How we collect, use, and protect your information when you use Opsite.
Effective Date: September 10, 2026
Opsite Solutions LLC ("Opsite," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our construction project management platform at useopsite.com and related services (the "Service").
By using our Service, you consent to the data practices described in this Privacy Policy. If you do not agree with the practices described in this Privacy Policy, please do not use the Service.
We collect information you provide directly, including:
When you use the Service, we automatically collect:
We may receive information from third-party services you connect:
If you opt in to SMS notifications from Opsite via our public opt-in form at useopsite.com/sms-opt-in, we process your phone number, message body, and delivery status solely to operate the messaging service and to honor opt-out requests. All SMS messages are sent from the Opsite brand and identify Opsite as the sender. STOP, UNSUBSCRIBE, QUIT, and END are honored as opt-out keywords; HELP returns a help response. Mobile information will not be shared with third parties or affiliates for marketing or promotional purposes. SMS consent is voluntary, is not required to create or use an Opsite account, and can be revoked at any time by replying STOP or emailing privacy@useopsite.com. See Section 15 below for the full SMS communications and consent disclosure.
When a contractor using Opsite enables the time-clock feature for its employees, Opsite collects the employee's device latitude, longitude, and accuracy at clock-in, at clock-out, and at periodic intervals during the shift while clocked in ("location pings"). This data is collected on behalf of and under the instruction of the contractor (the employer), who is the controller of the data for purposes of GDPR and the business for purposes of CCPA. Opsite acts as a service provider/processor. Contractors are responsible for providing the notices required by applicable law to their employees before enabling this feature, including (where applicable) under Cal. Penal Code § 637.7, Cal. Civ. Code § 1798.100(b), 820 ILCS 55, Conn. Gen. Stat. § 31-48d, and N.Y. Civ. Rights Law § 52-c. A model employee-monitoring notice is available at app.useopsite.com/legal/employee-monitoring-notice.
Opsite's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Your choice and account identity: Google integrations are optional. Each user connects their own Google account and grants the requested permissions. We use your Google account identifier and email address to identify the connected account; Google sign-in may also provide your name.
Google Calendar: With your permission, Opsite reads calendar event details, including titles, descriptions, dates and times, locations, and attendee details, to display and synchronize schedules. Opsite can create, update, and delete linked calendar events as you manage scheduling in Opsite.
Google Tasks: When you enable Tasks sync, you choose which Opsite projects to include. Opsite creates a Google task list for each selected project and sends tasks assigned to you, including their titles, descriptions, due dates, completion status, company and project names, and links back to Opsite. Opsite reads task-list identifiers and titles to find its project lists, and reads tasks in those lists to synchronize linked work and avoid duplicates. These responses can include task titles, notes, dates, status, and deletion indicators. Unrelated personal Google tasks are not imported as Opsite tasks.
Task changes and removal: Opsite creates and updates linked Google tasks and synchronizes completion and reopening in both directions. When a project is deselected, access is lost, or an assignment changes, Opsite removes the affected linked Google copies during a successful sync while the connection remains authorized. Deleting a Google copy stops that copy from syncing; it does not delete the original Opsite task. This functionality requires read and write access to Google Tasks; read-only access cannot create, update, or remove the linked copies.
Use and sharing: Google user data is used only to provide the connected account, calendar, and task-sync features you choose and that are visible in Opsite. Google user data includes information received from Google APIs and any data derived, aggregated, or anonymized from it. We do not sell this data or use or transfer it for advertising, marketing, unrelated analytics or research, creditworthiness or lending decisions, or to develop, train, fine-tune, or improve AI or machine-learning models. Anonymizing or aggregating Google user data does not remove these restrictions. These Google-specific restrictions take precedence over every other section of this policy, including the sections on service improvement, AI, sharing, business transfers, and retention.
Permitted transfers: We share Google user data with our hosting and database providers, Vercel and Supabase, only as necessary to operate the Google-connected features you authorize. Other transfers are limited to security needs, applicable legal requirements, or a merger, acquisition, or sale of assets after obtaining your explicit prior consent. We do not transfer Google user data to advertising platforms, data brokers, or information resellers. A general consent to this policy does not authorize otherwise prohibited uses or transfers.
Human access: Our personnel may access Google user data only with your affirmative agreement to access specific data, when necessary for security or legal compliance, or as otherwise permitted by the Limited Use requirements for aggregated internal operations. Employees, contractors, service providers, and successors must follow these restrictions.
Storage and protection: We store the connected Google account identifier and email, authorization scopes, access and refresh tokens, and the identifiers and synchronization records needed to link Google lists, tasks, and events to Opsite. Task-sync records include project and task links, due dates, status, sync timestamps, and errors; completion changes are recorded in Opsite's audit history. Google Tasks access and refresh tokens are encrypted before database storage. Connections to Google use HTTPS, and access to integration records is restricted to authorized application services.
Disconnecting and revoking access: In My Tasks → Google Tasks, select Disconnect to stop Tasks sync and remove the saved Tasks access and refresh tokens. Disconnecting does not delete existing Google copies or the original Opsite tasks. The connected account identifier, email, project selections, and sync links remain for reconnection; audit history remains with the project records. To remove linked Google copies through Opsite, deselect the projects and complete a successful sync before disconnecting, or delete the copies directly in Google Tasks. You may also revoke Opsite's Google permissions through your Google Account connections; revocation may affect other Google integrations connected to Opsite.
Retention and deletion requests: Integration records and project audit history follow the retention periods in Section 6. You may request deletion of stored Google account and sync records by emailing privacy@useopsite.com. Account deletion and any legally required retention follow Sections 6 and 7. Disconnecting or revoking Google access does not itself erase records already stored in Opsite or copies remaining in your Google account.
We use your information for the following purposes, subject to the Google-specific restrictions above. These purposes do not authorize additional uses of Google user data or data derived from it:
Our AI features (including the Lino assistant, document categorization, smart scheduling, and automated recommendations) process your data in real-time to provide personalized assistance. This section does not authorize using Google user data or data derived from it to train or improve AI models, or for any purpose outside the Google-specific restrictions above. Specifically:
The Service includes scheduled and triggered features that send communications on a contractor's behalf, including overdue-invoice reminders, lead-nurture emails, scheduled social-media posts, and WhatsApp digests. The contractor selects the recipients, the templates, and the schedule; Opsite executes the contractor's instructions. The contractor is responsible for ensuring the recipient has provided any consent required under the Telephone Consumer Protection Act, the CAN-SPAM Act, or analogous law before the automation is enabled.
If you are in the European Economic Area (EEA), UK, or Switzerland, we process your personal data based on:
We do not sell your personal information. We only share your information in the following circumstances:
We share information with third-party vendors who help us operate the Service, including those below. This list does not authorize every provider to receive Google user data; any transfer of Google user data must satisfy the Google-specific restrictions above:
When you connect integrations like QuickBooks or Google, we share data necessary to provide those features, as authorized by you.
We may share information with your consent, such as when you share project access with clients or team members.
We may disclose information if required by law, subpoena, court order, or government request, or to protect our rights, safety, or property.
In the event of a merger, acquisition, or sale of assets, your information may be transferred. We will notify you of any such change. Google user data, including data derived from it, will be transferred in such a transaction only after obtaining your explicit prior consent.
We maintain a current list of subprocessors who process personal data on our behalf. As of 2026-05-16, our subprocessors include:
| Subprocessor | Purpose | Data categories | Region |
|---|---|---|---|
| Vercel | Hosting, CDN, edge runtime, and Vercel Analytics | All Service data; aggregated traffic metrics | US (multi-region) |
| Supabase | Primary application database and authentication | All Service data, account credentials, session tokens | US |
| Stripe | Payment processing and subscription management | Billing identifiers, payment-card tokens, invoice metadata | US |
| Anthropic | AI assistant (Lino), document categorization, and generative features via the Claude API | Project data and prompts submitted by you to AI features; not used to train general-purpose models | US |
| Upstash | Vector embedding storage for retrieval-augmented generation | Anonymized vector representations of your data | US |
| Twilio | SMS and WhatsApp delivery and delivery-status webhooks | Recipient phone numbers, message bodies, delivery status | US |
| Resend | Transactional and outbound email delivery | Recipient email addresses, message bodies, deliverability metadata | US |
| Plausible Analytics | Privacy-preserving website analytics (cookieless, no PII) | Aggregated page-view counts, referrer, country | EU (Germany) |
| Intuit (QuickBooks) | Optional accounting integration for invoice and payment sync | Invoice and customer records you sync; OAuth identifiers | US |
| Google (Maps, Identity, Calendar, Tasks) | Address autocomplete, map display, optional sign-in, optional calendar and assigned-task sync | Address strings, sign-in identifiers, calendar metadata, selected project names and assigned-task titles, descriptions, due dates, and status — only on user authorization | US |
We will provide at least thirty (30) days' advance notice of material changes to this list by updating this page and, where required by law, notifying account administrators by email. Users may object to a new subprocessor by emailing privacy@useopsite.com; if we are unable to accommodate the objection, the user may terminate the affected portion of the Service for a pro-rata refund of prepaid fees.
We implement industry-standard security measures to protect your data:
While we strive to protect your data, no method of transmission over the Internet or electronic storage is 100% secure. See our Security page for more details.
Breach Notification
In the event of a data breach affecting your personal information, we will notify affected users via email and in-app notification without undue delay and no later than seventy-two (72) hours after confirmation. Where required by law, we will also notify relevant supervisory authorities. Breach notifications will include the nature of the breach, categories of data affected, our contact information, and steps taken to address the breach.
We retain your information for as long as necessary to provide the Service and fulfill the purposes described in this Privacy Policy:
You have the right to:
If you are in the EEA, UK, or Switzerland, you also have the right to:
If you are a California resident, you have the right to:
To exercise your rights, contact us:
Email: privacy@useopsite.com
We will respond within 30 days (or 45 days for complex requests).
We are based in the United States and process data in the U.S. If you are accessing the Service from outside the U.S., your information will be transferred to, stored, and processed in the U.S.
For transfers from the EEA, UK, or Switzerland, we rely on Standard Contractual Clauses approved by the European Commission and implement additional safeguards as necessary.
The Service is not intended for persons under 18 years of age. We do not knowingly collect personal information from anyone under 18. If we learn we have collected information from a person under 18, we will delete it within thirty (30) days of confirmation. If you believe we have collected information from a person under 18, please contact us at privacy@useopsite.com.
The Service may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies before providing any personal information.
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the revised policy on this page and updating the "Last Updated" date. For significant changes, we may also send you a notification via email or through the Service. Your continued use of the Service after changes become effective constitutes acceptance of the revised policy.
If you have questions about this Privacy Policy or our data practices, please contact us:
Opsite Solutions LLC
Privacy Inquiries: privacy@useopsite.com
General Support: support@useopsite.com
Website: https://useopsite.com
In the past 12 months, we have collected the following categories of personal information:
| Category | Examples | Collected |
|---|---|---|
| Identifiers | Name, email, IP address, device identifier | Yes |
| Commercial Information | Transaction history, invoices, subscription records | Yes |
| Internet Activity | Pages viewed, features used, referrer URLs | Yes |
| Geolocation Data | General IP-based location; precise location for map and employee time-clock features | Yes |
| Professional Information | Company name, contractor license info, tax ID/EIN | Yes |
| Sensitive Personal Information | Precise geolocation (employee time-clock); biometric authentication tokens (device-local only) | Yes |
| Inferences | Usage-based feature recommendations | Yes |
We do not respond to legacy "Do Not Track" (DNT) browser signals, which have been deprecated by most major browsers. However, we honor the Global Privacy Control (GPC) browser signal as a valid opt-out of any sale or sharing of personal information under the California Consumer Privacy Act, consistent with the California Attorney General's enforcement position in People v. Sephora USA (2022). When we detect a GPC signal, we automatically apply your opt-out preference for the current and future visits from the same browser.
We use AI and automated systems to provide features such as: document categorization, project recommendations, financial forecasting, automated communications, and the Lino AI assistant. These systems assist your decision-making but do not make legally significant decisions about you without human oversight.
You have the right to:
While we strive for accuracy, AI-generated outputs (including financial calculations, scheduling recommendations, and document analysis) may contain errors. You are responsible for reviewing and verifying all AI-generated outputs before acting on them. Opsite is not liable for decisions made based on AI-generated content.
Where the Service is used to deploy AI features in a jurisdiction with applicable AI-specific consumer disclosure laws (including the Colorado AI Act, Texas HB 149, California AB 2013, and New York City Local Law 144 for automated employment tools), the contractor using Opsite is responsible for providing the required consumer disclosures. Opsite provides configurable AI-disclosure banners and document watermarks in Settings, with defaults aligned to the strictest applicable state for accounts in Colorado, Texas, and California.
Opsite sends transactional SMS notifications to users who have voluntarily opted in. SMS opt-in is not required to use Opsite, is not a condition of purchase or of accessing any part of the Service, and is never bundled with account creation or any other agreement.
All SMS messages sent through Opsite are transactional and are sent from the Opsite brand. Opsite identifies itself as the sender in every message. We do not send marketing or promotional SMS.
The sole method of opting in to receive SMS from Opsite is by submitting your phone number through the public opt-in form at useopsite.com/sms-opt-in. The form:
SMS consent is never collected during account registration, never collected during client-portal invitation, and never collected as part of any other workflow. Phone numbers entered elsewhere in the Opsite product are used only for the specific operational purpose disclosed at the point of collection (for example, an account contact number for support) and are not used for SMS notifications unless the same individual has also separately and explicitly opted in through the public opt-in form above.
Message frequency varies based on project activity. Standard message and data rates may apply.
You can stop receiving SMS at any time by replying STOP to any message. You will receive a single confirmation message and no further SMS will be sent to that number from Opsite. To resume messages, reply START. For help, reply HELP or contact support@useopsite.com.
Mobile information will not be shared with third parties or affiliates for marketing or promotional purposes. Phone numbers and SMS opt-in data are used solely to deliver the messages described above. We share phone numbers only with our SMS service provider (Twilio) for the sole purpose of message delivery, and Twilio is contractually prohibited from using this data for any other purpose.
Carriers are not liable for delayed or undelivered messages. If you have any questions about your text plan or data plan, contact your wireless provider.