SimplySite Reports

Privacy Policy

Last updated: August 17, 2026

This Privacy Policy explains what information SimplySite Reports ("we," "us," "our") collects, how we use it, and the choices you have. It applies to the SimplySite Reports app (web and mobile) and website (the "Service"). By using the Service you agree to this Policy.

1. The short version

2. Information we collect

Account information. Your email address and a cryptographically hashed password (we never store your actual password). Session tokens are stored hashed on our servers.

Billing information. Payments are processed by Stripe. We receive and store your Stripe customer ID, subscription plan, and subscription status. We never see or store your full card number. Stripe's handling of your payment details is governed by Stripe's Privacy Policy.

Usage counters. Minimal event counts (such as "app opened" or "report exported") tied to your account — no content, no coordinates, no photos. On Basic plans we also count report sends to enforce plan limits.

Procore integration (optional, Pro plan). If you connect your Procore account, we store the authorization tokens Procore issues, along with basic profile details of the connected Procore account (name, email, and account ID), so the app can act on your behalf — importing project details you select, filing reports and export bundles you choose into your Procore project documents, and recording entries you create in the app (inspection checklist responses, observations, punch items and their photos, and daily log entries) into your Procore project. We do not store your Procore password (the connection uses Procore's standard sign-in), and we do not copy your Procore data to our servers beyond fulfilling the action you request. When you file a report or export bundle into your Procore project documents, the file itself is transferred directly from your device to Procore's storage service — the document's contents do not pass through or reside on our servers; our server only arranges the upload with Procore and confirms it (handling file name, type, and size, never the contents). In the rare case a direct upload cannot complete, smaller files may be delivered through our server transiently as a fallback and are never retained. Smaller entries you record (inspection responses, observations, punch items and their photos, and daily log entries) pass through our server transiently for delivery and are not retained. If an entry cannot be delivered right away (for example, while offline), it stays on your device — not on our servers — until it syncs or you discard it. Every action uses your own Procore account and is limited by the permissions your Procore administrator has granted you. Disconnecting Procore in the app deletes the stored tokens and connection details from our servers. Procore's handling of content delivered to it is governed by Procore's Privacy Notice.

Inspection content (stored on your device only). Photos, videos, floor plans, notes, item titles, severities, and location data you capture are stored on your device (or in your browser's local storage on web). When you export a report on the web, the file passes through our server transiently to deliver your download and is not retained.

3. Location and camera data

4. How we use information

We do not sell personal information, and we do not share it with third parties for their own marketing.

5. Sharing

We share information only with: (a) Stripe, to process payments; (b) infrastructure providers that host our servers and database; (c) Procore, but only if you connect the optional Procore integration and only the content you direct us to send there (project imports, filed reports and bundles, and entries you record in your Procore project); and (d) authorities when required by law or to protect our rights, users, or the public. Reports and bundles you choose to share (via email, messaging, ZIP export, etc.) are shared by you, under your control.

6. Subprocessors and data locations

Your inspection content (photos, videos, floor plans, report text) is stored on your device, not on our servers — so most of it never reaches any third party unless you export or file it yourself. The limited data we do process (account records, subscription state, usage counters) is handled by the following subprocessors:

SubprocessorPurposeData involvedLocation
Replit (on Google Cloud Platform)Application hostingAccount records, session tokens, usage countersUnited States
Neon (on AWS/GCP), via ReplitManaged PostgreSQL databaseSame as aboveUnited States
StripePayment processingName, email, payment card data (card data never touches our servers)United States; global card networks as required
Google (Gmail API)Transactional email (password resets, receipts)Email address, message contentUnited States / Google global infrastructure
Apple (App Store / TestFlight)App distributionNo customer inspection dataUnited States / global CDN
Expo (EAS)App builds and updatesApplication binaries only; no customer dataUnited States
ProcoreOptional, customer-initiated integrationOnly content you explicitly file to your own Procore accountUnited States

We rely on each provider's standard Data Processing Agreement and independently audited certifications (e.g. Stripe: PCI-DSS Level 1; Google Cloud: ISO 27001, SOC 2; AWS/Replit infrastructure: SOC 2), which obligate encryption in transit and at rest, breach notification, and confidentiality protections at least as strong as our own practices. We will update this list if our subprocessors change.

7. Data retention and deletion

8. Security

Passwords are hashed with a modern memory-hard algorithm (scrypt); session tokens are stored hashed; connections use HTTPS; subscription state is written only from verified payment-processor events. No system is perfectly secure, but we design so that a breach of our servers would not expose your inspection content — because it isn't there.

9. Children

The Service is a professional tool intended for adults. It is not directed to children under 13 (or the applicable age in your jurisdiction), and we do not knowingly collect personal information from them.

10. Your rights

Depending on where you live, you may have rights to access, correct, delete, or port your personal information. Because we store so little, the fastest path is usually the in-app account deletion, which removes everything we hold about you. For anything else, contact us at the address below and we will respond as required by applicable law (including the CCPA and GDPR where they apply). We do not discriminate against you for exercising your rights.

11. Changes to this Policy

We may update this Policy from time to time. We will post the updated version with a new "Last updated" date and, for material changes, provide additional notice where appropriate.

12. Contact

Privacy questions or requests: admin@simplysitereports.com (or simplysitereports@gmail.com)