ConCal
Home Free Calculator Pricing Blog
Sign In Open tool

Privacy Policy

Last updated: August 15, 2026

This policy explains what information ConCal collects, how it's used, and what choices you have. We don't sell your data and we never will. If you have questions, email us at support@con-cal.net.

1. What We Collect

Depending on how you use ConCal, we may collect:

DataWhen collectedWhy
Email address When you create an account Account login and transactional emails (receipts, alerts)
Name & company When you fill out your profile Personalizing proposals and estimates
Job estimates When you save a job (Pro/Teams) Cloud sync across your devices
Customer contact info When you add a customer record Storing your customer database
Proposal data When you create or share a proposal Generating and hosting shareable proposals
Billing info When you subscribe to Pro or Teams Processed by Stripe. ConCal never sees your full card number
Location / zip code When you use the weather feature Fetching local weather from OpenWeatherMap
Usage analytics While you use the app Understanding which features are used to improve the product

Data about your customers. ConCal lets you store contact details (name, phone, email, address) for your own clients and the people you send proposals to. We store and process that information solely on your behalf so the product works for you. We don't use it for our own purposes. You're responsible for having the right to add your customers' information to ConCal and for telling them how you use it.

2. How Your Data Is Stored

ConCal's backend runs on Supabase, hosted on Amazon Web Services (AWS) in the United States. Your data is stored in a PostgreSQL database with row-level security, so it isn't accessible to other users, with one exception: if you're on a Teams plan, the team owner can see jobs created by their team members, since that's the point of a shared team workspace.

Passwords are never stored in plaintext. Supabase Auth handles authentication using industry-standard hashed credentials. All data in transit is encrypted via HTTPS.

3. Cookies and Local Storage

We don't use advertising cookies or third-party tracking pixels. Here's what we do store in your browser:

  • Theme preference: saved in localStorage so dark/light mode sticks between visits.
  • Supabase session token: a secure token in localStorage to keep you logged in. It expires automatically.
  • App preferences: settings like unit system (imperial/metric) and onboarding state, saved locally.

There are no third-party tracking cookies on ConCal. The "usage analytics" we mention are first-party only: for example, error logs and basic feature-usage records stored in our own Supabase database to help us fix bugs and improve the app. We don't use Google Analytics or any third-party analytics SDK.

4. Third-Party Services

ConCal uses the following services to function. Each has its own privacy policy.

Netlify

Hosts and serves the ConCal website and app. Every page you load is a request to Netlify's servers, which may log your IP address, browser type, and the page requested as part of normal web-server operation. Netlify does not receive your job data. That goes to Supabase below. Netlify Privacy Policy

Supabase

Handles our database, authentication, and backend functions. Your account and job data live here. Supabase Privacy Policy

Google Sign-In

If you choose "Sign in with Google," Google handles that login and shares your email address and basic profile with ConCal so we can create or access your account. This is separate from the Google Fonts request below. Google Privacy Policy

Stripe

Handles all payment processing for Pro and Teams subscriptions. ConCal never stores your full card number. Stripe Privacy Policy

OpenWeatherMap

Used by the weather feature. When you enter a location or zip code, it is sent to OpenWeatherMap's API. OpenWeatherMap Privacy Policy

Resend

Used to deliver transactional emails (welcome emails, team invites, billing receipts). Your email address is shared with Resend for delivery only. Resend Privacy Policy

Google Fonts

We load the IBM Plex typefaces from Google Fonts, which involves a request to Google's servers that may log your IP address. Google Privacy Policy

Content delivery networks (CDNs)

ConCal loads a few open-source software libraries (for example the Supabase client and spreadsheet export) from public CDNs (jsDelivr, unpkg, and Cloudflare). Like any web request, loading these may expose your IP address to the CDN. We don't use them for tracking.

5. Data Sharing

ConCal does not sell your data. We don't share your information with advertisers, data brokers, or any third party for marketing purposes.

Your data is only shared with the third-party services listed above, and only as needed to provide the service. We may disclose data if required by law (e.g., a valid court order), and will notify you if legally permitted.

Shared proposals. When you send a proposal link, anyone with the link can view that proposal's contents until it expires. When a proposal is opened, ConCal records the view and stores a one-way hashed version of the viewer's IP address (we cannot recover the original IP from it) so we can show you that it was viewed. We don't otherwise identify proposal recipients.

6. Your Rights

You have full control over your data:

  • Export: Download all your data as a JSON file from your dashboard settings at any time.
  • Delete your data: From your dashboard settings you can permanently delete your jobs, customers, and proposals (including their revision history). To fully close your account and erase everything we hold (including your saved settings, price book, and billing record), email us at support@con-cal.net and we'll erase it within 30 days.
  • Correct: Update your name, email, or company from your profile settings. For corrections you can't make yourself, email us.
  • Opt out of emails: Use the unsubscribe link in any marketing email. Transactional emails (receipts, security notices) cannot be turned off while your account is active.

7. Data Retention

We keep your data as long as your account is active. When you delete your data in the app, or ask us to close your account, we remove it within 30 days.

If your subscription lapses, we keep your account and its data so you can pick up where you left off if you resubscribe. You can delete it yourself at any time using the steps in "Your Rights" above.

8. Security

  • All connections use HTTPS (TLS encryption in transit)
  • Passwords are hashed by Supabase Auth, so we never see your plaintext password
  • Row-level security in our database prevents one user from accessing another's data (except deliberate sharing, such as a Teams owner viewing their members' jobs)
  • Payment card data is handled entirely by Stripe, so we never store it

If you discover a security issue, please report it to support@con-cal.net.

9. Children

ConCal is not intended for users under 18. We don't knowingly collect personal information from minors. If you believe a minor has created an account, contact us and we'll remove it promptly.

10. Changes to This Policy

If we make significant changes, we'll email you before they take effect. The latest version is always at con-cal.net/privacy.

Privacy questions? Email us at support@con-cal.net. We'll get back to you within a few business days.
© 2026 ConCal · Home · Pricing · Blog · App · Changelog · Terms · Privacy