Privacy Policy
DigProof is currently operated by DigProof LLC.
Overview
DigProof provides Digital Site Services for construction and civil-contracting organizations, including digital time clocks, jobsite presence and location features, safety and incident capture, fleet and equipment records, fuel tracking, delivery and approval workflows, and related reporting. This Privacy Policy explains what information we collect, how we use it, and the choices available to visitors and users.
This policy is not legal advice. It describes DigProof's practices; it does not create legal obligations on our customers or their personnel beyond what applicable law already requires.
Who operates DigProof
The DigProof platform and website are operated by DigProof LLC, based in Fuquay-Varina, North Carolina, United States. For privacy and legal notices, contact legal@digproof.io. For product support, contact support@digproof.io.
Information we collect
Account and organization information
Names, email addresses, phone numbers, user roles, account credentials, organization names, company account settings, jobsite assignments, and other authorized-user information that customers or their administrators provide when creating and managing accounts.
Location and presence information
GPS information, jobsite geofences, arrival and departure information, jobsite presence, location timestamps, and assigned-jobsite information collected when a user actively performs a location-enabled field action.
The current iOS field app does not collect continuous background location. It requests one current GPS fix when a user clocks in or out, requires one when a user submits a trench or equipment inspection, and may attach one to selected production or jobsite records while the user actively submits that record.
These location features support authorized workforce and jobsite-management purposes such as verifying attendance, tying safety inspections to the correct jobsite, coordinating crews, and producing accurate records.
Time and work information
Clock-in and clock-out records, time-clock exceptions, timesheets, hours worked, crew and foreman assignments, Weekly Expectations, progress and completion statuses, completion notes, approval records, and audit histories.
Jobsite documentation
Jobsite photos, proof photos, uploaded files, delivery tickets, invoices, receipts, safety-meeting records, incident reports, witness statements, injury-related information submitted by users, equipment records, fleet information, fuel information, delivery information, job timelines, approvals, and expense and reimbursement requests.
Payment information
Subscription information, billing status, transaction identifiers, and limited payment-related information received from Stripe. Stripe processes payment-card information on our behalf; DigProofdoes not need to directly store complete card numbers.
Technical information
Device information, browser information, IP address, security logs, authentication events, application-usage information, error and diagnostic information, cookie selections, and consent records.
Communications
Support requests, legal and privacy requests, general inquiries, feedback, bug reports, and other customer-service communications.
How we use information
- To provide, secure, and improve the DigProof platform and its features.
- To operate accounts, organization workspaces, roles and permissions, jobsite assignments, and presence/time features.
- To generate the records customers rely on — timesheets, safety and incident documentation, proof photos, approvals, delivery tickets, and audit histories.
- To communicate about the service, respond to support and legal requests, and send required notices.
- To detect, investigate, and prevent fraud, abuse, and security incidents.
- To comply with legal obligations and enforce our Terms of Service.
Authentication and security
DigProof uses Supabase to authenticate users, manage sessions, and enforce row-level access controls in our database. This is an essential part of the service; if a visitor denies optional cookies, essential authentication still functions. See our Cookie Policy for details.
Payments and Stripe
DigProof enterprise service is purchased outside the iOS app. Customer organizations may be invoiced directly or use Stripe, our third-party payment processor. When Stripe is used, payment-card details are collected through Stripe-hosted checkout and never touch DigProof servers. The iOS app does not collect payment-card information or offer purchases.
To complete a transaction, the following categories of information are shared with (or collected directly by) Stripe: name, email address, billing address, payment-method details, transaction amount and currency, and transaction identifiers. Stripe may also collect device, IP, and fraud-signal information as described in its own privacy notice.
Stripe processes this information as an independent controller under its own Privacy Policy. DigProof receives back only limited billing metadata — such as subscription status, plan, amount, currency, and transaction identifiers — which we use to activate access, reconcile billing, and provide customer support.
Retention
We retain information for as long as needed to provide the service, maintain the customer organization's records, comply with legal obligations, resolve disputes, and enforce agreements. Retention periods vary by data type: customer-owned jobsite documentation and audit records are retained for the life of the customer's workspace so those records remain available; an individual user's sign-in and personal profile are removed when that user deletes the account; and consent records are retained as required by law.
Your privacy rights
Depending on your location and role, you may have the right to request access to, correction of, or deletion of personal information about you, and to withdraw consent for optional technologies. Submit requests to legal@digproof.io. We may need to verify your identity before acting on a request and may decline requests where law permits or requires.
Authorized users can delete their individual DigProof account from the in-app Help & account screen. This removes the user's sign-in, personal profile, and company access. It does not cancel the customer organization's enterprise service or delete company-owned operational records; retained audit records use the replacement identity "Deleted user."
U.S. state privacy rights
Several U.S. states — including California, Colorado, Connecticut, Virginia, and Utah — provide privacy rights to their residents when the state's threshold requirements apply to a business. Where those laws apply to DigProof, eligible residents may have rights to know, access, correct, delete, or receive a copy of their personal information, and to opt out of certain uses. We do not sell personal information and do not use it for cross-context behavioral advertising. To submit a state-privacy request, contact legal@digproof.io. Nothing in this policy claims automatic applicability of any specific state statute regardless of the statute's legal thresholds.
Customer-organization responsibilities
The customer organization owns and controls the operational content in its workspace. DigProof hosts, stores, and processes that content on the customer's behalf to provide and secure the service.
When DigProof is used by an organization, that customer organization generally decides:
- Which employees and authorized users receive accounts.
- Which jobsites and geofences are created.
- Which users are assigned to which jobs.
- Whether location and presence features are enabled for their users.
- What workforce and jobsite information is submitted to the service.
- How their personnel are directed to use the service.
Customer organizations are responsible for:
- Providing legally required workplace notices to their personnel.
- Obtaining any required employee permissions or acknowledgments for location, presence, time, and documentation features.
- Using location, time, presence, incident, and documentation features lawfully.
- Configuring appropriate user roles and permissions.
- Responding to employee or workforce requests when the customer controls the relevant information.
When a request concerns information that a customer organization controls, we may direct the requester to that organization and, where appropriate, assist the customer in responding.
Children
DigProof is not directed to children and is not intended for use by individuals under the age of 16. We do not knowingly collect information from children.
United States operation
DigProof is operated from the United States. If you access the service from outside the United States, you understand that your information will be processed in the United States, which may have different data-protection rules than your country.
Security
We use reasonable technical and organizational safeguards to protect the information we hold, including encrypted transport, authenticated access, row-level authorization, and access logging. No system is perfectly secure, and we do not guarantee absolute security.
Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date above and, when appropriate, by additional notice through the service.
Contact
Privacy and legal requests: legal@digproof.io
Support: support@digproof.io
DigProof LLC · Fuquay-Varina, North Carolina, United States