The short version
- We collect what we need to run PMT1: your account details, what your team puts in your workspace, and basic technical logs.
- We do not sell your personal information, share it for advertising, or use advertising or tracking cookies.
- Your workspace content is not used to train AI models.
- You can ask for a copy, a correction or deletion at any time using our privacy request form.
This summary is for convenience. The full text below is what applies.
This Privacy Policy explains how ConstructorIQ Inc. (“PMT1”, “we”, “us”) handles personal information when you visit pmt1.com, sign up for or use the PMT1 service, or contact us.
1. Two roles: our customers’ data and our own
Workspace content belongs to our customers. When a company uses PMT1, the records, photos, documents and other content its team adds are controlled by that company. We process that content on the company’s behalf, as its “service provider” or “processor”, under our Terms and Data Processing Addendum. If you are an employee, subcontractor or other person whose information appears in a company’s workspace, that company decides how it is used; please send your questions or requests to them first. We will help them respond.
For everything else — your account and sign-in details, billing, website visits, and messages to us — we are the “business” or “controller”, and this policy describes what we do.
2. Information we collect
Information you give us
- Account and profile: name, work email address, phone number (optional), password (stored only as a salted hash), role, company name, trade, team size, time zone, company logo, and — only if you add one — a profile picture. A photo you upload is cropped and re-encoded in your browser first, which strips any location or camera details, and is shown only to people in your workspaces.
- Workspace content: what you and your team enter or upload — projects, schedules, RFIs, tickets, crew rosters and certifications, contacts, photos, documents, signatures, comments, and your conversations with the assistant.
- Voice: if you use dictation or hands-free voice, audio from your microphone is sent for transcription while that feature is switched on. We do not keep the audio; we keep the resulting text as part of the conversation.
- Communications: messages you send through our contact, feedback, accessibility or privacy forms, and emails to our support addresses.
Information collected automatically
- Activity log: a record of who created, changed, signed or deleted what in a workspace, and sign-in events, with time and IP address.
- Technical data: IP address, browser and device type, pages requested, and error reports, in server and security logs.
- Cookies: one essential sign-in cookie. We do not use advertising, analytics or cross-site tracking cookies. See our Cookie Policy.
Information from others
- Your company’s administrators give us your name and email when they invite you.
- Stripe, our payment processor, tells us your plan, payment status, invoice history, billing country and postal code, and the brand and last four digits of your card. We never receive your full card number.
What we do not collect
We do not collect precise geolocation, do not use face or voice recognition to identify people, do not build advertising profiles, and do not buy personal information from data brokers. PMT1 is not designed for Social Security numbers, financial account numbers, medical information or information about children, and we ask customers not to put them in the service.
3. How we use information
- To provide the service: create accounts and workspaces, authenticate you, store and display your content, run the assistant when you ask it to, and send service emails such as verification, password reset, invitations and billing notices.
- To bill for the service and prevent fraud.
- To keep the service secure: detect abuse, investigate incidents, enforce our terms and rate limits.
- To support you and respond to your messages.
- To understand, in aggregate, how the service is used so we can fix and improve it.
- To tell customers about significant product changes. Any email that is promotional rather than service-related will include an unsubscribe link.
- To comply with law and protect our rights and the rights of others.
We do not use personal information for automated decisions that have legal or similarly significant effects on you, and we do not use your workspace content to train AI models.
4. The AI assistant
When you use the assistant, the text you type, the photos you attach, relevant records from your workspace that the assistant looks up to answer you, and — if you use voice — your audio, are sent to our AI provider, OpenAI, to generate the response. Under its business terms OpenAI does not use this content to train its models, and may retain it for up to 30 days to monitor for abuse before deleting it. We keep your conversation history in your workspace until you delete it. More detail is in our AI Terms. Administrators can switch the assistant off for the whole company.
6. How long we keep it
| Information | Kept for |
|---|---|
| Workspace content and activity log | As long as the company’s subscription is active, then 30 days to allow export, then deleted from active systems. Projects a customer deletes can be restored for 30 days and are then permanently removed. |
| Backups | Age out within about 35 days after deletion from active systems. |
| Account details | Until the account is removed from its last workspace, then deleted or de-identified within 30 days. |
| Billing records | Seven years, as required for tax and accounting. |
| Server and security logs | Up to 12 months. |
| Contact, feedback and privacy-request messages | Up to 24 months after the matter is closed. |
| Copies of emails we sent you | Up to 90 days. |
| Voice audio | Not stored by us. |
We may keep information longer where the law requires it or where it is needed to resolve a dispute or enforce our agreements.
7. How we protect it
We use encryption in transit and at rest, database-level separation between companies, hashed passwords, optional two-step sign-in (mandatory for our own staff), role-based access, and an activity log. Our Security page has the details. No system is perfectly secure; if we confirm a breach affecting your personal information we will notify you and the relevant authorities as the law requires.
8. Your privacy rights and choices
Depending on where you live — including California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon and other U.S. states with privacy laws — you may have the right to:
- Know and access the personal information we hold about you, and receive a portable copy;
- Correct inaccurate information;
- Delete your personal information, with some exceptions (for example, records we must keep by law);
- Opt out of the sale of personal information, of sharing for targeted advertising, and of profiling that produces legal or similarly significant effects — we do none of these;
- Limit the use of sensitive personal information — the only sensitive information we hold is your account sign-in credentials, used only to sign you in;
- Not be discriminated against for exercising any of these rights.
How to make a request. Use our privacy request form or email privacy@pmt1.com. We will verify your request by confirming control of the email address on your account and, if needed, asking for further information. We respond within 45 days, and will tell you if we need up to 45 more. You may use an authorized agent; we will ask for proof of their authority and may still verify your identity with you directly.
If your information is in a company’s workspace, we will pass your request to that company, because it controls that data.
Appeals. If we decline your request you may appeal by replying to our decision or emailing privacy@pmt1.com with the subject “Privacy appeal”. We will answer within 60 days (45 days where state law requires). If you are not satisfied, you may contact your state’s Attorney General.
Browser signals. We treat a Global Privacy Control (GPC) signal as a request to opt out of sale and sharing. Because we do not sell or share personal information or use tracking cookies, the signal does not change how the site works. For the same reason, we do not respond differently to “Do Not Track” signals.
Marketing email. You can unsubscribe from promotional email using the link in the message. Service messages about your account, security and billing are not promotional and cannot be switched off while you have an account.
9. California notice at collection
This section supplements the rest of this policy for California residents, using the categories defined in the California Consumer Privacy Act.
| Category | Examples we collect | Why | Sold or shared? |
|---|---|---|---|
| Identifiers | Name, email, phone, IP address | Provide, secure and support the service; billing | No |
| Customer records | Company name, billing postal code, card brand and last four digits (from Stripe) | Billing and tax | No |
| Commercial information | Plan, invoices, payment status | Billing and support | No |
| Internet or network activity | Pages requested, actions in the app, device and browser type | Security, troubleshooting, the activity log | No |
| Professional information | Role, trade, employer | Set up your workspace and permissions | No |
| Audio and visual | Photos you upload; voice audio while dictation is on (not stored) | Provide the features you use | No |
| Sensitive personal information | Account sign-in credentials | Authenticate you — no other use | No |
Retention periods are in “How long we keep it”. Sources, disclosures for business purposes and your rights are described above. We do not offer financial incentives for personal information. We do not knowingly sell or share the personal information of anyone under 16. Under California’s “Shine the Light” law: we do not disclose personal information to third parties for their direct-marketing purposes.
10. Nevada
We do not sell covered information as defined by Nevada law. Nevada residents may still submit a request to privacy@pmt1.com to record their preference.
11. Children
PMT1 is business software for adults. It is not directed to children, and we do not knowingly collect personal information from anyone under 18. If you believe a child has given us personal information, contact privacy@pmt1.com and we will delete it.
12. Users outside the United States
PMT1 is operated from, and hosts data in, the United States, and is offered to businesses in the United States. If you use it from another country, your information will be transferred to and processed in the United States, whose laws may differ from yours. Where the GDPR or UK GDPR applies, our legal bases are: performing our contract with you; our legitimate interests in securing, supporting and improving the service; compliance with legal obligations; and consent where we ask for it. You may have rights of access, rectification, erasure, restriction, portability and objection, and the right to complain to your data-protection authority. Where required, transfers rely on the European Commission’s Standard Contractual Clauses, as set out in our Data Processing Addendum.
13. Changes to this policy
We may update this policy. We will change the effective date above, and if a change is material we will notify workspace owners by email or in the app at least 30 days before it takes effect.
14. Contact us
Privacy questions and requests: privacy@pmt1.com or our privacy request form.
Questions about this page: privacy@pmt1.com