Privacy policy
Last updated October 1, 2026
This policy explains what personal information ConstructorIQ Inc., doing business as Project Financials (“we”), collects when you use projectfinancials.com and app.projectfinancials.com, why we collect it, and the choices you have. It is written to be read, not skimmed. If anything is unclear, email kevin@krselectric.net.
Two kinds of data
Account data is information about you and your colleagues as users: name, email, password hash, role, company, billing contact, and records of sign-ins and support conversations. We are the controller of this data.
Customer Data is what your company puts into the application: projects, contracts, draws, costs, forecasts, resource plans, and any names that appear in them (for example a project manager’s name on a job). Your company controls this data and decides who in it can see what; we process it only to provide the Service under the terms of service.
What we collect and why
- To create and secure your account: name, email, hashed password, company name, role, IP address and browser information at sign-in, and the tokens that keep you signed in. Legal basis: performing our contract with you and our legitimate interest in keeping accounts secure.
- To bill you: billing name, address and email, plan and invoices. Card numbers go directly to Stripe, our payment processor; we see only the last four digits and the card brand. Legal basis: contract.
- To send email you need: verification, password reset, invitations, trial and billing notices, and replies to support requests. These are not marketing and you cannot opt out of them while you have an account. Legal basis: contract.
- To tell you about the product: occasional product-update emails to account owners and admins. You can unsubscribe from these with one click. Legal basis: legitimate interest; consent where the law requires it.
- To run and improve the Service: server logs (requests, errors, timings) and in-app usage events such as which features a company uses. We do not run third-party advertising trackers, and the marketing website sets no cookies at all. Legal basis: legitimate interest.
- To keep records we must keep: invoices and tax records, and an audit log of operator access to customer accounts. Legal basis: legal obligation and legitimate interest.
We do not collect information from children, do not buy data about you from brokers, and do not use your data to train machine-learning models.
Who sees it
We share personal information only with the companies that help us run the Service, under contracts that limit what they can do with it:
- Amazon Web Services (US regions) hosts the application, database and backups.
- Stripe processes payments and stores card details.
- Resend delivers transactional email.
We also disclose information if the law requires it, to protect someone’s safety, or to a buyer if the business is sold (in which case this policy continues to apply and we will tell you). Our own staff see Customer Data only when supporting you or operating the system, and every such access by an operator is logged.
Where it lives
All production data is stored and processed in the United States. If you use the Service from outside the US, you are sending your data to the US. For customers who need European transfer terms, we offer the Standard Contractual Clauses on request.
How long we keep it
- Account and Customer Data: for as long as your company’s account is open, then 30 days, then deleted from live systems. Encrypted backups rotate out within 35 days after that.
- Billing records: 7 years, as tax law requires.
- Server logs: 90 days.
- Support email: 3 years.
Security
Traffic is encrypted in transit. Data is encrypted at rest. Passwords are hashed with Argon2id. Each company’s rows are isolated by row-level security in the database. Backups run nightly to a separate bucket. More on the security page. No system is perfectly secure; if we learn of a breach affecting your personal information we will tell you without undue delay and in any case within the time the law requires.
Your choices and rights
- You can see and change your name, email and password in the app at any time.
- Your company’s owner can export all Customer Data from Settings, and can close the account, which deletes it on the schedule above.
- Depending on where you live (for example under the GDPR, the UK GDPR, or US state privacy laws such as the Utah Consumer Privacy Act), you may have the right to access, correct, delete or receive a copy of your personal information, to object to or restrict certain processing, and to complain to a supervisory authority. Email kevin@krselectric.net and we will respond within 30 days. We will never treat you differently for exercising these rights.
- If your personal information is in another company’s Customer Data (for instance your name as a PM on their projects), that company controls it; please contact them, and we will help them respond.
- We do not sell personal information and do not share it for cross-context behavioural advertising, so there is nothing to opt out of on that front.
Cookies
The application uses two strictly necessary cookies to keep you signed in (an access token and a refresh token). They are HTTP-only and secure, and are not used for tracking. The marketing website sets no cookies. Because we use no analytics or advertising cookies, there is no cookie banner.
Changes
If we change this policy in a way that matters, we will email account owners before the change takes effect and note the date at the top. Minor clarifications may be made without notice.
Contact
Privacy questions and requests: kevin@krselectric.net, or by post at ConstructorIQ Inc., Cedar City, Utah.