This policy explains what information ConCal collects, how it's used, and what choices you have. We don't sell your data and we never will. If you have questions, email us at support@con-cal.net.
Depending on how you use ConCal, we may collect:
| Data | When collected | Why |
|---|---|---|
| Email address | When you create an account | Account login and transactional emails (receipts, alerts) |
| Name & company | When you fill out your profile | Personalizing proposals and estimates |
| Job estimates | When you save a job (Pro/Teams) | Cloud sync across your devices |
| Customer contact info | When you add a customer record | Storing your customer database |
| Proposal data | When you create or share a proposal | Generating and hosting shareable proposals |
| Billing info | When you subscribe to Pro or Teams | Processed by Stripe. ConCal never sees your full card number |
| Location / zip code | When you use the weather feature | Fetching local weather from OpenWeatherMap |
| Usage analytics | While you use the app | Understanding which features are used to improve the product |
Data about your customers. ConCal lets you store contact details (name, phone, email, address) for your own clients and the people you send proposals to. We store and process that information solely on your behalf so the product works for you. We don't use it for our own purposes. You're responsible for having the right to add your customers' information to ConCal and for telling them how you use it.
ConCal's backend runs on Supabase, hosted on Amazon Web Services (AWS) in the United States. Your data is stored in a PostgreSQL database with row-level security, so it isn't accessible to other users, with one exception: if you're on a Teams plan, the team owner can see jobs created by their team members, since that's the point of a shared team workspace.
Passwords are never stored in plaintext. Supabase Auth handles authentication using industry-standard hashed credentials. All data in transit is encrypted via HTTPS.
We don't use advertising cookies or third-party tracking pixels. Here's what we do store in your browser:
localStorage so dark/light mode sticks between visits.localStorage to keep you logged in. It expires automatically.There are no third-party tracking cookies on ConCal. The "usage analytics" we mention are first-party only: for example, error logs and basic feature-usage records stored in our own Supabase database to help us fix bugs and improve the app. We don't use Google Analytics or any third-party analytics SDK.
ConCal uses the following services to function. Each has its own privacy policy.
Hosts and serves the ConCal website and app. Every page you load is a request to Netlify's servers, which may log your IP address, browser type, and the page requested as part of normal web-server operation. Netlify does not receive your job data. That goes to Supabase below. Netlify Privacy Policy
Handles our database, authentication, and backend functions. Your account and job data live here. Supabase Privacy Policy
If you choose "Sign in with Google," Google handles that login and shares your email address and basic profile with ConCal so we can create or access your account. This is separate from the Google Fonts request below. Google Privacy Policy
Handles all payment processing for Pro and Teams subscriptions. ConCal never stores your full card number. Stripe Privacy Policy
Used by the weather feature. When you enter a location or zip code, it is sent to OpenWeatherMap's API. OpenWeatherMap Privacy Policy
Used to deliver transactional emails (welcome emails, team invites, billing receipts). Your email address is shared with Resend for delivery only. Resend Privacy Policy
We load the IBM Plex typefaces from Google Fonts, which involves a request to Google's servers that may log your IP address. Google Privacy Policy
ConCal loads a few open-source software libraries (for example the Supabase client and spreadsheet export) from public CDNs (jsDelivr, unpkg, and Cloudflare). Like any web request, loading these may expose your IP address to the CDN. We don't use them for tracking.
ConCal does not sell your data. We don't share your information with advertisers, data brokers, or any third party for marketing purposes.
Your data is only shared with the third-party services listed above, and only as needed to provide the service. We may disclose data if required by law (e.g., a valid court order), and will notify you if legally permitted.
Shared proposals. When you send a proposal link, anyone with the link can view that proposal's contents until it expires. When a proposal is opened, ConCal records the view and stores a one-way hashed version of the viewer's IP address (we cannot recover the original IP from it) so we can show you that it was viewed. We don't otherwise identify proposal recipients.
You have full control over your data:
We keep your data as long as your account is active. When you delete your data in the app, or ask us to close your account, we remove it within 30 days.
If your subscription lapses, we keep your account and its data so you can pick up where you left off if you resubscribe. You can delete it yourself at any time using the steps in "Your Rights" above.
If you discover a security issue, please report it to support@con-cal.net.
ConCal is not intended for users under 18. We don't knowingly collect personal information from minors. If you believe a minor has created an account, contact us and we'll remove it promptly.
If we make significant changes, we'll email you before they take effect. The latest version is always at con-cal.net/privacy.