If Projlog is involved in a merger, acquisition, or sale of assets, your information may transfer with the business; this policy would continue to apply.
Service providers
We use other companies to run parts of the Service. They may handle personal information to do their job, and they are bound by contracts that limit them to providing services to us. Here is the shape of it by category:
| Category | What they do | What they handle |
|---|---|---|
| Infrastructure | Application hosting, database, and file storage | All Service data, encrypted in transit and at rest |
| Payments | Card processing and subscription billing | Payment card details, billing name and address |
| Communications | Transactional email, text messages, and voice | Email addresses, phone numbers, message content |
| AI providers | Drafting help, the staff assistant, and speech-to-text | The text, audio, or image sent with a request. See Section 07 |
| Monitoring | Error and performance monitoring | Error reports and masked session replays |
| Optional integrations | Accounting, calendar, maps, measurement, supplier, and marketing tools | Only what the connected integration needs, and only when a Company turns it on |
The complete list, naming every vendor, is published at projlog.app/marketing/subprocessors. We update that page when a subprocessor is added or removed. If you want advance notice of changes, write to privacy@projlog.app and we will add you to the notice list.
Artificial intelligence
Some features send content to an AI provider to generate a suggestion. We use Anthropic and OpenAI. We do not host our own models, and neither provider uses what we send to train their models.
These are the only features that send anything to an AI provider:
| Feature | What gets sent |
|---|---|
| Draft a crew update or end-of-day summary | The job details and notes the crew member has entered, plus your company's writing-style settings |
| The staff assistant | What the staff member types, plus context about the record they are looking at |
| Voice notes and dictation | The audio recording itself, which is transcribed to text and returned |
| Roof assessment in the prospecting tools | A street-level photograph of a property. See below |
Nothing else in Projlog is sent to an AI provider. Your messages, photos, documents, invoices, and customer list are not fed to a model in the background, and there is no training on your data. Suggestions that appear elsewhere in the product, such as recommended next steps on a project, are produced by ordinary rules running on our own servers, not by a model.
A drafted message is a draft. Anything an AI feature produces is shown to a person to edit, approve, or discard before it is sent. No AI output reaches a Customer without a User choosing to send it.
Roof assessment on properties, including non-users
This one deserves to be called out separately, because it is the only place where we process information about people who never agreed to anything.
A Company using our prospecting tools can ask for an assessment of a property's roof condition. To produce it, we retrieve a street-level photograph of the property from an imagery provider, send that photograph to Anthropic for a visual assessment, and store the resulting condition rating alongside the property record. The property owner is typically not a Projlog user, has no account, and has not agreed to our terms.
- Who is responsible. The Company chooses which properties to assess and is the controller of that information, including responsibility for having a lawful basis to process it and for following the marketing and telephone consumer protection laws that apply to whatever they do next. We are the processor.
- What we store.The property address and parcel record, the imagery URL, the condition assessment, and when it was produced. We do not build a profile of the owner as a person, and this data is not combined with any Customer's project data.
- How to get it removed. Any property owner may write to privacy@projlog.app with the address and ask what we hold and to have it deleted. You do not need a Projlog account to make that request, and we will honor it whether or not the law where you live requires us to.
Text messages
The Service sends a small number of text messages: an invitation when a contractor sets up your project, and fallback alerts when something critical would otherwise go unseen. Message and data rates may apply.
- Consent.Companies are responsible for having their Customers' consent to receive these texts, and agree to that in our Terms of Service and Acceptable Use Policy.
- Opting out. Reply STOP to any text from the Service to stop receiving texts. Reply HELP for help. Opting out of texts does not close your portal; in-portal and push notifications continue per your preferences.
Cookies & tracking
We use cookies and similar technologies that are essential to the Service: keeping you signed in, remembering preferences, and protecting against request forgery. On our public marketing pages we use Plausible Analytics, a third-party service, to count page views in aggregate. It sets no cookies and does not track you across sites, and it does not run inside the Service once you are signed in. We do not use advertising cookies or tracking pixels anywhere.
Data retention
- Account data is kept while the account is active and deleted or anonymized within 30 days of account closure, except where law requires longer retention.
- Project datais retained under the Company's control. When a Company deletes a project or closes its account, associated data is deleted from production systems within 30 days and from backups within 60 days.
- Billing records are retained as required by tax and accounting law (typically 7 years).
- Log data is retained for up to 12 months for security purposes.
Security
We protect your information with industry-standard measures: encryption in transit (TLS) and at rest, hashed and salted passwords, two-factor authentication for Company accounts, least-privilege access controls, and logging of access to production systems. No system is perfectly secure; if we learn of a breach affecting your personal information, we will notify affected parties and regulators as required by law.
Your rights & choices
Depending on where you live (including California, Colorado, Connecticut, Texas, Utah, Virginia, and other states with privacy laws, the EEA, and the UK), you may have the right to:
- Access the personal information we hold about you, and receive a portable copy.
- Correct inaccurate personal information.
- Delete your personal information.
- Object to or restrict certain processing.
- Not be discriminated against for exercising any of these rights.
To exercise these rights, email privacy@projlog.app. We respond within the time required by applicable law (generally 30 to 45 days) and may need to verify your identity first. If you are a Customer and your request concerns project data, we may refer the request to the Company that controls it, and we will help them fulfill it. You may also appeal a decision by replying to our response, and you may lodge a complaint with your local supervisory authority.
Children
The Service is for business use and is not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will delete it.
International users
We are based in the United States and process data there. If you access the Service from outside the U.S., you understand that your information will be transferred to and processed in the U.S. Where required, we rely on appropriate safeguards such as standard contractual clauses for transfers from the EEA and UK.
Changes to this policy
When we make material changes, we will update the date at the top, notify Companies by email or in-product notice at least 30 days before the change takes effect, and keep prior versions available on request.
Contact us
Project Log LLC
Email: privacy@projlog.app
Support: support@projlog.app