← Back

Privacy Policy

Last updated: October 5, 2026

This Privacy Policy explains what information Impact Vis LLC ("we," "us," "our"), the operator of Construction Impact Viewer (the "Service"), collects, how we use it, and the choices you have. It applies to the platform signup pages at this domain and to every tenant workspace hosted on a subdomain of it.

The Service is not currently offered to organizations in the EU, EEA, or UK, or for processing the personal data of individuals located there — see our Terms & Conditions, section 2. This policy will be updated if that changes.

1. Information we collect

CategoryWhat's collectedWhy
Account information Username, email address, hashed password, role (admin/editor/viewer) To create and secure your login, and to control what you can access within your organization's workspace
Organization (tenant) information Organization name, workspace subdomain, branding (logo, colors) if configured To provision and operate your organization's isolated workspace
Project/impact data you create Construction impact records, project names, floor plans, drawn map areas, dates, notes, comments, mentions, uploaded PDF attachments This is the content of the Service itself — it exists because you and your team entered it
Billing information Subscription status and plan, handled through Stripe To manage your subscription. We do not receive or store your full card number — Stripe processes and stores payment details directly under its own privacy policy (stripe.com/privacy)
Single sign-on (SSO) If you sign in with Google or your organization's SAML identity provider: your name, email address, profile picture (Google only), and a unique account identifier from that provider To authenticate you without us ever seeing or storing a separate password
Audit & security logs Actions taken in the Service (who created/edited/deleted what, and when), login activity Account security, abuse prevention, and so your organization's admins can see who changed what
Session cookie One cookie (connect.sid) identifying your logged-in session Strictly necessary to keep you signed in. See the Cookies section below

2. How we use information

We do not sell your personal information, and we do not use your project/impact data to train any AI or machine-learning model.

3. Password security

Passwords are never stored in plain text — only a salted bcrypt hash. When you set a password, we additionally check it (using a privacy-preserving technique that never transmits your actual password) against a public database of passwords known to have appeared in prior data breaches, and reject it if it has, so you aren't able to reuse a compromised password here.

4. Email delivery and engagement

Transactional email (invites, password resets, mention notifications, digests) is sent on our behalf by Brevo, an email delivery service. Brevo may record whether an email was delivered, opened, or a link in it was clicked, for deliverability and anti-abuse purposes. See Brevo's privacy policy at brevo.com/legal/privacypolicy.

5. Cookies

The Service uses exactly one cookie: connect.sid, a strictly necessary session cookie that keeps you logged in. It is set to httpOnly (not readable by page scripts), secure (sent only over HTTPS), and expires automatically after 7 days of issuance. We do not use advertising, analytics, or tracking cookies on this site.

If you sign in via Google or a SAML identity provider, or complete payment through Stripe Checkout, those third parties may set their own cookies on their own domains during that process, governed by their own privacy policies — we do not control those cookies.

6. Data sharing

We share information only with the service providers who help us run the Service, under their own confidentiality and data-protection obligations:

We do not share your data with third parties for their own marketing purposes. We may disclose information if required to by law, or to protect the rights, safety, or property of our users or the public.

7. Data isolation between organizations

Each organization's data is stored in its own isolated database. Users in one organization's workspace cannot see another organization's data.

8. Our role, and data retention

For the account and project data your organization puts into the Service, your organization decides what is collected, how long it is kept, and when it is deleted. We process that data on your organization's behalf and follow its instructions. Many organizations, such as public agencies and universities, are subject to records-retention laws, so we do not delete organization data on our own initiative or on the request of an individual user, and deactivating a user preserves the records that user created.

We retain organization data for as long as the subscription is active, plus a reasonable period afterward so that your organization can reactivate or export it. Audit logs are retained for security and accountability purposes and are not automatically purged. If your organization needs data returned or destroyed at the end of the relationship, or needs a hold placed on it, arrange that with us in writing.

9. Your rights

Depending on where you live, you may have rights to access, correct, export, or delete your personal information, or to object to or restrict certain processing. Because your organization controls the data in its workspace, please direct requests about that data to your organization's administrator first. We'll assist the administrator in responding, and will respond directly to you for information we hold for our own purposes (such as billing contacts), as required by applicable law. These rights are not absolute: they may be limited where the data must be retained to comply with a legal obligation, including public-records retention requirements. We may need to verify your identity, or your organization admin's authority, before fulfilling a request. Contact us using the information below.

10. Children's privacy

The Service is intended for business use and is not directed at children. We do not knowingly collect personal information from children under 13 (or the relevant minimum age in your jurisdiction).

11. Changes to this policy

We may update this policy from time to time. If we make material changes, we'll update the "Last updated" date above, and where appropriate, notify active account admins by email.

12. Contact us

Impact Vis LLC
Email: diegojrosado@gmail.com

This document is a template drafted to reflect this application's actual data practices as of its last-updated date above. It is provided for informational purposes and does not constitute legal advice; have it reviewed by qualified legal counsel before relying on it, particularly for compliance with regimes such as GDPR or CCPA.