Privacy Policy
Last updated September 5, 2026
1. Scope and responsibilities
Spectura LLC provides construction management software for United States contractors. This notice explains personal information handled through our website and service, including information about account holders, customer contacts and workers whose information a customer provides.
We determine how information is used for our account administration, billing, security and direct communications. Customers direct the use of their organization's project, employment and payroll records and decide which authorized users may access them. We process those records to provide the service. Your employer or contractor may have its own privacy notice and responsibilities; the applicable controller, processor, business or service-provider role depends on the activity and law.
2. Information and sources
Information comes from you, your employer or other customer administrators, connected services and your use of the service. Depending on the features used, it includes:
- Account and workforce profiles: names, emails, profile images, organization membership, roles, job titles, preferences, onboarding progress, safety acknowledgments, and emergency contact names and telephone numbers.
- Payroll and worker identity: time entries, work classifications, wage rates, earnings, deductions, payment records and certified payroll reports. Dedicated worker identity fields hold the last four digits of a Social Security number, home address and date of birth. They do not collect a full Social Security number.
- Customer business records: projects, contacts, vendor information, tax identifiers where provided, financial records, estimates, requests for information, submittals, uploaded documents and their contents.
- Billing and integrations: billing contacts and addresses, payment-method references and limited payment details, invoice and transaction records, and information exchanged with services a customer connects, such as QuickBooks. Payment forms are provided through Stripe.
- Communications and technical information: inquiries, demo and support messages, account notices, session information, IP addresses, browser and device information, access and audit activity, errors and performance data.
Please provide only information needed for the task. Do not place passwords, full Social Security numbers or unnecessary sensitive information in general documents, messages or support emails.
3. Purposes
We use information to administer accounts and access, operate project and workforce workflows, prepare payroll records at a customer's direction, process billing and authorized integrations, respond to inquiries, send service communications, maintain reliability, prevent fraud and unauthorized access, investigate incidents, and address applicable legal and recordkeeping obligations. Emergency contacts support job-site emergency communication. Optional browser diagnostics help identify service failures.
4. Disclosures
Information is available to authorized customer users according to their access rights and to providers that support hosting, storage, email, payment processing, analytics, security and error monitoring. Connected integrations receive information through the workflows a customer authorizes. Customers control their own reports and exports and may disclose them to project participants, payroll recipients or government agencies.
We may also disclose information when required by law, to investigate misuse or protect legal rights, or in connection with a business transfer. We do not use third-party advertising cookies. Contact us to request a customer data processing addendum and information about the providers, processing locations and retention arrangements relevant to your use of the service.
Depending on configuration and the features used, providers include Cloudflare for delivery, storage and security, Resend for email, Sentry for diagnostics, Mapbox for address suggestions, and Stripe for payments. Address suggestions send entered address text to Mapbox. Password-security checks send a short hash prefix to Pwned Passwords, without sending your password, complete hash or email address. Google or Microsoft sign-in and QuickBooks exchanges depend on the services you or your organization authorize. Providers may have separate responsibilities for some of their activities.
5. Security
The service uses authenticated access, organization and project permission checks, recent sign-in checks for sensitive actions, and audit records for sensitive access. Dedicated worker SSN last-four, home-address and date-of-birth fields are encrypted by the application, as are certain integration secrets and tax identifiers. These controls do not mean that every stored field or uploaded document is encrypted by the application. We also use controls to reduce sensitive information in diagnostic reports. No security measure eliminates every risk.
6. Retention
Retention depends on the information, the customer's use of the service, and applicable recordkeeping, contractual and legal requirements. Offboarding a worker preserves payroll, timesheet and authorship history. Closing an account or submitting a deletion request does not automatically remove an employer's records. Payroll, financial, security and audit records may need to remain, including under a legal hold. We review requests with the responsible customer to determine which information can be deleted, returned or restricted and which must be retained. A customer's duty to keep an authoritative payroll record does not automatically require every service copy to remain.
Notifications and saved digest copies have a configurable retention period, with a default of 180 days. Account credentials, profile information, project files, accounting records and backups follow separate purposes and disposal reviews. A credential's expiration does not mean its stored record has been erased. We consider backup and provider copies when completing a deletion request and explain information that must remain and the applicable reason.
7. Privacy requests and account tools
Depending on applicable law and our role, you may have rights to know about and access personal information, receive a copy, correct inaccuracies, request deletion, and limit, restrict or object to particular uses. Where processing relies on consent, you can withdraw it. Applicable laws may also provide rights concerning sale or sharing, sensitive information and non-discrimination when exercising rights.
Signed-in users can open Settings → Profile → Privacy requests to download an account JSON export or submit an account deletion review request. The export includes account and membership profiles, session metadata, preferences, onboarding progress and a limited summary of your audit activity. It excludes encrypted payroll identity fields and organization-managed timesheets, payroll, project records and document contents. It is not a complete response to every privacy access request.
A deletion review request records your request and provides a reference; it does not delete your account or schedule automatic erasure. We verify the account email and may require a recent sign-in. Ownership transfers and records that must be retained are considered during review.
For additional access, corrections, worker records, other rights, follow-up, or requests without a Spectura account, contact your organization administrator or [email protected]. Tell us the request type and enough information to locate the relevant account or customer. We may need proportionate identity or authority verification and coordination with the customer responsible for the records. Do not send a full Social Security number or password. Applicable exceptions and response periods depend on the request and law.
8. Cookies and diagnostics choices
Essential cookies and storage support authentication, security and preferences. Where configured, Cloudflare Web Analytics measures website activity. Optional browser error and performance monitoring through Sentry starts only after you accept it. Use Privacy choices in the footer to change that choice or withdraw it for future browser monitoring. Withdrawal does not retrieve information already sent.
Server and edge diagnostics used for service operation and security continue independently of the optional browser choice. Our diagnostic filters remove or reduce known sensitive fields, email addresses and IP detail, but do not make all processing anonymous. Providers may receive network information when handling requests. Stripe's payment form loads when needed for a payment workflow; rejecting optional error monitoring does not disable that payment workflow.
9. Processing locations and external services
Information may be processed in the United States and other countries where service providers operate. Laws and protections can differ by location. Contact us for information relevant to your customer relationship. External websites and independently connected services have their own privacy practices.
10. Children
The service is marketed to businesses, not children. If you believe information about a child has been provided improperly, contact us so the circumstances, the customer's responsibilities and any required response can be reviewed.
11. Changes and contact
We post policy changes on this page and update the date above. Material changes may also be communicated through the service or by email. Send privacy questions and requests to [email protected].
Spectura LLC