Legal
Privacy Policy
Effective Date: July 27, 2026 · OpsBox
Your data belongs to you. OpsBox exists to help contractors run better operations — not to monetize your information. We store your data to power your tools, we use it to answer your Advisor questions, and we do nothing else with it. This policy explains exactly what we collect, how we use it, and what rights you have over it. OpsBox is not responsible for business decisions you make based on information within the platform, including AI Advisor responses. By using OpsBox, you agree that commercial communications we send will comply with the CAN-SPAM Act.
1. What We Collect
Information You Provide
- Account information — your name, email address, and company name when you sign up
- Project data — job names, addresses, budgets, draw schedules, punch lists, inspections, and any other project information you enter into OpsBox
- Vendor data — subcontractor names, contact information, insurance documents (COIs, W9s, Workers Comp), and compliance records
- Documents — bid PDFs, contracts, submittals, finish selections, and any other files you upload to OpsBox
- Team information — names and email addresses of team members you invite to your organization
- Communications — messages you send to our support team
Information Collected Automatically
- Usage analytics — which features you use, how often, and general interaction patterns. We use PostHog for this. It helps us understand what's working and what to build next.
- Session data — authentication tokens managed by Supabase to keep you logged in
- Security events — login attempts and other security-relevant actions are logged for incident response and abuse prevention
- Error data — when the application encounters an unexpected error, Sentry may capture technical error details (stack traces, browser environment) to help us diagnose and fix issues
2. How We Use Your Data
We use your data for one purpose: to operate OpsBox and make it work for your business.
- To power the OpsBox Advisor — when you ask the Advisor a question, we send relevant data from your organization to Anthropic's API to generate a response. Anthropic processes this query and returns an answer. For information on how Anthropic handles data submitted through their API, please review Anthropic's Privacy Policy at anthropic.com/privacy.
- To run your tools — your project data, vendor records, draw schedules, and documents are stored and organized so your team can access them
- To keep your account secure — we log security events and use rate limiting to protect your data from unauthorized access
- To improve OpsBox — aggregated, anonymized usage analytics help us understand which tools are most valuable and what to build next
- To process payments — we use Stripe to handle subscriptions. We never see or store your credit card details.
What we never do: We do not sell your data. We do not share your data with third parties for marketing or advertising. We do not use your project information, vendor data, or documents to train AI models. We do not run ads in OpsBox.
3. How the OpsBox Advisor Handles Your Data
The Advisor is powered by Anthropic's Claude API. When you ask a question, OpsBox sends relevant context from your organization — such as project details, vendor records, or document content — to Anthropic's servers to generate a response.
Your data travels to Anthropic's servers to process each Advisor query. For details on how Anthropic handles that data — including retention and training practices — please review Anthropic's Privacy Policy at anthropic.com/privacy. OpsBox makes no independent representations about Anthropic's data practices.
Important: The OpsBox Advisor provides information based on the data you've entered. Advisor responses may contain inaccuracies. Always verify contracts, financial information, legal documents, and specifications independently before relying on them. OpsBox is not a licensed contractor, attorney, or financial advisor.
4. Data Isolation and Access Controls
Every OpsBox organization is a completely isolated workspace. Your data is scoped to your organization and is inaccessible to other OpsBox customers — this is enforced at multiple layers of our infrastructure, not just application logic.
Within your organization, only users you have explicitly invited can access your data. You control who has access and can remove team members at any time from your Settings.
5. Data Security
- Encryption in transit — all data transmitted between your browser and OpsBox is encrypted using TLS (HTTPS)
- Encryption at rest — your data is stored in Supabase, which encrypts all data at rest using AES-256
- Authentication — OpsBox uses industry-standard password hashing. We never store plain text passwords.
- Rate limiting — API endpoints are rate limited to protect against abuse and unauthorized access attempts
- Security logging — important actions are logged for incident response and audit purposes
- Access verification — every request is verified against your organization membership before any data is returned
6. Third-Party Services
OpsBox uses a small number of trusted third-party services to operate. Each receives only the data necessary for their function:
- Supabase — database and authentication. Your structured data (projects, vendors, records) is stored here.
- Cloudflare R2 — file and document storage. Uploaded files, documents, and images are stored here. Cloudflare's privacy policy is available at cloudflare.com/privacypolicy.
- Anthropic — powers the OpsBox Advisor. Receives query context per request. See Anthropic's Privacy Policy at anthropic.com/privacy for details on how they handle submitted data.
- OpenAI — used for document embeddings (turning uploaded documents into searchable data). Receives document text.
- Stripe — payment processing. Receives billing information only. We never see your card details.
- Vercel — application hosting and deployment
- PostHog — product analytics. Receives anonymized usage data.
- Sentry — application error monitoring. Receives error reports and stack traces when the application encounters an unexpected error. No personal data beyond what is captured in the error context.
We do not use any advertising networks, data brokers, or marketing platforms that receive your personal or business information.
7. Data Retention and Deletion
Your data is yours. When you cancel your OpsBox subscription:
- Your subscription remains active until the end of your current billing period
- After that, your account enters read-only mode — you can still log in and view your data, but cannot create, edit, or delete records
- Your data is preserved indefinitely — we do not automatically delete it
- If you resubscribe at any time, full access is restored immediately with all your data intact
If you want your data permanently deleted, email us at support@opsboxapp.com and we will permanently delete all of your organization data — projects, vendors, documents, and team records — within 7 business days. Backup copies may persist for up to 30 additional days before being fully purged from backup systems.
You can request a full export of your data at any time by emailing support@opsboxapp.com.
8. Your Rights
- Access — you can view all data in your OpsBox account at any time
- Export — you can request a copy of your data by emailing support@opsboxapp.com and we will provide it within 5 business days
- Correction — you can edit or correct any information in your account
- Deletion — you can delete your account and all associated data at any time
- Portability — you can request your data in a portable format so you can transfer it to another service
9. Cookies
OpsBox uses a small number of cookies:
- Authentication cookies — set by Supabase to keep you logged in. These are essential and cannot be disabled.
- Analytics cookies — set by PostHog to track feature usage. These help us improve the product. You can opt out of PostHog tracking by contacting us.
- Error tracking — Sentry may set a session ID cookie to correlate errors within a single browser session. This is used solely for error diagnosis and does not track you across sites.
We do not use advertising cookies, retargeting cookies, or any cookies set by third-party marketing platforms.
10. Email Communications and CAN-SPAM Compliance
If we send you commercial email communications, each message will include:
- (a) our physical mailing address — 2519 South Shields St STE 1k PMB 1056, Fort Collins, CO 80526
- (b) a clear and conspicuous notice that the message is a commercial advertisement
- (c) a working opt-out mechanism
You may opt out of commercial emails at any time by clicking the unsubscribe link in any commercial email or by visiting https://www.opsboxapp.com/unsubscribe. We will process your opt-out within 10 business days.
Transactional emails (billing confirmations, password resets, security alerts, account notifications) are not subject to opt-out as they are required to operate your account.
We do not send your email address to third-party marketing platforms or advertising networks.
11. Children's Privacy
OpsBox is a professional business tool intended exclusively for adults operating construction businesses. We do not knowingly collect personal information from anyone under the age of 18, and we do not permit account creation by anyone under 18.
In compliance with the Children's Online Privacy Protection Act (COPPA), we do not knowingly collect any information from children under the age of 13. If we discover that a user is under 13, we will immediately delete their account and all associated data. If you believe a child under 13 has provided us with personal information, please contact us immediately at support@opsboxapp.com.
12. Data Breach Notification
In the event of a security breach that affects your personal information, we will notify you by email within 72 hours of becoming aware of the breach, to the extent reasonably practicable. The notification will describe the nature of the breach, the data affected, and the steps we are taking to address it. We will cooperate with relevant authorities as required by applicable law.
14. Do Not Sell or Share My Personal Information
OpsBox does not sell your personal information and never will. We do not share your personal information with third parties for cross-context behavioral advertising or targeted advertising purposes.
If you use a browser or device that sends a Global Privacy Control (GPC) signal, we will treat that as a valid opt-out of any sale or sharing of your personal information for targeted advertising. Our analytics provider (PostHog) is configured to respect GPC signals.
To explicitly opt out or to request confirmation that your data is not being sold or shared, email support@opsboxapp.com. We will confirm within 15 business days.
15. US Privacy Rights
Regardless of what state you live in, OpsBox treats your data the same way. We do not sell your personal information. We do not share it for targeted advertising. We do not use it for cross-context behavioral advertising.
As a user of OpsBox, you have the following rights with respect to your personal information:
- Right to know — you can request confirmation of what personal information we hold about you and how we use it
- Right to access — you can request a copy of the personal information we hold about you
- Right to correct — you can request that we correct inaccurate personal information we hold about you
- Right to delete — you can request that we delete your personal information. See Section 7 for details on how deletion works.
- Right to portability — you can request a copy of your data in a portable format by contacting us at support@opsboxapp.com
- Right to opt out of sale or sharing — we do not sell or share your personal information for advertising purposes, and we confirm we never will
- Right to non-discrimination — we will never treat you differently or provide a lower quality of service because you exercised any of these rights
To exercise any of these rights, email us at support@opsboxapp.com. We will respond within 30 days. We do not charge a fee for these requests.
We will need to verify your identity before processing requests related to your personal information. If you submit a request, we will use the information provided solely to verify your identity and fulfill the request.
16. International Users and GDPR
OpsBox is designed for US-based construction businesses. We do not actively market to or seek customers outside the United States. If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, please be aware of the following:
- Your data will be transferred to and processed in the United States, which may not provide the same level of data protection as your home jurisdiction
- Our legal basis for processing your personal data is performance of a contract (providing the OpsBox service you have requested)
- You have rights under GDPR including the right to access, correct, delete, and port your data — contact support@opsboxapp.com to exercise these rights
- You have the right to lodge a complaint with your local supervisory authority
Enterprise customers requiring a Data Processing Addendum (DPA) may request one by emailing support@opsboxapp.com.
17. Changes to This Policy
If we make material changes to this Privacy Policy, we will notify you via email at least 14 days before the changes take effect. We will never retroactively change how we handle data you've already provided without your explicit consent.