Privacy Policy
This policy explains how Scope-to-Go handles information when facility professionals use the service to scope projects, solicit proposals, compare contractor responses, and prepare approval records.
Information we collect
We collect pilot-request information such as name, work email, organization, facilities role, facility-count range, and the project challenge submitted; founder application notes; pilot feedback; account identity information; organization and membership information; project scopes, facility details, contractor contacts, proposals, uploaded documents, clarification records, recommendations, onboarding progress, product usage, audit events, and billing status. Payment-card information is entered directly into Stripe-hosted services and is not stored by Scope-to-Go.
Contractor submissions
When a contractor uses a secure proposal link, Scope-to-Go processes the contractor identity supplied by the requesting organization, the proposal PDF, optional submission notes, submission and replacement timestamps, and an audit record of the accepted submission terms. Expiring one-way identifiers derived from the secure link and network request may be used to limit abusive upload attempts; raw network addresses are not stored in the submission-limit record.
Public-site analytics
Scope-to-Go records privacy-conscious, aggregated counts for public page views, product-tour plays, pilot-form starts, and submitted pilot requests. These counts help evaluate whether the public page is useful. Raw IP addresses and full referring-page URLs are not stored as analytics data.
How information is used
Information is used to review pilot applications, provision invitation-only workspaces, follow onboarding and first-project milestones, respond to pilot feedback, provide and secure the service, isolate customer workspaces, generate requested AI assistance, process subscriptions, communicate service information, troubleshoot problems, enforce plan limits, preserve audit history, and comply with legal obligations.
AI processing
When an authorized user requests AI assistance, relevant project text or contractor documents may be sent to OpenAI’s API to produce the requested output. Users must avoid submitting information they are not authorized to process. AI output must be reviewed by a qualified person before procurement, contracting, safety, legal, or financial decisions are made. OpenAI states that API business data is not used to train its models by default.
Service providers
Scope-to-Go uses infrastructure and service providers to operate the application, including OpenAI for AI processing, Stripe for subscription billing, and hosting and storage providers for application delivery and customer files. These providers process information under their own agreements and privacy practices.
Customer control and retention
Organization administrators can select document-retention settings, manually delete uploaded proposal PDFs, and export organization records. Deleting a PDF removes the stored file while retaining the proposal’s normalized comparison data and audit record. Some information may be retained when required for security, fraud prevention, legal compliance, backup integrity, or dispute resolution.
Security
Scope-to-Go uses authenticated access, organization-level authorization, protected storage paths, non-cacheable customer responses, signed billing webhooks, and activity records. No internet service can guarantee absolute security, and customers remain responsible for managing authorized users and the sensitivity of submitted information.
Sharing and disclosure
Scope-to-Go does not sell customer project data. Information may be shared with authorized organization users, service providers needed to deliver the service, or authorities when legally required. Data may be processed in the United States or other locations where service providers operate.
Your choices
Organization administrators may correct account information, manage members, export records, change document-retention settings, and request account closure. Requests concerning access, deletion, or privacy can be sent to thesimpletim@gmail.com.
Changes
This policy may be updated as Scope-to-Go develops. Material changes will be communicated through the service or another reasonable channel, and the effective date will be revised.