Privacy
Last updated 20 August 2026
Foorsite is construction project management software. This page says what we collect, why we have it, who else it reaches and how long we keep it. It describes what the software actually does today, not what we intend it to do.
Who we are
Foorsite is operated by [registered company name], registered in [jurisdiction] with company number [company number], at [registered address]. For anything on this page, write to [privacy contact address].
For data protection purposes we are the controller of the account data described below. For the project content your company uploads, your company is the controller and we act as processor on its instructions.
What we collect
Account details. Your name, email address and the company you belong to, so you can sign in and colleagues can see who did what.
Project content. Everything you put into a project: documents, drawings, programmes, site diaries, snags, RFIs, photographs and commercial records. Some of this is personal data about identifiable people — names on a site diary, who signed an induction, who raised a snag.
Site attendance and inductions. When someone signs in at a site gate or completes an induction, we record their name, the company they work for, their trade, the time, and — if their device offers it — the location of the sign-in. An induction may also record a phone number, an email address, a CSCS card number and a signature. People signing in this way often have no Foorsite account; the record is made on behalf of the company running the site.
Technical data. IP address, browser type and pages visited, as part of normal operation and error monitoring.
We do not hold card numbers. Payment details are entered directly with Stripe.
Why we are allowed to hold it
We hold account and project data to perform the contract with your company. We hold technical and error data on the legitimate interest of keeping the service working and secure. Where we ask for consent — for optional communications — you can withdraw it at any time.
Artificial intelligence
Foorsite uses AI to answer questions about a project, review documents, draft text and read uploads. This means the content being worked on is sent to a third-party AI provider to be processed. In practice that includes document and drawing text, PDFs, site photographs, chat messages, forwarded emails and register data such as snags and RFIs. Voice notes are sent for transcription. Documents indexed for search are sent to generate that index.
Two things follow from that, and we would rather say them plainly. First, if you put something into Foorsite, expect the AI features to be capable of reading it. Second, AI output can be wrong, incomplete, or confidently mistaken. Everything the AI produces is advisory and cited back to source documents so you can check it. It is not professional, legal or safety advice, and it does not take decisions — a person reviews and approves.
Who else your data reaches
These are the third parties customer data actually reaches, and what each one receives.
| Provider | What it does | What it receives |
|---|---|---|
| Anthropic (Claude) | The AI features: answering questions about a project, reviewing documents, drafting text. | Whatever the feature is working on — document and drawing text, PDFs, site photos, chat messages, forwarded emails, and register data such as snags and RFIs. |
| OpenAI | Turning documents into a searchable index, and transcribing voice notes. | The text of every document indexed for search, every question asked of that search, and any audio recorded for a voice note. |
| Supabase | The database, file storage and sign-in that the product runs on. | All account and project data, and every uploaded file. |
| Vercel | Hosting. Every request to the application passes through it. | All traffic, including IP addresses and request metadata. |
| Resend | Sending notification and invitation email. | Recipient email addresses and the contents of those messages. |
| Stripe | Subscription billing. | Billing contact and payment details. Card numbers are entered directly with Stripe and are never held by us. |
| Sentry | Error monitoring, so faults are noticed and fixed. | Error reports with technical context. When an error occurs, a replay of that browser session may be captured, which can include what was on screen at the time. |
| PDF extraction service | Reading text and programme data out of large PDFs, which is too slow to do in the main application. | The PDF being processed. |
| OpenWeatherMapcalled by your browser | Showing site weather on the dashboard. | The approximate location of the site being viewed. Called from the browser. |
| OpenStreetMapcalled by your browser | The small map shown against a project. | The project location, and the fact that a browser loaded that map. |
We do not sell personal data and we do not use it for advertising. Foorsite loads no analytics or advertising trackers: There are none. No Google Analytics, Plausible, PostHog or similar is loaded anywhere in the product.
How long we keep it
Project records are kept for as long as your company has an account with us, because a construction record generally has to outlive the job it belongs to. When an account is closed we delete it on request as described below; otherwise project content is removed [retention period after account closure — a commercial decision] after closure.
Error reports and technical logs are kept for a short period only, in line with our providers' defaults.
Your rights
You can ask for a copy of your personal data, ask us to correct it, ask us to delete it, or object to how we use it. Signed-in users can do the first and the third from Settings, at any time and without asking: download everything we hold about you, or delete your account. Deletion shows you exactly what was removed and what was kept. If you have no account — for example you signed in at a site gate — contact the company running that site, or write to us and we will help.
Deleting an account removes your sign-in, your personal profile, your profile photo, your assistant conversations and your notifications. Work records that belong to the business — a diary entry, a snag, an approval — are kept, but your name no longer attaches to them, because a construction project has to keep a coherent record of what happened. Site induction and attendance records are held for the company running that site rather than for us, so we cannot delete their safety evidence on our own initiative; ask them, and we will help if they need us to.
If you think we have handled your data badly, please tell us first so we can put it right. You also have the right to complain to a supervisory authority — [relevant authority, e.g. the ICO in the UK].
Security
Access is restricted to your own company's projects, checked on the server for every request. Files are held in private storage and served through short-lived links. Passwords are handled by our authentication provider and never stored by us. We describe our security practices in more detail on request, and welcome reports of problems — [security contact address].
Changes
If this page changes in a way that matters, we will say so rather than quietly editing it. The date at the top is the last change.