Privacy Policy
1. Introduction
Welcome to Construction AI Billing, a product of Varshyl Inc. ("Varshyl," "we," "us," or "our"). This Privacy Policy explains how we collect, use, share, and protect your personal information when you use our platform at constructinv.varshyl.com.
By using Construction AI Billing, you agree to the collection and use of information in accordance with this policy. If you do not agree with any part of this policy, please discontinue use of the Service.
2. Information We Collect
Account Information: When you create an account, we collect your name, email address, and password (stored in hashed form). You may optionally provide your company name, phone number, and contact information.
Project Data: We store the project information you enter, including project names, owner/contractor names, contract amounts, Schedule of Values, pay application data, retainage percentages, change orders, and uploaded files (such as SOV spreadsheets).
Company Profile: If you configure your Settings, we store your company name, logo, signature image, and contact profile details to pre-fill your pay applications.
Usage Data: We collect data about how you interact with the platform — features used, pages visited, and time spent — to improve the Service. This is collected via PostHog, our analytics provider.
Device and Technical Information: We collect standard technical information such as your IP address, browser type, operating system, and device type to troubleshoot issues and optimize performance.
Communications: If you contact us by email, we retain those communications to respond to you and improve our support.
3. How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain the Construction AI Billing platform
- Generate your AIA G702/G703 pay application PDFs and billing documents
- Send transactional emails (account verification, password reset, pay app confirmations)
- Respond to support requests and communications
- Analyze usage patterns to improve the platform and develop new features
- Ensure the security and integrity of our systems
- Comply with legal obligations
4. Information Sharing and Disclosure
We do not sell, rent, or trade your personal information. We may share your information only in the following limited circumstances:
- Service Providers: We share data with trusted third-party vendors who help us operate the Service, including our hosting provider (Railway), analytics (PostHog), and email delivery. These providers are contractually prohibited from using your data for any purpose other than providing services to us.
- Legal Compliance: We may disclose information if required by law, subpoena, court order, or to protect the rights, property, or safety of Varshyl, our users, or the public.
- Business Transfers: If Varshyl is acquired or merges with another company, your information may be transferred as part of that transaction. We will notify you in advance and you will have the option to delete your account.
5. Third-Party Services We Use
- Railway (railway.app) — Cloud hosting and infrastructure. Your data is stored on Railway's servers in the United States.
- PostHog — Behavioral analytics and session recording. PostHog helps us understand how users navigate the platform so we can improve it. PostHog does not receive your project financial data.
- Google OAuth — Optional sign-in with Google. If you use Google Sign-In, we receive your name and email address from Google in accordance with Google's Privacy Policy.
We do not use Google Analytics, Facebook Pixel, or any advertising networks.
6. Data Security
We take data security seriously. We use industry-standard security measures including:
- HTTPS/TLS encryption for all data in transit
- Passwords stored using bcrypt hashing (never in plaintext)
- JWT-based authentication with secure token handling
- Access controls limiting which team members can access production data
No method of transmission over the internet or electronic storage is 100% secure. While we use commercially reasonable measures to protect your data, we cannot guarantee absolute security. In the event of a data breach that affects your personal information, we will notify you as required by applicable law.
7. Data Retention
We retain your account and project data for as long as your account is active, or as needed to provide the Service. If you delete your account, we will delete or anonymize your personal information within 30 days, except where retention is required by law or for legitimate business purposes (such as resolving disputes or enforcing our agreements).
8. Your Choices and Rights
You have the following rights regarding your information:
- Access and Correction: You can view and update your account information at any time in your Settings page.
- Data Export: Contact us to request an export of your project data.
- Account Deletion: You can request deletion of your account and all associated data by emailing support@varshyl.com. We will process your request within 30 days.
- Opt-Out of Analytics: You can opt out of PostHog session recording by contacting us or using your browser's "Do Not Track" setting.
9. California Privacy Rights (CCPA)
If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect, the right to delete your personal information, the right to opt out of the sale of your personal information (we do not sell personal information), and the right to non-discrimination for exercising your privacy rights.
To exercise any of these rights, contact us at support@varshyl.com. We will respond within 45 days.
10. International Users (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have rights under the General Data Protection Regulation (GDPR) and applicable local laws, including rights of access, rectification, erasure, restriction, portability, and objection.
Our legal basis for processing your personal data is: (a) performance of a contract when we provide the Service to you; (b) your consent where applicable; and (c) our legitimate interests in operating and improving the Service. To exercise your GDPR rights, contact support@varshyl.com.
11. Children's Privacy
Construction AI Billing is intended for use by business professionals and is not directed at children under the age of 18. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us personal information, please contact us and we will delete it promptly.
12. Cookies and Tracking
We use session cookies and local storage for authentication (to keep you logged in) and for analytics. We do not use advertising cookies or third-party tracking cookies. You can control cookie settings through your browser, though disabling cookies may affect your ability to use the Service.
13. Updates to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by posting the new policy on this page with an updated effective date and, where appropriate, by email. We encourage you to review this policy periodically.
14. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:
- Email: support@varshyl.com
- Website: constructinv.varshyl.com
- Company: Varshyl Inc., California, USA