Legal

Privacy Policy

Practical policies for companies using Pillar OS to manage leads, projects, communications, financial workflows, and operational notifications.

Effective Date: July 21, 2026

This Privacy Policy explains how Pillar OS collects, uses, stores, shares, and protects information when customers and users access or use the Pillar OS platform, website, services, features, integrations, and related communications.

By using Pillar OS, you agree to this Privacy Policy.

1. Information We Collect and Process

We may collect the following types of information:

Account Information. This may include name, email address, phone number, company name, role, login credentials, account settings, and user permissions.

Company and Business Information. This may include company profile details, team members, customer records, leads, proposals, project information, tasks, approvals, financial workflow records, invoices, expenses, payments, documents, notes, communications, and related construction business data.

Billing Information. We may collect billing details, subscription status, seat count, payment metadata, transaction records, and related information through our payment processor.

We do not directly store full payment card numbers unless clearly stated otherwise by the payment provider.

Connected Financial Account Information. If a customer connects a financial account through Plaid, we may receive account names and types, partial account numbers, balances, transaction history, merchant information, and recurring-transaction information. We do not receive or store online banking credentials.

Uploaded Content. Customers may upload documents, photos, invoices, contracts, estimates, project files, receipts, images, or other business materials.

Usage and Technical Information. We may collect usage data, device information, browser type, IP address, login activity, pages viewed, feature usage, error logs, diagnostics, and other technical information needed to operate, secure, and improve the platform.

Support Communications. If you contact us, we may collect the contents of your messages, attachments, support requests, and related communications.

2. Data We Process for Customers

Pillar OS is a business software platform. Customers may use it to store and process their own business records, including construction project information, client and lead details, addresses, proposals, contracts, scopes, pricing, invoices, expenses, approvals, field logs, documents, photos, messages, vendor information, and subcontractor information.

This customer business data belongs to the customer. We process it to provide, support, secure, maintain, improve, and operate the platform, or as otherwise permitted by agreement, law, or customer instruction.

Customers are responsible for the accuracy, legality, and appropriateness of the data they enter intoPillar OS, including any client, employee, subcontractor, vendor, financial, or project information.

3. How We Use Information

We may use information to:

  • Provide and operate the Pillar OS platform.
  • Create and manage customer accounts.
  • Process subscriptions and billing.
  • Support onboarding, setup, training, and customer success.
  • Provide technical support and troubleshooting.
  • Improve platform features, workflows, usability, and performance.
  • Secure the platform and prevent unauthorized access.
  • Monitor usage, errors, and system performance.
  • Record proposal engagement, including viewing sessions, reading depth, PDF downloads, and voluntarily confirmed viewer identity, so customer teams can follow up.
  • Import, categorize, reconcile, and report connected-account activity requested by the customer.
  • Communicate about product updates, service changes, billing, security, and support.
  • Comply with legal, tax, regulatory, fraud prevention, and contractual obligations.

4. Google User Data and Google API Services

Connecting a Google account is optional. If a user chooses to connect Google, Pillar OS requests only the permissions needed for the features the user enables.

Google account information. We may access the connected account's name, email address, and basic profile information to identify the connection and show which Google account is connected.

Google Calendar data. If Google Calendar is connected, Pillar OS uses the Google Calendar Events permission to display events from the user's primary calendar, check availability for scheduling, and create or update project appointments and client meetings at the user's direction. Event details may include titles, descriptions, dates and times, locations, attendees, organizers, and Google Calendar links. The integration does not request permission to read Gmail messages or send email from the connected Google account.

Google user data is used only to provide and secure the connected features requested by the user. We do not sell Google user data, use it for advertising, transfer it to data brokers, or use it to create, train, or improve generalized AI or machine-learning models. Google Calendar event data is not sent to third-party AI providers. We share Google user data only with service providers acting on our behalf when reasonably necessary to operate or secure the requested Google Calendar feature, or when required by law.

OAuth access and refresh tokens are encrypted at rest. We retain connection metadata and tokens while the integration remains connected and retain synced business records according to the workspace's normal data retention settings. Disconnecting Google Calendar stops future access and removes the OAuth connection fromPillar OS. A user may also revoke access from their Google Account security settings. Previously created or synced business records may remain in the workspace until they are deleted by the customer or through an authorized deletion request.

Pillar OS's use and transfer of information received from Google Workspace APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

5. Customer Data Ownership

Customers retain ownership of the business data they submit to Pillar OS.

Pillar OS does not claim ownership over customer project records, client information, documents, proposals, estimates, invoices, expenses, messages, photos, field logs, or other business data uploaded or entered into the platform.

Pillar OS does not sell customer business data.

Mobile phone numbers, text messaging opt-in data, and SMS consent records are not shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent will not be shared with any third parties, except as needed to provide the messaging service, comply with law, or operate and secure the platform.

6. AI Features and Automated Assistance

Pillar OS may include AI-assisted features that help generate summaries, drafts, project notes, financial organization, task recommendations, workflow suggestions, and other business support.

When AI features are used, customer data may be processed by third-party AI providers or internal AI systems to complete the requested workflow.

AI outputs may be inaccurate, incomplete, or unsuitable for final use. Customers are responsible for reviewing and approving all AI-generated content before relying on it or sharing it with clients, employees, vendors, subcontractors, accountants, attorneys, or other third parties.

Customers should avoid entering unnecessary sensitive personal data into AI prompts and should verify all generated scopes, estimates, summaries, financial notes, messages, recommendations, and reports before using them for business, legal, financial, client-facing, or operational decisions.

7. Third-Party Services, Integrations, and Subprocessors

Pillar OS may connect with or rely on third-party services, including hosting providers, database providers, payment processors, authentication providers, email providers, storage providers, analytics tools, AI providers, and business integrations.

Customer data may be shared with these providers only as reasonably necessary to operate the platform, complete requested actions, process payments, provide support, or comply with legal obligations.

Depending on the customer's use of the platform, subprocessors may include providers in these categories:

  • Infrastructure, hosting, deployment, and network services.
  • Database, authentication, file storage, and backup services.
  • Payment processing, invoicing, subscription, and billing services.
  • Email, SMS, WhatsApp, and operational communications services.
  • AI, automation, transcription, summarization, and content-generation services.
  • Analytics, error monitoring, logging, diagnostics, and security services.
  • Customer support, onboarding, documentation, and business operations tools.

Specific provider lists may change over time as the platform evolves or as features are added, replaced, or retired. We expect subprocessors to provide appropriate security and confidentiality commitments for the services they perform.

Plaid provides the account-linking service for connected financial accounts. Plaid processes information according to its End User Privacy Policy. We use information received through Plaid only for customer-requested financial management, reporting, and automation.

Pillar OS is not responsible for the privacy practices, security practices, errors, outages, or data handling of third-party services outside our control.

8. Payments and Billing

Payments may be processed by third-party payment providers. Your payment information is handled according to the payment provider's terms and privacy practices.

We may receive and store payment metadata, subscription status, customer ID, invoices, receipts, seat count, billing plan, and transaction history.

9. Data Retention

We retain active workspace data for the contract term and generally provide a 30-day export and recovery window after verified cancellation or termination before deleting or de-identifying it from primary systems.

We may also retain certain information where needed for legal, tax, billing, audit, backup, fraud prevention, security, dispute resolution, or legitimate business purposes.

Backup copies, provider logs, diagnostics, and security records may remain for a limited period according to normal backup, security, and retention cycles before being deleted or overwritten.

Disconnecting an account stops future imports and removes the stored Plaid connection and imported bank-feed records. Expense or accounting records previously reviewed and created by the customer may remain as customer business records.

Typical retention periods include up to seven years for records subject to accounting, tax, contractual, or legal obligations; twelve months for authentication and material security-event records; ninety days for routine application and deployment logs where provider configuration permits; and two years after closure for support communications. Shorter periods apply where required by law, contract, or an authorized deletion request.

Proposal engagement history and voluntarily confirmed proposal-viewer identity are retained for up to 24 months after the recorded interaction, or for the active workspace term when needed for an ongoing customer relationship. They may be deleted or de-identified earlier through an authorized workspace request.

10. Data Exports and Deletion Requests

Customers may request a reasonable export of their business data, subject to technical limitations, account status, payment status, legal obligations, and platform policies.

Deletion requests may be limited where data must be retained for legal, billing, tax, security, backup, fraud prevention, or dispute-related reasons.

Exports may not include data that belongs to another customer, internal security logs, proprietary platform metadata, or third-party records that cannot reasonably be exported. Some retained records may be deleted only after normal backup and provider retention cycles complete.

11. Security

We use reasonable safeguards designed to protect information from unauthorized access, disclosure, alteration, misuse, or loss.

However, no platform, database, hosting provider, storage system, internet transmission, or electronic communication can be guaranteed to be completely secure.

Customers are responsible for protecting their login credentials, devices, internal access, user permissions, and employee or subcontractor activity.

12. Confidential Business Information

Customer business data may include confidential project, client, financial, pricing, vendor, subcontractor, or operational information.

We will use reasonable efforts to protect such information and use it only for legitimate platform, support, security, legal, or business purposes.

13. Communications

We may send service-related emails, billing notices, security alerts, product updates, onboarding messages, and support communications.

Some service-related communications are necessary and may not be fully opt-outable while using the platform.

14. SMS Messaging Privacy

Pillar OS may collect mobile phone numbers and SMS consent records for transactional SMS notifications and updates. Examples include dispatch, field logs, project updates, appointment reminders, proposal notifications, vendor coordination, subcontractor reminders, account notifications, and related project-management communications.

Mobile information and SMS consent are not shared with third parties or affiliates for marketing or promotional purposes.

Text messaging originator opt-in data and consent will not be shared with any third parties.

Message frequency may vary. Message and data rates may apply. Reply STOP to opt out, HELP for help.

15. Children's Privacy

Pillar OS is intended for business use and is not directed to children under 13. We do not knowingly collect personal information from children.

16. Changes to This Policy

We may update this Privacy Policy from time to time. Updated versions may be posted on our website or provided through the platform.

Continued use of Pillar OS after changes are posted means you accept the updated policy.

17. Contact

Questions about this Privacy Policy can be sent to:

privacy@pillaros.app