Back to RoughBid

RoughBid Privacy Policy

Operational draft. This policy documents intended product behavior. It is not legal advice and should be reviewed by qualified counsel before broad commercial use.

1. Data RoughBid Processes

2. How Data Is Used

Data is used to operate RoughBid, authenticate users, separate organizations and projects, enforce permissions, process plan files, generate estimate drafts, share client proposals, send transactional emails, track proposal opens and signatures, process payments, manage credits and usage limits, troubleshoot issues, maintain security, and improve product reliability.

3. Organization and Project Access

RoughBid is designed so each organization controls access to its own projects, files, estimates, price lists, proposals, and billing data. Administrators should review access regularly. Client proposal links may allow limited public access to a specific proposal without a RoughBid login.

4. AI Plan Reading and Model Providers

When AI plan reading is enabled, uploaded plans and related project context may be sent to AI providers or internal processing systems to extract candidate scope, quantities, notes, and review flags. AI output is a draft suggestion and should be reviewed by a user.

RoughBid should not use customer project files to train shared or public AI models unless the customer has clearly agreed in writing or the data has been handled under an approved de-identification and governance process.

5. Sensitive Data

Construction plans can include confidential business, property, client, and contractor information. Users should avoid uploading unnecessary personal data, payment card data, government identifiers, health data, biometric data, children's data, passwords, secrets, or unrelated sensitive data.

6. Sharing and Service Providers

RoughBid may rely on hosting, database, authentication, storage, email, payment, logging, analytics, and AI providers. Production processor configuration should match the actual deployed environment and be reviewed before broad commercial use.

7. Security

RoughBid uses a combination of workspace roles, row-level security, private plan storage, server-side credentials, hashed invite or proposal tokens, and access checks. No system is perfect. Users should report suspected unauthorized access quickly and remove users who no longer need access.

8. Retention and Deletion

Project and account data may be retained while an organization account is active and for a reasonable period needed for security, audit, dispute, billing, legal, backup, or operational purposes. Deletion requests may be limited where retention is required for payment records, security logs, legal claims, or backup integrity.

9. Privacy Requests

Users and proposal recipients may contact RoughBid about access, correction, deletion, or other privacy requests. The response process and deadlines depend on the person's location, the applicable law, the user's relationship to a RoughBid customer, and identity verification.

10. Jurisdiction-Specific Review

Approval needed: privacy rights, notice language, retention periods, international transfers, subprocessor disclosures, cookie/analytics notices, and state-specific US privacy obligations should be reviewed by counsel before broad commercial launch.

11. Contact

Privacy questions: hello@kspdominion.group