Privacy Policy
Effective Date: June 29, 2026 • Last Updated: June 29, 2026
This Privacy Policy (the “Policy”) describes how Scope Conductor, LLC, a Georgia limited liability company (“Scope Conductor,” “we,” “us,” or “our”), collects, uses, discloses, retains, and protects personal information in connection with our software-as-a-service platform for construction-management workflows (Change Orders, Daily Reports, and related communications), websites located at scopeconductor.com and related subdomains, and any other services that link to this Policy (collectively, the “Service”).
This Policy applies to: (i) personal information of our customers and their authorized users (including Admins, Project Managers, and Field Users); (ii) personal information of General Contractors, project owners, or other third parties whose data our customers submit to the Service, and personal information of External Approvers who interact with Service-generated links to review Change Orders; and (iii) personal information of visitors to our public websites. By accessing or using the Service, you acknowledge that you have read and understood this Policy.
Our role. When our customers submit data to the Service to operate their construction-management workflows, Scope Conductor acts as a “service provider” (under the California Consumer Privacy Act, as amended by the California Privacy Rights Act, collectively the “CCPA/CPRA”) and as a “processor” (under other state privacy laws). The customer is the “business” or “controller” of that data. With respect to our own websites, marketing activities, and account administration, Scope Conductor acts as the “business” or “controller.”
1. Information We Collect
We collect the categories of personal information described below. The actual information collected about you depends on how you interact with the Service.
1.1 Information You Provide Directly
- Account and identifiers: name, email address, hashed password, role (Admin, Project Manager, Field User), avatar, company affiliation, and account preferences.
- Company and project information: company name, address, city, state, ZIP code, telephone, logo, primary color, internal project codes, and project descriptions used to organize construction-management workflows.
- Construction contact information: names, telephone numbers, email addresses, and mailing addresses of General Contractors, project owners, subcontractors, suppliers, and other business contacts submitted by our customers to operate the Service.
- Construction operational records: Change Orders (including title, code, description, dates, line items, totals, markup, status, version history, invoice numbers, and approval records), Daily Reports (including original and AI-translated comments, detected language, tags, and project manager comments), Evidence Files (photographs, PDFs, and other attachments uploaded in connection with a Change Order or Daily Report), and audit records.
- Audio recordings (transient): audio captured by an Authorized User for transcription. The audio is transmitted to our transcription provider, converted to text, and the audio is discarded. Only the text transcript is retained.
- External Approver information: for individuals who interact with Service-generated approval links (typically General Contractor representatives), we process the recipient’s email address (provided by our customer), and, upon their interaction with the link, their name, approval status, comments, signature data, IP address, and user-agent, solely to record and transmit the response to our customer.
- Support and communications: messages you send to our support channels, including the contents of emails, chat conversations, and any information you choose to provide.
1.2 Information Collected Automatically
- Authentication and audit metadata: IP address, user-agent string, timestamps, and event types (LOGIN, LOGOUT, LOGIN_FAILED, DATA_ACCESS, DATA_MODIFY, DATA_DELETE, CONSENT_CHANGE, EXPORT_REQUEST, PASSWORD_CHANGE, PASSWORD_RESET) recorded in our audit log for security, compliance, and incident-response purposes.
- Essential cookies: a refresh-token cookie (HttpOnly, Secure, SameSite=Lax) with a seven (7) day validity, used solely to keep you signed in. We do not use this cookie for marketing or cross-site tracking.
- Analytics and marketing on our public website: our public marketing site (scopeconductor.com, including landing pages) uses analytics tools, pixels, and similar technologies (which may include Google Analytics, Meta Pixel, Google Ads, and live-chat providers) to measure performance, analyze usage, and support marketing and remarketing campaigns. These tools may set cookies and similar identifiers in your browser.
- Consent records: the categories of consent you grant or withdraw, whether a Global Privacy Control (GPC) signal was detected, the version of the policy in effect, IP address, and user-agent.
1.3 Information We Do Not Collect
Except for limited audit metadata, we do not intentionally collect: precise geolocation, biometric identifiers, government identifiers (such as Social Security numbers), payment-card data, health information, or other categories of sensitive personal information. We do not knowingly collect personal information of children under 13. We do not knowingly sell or share for cross-context behavioral advertising the personal information of consumers under 16.
2. How We Use Personal Information
We use personal information for the following purposes:
- To provide the Service: operate, maintain, secure, and improve the Service; authenticate users; route Change Order emails and notifications; record External Approver responses; transcribe audio and translate content when affirmatively requested; render PDF reports; and execute customer-configured automated follow-ups (up to three per Change Order).
- To communicate with you: send operational emails such as invitations, Change Order notifications, follow-ups, status updates, Daily Report notifications, password resets, and project-access notices via our transactional email provider; respond to support inquiries; and provide service announcements.
- For marketing (separate consent): with your consent, send newsletters and commercial communications and operate digital marketing automation, including lead capture, nurturing, and integration with marketing tools. You may opt out at any time using the unsubscribe link in any marketing email.
- For security and compliance: detect, investigate, and prevent fraud, unauthorized access, and abuse; maintain audit logs; respond to legal requests; and comply with our legal obligations.
- For internal product improvement: analyze how the Service is used and improve features, usability, performance, and reliability, including through de-identified data used solely for internal purposes.
- To enforce our agreements: enforce our Terms of Service, billing terms, and other agreements with you.
No use of Customer Data for cross-customer benchmarking. We do not use Customer Data to produce cross-customer benchmarking, comparative industry analytics, or aggregated industry datasets for marketing or commercial distribution.
No use for AI model training. We do not use Customer Data to train general-purpose AI models. Our generative-AI provider has confirmed by default that API inputs and outputs are not used to train its models.
3. Cookies and Tracking Technologies
3.1 Categories of Cookies and Similar Technologies
- Strictly necessary: required for the Service to function, including authentication (refresh-token cookie). These cannot be disabled.
- Analytics: used on our public website to understand how visitors interact with our pages.
- Marketing and advertising: used on our public website to measure campaign performance and deliver relevant advertising on third-party platforms (including remarketing).
3.2 Your Choices and Global Privacy Control
On our public website you may manage non-essential cookies through our cookie banner. Where required by law (including for California consumers), we recognize the Global Privacy Control (GPC) browser signal as a valid request to opt out of the sale or sharing of personal information for cross-context behavioral advertising. The authenticated application does not use marketing or advertising cookies.
4. How We Share Personal Information
We share personal information only as described below. We do not sell personal information for monetary consideration. On our public website, we may “share” personal information (as defined under the CCPA/CPRA) with advertising partners for cross-context behavioral advertising; you may opt out as described in Section 7.4 and Section 3.2.
4.1 Service Providers and Subprocessors
We share personal information with vendors who process it on our behalf under written contracts that restrict use to providing services to us. Our current subprocessors are:
- Amazon Web Services, Inc. — cloud hosting (EC2, EBS), object storage (S3), transactional email delivery (SES), and logging (CloudWatch). Region: us-east-1 (Northern Virginia, U.S.A.).
- OpenAI, L.L.C. — audio transcription (Whisper), AI-assisted Change Order drafting, and language translation. Inputs and outputs are not used by OpenAI to train its models by default.
- Let’s Encrypt (Internet Security Research Group). — issuance of TLS certificates.
Additional subprocessors may be added in the future, including for payment processing (e.g., Stripe), error monitoring (e.g., Sentry/Datadog), and customer-relationship management. We will update this Policy when material changes occur.
4.2 Recipients You Direct (Including External Approvers)
When you send a Change Order or other communication to a General Contractor, External Approver, or other third party via the Service, you direct us to transmit that content to the recipient using the contact information you provide. Email replies are routed by Reply-To header to your designated email and are not interpreted or stored by the Service, except where the External Approver affirmatively interacts with a Service-generated link using a secure access token, in which case the response is recorded as part of the Change Order audit history.
4.3 Legal and Safety Disclosures
We may disclose personal information if we believe in good faith that disclosure is necessary to: (a) comply with a subpoena, court order, or other legal process; (b) protect the rights, property, or safety of Scope Conductor, our customers, or others; (c) enforce our agreements; or (d) investigate or prevent fraud or security incidents.
4.4 Business Transfers
If we are involved in a merger, acquisition, financing, reorganization, or sale of all or part of our business, personal information may be transferred as part of that transaction, subject to applicable law.
5. International Data Transfers
The Service is hosted in the United States (AWS us-east-1, Northern Virginia). Personal information processed through the Service is stored in the United States. Members of our team and certain personnel are located in Brazil and may access personal information from outside the United States to provide development, support, and operational services. We rely on appropriate contractual safeguards and access controls to protect personal information when accessed across borders.
6. Data Retention
We retain personal information for as long as we have an active business relationship with you and as needed to provide the Service. Specific retention periods include:
- Active accounts: Customer Data is retained for the duration of the subscription.
- After cancellation or termination: Customer Data is made available for export for sixty (60) days following the effective date of termination (the “Export Window”). After the Export Window, Customer Data is deleted from production systems in the ordinary course.
- Audit and security logs: retained for the period required to detect and investigate security incidents and to comply with legal obligations, typically not less than twelve (12) months.
- Access logs: general account access logs are retained for ninety (90) days, after which they are deleted unless required by applicable law to retain them.
- Backups: personal information may persist in encrypted backups for a limited period after deletion from production, after which it is overwritten in the ordinary backup-rotation cycle.
- Legal holds: where required by law, contract, or a pending dispute, we may retain personal information for the duration of the obligation or dispute.
7. Your Privacy Rights
7.1 Rights for U.S. Consumers
Depending on where you reside, you may have the following rights, subject to verification and applicable exceptions:
- Right to know / access: request confirmation of whether we process your personal information and access to that information, including categories collected, sources, purposes, and recipients.
- Right to correct: request correction of inaccurate personal information.
- Right to delete: request deletion of personal information we have collected from you.
- Right to portability: request a copy of your personal information in a portable, machine-readable format.
- Right to opt out of sale or sharing: opt out of the “sale” or “sharing” of personal information for cross-context behavioral advertising on our public website.
- Right to limit use of sensitive personal information: to the extent we process sensitive personal information for purposes other than those permitted as a service provider, you may request limitation of such use.
- Right to non-discrimination: you will not receive discriminatory treatment for exercising any of these rights.
- Right to appeal: in states that provide an appeal right (e.g., Virginia, Colorado, Connecticut), you may appeal a denial of your request as described in Section 7.3.
7.2 Rights Specifically for California Residents (CCPA/CPRA)
Under California law you have the rights described in Section 7.1. In the twelve (12) months preceding the effective date of this Policy, we have collected the categories of personal information described in Section 1 from the sources described in Section 1, for the purposes described in Section 2, and disclosed those categories to the recipients described in Section 4. We have not sold personal information for monetary consideration. We may “share” identifiers and internet-activity information with advertising partners for cross-context behavioral advertising on our public website, and you may opt out as described in Section 7.4.
7.3 How to Submit a Request
To exercise your rights, contact us at support@scopeconductor.com or use the in-app data-rights tools where available. We will verify your request using account information and may request additional information to confirm your identity. Authorized agents may submit requests with verifiable authorization. We will respond within the time period required by applicable law, typically forty-five (45) days, which may be extended once by an additional forty-five (45) days where reasonably necessary.
If your request is denied, you may appeal by replying to our response or emailing support@scopeconductor.com with the word “Appeal.” We will inform you of the outcome of the appeal within sixty (60) days, or as otherwise required by applicable law.
Where Scope Conductor acts as a service provider or processor on behalf of a customer (for example, with respect to General Contractor or External Approver information submitted by the customer), we will refer your request to the relevant customer, who is the controller of that data.
7.4 Opt Out of Sale or Sharing
To opt out of the “sale” or “sharing” of your personal information for cross-context behavioral advertising on our public website, you may: (a) use the “Do Not Sell or Share My Personal Information” link in our website footer; (b) enable a Global Privacy Control (GPC) signal in your browser, which we honor as an opt-out request; or (c) email support@scopeconductor.com.
8. Marketing Communications
We send marketing communications only with your consent (opt-in). Every marketing email includes a working unsubscribe link, and unsubscribe requests are honored within ten (10) business days as required by the CAN-SPAM Act. Operational emails (such as account, security, and transactional notices, including Change Order communications you direct us to send) are necessary to provide the Service and are not subject to unsubscribe.
9. Security
We maintain commercially reasonable administrative, technical, and physical safeguards designed to protect personal information, including:
- Encryption in transit: TLS 1.2 or higher for all connections to the Service.
- Encryption at rest: AES-256 server-side encryption for storage volumes and object storage.
- Access controls: role-based access (Admin, Project Manager, Field User) and least-privilege internal access.
- Authentication: passwords are hashed using bcrypt; multi-factor authentication may be offered in the future.
- Audit logging: authentication and privacy-related events are recorded with IP address and user-agent.
- Network controls: CORS restrictions, isolated environments, and firewall rules.
No system is perfectly secure. You are responsible for protecting your credentials and promptly notifying us of any suspected unauthorized access at support@scopeconductor.com.
10. Children’s Privacy
The Service is not directed to children under thirteen (13), and we do not knowingly collect personal information from children under thirteen (13). We do not knowingly sell or share personal information of consumers under sixteen (16) for cross-context behavioral advertising. If you believe a child has provided us with personal information, please contact us at support@scopeconductor.com and we will take appropriate steps to delete the information.
11. Third-Party Links and Services
Our website and Service may link to third-party websites or services. We are not responsible for the privacy practices or content of third parties. We encourage you to review the privacy notices of any third-party services you use.
12. Changes to This Policy
We may update this Policy from time to time. If we make a material change, we will provide reasonable advance notice (typically at least thirty (30) days) by email or in-app notification before the change takes effect. The “Last Updated” date at the top of this Policy indicates when it was most recently revised. Your continued use of the Service after the effective date of an updated Policy constitutes acknowledgement of the change.
13. Contact Us
If you have questions about this Policy, our privacy practices, or to exercise your privacy rights, contact us at:
Scope Conductor, LLC
Email: support@scopeconductor.com
Website: https://scopeconductor.com
© Scope Conductor, LLC. All rights reserved.