RoughBid Privacy Policy
Operational draft. This policy documents intended product behavior. It is not legal advice and should be reviewed by qualified counsel before broad commercial use.
1. Data RoughBid Processes
- Account data: email address, session identifiers, organization membership, role, invite status, and authentication events.
- Organization data: workspace name, teammates, permissions, billing status, usage limits, subscription status, and credit metadata.
- Project data: project names, addresses or regions if entered, client names or contacts if entered, plan files, drawings, specifications, photos, notes, quantities, estimate line items, proposals, signatures, and audit events.
- Usage and security data: device/browser metadata, API events, proposal open events, logs, error reports, abuse signals, and operational diagnostics.
- Payment data: payment status, subscription identifiers, checkout events, invoices, and limited billing metadata. Full payment card details should be handled by the payment processor, not stored directly by RoughBid.
2. How Data Is Used
Data is used to operate RoughBid, authenticate users, separate organizations and projects, enforce permissions, process plan files, generate estimate drafts, share client proposals, send transactional emails, track proposal opens and signatures, process payments, manage credits and usage limits, troubleshoot issues, maintain security, and improve product reliability.
3. Organization and Project Access
RoughBid is designed so each organization controls access to its own projects, files, estimates, price lists, proposals, and billing data. Administrators should review access regularly. Client proposal links may allow limited public access to a specific proposal without a RoughBid login.
4. AI Plan Reading and Model Providers
When AI plan reading is enabled, uploaded plans and related project context may be sent to AI providers or internal processing systems to extract candidate scope, quantities, notes, and review flags. AI output is a draft suggestion and should be reviewed by a user.
RoughBid should not use customer project files to train shared or public AI models unless the customer has clearly agreed in writing or the data has been handled under an approved de-identification and governance process.
5. Sensitive Data
Construction plans can include confidential business, property, client, and contractor information. Users should avoid uploading unnecessary personal data, payment card data, government identifiers, health data, biometric data, children's data, passwords, secrets, or unrelated sensitive data.
6. Sharing and Service Providers
RoughBid may rely on hosting, database, authentication, storage, email, payment, logging, analytics, and AI providers. Production processor configuration should match the actual deployed environment and be reviewed before broad commercial use.
7. Security
RoughBid uses a combination of workspace roles, row-level security, private plan storage, server-side credentials, hashed invite or proposal tokens, and access checks. No system is perfect. Users should report suspected unauthorized access quickly and remove users who no longer need access.
8. Retention and Deletion
Project and account data may be retained while an organization account is active and for a reasonable period needed for security, audit, dispute, billing, legal, backup, or operational purposes. Deletion requests may be limited where retention is required for payment records, security logs, legal claims, or backup integrity.
9. Privacy Requests
Users and proposal recipients may contact RoughBid about access, correction, deletion, or other privacy requests. The response process and deadlines depend on the person's location, the applicable law, the user's relationship to a RoughBid customer, and identity verification.
10. Jurisdiction-Specific Review
Approval needed: privacy rights, notice language, retention periods, international transfers, subprocessor disclosures, cookie/analytics notices, and state-specific US privacy obligations should be reviewed by counsel before broad commercial launch.
11. Contact
Privacy questions: hello@kspdominion.group