Privacy Policy
Last updated: August 1, 2026
This Privacy Policy explains how SubDox (“SubDox,” “we,” “us,” or “our”) collects, uses, discloses, and safeguards information when you use our website (subdox.net) and our subcontractor compliance management software (together, the “Service”).
By using the Service, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use the Service.
1. Who This Policy Covers
This policy applies to:
- General contractors and their team members (“Customers”) who create an account and use SubDox to manage subcontractor compliance.
- Subcontractors whose information is uploaded or entered into SubDox by a Customer, or who submit documents through a SubDox self-service portal link, even though subcontractors do not create their own SubDox account.
If you are a subcontractor and have questions about information a general contractor has entered about you, please also refer to Section 9 below.
2. Information We Collect
2.1 Information you provide directly
- Account information: name, email address, password (or authentication via Google/Microsoft sign-in), company name, phone number.
- Billing information: handled entirely by our payment processor (see Section 6). We do not directly store your full payment card number.
- Subcontractor and compliance data entered by Customers: subcontractor company names, contact names, emails, phone numbers, trade classifications, and any notes added by the Customer.
- Uploaded documents: Certificates of Insurance, contractor licenses, W-9 forms, lien waivers, and any other compliance documents uploaded to the Service by a Customer or by a subcontractor via a portal link. These documents may contain sensitive information such as insurance policy numbers, coverage amounts, license numbers, business addresses, and taxpayer identification numbers (EINs/TINs).
- Communications: information you provide when you contact us for support.
2.2 Information collected automatically
- Usage data: pages visited, features used, timestamps, and general interaction data within the Service.
- Device and log data: IP address, browser type, operating system, and referring URLs, collected automatically by our hosting and analytics infrastructure.
- Cookies and similar technologies: used for authentication (keeping you signed in) and basic functionality. We do not use third-party advertising cookies.
2.3 Information from third parties
- Authentication providers: if you sign in with Google or Microsoft, we receive your name and email address from that provider as permitted by your settings with them.
- AI document processing: uploaded documents are processed by Anthropic’s Claude AI to extract structured data (such as expiration dates and coverage amounts). See Section 6 for details on this sub-processor.
3. How We Use Information
We use collected information to:
- Provide, operate, and maintain the Service, including compliance tracking, automated reminders, and the AI compliance assistant.
- Extract structured data from uploaded compliance documents using AI processing.
- Send transactional emails and SMS messages (such as document expiration reminders) on behalf of Customers to their subcontractors.
- Process payments and manage subscriptions.
- Respond to support requests and communicate with you about the Service.
- Monitor and improve the security, performance, and reliability of the Service.
- Comply with legal obligations.
We do not sell personal information to third parties, and we do not use subcontractor compliance data to train AI models outside of the immediate document-extraction request.
4. Legal Basis for Processing (EEA/UK Users)
If you are located in the European Economic Area or United Kingdom, our legal bases for processing personal data include: performance of a contract (providing the Service you signed up for), legitimate interests (improving and securing the Service), and consent (where explicitly requested, such as marketing communications).
5. How We Share Information
We share information only in the following circumstances:
- With your organization: if you are a subcontractor contact, the general contractor who added you to SubDox can see the information and documents associated with your company.
- With service providers (sub-processors): listed in Section 6, who process data on our behalf under contractual confidentiality and data protection obligations.
- For legal reasons: if required to comply with a legal obligation, protect the rights and safety of SubDox, our users, or the public, or investigate potential violations of our Terms of Service.
- Business transfers: if SubDox is involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction, subject to standard confidentiality protections.
6. Sub-Processors
We use the following third-party service providers to operate SubDox. Each processes data solely to provide their respective service to us.
| Provider | Purpose | Data Involved |
|---|---|---|
| Supabase | Database hosting | All account and compliance data |
| Vercel | Application hosting | All data in transit and at rest during use |
| Clerk | Authentication | Name, email, login credentials |
| Cloudflare (R2) | Document file storage | Uploaded compliance documents |
| Anthropic (Claude AI) | AI document data extraction | Contents of uploaded documents, processed transiently |
| Lemon Squeezy | Payment processing and billing | Billing name, email, payment details (Merchant of Record) |
| Resend | Transactional email delivery | Recipient email address, email content |
| Twilio | Transactional SMS delivery | Recipient phone number, message content |
We periodically review this list and will update it as our infrastructure evolves.
7. Data Retention
- Account data is retained for as long as your account is active.
- Compliance documents and records are retained for as long as your account is active, and for up to 90 days after account cancellation, to allow you to export your data or reactivate.
- Audit logs are retained indefinitely in immutable form for compliance and security purposes, as they form part of the compliance record for regulated construction work.
- You may request earlier deletion of your account and associated data by contacting us, subject to any legal retention obligations.
8. Data Security
We implement industry-standard safeguards, including:
- Encryption of data in transit (TLS) between your browser and our servers.
- Encryption at rest for stored documents and database records.
- Row-level security controls ensuring one Customer’s data is never accessible to another.
- Masking of sensitive taxpayer identification numbers (EINs/TINs) extracted from W-9 forms — only the last four digits are stored in the application database.
- Access controls limiting internal access to production data.
No method of transmission or storage is 100% secure. We cannot guarantee absolute security, but we work to protect your information using commercially reasonable safeguards appropriate to the sensitivity of the data involved.
9. Subcontractor Information
If you are a subcontractor whose information was added to SubDox by a general contractor, or who uploaded documents via a portal link:
- SubDox acts as a data processor on behalf of the general contractor (the Customer), who determines what information is collected and how it is used.
- To access, correct, or request deletion of your information, please contact the general contractor directly. If you are unable to reach them, you may contact us at the email below and we will make reasonable efforts to assist.
- Documents you upload via a portal link are visible only to the general contractor who issued that link.
10. Your Rights
Depending on your location, you may have the right to:
- Access the personal information we hold about you.
- Correct inaccurate information.
- Request deletion of your information, subject to legal retention requirements.
- Object to or restrict certain processing.
- Request a copy of your data in a portable format.
- Withdraw consent where processing is based on consent.
To exercise these rights, contact us at the email below. We will respond within the timeframe required by applicable law.
11. International Data Transfers
SubDox is operated from Nigeria, with infrastructure providers located in the United States and other jurisdictions. By using the Service, you acknowledge that your information may be transferred to, stored, and processed in countries other than your own, which may have different data protection laws.
12. Children’s Privacy
The Service is intended for business use by adults. We do not knowingly collect personal information from individuals under 18. If we become aware that we have inadvertently collected such information, we will take steps to delete it.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or a prominent notice within the Service prior to the change becoming effective. Your continued use of the Service after changes take effect constitutes acceptance of the revised policy.
14. Contact Us
If you have questions about this Privacy Policy or how we handle your information, contact us at:
Email: support@subdox.net
Website: https://subdox.net