- The app is local-first and stores business data in an encrypted local database.
- Authorized records can sync through Firebase according to company, role and project permissions.
- Android release builds may send crash diagnostics to Firebase Crashlytics.
- We do not sell personal information or use advertising SDKs in the current app.
- Users can delete personal sign-in accounts; company records may remain under the company’s control or legal retention duties.
1. Scope and controller
This policy applies to the Construction ERP Android application, Windows application and public website published by REPLACE WITH YOUR LEGAL PUBLISHER NAME. The company or organization using the app is responsible for deciding what construction-business information its authorized users enter and how that information is lawfully used.
2. Information processed
Account and identity
Email address, display name, authentication identifiers, sign-in provider, company memberships, staff profile, role, project assignments, access status and device registration metadata.
Business and user content
Information entered into the ERP, including tenders, projects, Daily Diary and DPR records, BOQ and measurements, material and stock records, supplier and subcontract records, labour and attendance, machinery and fuel, billing, finance, safety, quality, documents, actions, reports and audit history. This content may include names, phone numbers, identifiers, commercial details and financial records supplied by the customer organization.
Device, security and synchronization
Device identifier, platform, app/schema version, synchronization status, versions, timestamps, permission context, conflict metadata and security information needed to authenticate, authorize, order and recover synchronized changes.
Diagnostics
In Android release builds, Firebase Crashlytics may receive crash details, stack traces, app/device context and related diagnostics. The Windows app records errors locally unless another configured service is explicitly introduced in a future release.
Website information
The static website uses no analytics, advertising trackers or website account system by default. When a visitor submits the support form, the entered name, reply email, platform, topic, company/project and message are sent to FormSubmit for delivery to the publisher’s support inbox. The hosting provider and form-delivery provider may process standard technical logs according to their own policies. Do not include passwords, OTPs, private keys, recovery passwords or complete payment details.
3. Why information is used
- Authenticate users and maintain company memberships.
- Provide ERP workflows, calculations, approvals, reports and exports.
- Enforce company, role, entity and project permissions.
- Synchronize authorized records between devices and resolve conflicts.
- Protect accounts, investigate errors, maintain audit history and recover failed synchronization.
- Create and restore user-requested encrypted backups.
- Respond to support, security and account-deletion requests.
- Meet applicable contractual, safety, tax, audit or legal obligations.
4. Local storage, cloud sync and attachments
The app is local-first. Business records are stored in an encrypted SQLite database on the device. When Firebase services are available and the user is authorized, account metadata and versioned business changes may be synchronized through Cloud Firestore. Google Sign-In is available only on Android when enabled; Windows uses email/password authentication.
Firebase Storage is not included in the current release. Attachment bytes and site-photo files are not cloud-synchronized. Supported local file bytes may be included in a user-created encrypted .construction.erp backup, subject to product limits.
5. Service providers and disclosures
Information may be processed by service providers used to operate the app, including Firebase Authentication, Cloud Firestore, Firebase App Check and Android Firebase Crashlytics. These providers act under their applicable terms and security measures. Information may also be disclosed when required by law, to protect users or the service, or as part of a lawful business transfer with appropriate safeguards.
We do not sell personal information, rent it to advertisers or include an advertising SDK in the current app.
6. Security
Security measures include an encrypted local database, secure device key storage, password-encrypted backups using Argon2id and AES-256-GCM, Firebase authentication, App Check support, company and project permission rules, versioned synchronization, immutable delta controls, conflict review and audit records. No method of storage or transmission can be guaranteed absolutely secure.
7. Retention
Personal identity and access metadata are retained while needed to operate the account, secure the service, meet legal obligations and resolve disputes. Account deletion removes supported personal identity and membership metadata as described below. Company business records may remain under the organization’s control for contractual, safety, audit, tax, payroll, regulatory or legal reasons. Backup files remain wherever the user saved them until the user deletes them.
8. Choices, access and deletion
Users can update appropriate profile and business information through the app, subject to role and audit controls. Users can delete their personal sign-in account from Account settings or follow the account deletion instructions. Active company owners must transfer ownership or close the workspace before personal account deletion.
Depending on applicable law, users may request access, correction, restriction, objection or deletion by contacting baishalya@gmail.com. We may need to verify identity and company authority before acting.
9. Children
Construction ERP is a business application for construction companies and authorized staff. It is not directed to children.
10. International processing
Firebase and hosting providers may process information in locations outside the user’s country. The publisher and customer organization are responsible for using appropriate contractual and legal safeguards where required.
11. Policy changes
We may update this policy when features, service providers or legal obligations change. The updated date will be shown at the top. Material changes should be communicated through the app, store listing, website or customer channel as appropriate.
12. Contact
REPLACE WITH YOUR LEGAL PUBLISHER NAME
App: Construction ERP
Support and privacy email: baishalya@gmail.com
Website: https://REPLACE-WITH-YOUR-SITE-URL