DocuSub
Privacy Policy
Effective date: August 7, 2026
This Privacy Policy explains how DocuSub (“DocuSub,” “we,” “us,” or “our”) collects, uses, stores, and shares information when you use the DocuSub Document Tracker web application at www.docusub.com and related subdomains or embed experiences (the “Service”).
DocuSub is a multi-tenant portal for general contractors (GCs) to define project document requirements, invite subcontractors, collect PDF uploads, review submissions, track payment-readiness status for documents, and send related notifications. It is not a payment processor or banking product.
1. Who this policy covers
- GC users (tenant admins and staff) who create accounts, manage projects, and review documents.
- Subcontractor users invited to upload documents for assigned projects.
- System administrators who operate the platform (tenant and template management).
- Visitors to public pages (home, login, signup, legal pages, and optional embed login).
When a GC organization uses DocuSub, that organization typically acts as the controller of project and subcontractor business data it enters or receives through the Service. DocuSub processes that data to provide the Service.
2. Information we collect
Account and profile information
- Email address and password (passwords are handled by our auth provider; we do not store plaintext passwords).
- Role within the Service (for example GC admin, GC staff, sub user, or system admin).
- Association to a tenant (GC organization) and, for subcontractors, a subcontractor company.
Organization and project data
- GC company name, unique slug, branding (logo URL, colors), and optional embed settings.
- Tenant notification email addresses used for platform alerts (for example upload-activity notices).
- Projects, categories, document requirements, templates, and assignment of subcontractors to projects.
- Subcontractor company details such as name, contact email, phone, and notes entered by the GC.
Documents and review activity
- PDF files and related metadata uploaded to fulfill document requirements (including version history, uploader notes, and optional expiration dates).
- Review decisions (approve, reject, reopen, waive, and similar status changes), comments, and related timestamps.
- Audit-style event records generated by the application for operational history.
Email and mailbox connection data
- Auth and invite mail: invite and password-reset messages sent through our authentication provider’s mailer (or configured custom SMTP).
- Platform transactional mail: operational alerts (such as upload-activity digests) sent via our email delivery provider (Resend) to addresses configured by the tenant.
- GC mailbox OAuth: if a GC connects Gmail or Outlook under Settings, we store OAuth tokens (encrypted at rest) so the Service can send reminders, reject/reopen notices, expiration reminders, and related messages from the GC’s connected mailbox. Scopes are limited to send-mail capabilities (not full mailbox read access for unrelated purposes).
- Queued notification records used to batch and deliver those emails.
Technical and usage data
- Session cookies and authentication tokens required to keep you signed in.
- Server logs, request metadata, and error diagnostics from our hosting environment.
- Security-related signals used for rate limiting, same-origin checks, and abuse prevention.
3. How we use information
- Provide, operate, secure, and improve the Service.
- Authenticate users and enforce role- and tenant-based access controls.
- Store and display project requirements, uploads, and review status (including payment-readiness indicators derived from document status).
- Send transactional emails and, when connected, send mail on behalf of a GC mailbox.
- Run scheduled and delayed jobs (for example batch notification wakeups) needed for reminders and catch-up processing.
- Support customer administration, troubleshooting, and platform operations.
- Comply with law and enforce our Terms of Service.
4. How we share information
We do not sell personal information. We share data only as needed to run the Service:
- Within a tenant: GC users see data for their organization; subcontractor users see data scoped to their company and assigned projects.
- Infrastructure providers: hosting and edge delivery (Vercel), database/auth/file storage (Supabase), delayed job scheduling (Upstash QStash), transactional email (Resend), and—if you connect a mailbox—Google or Microsoft for OAuth and send-mail APIs.
- Legal and safety: if required by law, or to protect the Service, users, or others from fraud, abuse, or security threats.
- Business transfers: in connection with a merger, acquisition, or asset sale, subject to appropriate confidentiality protections.
5. Storage, security, and retention
- Application data is stored in cloud infrastructure (including Supabase Postgres and the documents storage bucket).
- Access is restricted using authentication, application role checks, and database row-level security for user-scoped access paths.
- Mailbox OAuth tokens are encrypted at rest by the application before storage.
- Uploaded documents and account data are retained while the tenant account remains active and as needed for legitimate operational, security, and legal purposes. GCs may delete or supersede uploads and manage users within product capabilities; contact us for account closure requests.
No method of transmission or storage is completely secure. We implement reasonable safeguards appropriate to the Service, but we cannot guarantee absolute security.
6. Cookies and similar technologies
We use essential cookies and similar technologies for authentication and session management. The Service is not designed around third-party advertising cookies. Disabling cookies may prevent sign-in and core features from working.
7. Your choices and rights
- Update profile and tenant settings available in the product (for example notification email and mailbox connection).
- Disconnect a connected Gmail/Outlook mailbox at any time in Settings (this stops send-as-GC mail until reconnected).
- Request access, correction, or deletion of personal information we hold about you, subject to applicable law and legitimate retention needs (for example security logs or records we must keep).
- GC organizations are responsible for handling requests from their subcontractors regarding data the GC entered or controls in the tenant workspace.
To exercise a request, email privacy@docusub.com.
8. Children’s privacy
The Service is intended for business use by adults. It is not directed to children under 16, and we do not knowingly collect personal information from children.
9. International processing
We and our providers may process data in the United States and other countries where our infrastructure operates. If you access the Service from elsewhere, you understand that your information may be transferred to and processed in those locations.
10. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version on this page and revise the effective date. Continued use of the Service after changes become effective constitutes acceptance of the updated policy.
11. Contact
Questions about privacy: privacy@docusub.com
Service: https://www.docusub.com