Privacy Policy
Effective July 27, 2026
1. Scope of This Policy
This Privacy Policy describes the practices of Bow Construction ("Provider," "we," "us," or "our") with respect to information collected, received, processed, stored, transmitted, or otherwise handled in connection with BowtieOS and any related websites, applications, interfaces, and services (collectively, the "Service"). It applies to all persons who access or use the Service in any capacity, including administrators, office personnel, field personnel, subcontractors, viewers, and recipients of documents generated through the Service.
The Service is business software provided to organizations (each, a "Customer"). Your account is created and administered by a Customer, which determines what data is entered into its workspace, which features are enabled, and which integrations are connected. As between Provider and Customer, the Customer is, for most purposes, the controller of the data in its workspace, and Provider processes such data on the Customer's behalf and instruction. To the extent any practice of the Service is not expressly described in this Policy, Provider may collect, use, and disclose information as reasonably necessary to provide, secure, maintain, and improve the Service and as otherwise permitted by applicable law.
2. Information We Collect
We collect information in the following general categories, in each case including, without limitation, the examples given:
- Information provided to the Service. Any information that you, your organization, or any other user enters into, uploads to, imports into, or otherwise makes available through the Service, including account and profile information (such as name, email address, and telephone number); operational and project records (such as site visits, measurements, dimensions, photographs, video, audio and voice notes, drawings, markups, documents, estimates, proposals, invoices, schedules, tasks, time and attendance records, check-ins, comments, and communications); client, vendor, and contact records; and any other information a user chooses to provide.
- Information collected automatically. Technical and usage information generated in the course of operating the Service, including request metadata (such as IP address, browser and device characteristics, and pages accessed), authentication and session records, notification tokens, audit and activity logs, and diagnostic and error information.
- Location information. Where the Customer enables location features, geolocation data relating to persons, devices, and vehicles, as further described in Section 3.
- Electronic-signature records.Where a document is executed through the Service, the signer's name, signature, date and time, the consent and disclosure text presented, and technical details of the submission (including IP address and browser information), retained as evidence of execution.
- Information from third parties. Information received from integrations, services, and data sources that the Customer or a user connects or directs (such as accounting, payroll, vehicle-tracking, file-storage, calendar, and mapping services), including credentials required to operate them (provider secrets are encrypted before storage).
The Service does not use third-party advertising trackers, tracking pixels, session recording, or behavioral advertising.
3. Location Data
The Service includes optional location functionality, which is disabled by default and activated only by the Customer. Where activated, the Service may collect geolocation data by any means the Customer configures, including, without limitation: (a) tracking applications installed on devices (reporting position, speed, heading, accuracy, and battery level); (b) vehicle telematics providers connected using the Customer's credentials; and (c) clock-in/out positions supplied by a connected payroll provider.
Employee-linked positions are displayed to the Customer's office and administrative personnel only, and only for periods within the employee's scheduled working hours (a restriction enforced at the database layer); positions of unassigned vehicles may be displayed without that restriction. A reporting device or vehicle tracker may record and transmit positions whenever it is powered on and reporting, including outside working hours, notwithstanding that the Service displays employee positions only within working hours. Raw position reports are automatically deleted after 90 days; derived summaries are computed exclusively from working-hours positions.
The decision to enable location functionality, and responsibility for providing all legally required notices and obtaining all legally required consents from affected individuals prior to enablement, rests solely with the Customer, as required by our Terms of Service. Questions concerning a Customer's use of location features should be directed to the Customer's administrator.
4. How We Use Information
We may use information described in this Policy for any legitimate business purpose consistent with providing the Service, including, without limitation: to provide, operate, maintain, secure, support, and improve the Service; to authenticate users and enforce access controls; to transmit notifications and communications relating to the Service; to respond to inquiries and support requests (support submissions may be processed with the assistance of automated and AI-based tools); to generate, store, and preserve records the Service is designed to produce (including signature-evidence records); to monitor for, prevent, and address technical, security, and fraud issues; to comply with legal obligations and enforce our agreements; and for any other purpose disclosed to the Customer or directed by the Customer.
We do not sell personal information, do not use Customer workspace data for advertising, do not share information with third parties for their own independent commercial purposes, and do not use Customer workspace data to train artificial intelligence models.
5. Storage, Security & Backups
Customer workspace data is stored with our hosting providers in the United States (primary storage in the us-west-2 (Oregon) region). Access is restricted by role-based, row-level security controls, and data is encrypted in transit and at rest. Files are stored in private, per-Customer storage locations and served through short-lived signed URLs, subject to two exceptions: images published in the shared help center (product documentation, never Customer data), and documents the Customer elects to share by link, which are accessible to any holder of the link.
For disaster-recovery purposes we maintain an off-site backup process that encrypts a copy of the database and stored files (AES-256, encrypted before leaving our systems) and writes it to Cloudflare R2 object storage by a scheduled job executed on GitHub Actions, retained for 30 days and then deleted. Backup copies accordingly reside outside the primary storage region. No security measure is infallible, and we do not warrant that security measures will be effective in all circumstances.
6. Disclosure of Information
We may disclose information described in this Policy: (a) within the Customer's workspace, in accordance with the role-based permissions the Service enforces (financial and pricing data is restricted to office and administrative roles); (b) to the service providers and subprocessors described in Section 7, for the purposes described there; (c) to recipients the Customer or its users direct, including integrations, webhook endpoints, API applications, calendar services, and holders of shared links; (d) to our personnel and professional advisors, to the extent reasonably required to operate, secure, and support the Service, to investigate reported issues, or to obtain professional advice; (e) in connection with an actual or contemplated merger, acquisition, financing, reorganization, or sale of all or part of the business, subject to customary confidentiality protections; (f) as required or permitted by law, regulation, subpoena, court order, or governmental request, or to establish, exercise, or defend legal claims, or to protect the rights, property, safety, or security of the Service, our users, or the public; and (g) with the consent or at the direction of the Customer.
Where lawful and practicable, we will notify the Customer's administrator before disclosing Customer workspace data in response to legal process. If we become aware of a security breach affecting Customer workspace data, we will notify the affected Customer's administrator without undue delay, consistent with applicable law and the legitimate needs of law enforcement, and will reasonably cooperate with the Customer's own notification obligations.
7. Service Providers & Subprocessors
We use third-party service providers to operate the Service. The categories of data each may receive include, without limitation, the following (providers marked "optional" are engaged only when the Customer or a user enables the related functionality):
| Service | Purpose | Data shared |
|---|---|---|
| Supabase | Database, storage & authentication | All Customer workspace data |
| Vercel | Application hosting | Request metadata (IP, headers) |
| Cloudflare (R2) | Encrypted off-site backup storage | Encrypted copies of all Customer workspace data and stored files (Cloudflare holds no decryption key) |
| GitHub (Actions) | Executes the scheduled backup job | All Customer workspace data, transiently, while each backup is created and encrypted |
| Resend | Transactional email | Recipient addresses, message content, and attached documents |
| Email delivery (SMTP) | Account & credential email | Recipient address and initial sign-in credentials |
| Stripe | Subscription billing (optional) | Company name, billing contact, subscription & payment metadata |
| Intuit QuickBooks | Accounting sync (optional) | Clients, projects, vendors, and invoice/bill/payment records |
| Fingercheck / Friday | Payroll hours import (optional) | Credentials, date ranges, and job/task codes and descriptions (employee pay and SSN are neither sent nor retained) |
| Samsara / Bouncie | Vehicle telematics (optional) | Customer credentials and position queries; positions received in return (Section 3) |
| Calendar providers (Google / Apple / Microsoft) | Schedule subscription or calendar sync (optional, per user) | The subscribing user's schedule (job titles, site addresses, notes; never pricing or financial data) |
| Anthropic Claude | Support-request analysis & help-content drafting | Support-request text, page URL, and device context; help-article source content |
| Dropbox | User-directed file import (optional) | The selected file and a temporary download link |
| OpenStreetMap & Photon | Maps & address autocomplete (default map stack) | Typed addresses; map requests from the user's browser (revealing IP) |
| Google Maps Platform | Maps, geocoding & routing (optional) | Typed and stored addresses, place details, routes, and map display requests |
| jsdelivr & unpkg (CDNs) | Delivery of in-browser processing code | No Customer data; the browser reveals its IP and referring page when fetching code |
| Web push (Apple / Google / Mozilla) | Notification delivery (optional) | Notification content and a device push token |
| Sentry | Error monitoring (when enabled) | Error details and browser context, after scrubbing of emails, tokens, and keys |
Core infrastructure (hosting, the default map stack, code delivery, and support-request processing) operates for all Customers; the remaining providers are engaged only upon enablement of the related feature. We may add, remove, or replace service providers from time to time, and will update this Policy accordingly. Recipients to which the Customer or its users direct data — including integrations, webhook endpoints, API applications, and calendar subscriptions — act on the Customer's instruction, and the Customer is responsible for them; internal cost and margin fields are stripped from financial records before transmission to Customer-directed recipients.
8. Retention
We retain information for as long as reasonably necessary for the purposes described in this Policy, including, without limitation: Customer workspace data for the duration of the Customer's subscription and for a wind-down period of 90 days thereafter to permit export, after which it is deleted; raw location reports for 90 days (Section 3); signature-evidence records for as long as the executed document exists; and encrypted backups, as described in Section 5, for 30 days on a rolling basis (deleted data may persist within a backup until that backup expires). We may retain information longer where required by law or reasonably necessary to resolve disputes, enforce agreements, or maintain security, and the Customer may request earlier deletion.
9. Your Rights
Depending on your jurisdiction, you may have rights with respect to your personal information, including rights of access, correction, deletion, and portability. Because the Customer controls its workspace, requests by individual users are ordinarily routed through the Customer's administrator; where that is not practicable, you may contact us directly and we will coordinate with the Customer. We will honor requests to the extent required by applicable law, respond within the time the law prescribes (and in any event endeavor to respond within 30 days), and will not discriminate against any person for exercising a legal right.
10. Changes to This Policy
We may revise this Policy from time to time, including to reflect changes in the Service, our providers, or applicable law. Material changes will be notified to the Customer's administrator before taking effect, and the effective date above will be updated. Continued use of the Service after the effective date constitutes acceptance of the revised Policy to the extent permitted by law.
11. Contact
Privacy inquiries and data requests may be directed to support@bowtie.app.