Privacy Policy
Last updated: August 17, 2026 (version 2026-08-17)
This Privacy Policy describes how SubMark ("SubMark," "we," "us") collects, uses, and shares information in connection with the SubMark application and related services (the "Service"). By using the Service you agree to this Policy.
SubMark is a business tool used by construction companies ("Customers"). Much of the data in the Service is entered by Customers about their own business and workforce; for that data we act on the Customer's behalf.
1. Information We Collect
Account information. Name, work email address, password credentials (stored by our authentication provider in hashed form), role, phone number if provided, and company affiliation.
Customer business data. Information Customers and their users enter or upload into the Service: projects, bids, estimates, contracts and financial figures, change orders, schedules, daily logs, purchase orders, invoices and draw records, safety records, photos, plans, and documents. This can include information about a Customer's workers — such as names, crew assignments, time and attendance records, and certifications — which the Customer is responsible for having the right to submit.
Usage and device information. Log data (IP address, browser and device type, pages viewed, actions taken), approximate location derived from IP, and diagnostic data such as error reports. We use this to operate, secure, and improve the Service.
Acceptance records. When you accept our Terms of Service and this Policy, we record the version accepted, your user ID, the time, your IP address, and your browser's user-agent string, to maintain an auditable record of the agreement.
Support and feedback. Messages, feedback submissions, and any screenshots or attachments you send us.
2. How We Use Information
We use information to: provide, maintain, and secure the Service; authenticate users and enforce tenant isolation between customers; process billing; provide support; send service and account emails; monitor for errors, abuse, and fraud; analyze usage to improve the product; and comply with legal obligations. Some features use artificial intelligence to process documents and data you submit (for example, extracting values from an uploaded PDF); this processing is performed to provide the feature, not to build advertising profiles.
We do not sell personal information, and we do not use Customer business data for advertising.
3. Service Providers (Subprocessors)
We share information with service providers that help us run the Service, under agreements that limit their use of the data:
- Railway — application and database hosting (United States)
- Vercel — web application hosting and delivery
- Amazon Web Services (S3) — file and document storage
- Stripe — payment processing (we do not store full card numbers)
- Anthropic — AI processing for document extraction and AI-assisted features
- PostHog — product analytics (United States region)
- Sentry — error monitoring
- Resend — transactional email delivery
- Intuit (QuickBooks Online) — accounting integration, only when a Customer connects it
- Microsoft (Microsoft 365 / Outlook) — connected email accounts, only when an individual user connects their mailbox (see Section 5)
- Google (Gmail / Google Workspace) — connected email accounts, only when an individual user connects their mailbox (see Section 5)
- Google Maps — address lookup and mapping features
We may also disclose information if required by law, to protect the rights and safety of SubMark or others, or in connection with a merger, acquisition, or sale of assets (with notice where required).
4. Collaboration Features
Customers can invite subcontractors or other collaborators into specific projects. Data you attach to a shared project may be visible to those invited parties according to the access granted by the project owner. Financial fields are withheld from cross-company collaborators by design.
5. Connected Email Accounts (Email Intelligence)
SubMark's Email Intelligence feature lets an individual user optionally connect their own work email account — Microsoft 365 (Outlook) or Google Workspace (Gmail) — so the Service can surface construction-relevant emails, such as invitations to bid, general-contractor replies on change orders, and due-date changes, alongside their project data. Connecting is optional and per person; only the connecting user sees the results, and they can disconnect at any time in Settings → Integrations.
What we access. For Gmail, SubMark requests read-only access to messages (the gmail.readonly scope) and the account's email address. For Microsoft 365, the equivalent read-only permission (Mail.Read). SubMark cannot send, modify, delete, or label email, and never requests permission to do so.
How we use it. Approximately every 15 minutes, SubMark checks the connected inbox for new messages and compares message headers (sender, subject) and a short preview against the Customer's records in the Service — project names, general contractors, and bids. Only matching messages are examined further: for those, SubMark retrieves the message text momentarily so an automated classifier can determine whether it is one of a fixed set of construction events and produce a one-sentence summary. Users control which categories are active in their settings.
What we store — and never store. For each matched message we store only: sender name and address, subject line, date received, the detected category, a one-sentence summary, any specific fact the message stated (such as a new due date), and a link that opens the original message in the user's own email client. We never store email bodies or attachments. Message content is processed transiently and immediately discarded; non-matching messages are not analyzed beyond their headers and are not retained in any form. Stored email insights are deleted automatically after at most 90 days (sooner if dismissed). Mailbox access tokens are stored encrypted (AES-256-GCM) and are deleted on disconnect; disconnecting also permanently deletes every stored insight derived from that mailbox.
Automated processing and human access. Classification is performed by an automated AI model operated by our AI service provider (see Section 3), which processes matched message text transiently as a data processor and does not use it to train its models. SubMark does not use Google user data to develop, improve, or train generalized artificial-intelligence or machine-learning models. No human at SubMark reads messages or the transient classification data, except with the user's explicit consent, for security investigation, to comply with applicable law, or as part of aggregated, anonymized internal operations that no longer identify the user or their messages. We do not sell Google user data and do not share it with advertisers or data brokers.
Google API Services — Limited Use. SubMark's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Revoking access. Disconnect at any time in the Service under Settings → Integrations. You can additionally revoke SubMark's access with your provider directly: for Google at myaccount.google.com/permissions; for Microsoft at myapps.microsoft.com.
6. Cookies
We use cookies necessary for the Service to function — primarily the session cookie that keeps you signed in. We do not use third-party advertising cookies.
7. Security
We use administrative, technical, and physical safeguards appropriate to the nature of the data, including encryption in transit, tenant-scoped access controls, role-based permissions, audit logging, and monitored backups. No system is perfectly secure; please use a strong, unique password and contact support@submark.io immediately if you suspect unauthorized access.
8. Data Retention
We retain account and Customer business data while the Customer's account is active. Audit and financial compliance records are retained for up to seven years consistent with construction-industry and tax record-keeping standards. After account termination, Customer Data is available for export for 30 days (see the Terms of Service), after which it is scheduled for deletion, except records we are required or permitted to retain for compliance, dispute resolution, or backup-cycle purposes.
9. Your Choices and Rights
You may access and update your account information in the Service. Depending on your jurisdiction, you may have rights to access, correct, delete, or export personal information; to exercise them, contact support@submark.io. If your information was entered by your employer as part of their use of the Service (for example, time records), we may direct your request to them, since they control that data.
10. Workers and Field Personnel
If your employer uses SubMark, information about you (such as your name, hours, and certifications) may be stored in the Service by your employer. Your employer is responsible for that data and for informing you about its use. Questions about it should go to your employer; we will assist them in responding.
11. Children
The Service is a business tool and is not directed to children under 16. We do not knowingly collect personal information from children.
12. International Use
The Service is operated from the United States and data is stored in the United States. If you use the Service from outside the U.S., you understand your information will be processed in the U.S.
13. Changes to This Policy
We may update this Policy from time to time. Each version is identified by its version date. Material changes will be notified through the Service and, where required, will be subject to re-acceptance. Continued use after a non-material update constitutes acceptance.
14. Contact
Questions or requests: support@submark.io.