1. Who we are
SiteGlance is operated in the United Kingdom. We provide a cloud-based project reporting and dashboard service for construction professionals. References to “we”, “us”, and “our” mean SiteGlance. Contact: support@siteglance.co.uk
2. What data we collect
- Account data: Name, email address, and company name provided on signup.
- Project data: Project names, timelines, stage progress, cost figures, risk registers, status notes, highlights, concerns, and weekly update summaries you create.
- Site photos: Images you upload to project dashboards. EXIF metadata (including GPS location) is stripped on upload.
- Access logs: When your shared dashboard links are viewed — including viewer email (if email-gated), IP address, and timestamp.
- Session data: Authentication session tokens, login timestamps, and IP addresses for security purposes.
- Usage data: Aggregated, anonymised usage information to help us improve the product. No individual behaviour is profiled or sold.
- Payment data: Handled directly by Stripe. We do not store card numbers or payment credentials.
3. How we use your data
- To provide and operate the SiteGlance service.
- To send transactional emails — account verification, share link magic links, stale project reminders, and viewer access notifications — via Resend.
- To process subscription payments via Stripe.
- To generate AI-assisted update summaries when you choose to use that feature (see Section 4).
- To display site weather information based on your project postcode via OpenWeatherMap.
- To improve the product through aggregated, anonymised analytics.
- We do not sell your data. We do not use your project content to train AI models.
4. AI processing
When you use the AI draft feature, your project data — including stage names, progress percentages, status notes, highlights, concerns, and next-week plans — is sent to the Google Gemini API (operated by Google LLC) to generate a draft weekly update summary. This feature is available on paid plans only. Google does not use API request data to train their models under their API terms of service. No project data is retained by Google after the request completes. You can review Google’s data handling at ai.google.dev/terms.
5. Data storage and security
- All data is stored on encrypted servers hosted in the United Kingdom.
- Data is encrypted in transit (TLS 1.3) and at rest (AES-256).
- Access is controlled by role-based permissions. Your organisation’s data is never accessible to any other organisation on the platform.
- Photos are stored server-side and served via authenticated or token-scoped URLs only.
6. Data retention
We retain your data for as long as your account is active. If you delete your account, all your data — including projects, stages, photos, and updates — is permanently deleted within 30 days. You can initiate account deletion at any time from the Profile settings page. A GDPR data export is also available from your profile before deletion.
7. Your rights (UK GDPR)
Under UK GDPR you have the right to: access your personal data, correct inaccuracies, request erasure, restrict or object to processing, and data portability. To exercise these rights, use the tools in your Profile settings page (data export and account deletion are self-service) or contact us at support@siteglance.co.uk. We will respond within 30 days.
8. Cookies
We use only essential cookies: a session token for authentication, and short-lived tokens for PIN and email verification on shared project links. We do not use tracking, analytics, or advertising cookies of any kind.
9. Sub-processors
We use the following third-party services to deliver SiteGlance. All are bound by appropriate data processing agreements.
- Google LLC (Gemini API) — AI summary generation. US-based. No data retention after request completes. API terms prohibit use for model training.
- Stripe — Payment processing. US/EU. PCI DSS Level 1 certified.
- Resend — Transactional email delivery. US. Used for magic links, verification, and notifications only.
- OpenWeatherMap — Site weather data. EU. Only a project postcode is sent; no personal data.
10. Changes to this policy
We may update this policy from time to time. We will notify you by email if we make material changes. The “Last updated” date at the top of this page reflects the most recent revision.