At a glance
- We process account, project, and technical information to operate and support North Trail.
- Your organization manages access to its shared project records.
- You can contact privacy@northtrail.dev about your information or a privacy request.
1. Who this notice covers
North Trail, LLC provides construction project collaboration software. This notice explains how we handle personal information through our website, web and mobile applications, account services, and support communications. It applies to visitors, account holders, invited collaborators, and people whose information is included in project records.
When your employer, customer, or another organization gives you access to North Trail, that organization also makes decisions about the information it brings into its workspace. Its policies and agreements may apply in addition to this notice. Third-party services you connect or visit have their own privacy practices.
2. Information we collect
The information processed depends on the features you and your organization use.
- Account and profile information. Name, email address, username, company, phone number when provided, sign-in identifiers, account status, and records of policy acceptance.
- Organization and membership information. Organization details, invitations, roles, project assignments, access permissions, and membership history.
- Project content. Plans, specifications, tasks, comments, photos, files, annotations, forms, signatures, reports, and the names, timestamps, locations, or other information included in those records. Uploaded files may contain embedded metadata.
- Financial and work records. Where these features are used, budgets, commitments, invoices, expenses, receipts, labor entries, rates, approvals, and related audit history.
- Subscription information. For paid services, billing contacts, plan and seat information, payment-provider references, invoices, and payment or subscription status. Payment details entered in a provider’s checkout or billing portal are handled by that provider.
- Technical and usage information. Network and request information such as IP addresses, browser or device details, application versions, security events, errors, performance diagnostics, and synchronization activity. Notification delivery may use a device push token.
- Communications. Questions, feedback, support correspondence, career inquiries, and diagnostic information you provide.
We receive information from you, from people using the same organization or project, from services your organization connects, and from the devices and systems used to operate the service.
3. How we use information
We use information to:
- Create accounts, authenticate users, and administer organizations and project access.
- Store, display, organize, and deliver project content, including reports and authorized exports.
- Process changes, synchronize supported offline work, and maintain activity and approval history.
- Send invitations, account messages, project notifications, and requested reports.
- Administer subscriptions, usage limits, invoices, and billing support where applicable.
- Investigate errors, answer support and career inquiries, assess performance, and improve service reliability.
- Protect accounts and content, investigate misuse, enforce service rules, and address legal obligations or disputes.
Please limit information you submit to what is needed for the work. Do not include passwords, access tokens, or unnecessary sensitive personal information in project records or support messages.
4. Your organization and project records
North Trail is a shared workspace. Organization owners, administrators, and other authorized collaborators can access information according to their roles and project permissions. The person who uploads a record is not necessarily the only person entitled to manage it.
Your organization controls membership, project access, and how its teams use shared records. It may retain business records after you leave a project or organization. Removing your account does not necessarily remove every mention of you from a shared record or delete documents that the organization needs to retain.
Contact your organization’s administrator about its use of project information, changes to shared records, or access decisions. You can also contact us about the information we handle and the assistance available for a privacy request.
6. Service providers and integrations
North Trail uses external services for parts of its operation. Depending on the environment and enabled features, these include:
- Supabase for authentication and database services.
- Cloudflare for application delivery, hosting, and file storage.
- Sentry for error and performance diagnostics when configured.
- Resend and Expo for email and mobile push delivery when enabled.
- Stripe for checkout, subscription billing, and payment administration when paid services are enabled.
- Google Fonts to deliver website fonts; font requests include the network information needed to serve them.
Optional integrations, such as Microsoft OneDrive, exchange authorized files and connection information when your organization connects and uses them. Connection credentials are used to perform the authorized operations. Disconnecting an integration stops its future use through that connection; it does not automatically erase files already imported or copies previously sent to the connected service.
This overview explains provider functions. Contact us if you need more detail about providers relevant to your organization or a particular feature.
7. Cookies and device storage
North Trail uses browser and application storage to keep sessions working, remember preferences and workspace selections, and support drafts, queued uploads, and offline project data. Depending on the client, this includes local storage, session storage, browser databases, and files or databases stored on your device.
Some connected-service authorization flows also use short-lived cookies to link a connection request to the browser that started it. Infrastructure and connected providers may process their own cookies or similar information as part of delivering their services.
You can manage cookies and site storage through your browser and application settings. Blocking or clearing them can sign you out, reset preferences, or remove downloaded content and unsynchronized work. Check that important work has synchronized before clearing storage or uninstalling the application.
Signing out restricts access to your session, but should not be treated as a guarantee that every local file, export, or pending draft has been erased. Use device access controls, especially on shared equipment.
8. Device permissions and notifications
Features such as taking a jobsite photo, choosing an existing image, or receiving push notifications may request device permissions. You can manage these permissions in your operating-system settings. Turning a permission off may prevent the associated feature from working.
Project notifications can contain project details. Consider the visibility of email inboxes and lock-screen previews on shared devices. Where notification preferences are available, use them to manage project alerts. Account, security, and service communications may still be needed to administer your account.
9. Retention and deletion
Retention depends on the type of information, the organization’s use of the service, contractual requirements, and security, accounting, dispute-resolution, or other legal needs. Account information, project records, billing history, diagnostics, and backups do not necessarily have the same retention period.
Account deletion is a request that requires review and processing. We may need to verify your identity, resolve organization ownership or administrator responsibilities, and determine which information can be deleted, anonymized, or must be retained. Subscription cancellation and deletion of personal information are separate actions.
Shared project history may remain with your organization. Backup copies, downloaded files, and records already transferred to others may follow different deletion processes. Contact us about the particular records involved rather than assuming that removing a user or deleting an item erases every copy immediately.
10. Your choices and privacy requests
Depending on the law that applies to you and the information involved, you may have rights to access, correct, delete, or receive a copy of personal information; object to or restrict certain processing; withdraw consent where processing relies on it; or raise a concern with a privacy regulator. Not every right applies to every record or request.
To make a request, email privacy@northtrail.dev. Tell us the account email, the organization involved, the type of request, and enough context to locate the relevant information. Do not send passwords, identity documents, or sensitive project files with your initial message.
We may ask for information needed to verify your identity or the authority of someone acting on your behalf. For organization-managed content, we may need to coordinate with the organization. We consider applicable rights, other people’s privacy, access permissions, and retention obligations when responding. If you disagree with a response, contact us to request a further review.
Account exports are scoped to your information and authorized access; they are not an unrestricted export of an organization’s confidential project records. You may also be able to update profile details or notification choices within the application.
11. Protecting information
North Trail uses authentication, permission checks, and controlled file access to limit access to account and project information. Operational records help investigate errors and security events. No online service, transmission method, or storage system can guarantee absolute security.
Keep account credentials private, protect devices, review collaborator access, and report suspected unauthorized access promptly to support@northtrail.dev. Please describe the issue without sending credentials or another person’s confidential information.
12. International processing
Using cloud infrastructure and external providers can involve processing information in countries other than the one where you live or work. Requirements and protections can differ by location. Contact us before uploading information subject to a specific residency or transfer requirement so that the applicable service arrangement can be assessed.
13. Children’s information
North Trail is intended for business use by construction teams and is not directed to children. If you believe a child has provided personal information through the service, contact privacy@northtrail.devso that we can investigate and address the request.
14. Updates and contact
We may update this notice as the service, our practices, or applicable requirements change. The version and update date appear at the top. Where required, we will provide additional notice or request an appropriate acknowledgment or consent for a change.
For questions about this notice or our handling of personal information, contact North Trail, LLC at privacy@northtrail.dev. For product or account support, use our Contact page.