Legal

Privacy Policy

Effective: July 17, 2026
Last updated: August 2, 2026

DigProof is currently operated by DigProof LLC.

Overview

DigProof provides Digital Site Services for construction and civil-contracting organizations, including digital time clocks, jobsite presence and location features, safety and incident capture, fleet and equipment records, fuel tracking, delivery and approval workflows, and related reporting. This Privacy Policy explains what information we collect, how we use it, and the choices available to visitors and users.

This policy is not legal advice. It describes DigProof's practices; it does not create legal obligations on our customers or their personnel beyond what applicable law already requires.

Who operates DigProof

The DigProof platform and website are operated by DigProof LLC, based in Fuquay-Varina, North Carolina, United States. For privacy and legal notices, contact legal@digproof.io. For product support, contact support@digproof.io.

Information we collect

Account and organization information

Names, email addresses, phone numbers, user roles, account credentials, organization names, company account settings, jobsite assignments, and other authorized-user information that customers or their administrators provide when creating and managing accounts.

Location and presence information

GPS information, jobsite geofences, arrival and departure information, jobsite presence, location timestamps, and assigned-jobsite information collected when a user actively performs a location-enabled field action.

The current iOS field app does not collect continuous background location. It requests one current GPS fix when a user clocks in or out, requires one when a user submits a trench or equipment inspection, and may attach one to selected production or jobsite records while the user actively submits that record.

These location features support authorized workforce and jobsite-management purposes such as verifying attendance, tying safety inspections to the correct jobsite, coordinating crews, and producing accurate records.

Time and work information

Clock-in and clock-out records, time-clock exceptions, timesheets, hours worked, crew and foreman assignments, Weekly Expectations, progress and completion statuses, completion notes, approval records, and audit histories.

Jobsite documentation

Jobsite photos, proof photos, uploaded files, delivery tickets, invoices, receipts, safety-meeting records, incident reports, witness statements, injury-related information submitted by users, equipment records, fleet information, fuel information, delivery information, job timelines, approvals, and expense and reimbursement requests.

Payment information

Subscription information, billing status, transaction identifiers, and limited payment-related information received from Stripe. Stripe processes payment-card information on our behalf; DigProofdoes not need to directly store complete card numbers.

Technical information

Device information, browser information, IP address, security logs, authentication events, application-usage information, error and diagnostic information, cookie selections, and consent records.

Communications

Support requests, legal and privacy requests, general inquiries, feedback, bug reports, and other customer-service communications.

How we use information

  • To provide, secure, and improve the DigProof platform and its features.
  • To operate accounts, organization workspaces, roles and permissions, jobsite assignments, and presence/time features.
  • To generate the records customers rely on — timesheets, safety and incident documentation, proof photos, approvals, delivery tickets, and audit histories.
  • To communicate about the service, respond to support and legal requests, and send required notices.
  • To detect, investigate, and prevent fraud, abuse, and security incidents.
  • To comply with legal obligations and enforce our Terms of Service.

Authentication and security

DigProof uses Supabase to authenticate users, manage sessions, and enforce row-level access controls in our database. This is an essential part of the service; if a visitor denies optional cookies, essential authentication still functions. See our Cookie Policy for details.

Payments and Stripe

DigProof enterprise service is purchased outside the iOS app. Customer organizations may be invoiced directly or use Stripe, our third-party payment processor. When Stripe is used, payment-card details are collected through Stripe-hosted checkout and never touch DigProof servers. The iOS app does not collect payment-card information or offer purchases.

To complete a transaction, the following categories of information are shared with (or collected directly by) Stripe: name, email address, billing address, payment-method details, transaction amount and currency, and transaction identifiers. Stripe may also collect device, IP, and fraud-signal information as described in its own privacy notice.

Stripe processes this information as an independent controller under its own Privacy Policy. DigProof receives back only limited billing metadata — such as subscription status, plan, amount, currency, and transaction identifiers — which we use to activate access, reconcile billing, and provide customer support.

Cookies and consent

DigProof uses Usercentrics as its consent-management platform. Visitors can Accept All, Deny optional technologies, make individual selections, and change or withdraw their choices at any time through the Cookie Settings control in the footer or the dedicated Cookie Policy page.

How information may be shared

We share information only as needed to operate the service or as required by law:

  • Service providers that host, store, secure, and support the platform, including Supabase (authentication, database, storage), Stripe (payments), Usercentrics (consent management), Resend (transactional email), OpenStreetMap and Nominatim (map display and jobsite address lookup), and infrastructure hosting used to run the website and application.
  • Customer organizations — content submitted through a customer's workspace (photos, timesheets, incidents, approvals, etc.) is available to that organization's authorized users according to the roles and permissions the customer configures.
  • Legal, safety, and enforcement — when required by law, subpoena, or to protect rights, safety, or property.
  • Business transfers — as part of a merger, acquisition, financing, or sale of assets, subject to customary confidentiality protections.

When an authorized administrator uses jobsite address lookup, the submitted jobsite address is sent to Nominatim only to return map coordinates. DigProof does not send the administrator's account profile or workforce records with that lookup.

DigProof does not sell personal information.

Retention

We retain information for as long as needed to provide the service, maintain the customer organization's records, comply with legal obligations, resolve disputes, and enforce agreements. Retention periods vary by data type: customer-owned jobsite documentation and audit records are retained for the life of the customer's workspace so those records remain available; an individual user's sign-in and personal profile are removed when that user deletes the account; and consent records are retained as required by law.

Your privacy rights

Depending on your location and role, you may have the right to request access to, correction of, or deletion of personal information about you, and to withdraw consent for optional technologies. Submit requests to legal@digproof.io. We may need to verify your identity before acting on a request and may decline requests where law permits or requires.

Authorized users can delete their individual DigProof account from the in-app Help & account screen. This removes the user's sign-in, personal profile, and company access. It does not cancel the customer organization's enterprise service or delete company-owned operational records; retained audit records use the replacement identity "Deleted user."

U.S. state privacy rights

Several U.S. states — including California, Colorado, Connecticut, Virginia, and Utah — provide privacy rights to their residents when the state's threshold requirements apply to a business. Where those laws apply to DigProof, eligible residents may have rights to know, access, correct, delete, or receive a copy of their personal information, and to opt out of certain uses. We do not sell personal information and do not use it for cross-context behavioral advertising. To submit a state-privacy request, contact legal@digproof.io. Nothing in this policy claims automatic applicability of any specific state statute regardless of the statute's legal thresholds.

Customer-organization responsibilities

The customer organization owns and controls the operational content in its workspace. DigProof hosts, stores, and processes that content on the customer's behalf to provide and secure the service.

When DigProof is used by an organization, that customer organization generally decides:

  • Which employees and authorized users receive accounts.
  • Which jobsites and geofences are created.
  • Which users are assigned to which jobs.
  • Whether location and presence features are enabled for their users.
  • What workforce and jobsite information is submitted to the service.
  • How their personnel are directed to use the service.

Customer organizations are responsible for:

  • Providing legally required workplace notices to their personnel.
  • Obtaining any required employee permissions or acknowledgments for location, presence, time, and documentation features.
  • Using location, time, presence, incident, and documentation features lawfully.
  • Configuring appropriate user roles and permissions.
  • Responding to employee or workforce requests when the customer controls the relevant information.

When a request concerns information that a customer organization controls, we may direct the requester to that organization and, where appropriate, assist the customer in responding.

Children

DigProof is not directed to children and is not intended for use by individuals under the age of 16. We do not knowingly collect information from children.

United States operation

DigProof is operated from the United States. If you access the service from outside the United States, you understand that your information will be processed in the United States, which may have different data-protection rules than your country.

Security

We use reasonable technical and organizational safeguards to protect the information we hold, including encrypted transport, authenticated access, row-level authorization, and access logging. No system is perfectly secure, and we do not guarantee absolute security.

Changes to this policy

We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date above and, when appropriate, by additional notice through the service.

Contact

Privacy and legal requests: legal@digproof.io
Support: support@digproof.io
DigProof LLC · Fuquay-Varina, North Carolina, United States