Legal

Privacy policy

Draft (counsel review pending).

This is a complete working draft of our Privacy policy, authored ahead of outside counsel review (spec 54). It reflects how PipeTakeoff.com actually handles data, but it has not yet been approved by an attorney; the counsel-final version will replace it before any paid customer signs up.

Who we are and what this covers

PipeTakeoff.com is operated by TGC Works LLC, a Wyoming limited liability company ("PipeTakeoff," "we"). This policy describes how we handle personal data when you visit our website or use the PipeTakeoff.com service (the "Service").

The Service is business software. For the content your organization uploads (drawings, extracted BOM data, quotes), your organization controls the data and we process it on the organization's behalf under our Terms of service and, where signed, a data processing agreement. For account, billing, and website data, we determine how processing happens as described here.

What we collect

  • Account data, stored first-party in our database (Neon Postgres, US-East): name, email address, sign-in credentials (passwords stored only as salted scrypt hashes), sign-in method, and organization membership.
  • Content your organization uploads: PDF drawings stored in Cloudflare R2 (United States); extracted and edited BOM rows, projects, catalogs, and quotes in a Neon Postgres cluster (US-East). Uploaded drawings may incidentally contain personal data, such as names on title blocks; your organization is responsible for having the rights to upload them.
  • Audit records: an immutable log of compliance-relevant actions (who committed a BOM, who reviewed a quote, when, and what changed), plus Terms-acceptance records (accepted version, timestamp, IP address, and browser user agent).
  • Billing data, via Stripe: subscription state and invoice history. Card numbers never touch our servers.
  • Product analytics, via PostHog: pageviews and feature-usage events keyed to pseudonymous user and organization identifiers. Email addresses are never sent to PostHog; session recording is disabled; automatic capture of clicks and form interactions is off. In the EEA, UK, and Switzerland, none of this runs until you consent; see "Cookies and analytics choices" below.
  • Operational logs and security data: request logs (IP address, user agent, path) at our hosting providers, error reports and application logs with personal data scrubbed before sending, and rate-limit counters keyed by organization identifier and IP address.
  • Correspondence: emails you send to our support, legal, privacy, or abuse addresses.

We do not collect special categories of personal data and the Service is not directed to children.

How we use it

  • To provide the Service: render extractions, surface BOM rows, aggregate projects, run RFQ and quote workflows, and deliver transactional email (invitations, payment notices, extraction results).
  • To secure and operate the Service: authentication, tenant isolation, rate limiting, abuse prevention, debugging, and incident response. Internal access to customer content is role-gated and audited.
  • To bill you, via Stripe.
  • To understand product usage in aggregate and improve the product, using the pseudonymous analytics described above.
  • To meet legal obligations and to establish or defend legal claims; the audit log exists in part to evidence that required human review of extractions occurred.

AI processing: pages of uploaded drawings are sent to Anthropic to perform extraction. We do not train AI models on your data, and Anthropic's commercial API terms prohibit training on it; Anthropic retains extraction inputs only for a limited period under those terms.

Aggregated statistics: we compute de-identified, aggregated statistics across customers (for example, material-price benchmarks), only where a minimum number of distinct organizations contribute to each statistic. These never include drawings and never identify you, your vendors, or your projects.

Cookies and analytics choices

Strictly necessary cookies (your sign-in session, the Terms-acceptance record, and the cookie that stores your analytics choice itself) are set on every visit and cannot be turned off, because the Service does not function without them. We set no advertising cookies and no third-party tracking pixels of any kind.

The one non-essential cookie is PostHog product analytics, described above. How it is handled depends on where you are:

  • European Economic Area, United Kingdom, and Switzerland: analytics does not run until you accept. We ask once, with a banner offering Accept and Decline as equally prominent choices, and nothing analytics-related is loaded or set before you answer. Declining is remembered and never re-prompts you within the same six-month window.
  • Elsewhere: analytics runs by default as described in this policy, and you can opt out at any time by enabling Global Privacy Control in your browser.
  • Global Privacy Control: we honour the GPC signal everywhere, not only in jurisdictions that legally require it. If your browser sends GPC, analytics never initializes and you are never shown the consent banner.

Your choice is stored in a first-party cookie for six months, after which we ask again rather than assume the answer still holds.

How we share it

We do not sell personal data and we do not share customer drawings or BOM data with third parties, except:

  • Subprocessors that operate the Service on our behalf, listed with purposes and data categories at /legal/subprocessors. Organization administrators receive 30 days' notice before a new subprocessor is added.
  • Vendors your organization invites: when your organization sends an RFQ, the vendor sees the RFQ content your organization chose to send.
  • Legal reasons: where required by law or legal process, or to protect the rights, safety, or property of PipeTakeoff, our customers, or the public.
  • Corporate transactions: in a merger, acquisition, or asset sale, data may transfer to the successor under this policy's protections.

Data retention

We keep account and content data while your organization's account is active. Audit logs are retained for a minimum of seven years, reflecting construction-industry record-retention norms. Vendor-side windows (error reports, application logs, analytics) are enforced by each vendor on the plan we use. Our published retention schedule, maintained for auditors and privacy reviewers, is the authoritative reference for each data class and its window.

Security

Data is encrypted in transit and at rest. Tenant isolation is enforced at both the application and database layers, access is role-based and audited, and the audit log is insert-only and tamper-evident. Details, including our incident-notification commitment (72 hours after a confirmed breach affecting your data), are published at /security.

Your controls

You can export every committed BOM in xlsx or csv format at any time. You can delete an organization from the settings panel; its database records (projects, extraction data, BOM rows, and audit history) are permanently deleted immediately, and an automated cleanup purges its uploaded files from object storage. Residual copies in backups expire on the schedule published in our retention documentation.

To access, correct, export, or delete personal data we hold about you, email privacy@pipetakeoff.com. If your request concerns content controlled by an organization you belong to (for example, data inside a workspace), we may route the request to that organization's administrators, and we will assist them in responding.

Where data lives

We are a United States company and process data in the United States, using the providers listed at /legal/subprocessors. If you access the Service from outside the United States, you understand your data is processed in the United States.

How we review this policy

We review this policy, and the tracking and data-handling technologies it describes, at least annually and additionally whenever any of the following happens: we add or remove a subprocessor, we change what the Service collects or how long it is kept, we introduce or alter any analytics or tracking technology, or a privacy law that applies to us changes materially.

Each review checks that every technology in use is still accurately described here, still has a lawful basis, and still matches the consent behaviour described under "Cookies and analytics choices." Reviews are recorded with a date and an owner alongside our security review records, so the review history is auditable rather than asserted. The owner of this review is the founder until a privacy lead is hired.

Changes to this policy

We will post changes to this page and, for material changes, notify organization administrators by email at least 30 days in advance. The date of the current version appears on this page once the counsel-final version is published.

Contact

Privacy questions? Email privacy@pipetakeoff.com.