Legal
Privacy Policy
Effective August 1, 2026
This policy describes how SiteSignal handles personal data across the application and this website. It is written to be readable by the people who have to review it — security teams, procurement, and counsel — rather than to be maximally vague.
1.Who we are
SiteSignal LLC (“SiteSignal,” “we,” “us”) provides a software-as-a-service platform that helps general contractors track budget, schedule, RFI, and change order data across a portfolio of construction projects, and surfaces risk signals from that data.
This policy explains what we do with personal data in connection with the SiteSignal application at getsitesignal.io and our marketing site. For most of our activity, the customer organization that subscribes to SiteSignal is the controller of project data and SiteSignal is the processor acting on that organization's instructions. Those roles are set out in our Data Processing Addendum.
Privacy questions and requests: privacy@getsitesignal.io. Legal and procurement: legal@getsitesignal.io.
2.Data we collect
We collect three categories of data.
Account and identity data
Name, work email address, organization name, assigned role (Admin, Project Manager, Executive, Viewer), and account status. Passwords are stored only as salted hashes by our authentication provider; we never receive or store plaintext passwords.
Customer project data
The project records your team enters or imports: project names, contract values, budget line items, milestones and dates, subcontractor records, RFIs, change orders, risk assessments, recovery actions, and status reports. This is your data. We treat any personal data inside it (for example, a subcontractor contact email) as customer data processed on your behalf.
Operational and usage data
- Audit log entries recording who changed what record and when, including before and after values.
- Application and security logs, including IP address, timestamp, request path, and error diagnostics.
- Marketing site submissions: demo requests, including the contact and firm details you provide on the contact form.
We do not use third-party advertising trackers or sell behavioral profiles. We do not knowingly collect data from anyone under 18.
3.How we use data
We use data only for the following purposes:
- Providing the service — authenticating users, enforcing role permissions, storing and displaying your project records, and calculating risk scores.
- Communicating with you — risk escalation alerts, weekly status report delivery, invitations, and service notices sent to the addresses your admins configure.
- Security and abuse prevention — audit logging, rate limiting, and investigation of suspected unauthorized access.
- Support and troubleshooting — diagnosing issues you report, with access limited to personnel who need it.
- Service improvement — aggregate, de-identified usage measurements such as feature adoption counts. We do not use customer project data to train machine learning models.
- Sales and marketing — responding to demo requests you submit. We do not add users of a customer account to marketing lists without consent.
Where a legal basis is required (for example under GDPR), we rely on performance of a contract for service delivery, legitimate interests for security and product improvement, and consent for marketing communications.
4.AI processing
SiteSignal's risk narrative, recovery plan, and status report drafting features call the Anthropic API. This is how that works:
- What is sent: aggregated project metrics — budget totals and variance percentages, schedule completion percentages, milestone counts, open RFI counts, change order totals, and the project name and type.
- What is not intentionally sent: employee names, contact details, credentials, or attached documents. Free-text fields you type into a project (for example, a subcontractor note) may be included in context, so treat free-text fields as you would any field visible to the model.
- Retention at the provider: Anthropic processes API inputs to return a response and does not use business API inputs or outputs to train its models.
- Deterministic scoring: your Red/Yellow/Green risk score is computed by our own rules engine from your numbers. The AI layer adds narrative interpretation on top of that score; it does not set it.
- Human review: AI output is assistive. Every generated narrative, recovery plan, and status report is presented as a draft for your team to review before it is approved or sent.
If your organization cannot send project metrics to a third-party model provider, contact privacy@getsitesignal.io — AI features can be disabled at the organization level.
5.Subprocessors
We engage the following subprocessors to deliver the service. Each is bound by a written agreement with confidentiality and security obligations no less protective than those in our DPA.
| Subprocessor | Purpose | Data processed | Location |
|---|---|---|---|
| Supabase | Managed Postgres database, authentication, and storage | Account data and all customer project records | United States |
| Vercel | Application hosting, edge network, and request logging | Request metadata, IP addresses, and data in transit | United States |
| Resend | Transactional email delivery (alerts, reports, invitations) | Recipient email addresses and message contents | United States |
| Anthropic | AI risk narratives, recovery plan drafts, and status reports | Aggregated project metrics; no intentional PII | United States |
We will provide notice of new subprocessors to customers who subscribe to notifications at privacy@getsitesignal.io, and customers may object on reasonable data protection grounds as described in the DPA.
6.Retention
| Data | Retention |
|---|---|
| Customer project data | For the life of the subscription. Deleted or returned within 30 days of written request after termination. |
| Audit log entries | Retained for the life of the account so admins keep a complete change history. |
| Encrypted backups | Rolling 30-day window, then overwritten. |
| Application and security logs | Up to 90 days, then deleted. |
| Demo requests from the marketing site | Up to 24 months, or until you ask us to delete them. |
7.Security
Technical and organizational measures currently in place include TLS 1.3 in transit and AES-256 at rest, row-level security policies that isolate each organization's data at the database layer, server-side role enforcement on every request, immutable audit logging, least-privilege internal access, and encrypted backups. Optional organization-enforced multi-factor authentication is available in the application under Settings.
Our current certification posture and roadmap — including our SOC 2 timeline — is published honestly on the Security page. We do not claim certifications we have not completed.
Suspected vulnerabilities: security@getsitesignal.io.
8.Customer rights
Individuals may have rights to access, correct, delete, restrict, or port their personal data, and to object to certain processing. Because SiteSignal typically acts as a processor, we direct individual requests about project data to the customer organization that controls it, and we assist that organization in responding.
- Access and export: organization admins can export all organization records as CSV at any time from Settings, with no charge.
- Correction and deletion: admins can edit or remove records directly, and can deactivate users to revoke access immediately.
- Account deletion: email privacy@getsitesignal.io and we will delete or return organization data within 30 days.
- Complaints: you may lodge a complaint with your local supervisory authority. We ask that you contact us first so we can resolve it.
We do not sell personal information and do not share it for cross-context behavioral advertising, as those terms are defined under US state privacy laws.
9.International transfers
SiteSignal hosts customer data on United States infrastructure. If you access the service from outside the United States, your data is transferred to and processed in the US.
Where a transfer of personal data out of the European Economic Area, United Kingdom, or Switzerland is subject to applicable data protection law, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum where relevant), which are incorporated into our DPA, together with supplementary measures including encryption in transit and at rest.
10.Contact
SiteSignal LLC — privacy inquiries: privacy@getsitesignal.io
Legal, DPA, and procurement: legal@getsitesignal.io · Security disclosures: security@getsitesignal.io
A postal address for formal notices is available on request. We aim to acknowledge privacy requests within one business day and to resolve them within 30 days.
11.Changes to this policy
We will post any revision to this page and update the effective date above. For changes that materially reduce your rights or materially expand how we use personal data, we will give registered customer admins at least 30 days' notice by email before the change takes effect.
Superseded versions are retained and available on request for procurement or audit purposes.
Reviewing SiteSignal as a vendor? The Trust Center collects every document a security or procurement team typically asks for, and legal@getsitesignal.io will respond to questionnaires within one business day.
Related documents