Confidentialité (FR) · Conditions (FR)

Effective October 5, 2026

Privacy Policy

Effective date: October 5, 2026 · Operator: GridReader (“we”, “us”) · Contact: support@gridreader.com · Privacy: support@gridreader.com

This policy explains what personal information GridReader collects, why, who we share it with, and the choices you have. It applies to gridreader.com, app.gridreader.com and api.gridreader.com.

We designed this policy for Canadian law (PIPEDA and Alberta’s Personal Information Protection Act — PIPA) and for US users under state privacy laws such as the California Consumer Privacy Act as amended by the CPRA (“CCPA/CPRA”). Where Quebec’s Law 25 applies to individuals in Quebec, we aim to meet its core expectations described below. Plain-language promise: we collect the minimum needed to run the service, we never sell your personal information, and we never see your card numbers.

1. Accountability and privacy contact

GridReader is accountable for personal information under its control. The person in charge of the protection of personal information (Privacy Officer) is published as: Privacy Officer, GridReader — support@gridreader.com. Email that address for privacy questions, access, correction, deletion, portability, or complaints. That role covers PIPEDA / Alberta PIPA and Quebec Law 25 (personne responsable de la protection des renseignements personnels). We respond to access and similar requests within 30 days where those laws require it (or sooner when we can).

Français (Québec) : Politique de confidentialité — the complete French version, shown first to customers in Quebec. For customers in Quebec, if the French and English versions differ, the French version governs.

2. What we collect (categories)

Depending on how you use the service, we may collect:

  • Identifiers and account information — name, email, company name, phone you provide, and (if you use Google sign-in) Google profile name and email. Passwords are stored only as salted hashes.
  • Commercial and business records — jobs, quotes, invoices, clients’ names, addresses and contacts your team enters, crew profiles (including a profile photo and working days, hours and availability if you add them), time entries, crew payment records (pay rates, payouts and the lien waivers your crews sign), site photos, purchase orders, and similar records.
  • Location — only where a feature needs it: when a crew member clocks in or out with location turned on, the device’s GPS position at that moment (used to check it against the job-site area the office set); when a client signs off work on the crew’s device, the position at signing; and the job-site pin the office places on a map. We do not track location in the background.
  • Signatures — when a client signs off work or a document on a crew member’s device, the drawn signature image, the name typed, and the time and position of signing.
  • Customer content / drawings — PDF drawing sets you upload, measurements and takeoff results, and notes or corrections you add.
  • Payment-related information — Stripe customer/subscription identifiers, invoice and pay-link status. Card numbers are entered on Stripe’s pages and never touch GridReader servers.
  • Internet / technical information — sign-in session records (device and approximate sign-in details under Settings → My account → “Where you’re signed in”), IP-related security logs, rate-limiting data, and service logs.
  • Communications — emails with us, and emails we send through Resend. If bid-inbound email is enabled, each account gets a private forwarding address; mail to it is stored for that account.
  • Inferences / product use — feature use needed to operate metering, security and support (not advertising profiles).
  • Address lookups and weather — when you type a job-site address, the text you type is sent to our address-lookup provider (Geoapify) to suggest matches. The job calendar asks the Norwegian Meteorological Institute (MET Norway) for a forecast straight from your browser, using the job city’s approximate coordinates; like any website, MET Norway receives your IP address with that request.
  • Agreement records — when you create an account or start or change a plan, the version of the Terms, Privacy Policy or renewal notice you agreed to, the language it was shown in, and the time and IP address.
  • Push tokens — only if you opt in; removing the subscription deletes the token.
  • Referral codes — if you use the referral program, the code linking accounts and whether a referral was credited.

3. What we do NOT collect

  • Card numbers or full payment credentials (Stripe hosted checkout).
  • Advertising, analytics or cross-site tracking cookies. We set no ad or analytics cookies.
  • We do not knowingly collect personal information from anyone under 18 (see Children / COPPA).

4. Purposes and consent

We use personal information to:

  • Provide the service (accounts, takeoffs, quotes, invoices, crew and related tools);
  • Authenticate, secure accounts, prevent fraud and abuse;
  • Bill plans and top-ups through Stripe, including dunning;
  • Send transactional email; send promotional email only with consent (CASL / CAN-SPAM);
  • Improve reliability using aggregated or account-scoped operational data;
  • Meet legal and accounting obligations.

Under PIPEDA / Alberta PIPA, we rely on consent you give when you create an account and use the service, and on purposes a reasonable person would consider appropriate. You may withdraw consent where the law allows (which may limit features). For US state laws, we process personal information to provide the business services you request, for security, and as otherwise described here.

5. How your blueprints are processed (AI disclosure)

To read a drawing set we send PDF contents to AI processing providers solely to produce your takeoff. We use uploads to provide the service you asked for, not to advertise. Customer PDFs are not used to train AI models. Uploaded PDFs are kept for about 14 days so a set can be re-read; the page images the app cuts from them (black-and-white crops of each unit plan) stay with the job. Corrections you make on your account are saved and may be reused to improve results on your company’s later jobs. We also keep a log of the automatic fixes the reader made to each drawing (geometry and numbers only — no client names, addresses, drawing text or images), linked to your account, and count it across accounts to find and fix mistakes in our own measuring rules. That log is not shown to other customers, not used to train AI models, and is deleted with your account data. Automatically generated measurements can be wrong; they are working numbers to check, not certified quantities (see Terms §5).

6. Service providers and subprocessors

We share personal information only with providers needed to run the service, under contracts that require appropriate protection. Categories include: payments (Stripe); email delivery (Resend); AI processing providers (automated reading of content you upload — we do not name individual AI vendors here); identity (Google sign-in, profile/email scopes only); hosting, database and file storage (Render, Vercel, MongoDB Atlas, Cloudflare R2); address lookup (Geoapify); weather forecasts (MET Norway, called from your browser); and, only if we switch it on, text recognition for scanned pages (Amazon Web Services, Canada region).

For a current list of subprocessors in these categories, email support@gridreader.com. We may update providers over time; this policy describes the categories rather than promising a public live directory (which we do not currently publish as a product page).

We also disclose information if the law requires it, or to protect GridReader, our users, or the public. We do not sell personal information and do not share it for cross-context behavioural advertising.

7. Cross-border processing

Several of our key providers host data in the United States, and personal information may be processed in the United States and other countries where our providers operate. When information leaves Canada, it may be subject to the laws of that country, including lawful access by foreign authorities. For personal information about people in Quebec, before communicating it outside Quebec we assess, for each provider, the sensitivity of the information, the purposes, the safeguards in our agreement with the provider and the legal framework where it is processed (Quebec Law 25, s.17), and we document those assessments internally. Contact us if you need more detail for your organisation’s own assessment.

8. Retention and deletion

  • Uploaded source PDFs are kept so you can re-read a set and are deleted about 14 days after upload. The page images cut from them, the takeoff results and the rest of the job stay until you delete the job or close your account.
  • Deleted jobs go to “Recently deleted” for 14 days so you can bring them back; after that they are deleted, with their photos and files.
  • Account closure is started from Settings → Your data and takes effect after 14 days unless you undo it. When the account closes, billing stops and everyone is signed out. 90 days after closing, we delete the account’s data — jobs, drawings, takeoffs, quotes, invoices, clients, crew records, photos and files — and the team members’ logins.
  • We keep billing and tax records (our invoices and payments, closing invoices, plan changes, and the agreement records described in §2) and a minimal record of the account owner (name, email, company and payment-provider customer id) for 6 years after the end of the year they relate to, as tax law requires, and then delete them.
  • Records about security incidents are kept as the law requires (see §9).

9. Safeguards and security incidents

Safeguards include hashed passwords (PBKDF2), httpOnly session cookies, TLS in transit, per-account isolation, upload checks, rate limiting, signed payment webhooks, least-privilege staff access, and an admin audit log. No system is perfect.

If an incident involving personal information creates a real risk of significant harm, we notify the Office of the Information and Privacy Commissioner of Alberta without unreasonable delay (Alberta PIPA s.34.1) and the affected individuals as that office directs; we also report to the Office of the Privacy Commissioner of Canada and notify affected individuals where PIPEDA applies, and, for people in Quebec, we notify the Commission d’accès à l’information and the people concerned when an incident presents a risk of serious injury (Quebec Law 25). US breach-notification duties may also apply depending on the residents affected. We keep a register of incidents (24 months under PIPEDA; 5 years for Quebec). Report suspected incidents to support@gridreader.com.

10. Cookies and local storage

The main sign-in cookie is gl_session (httpOnly, Secure, 30 days or until sign-out). During Google sign-in we briefly set two short-lived cookies: an OAuth state cookie, and one recording which language the Terms were shown in. Platform staff may use short-lived admin “view as” cookies. The app uses browser local storage for preferences (for example theme). All of these are needed for the service to work; we use no analytics or advertising cookies and no third-party trackers.

11. Your clients’, crews’ and suppliers’ data

When you enter information about your clients, crews or suppliers (including crew locations, hours, pay and lien waivers, and client signatures), your business decides what is collected and why and is responsible for it under privacy law — including telling those people and getting any consent required. We act as your service provider: we process that information only to provide the service to you, on your instructions and under this policy, and we do not use it for our own marketing. Requests from those people go to you; we will help you answer them.

GridReader is not a party to contracts, orders, sales, deliveries, payments, warranties or disputes between you and your clients, or between you and suppliers or vendors (including marketplace purchase orders).

12. Your rights — Canada (PIPEDA / Alberta PIPA / Quebec Law 25)

  • Access personal information we hold about you (within 30 days where required);
  • Correct it (much of it in Settings → My account → Profile);
  • Withdraw consent — sign out devices (Settings → My account), unsubscribe from promotional email, disable push, or close your account (Settings → Your data);
  • Complain to us first at support@gridreader.com; then to the OPC (priv.gc.ca), Alberta OIPC, or the Commission d’accès à l’information du Québec as applicable.

12b. Data portability and automated processing

You may download your business records in a structured, commonly used format from Settings → Your data (spreadsheet zip / CSV, and a technical backup file). That supports Quebec Law 25 portability for information you provided.

Takeoff measurements are produced with automated (including AI-assisted) processing of drawings you upload. They are tools to assist a qualified person — not solely automated decisions that produce legal effects about you without human involvement. You can correct measurements in the app. See Terms §5.

13. Your rights — United States (CCPA/CPRA and similar state laws)

If you are a resident of California or another US state with a comprehensive privacy law, you may have rights to know/access, delete, correct, and opt out of “sale” or “sharing” of personal information, and to non-discrimination for exercising those rights.

We do not sell personal information and we do not share it for cross-context behavioural advertising. There is nothing to opt out of under a “Do Not Sell or Share My Personal Information” request today; if that ever changes we will update this policy and provide a clear opt-out. To exercise know, delete or correct rights, email support@gridreader.com from your account address. We will verify the request and will not discriminate against you for exercising privacy rights. Some state laws also recognise authorised agents; we will follow the verification rules that apply.

Categories collected in the last 12 months match Section 2. We disclose them to service providers for the business purposes in Sections 4–6. We do not use sensitive personal information for the purpose of inferring characteristics about you beyond what is needed to run your account.

14. CASL and CAN-SPAM

We send promotional email only to people who agreed to receive it or where Canada’s Anti-Spam Legislation (CASL) otherwise allows. Each promotional email identifies GridReader, includes our contact information and mailing address, and has an unsubscribe link; unsubscribes take effect promptly and in any event within 10 business days, as CASL and US CAN-SPAM require. Transactional messages (security, billing, renewal reminders, service notices) are not promotional.

15. Children (COPPA and similar)

GridReader is a business tool for contractors. We do not knowingly collect personal information from anyone under 18, and we do not direct the service to children under 13 (COPPA). Accounts found to belong to minors are closed.

16. Copyright complaints

If you believe content on the service infringes your copyright, email support@gridreader.com with enough detail to locate the material and a statement of your rights. We will review DMCA-style notices in good faith.

17. Changes

Material changes will be announced by email and in-app notice at least 30 days before they take effect, and we will update the effective date above.

18. Contact

GridReader · support@gridreader.com · Privacy: support@gridreader.com

See also our Terms of Service · Confidentialité (FR) · Conditions (FR).