1. Introduction
Easy Takeoffs (“we,” “our,” or “us”) operates the website at easytakeoffs.com and the Easy Takeoffs web application. This Privacy Policy explains what personal information we collect, exactly where it goes, how long we keep it, and the choices and rights you have. We have written it to describe what the software actually does, not what a template says.
By creating an account or using Easy Takeoffs, you agree to the collection and use of information as described in this policy. If you do not agree, please do not use the service.
2. Information We Collect
Account information
When you create an account, we collect your first name, last name, email address, password (stored only in hashed form by our authentication provider), phone number (optional), company name, company size, trade, country, and state or province. We also record the date and version of the Terms of Service you accepted at signup, and, if you accepted analytics cookies before signing up, how you first found us (the referring site, the page you landed on, and any campaign tags in the address).
Payment and billing information
When you subscribe, you provide payment information directly to Stripe, our payment processor. Stripe collects your name, billing address, card or bank details, and the IP address of your transaction. We never see or store card numbers, CVV codes, or bank account numbers. We store your Stripe customer ID, your subscription details (plan, status, billing dates, and the card's expiry month and year so we can remind you before a saved card expires), invoice references, and copies of the billing event notifications Stripe sends us, which we retain for accounting, tax, and fraud-prevention purposes. Details like the card brand and last four digits are shown in your billing settings by asking Stripe live; we do not store them.
Uploaded files and project data
Your uploaded PDF construction drawings, together with the page images and thumbnails we render from them, are stored in cloud storage (Cloudflare R2). Files are not listed, indexed, or discoverable anywhere; each file is reachable only through a web address containing long randomized identifiers, and those addresses exist only inside your account and in any share links you choose to create. The projects, documents, measurements, annotations, groups, labels, page names, and scale calibrations you create are stored in our database (hosted on Supabase) and used exclusively to provide the service.
AI features
When you use our AI features (automatic page naming and scale detection), we send images of the relevant plan pages to Google's Gemini API for analysis. These requests carry no name, email address, or account identifier. We use Google's paid API tier, which carries stronger commitments than its free tier: Google does not use these page images or the AI's responses to train or improve its models, and Google processes them as our data processor under the Google Data Processing Addendum. Google temporarily logs API requests solely to detect abuse of its service and to meet legal requirements, for a limited period (currently 55 days per Google's documentation). AI analysis is on by default when you upload a document, and you can turn it off with the AI toggles in the upload window.
Support requests
When you submit a support, bug, or feature request from inside the app, your message, the subject line, your name, your email address, and your browser version are sent to Monday.com, the ticketing tool we use to track and answer requests.
Automatically collected information
We collect technical and usage information through these channels:
- Internal product analytics: While you are signed in, we record usage events in our own database: which features you use, the in-app page paths you visit, your browser's user-agent string, and session identifiers with start and end times. This data stays on our infrastructure and tells us which features matter and where to focus improvements.
- Google Analytics 4 (only with your consent): If you accept analytics cookies in our cookie banner, we load Google Analytics 4, which collects page views, session data, and traffic sources. If you do not accept, the Google Analytics script never loads and nothing about your visit is sent to Google. See Section 3 for the full cookie details. With your consent, we may also send key account milestones (for example, that a signup or subscription happened) to Google Analytics from our servers, tagged with an internal account identifier, never your name or email.
- Error monitoring: We use Sentry to capture application errors so we can fix them. Error reports can include your internal account identifier and technical context about what went wrong. We automatically strip email addresses from error reports before they are stored, and we do not use session recording or screen capture of any kind.
- Server logs: Our hosting provider (Vercel) keeps standard, short-lived request logs, including IP address, browser type, and pages requested, and our authentication provider (Supabase) keeps its own security logs of sign-in activity. These are used for security monitoring and operations. Our own application records do not store IP addresses.
- Email engagement: Our email provider (Resend) reports delivery status, bounces, complaints, opens, and link clicks for the emails we send you. We use opens and clicks to measure whether our emails are useful and to stop sending to addresses that bounce or complain.
3. Cookies, Browser Storage, and Your Choices
We ask before using any cookie that is not essential. On your first visit, a banner offers a clear choice: Accept analytics or Reject, with both options one click away. Nothing non-essential runs until you choose, and you can change your mind at any time using the button below or the Cookie Preferences link in the page footer.
- Authentication (essential): Our authentication provider (Supabase) sets first-party cookies and browser storage entries to keep you signed in. A short-lived cookie (one hour) also carries you through email verification. These are required for the service to work and are removed when you sign out.
- Google Analytics (optional, off until you accept): If you accept, Google Analytics sets two first-party cookies,
_gaand_ga_*, which distinguish visitors and persist session state, with a requested lifetime of up to two years (browsers may cap this sooner). These are analytics cookies, not advertising cookies. If you reject, they are never set; if you withdraw consent later, we tell Google to stop and expire them. - First-visit attribution (optional, off until you accept): If you accept analytics, we store how you first found us (referrer and campaign tags) in your browser's local storage, and save it to your profile if you sign up.
- Working data (essential): The app uses browser local storage for functional needs: caching your preferences so pages load with your settings, and keeping an emergency copy of unsaved measurement work so a closed tab does not lose it.
- Cloudflare Turnstile (essential, security): Our authentication forms (signup, sign in, password reset, and email verification) use Turnstile for bot detection. It may set tokens in your browser during verification, used solely for security.
- Stripe (essential for payments): When you reach Stripe Checkout or the Stripe customer portal, Stripe sets its own cookies to secure your billing session and prevent fraud.
Browser privacy signals: We honor both the Global Privacy Control (GPC) signal and the legacy Do Not Track (DNT) signal. If your browser sends either, we treat it as a rejection of analytics and never load our analytics tools for your visits, without showing you the banner. We do this voluntarily, even though we do not sell or share personal information and are not currently required by law to respond to these signals.
4. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve the Easy Takeoffs service
- Authenticate your identity and manage your account
- Store and serve your uploaded construction plans, and run the AI page naming and scale detection you request
- Save your measurements, projects, and preferences
- Process payments, manage your subscription, and handle billing matters (including invoicing, failed-payment recovery, tax calculation, and refunds where applicable)
- Send transactional emails about your account (verification, billing notices, trial reminders, renewal reminders, receipts, security alerts)
- Send product updates, tips, and offers, which you can decline at signup and unsubscribe from at any time (see Section 8)
- Understand how the product is used so we can prioritize improvements
- Monitor performance, capture errors, and diagnose technical issues
- Detect and prevent fraud, abuse, and unauthorized access
- Answer your support requests and communicate about changes to the service
We do not sell, rent, or trade your personal information. We do not use your data for advertising, and we do not use your uploaded plans for anything except providing the service to you, including the AI analysis described above.
5. Third-Party Service Providers
These are all of the third-party services that receive personal data in order to run Easy Takeoffs, and what each one receives:
- Supabase (authentication and database hosting): your account information, project and measurement data, product analytics events, and email preferences.
- Cloudflare R2 (file storage): your uploaded PDFs and the page images rendered from them.
- Stripe (payments): your billing details, collected by Stripe directly. Stripe is a PCI-DSS Level 1 certified processor, calculates applicable sales tax and VAT via Stripe Tax, and may retain billing records for up to seven (7) years to comply with tax and accounting law. See Stripe's privacy policy.
- Google (Gemini API) (AI analysis): images of plan pages you run AI analysis on, under the paid-tier processor terms described in Section 2.
- Google Analytics 4 (website analytics, only with your consent): page views, session data, traffic sources, and account milestone events tagged with an internal identifier.
- Resend (email delivery): your email address, name, and the content of the emails we send you, plus delivery, open, and click reporting.
- Sentry (error monitoring): error reports that can include your internal account identifier, with email addresses automatically stripped.
- Vercel (hosting): standard web request logs (IP address, browser type, pages requested) as an unavoidable part of serving the site.
- Cloudflare Turnstile (bot protection): browser signals on our authentication forms, used to distinguish humans from automated access.
- Monday.com (support ticketing): the name, email address, and message content of support requests you submit.
- unpkg (CDN): the PDF viewer loads font and character-map helper files from this public content delivery network, which sees your IP address as part of serving those files, like any website asset host. No account data is sent to it.
Each provider operates under its own privacy policy and, where it processes personal data on our behalf, under a data processing agreement with us. We do not use any advertising pixels, session recording, heatmaps, or data brokers.
6. Where Your Information Is Processed
Easy Takeoffs is based in the United States and provides the service from the United States. When you use Easy Takeoffs from the European Economic Area, the United Kingdom, or Switzerland, you provide your information directly to us in the United States, and we store and process it there. The European Commission has not issued a decision finding that United States law in general provides the same level of data protection as EU law, and we are not certified under the EU-US Data Privacy Framework, so we protect your information by applying the GDPR's requirements to everything we do with it, regardless of where it is processed.
When we share personal data with the service providers listed above, our agreements with them incorporate the Standard Contractual Clauses approved by the European Commission (and the UK and Swiss equivalents), which contractually require them to protect your data to EU standards. Several of these providers are additionally certified under the EU-US Data Privacy Framework. You can read the Standard Contractual Clauses at the European Commission's official text, and you can request a copy of the clauses in place with any provider by emailing hello@easytakeoffs.com.
7. Data Retention and Deletion
We retain your data for as long as your account is active. You can delete your account at any time from the Danger Zone in your account settings. When you delete your account:
- Your profile and account information are permanently deleted
- All your projects and measurement data are permanently deleted
- All uploaded PDF files, page images, and thumbnails are permanently removed from cloud storage
- Any active subscription is immediately canceled with Stripe (no further charges)
- Any share links you created stop working, because the underlying data is gone
Two narrow categories survive deletion, and we want to be precise about them. First, aggregate usage analytics are retained with only an internal random identifier; your email address and name are removed from them, so they can no longer be connected to you. Second, billing records (the payment event notifications described in Section 2) are retained because tax, accounting, and fraud-prevention law requires keeping transaction history; Stripe likewise retains its own billing records for up to seven (7) years. Emails already delivered to your inbox cannot be recalled, and our email provider retains standard delivery logs for a limited period.
Account deletion is permanent and cannot be reversed. We recommend exporting any measurements you need first.
8. Marketing Emails and Your Email Choices
When you sign up, you are enrolled in our product emails (product updates, tips and reminders, and occasional offers) unless you uncheck the marketing box on the signup form. Every marketing email we send includes working unsubscribe links, including a single link that stops all marketing email at once, and honoring them requires no login and no fee. You can also manage categories individually in your account settings. Transactional messages (billing notices, renewal reminders, security alerts, account confirmations) continue regardless, because they are part of operating your account. We stop sending to addresses that hard bounce or mark our email as spam.
9. Data Security
We take reasonable measures to protect your information from unauthorized access, alteration, disclosure, or destruction, including:
- Encryption of all data in transit using TLS/HTTPS
- Row Level Security policies on our database so users can only access their own data
- Secure authentication with password hashing
- File storage addresses built from long randomized identifiers that cannot be guessed or enumerated, with uploads requiring your authenticated session
- Rate limiting on authentication and API endpoints
- Payment data handled exclusively by Stripe, a PCI-DSS Level 1 certified processor; we never store card numbers
- Automatic stripping of email addresses from error reports
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we ever learn of a breach affecting your personal information, we will notify you and the relevant authorities as applicable law requires. If you discover a security vulnerability, please report it to hello@easytakeoffs.com.
10. Your Rights
Regardless of where you live, you can:
- Access: Request a copy of the personal information we hold about you. Most of it is already visible in your account settings, and we will provide the rest free of charge within one month of your request, including if your subscription has lapsed.
- Correction: Update inaccurate information at any time through your account settings, or ask us to correct it.
- Deletion: Delete your account and all associated data through the Danger Zone in your account settings, subject only to the legal retention of billing records described in Section 7.
- Portability: Export your measurements and project data via the in-app PDF and CSV export, or email us for a copy of your data in a portable format, free of charge, including if your subscription has lapsed.
- Marketing opt-out: Decline marketing at signup, unsubscribe from any or all marketing email with the links in every message, or use the toggles in your account settings.
- Analytics opt-out: Reject or withdraw analytics cookies at any time (Section 3).
To exercise any of these rights, email hello@easytakeoffs.com. We respond to all requests within one month.
California residents
Easy Takeoffs does not currently meet any of the thresholds that make a company a “business” regulated by the California Consumer Privacy Act (CCPA), such as annual gross revenues above $26,625,000 or buying, selling, or sharing the personal information of 100,000 or more California consumers or households each year. We do not sell or share personal information as the CCPA defines those terms. Even so, we voluntarily extend the rights listed above (know, access, correct, delete, and no retaliation for exercising them) to all users, wherever they live. California's online privacy law also requires us to say how we respond to browser privacy signals: as described in Section 3, we honor both Global Privacy Control and Do Not Track signals by disabling analytics, and the only third party that could collect information about your visits over time on our site (Google Analytics) runs only with your consent. If we ever meet the CCPA's thresholds, we will update this policy and adopt the full set of processes the law requires.
European Economic Area, United Kingdom, and Switzerland
If you are in the EEA, the UK, or Switzerland, the GDPR and its UK equivalent give you additional rights: restriction of processing, objection to processing, withdrawal of consent at any time, and the right to lodge a complaint with your local data protection authority. Our legal bases for processing are: contract (providing the service you signed up for, including file storage, AI analysis you request, and billing), legitimate interests (first-party product analytics, error monitoring, fraud prevention, securing the service, and sending existing customers product emails they can decline at signup and opt out of at any time), consent (analytics cookies and Google Analytics, which never run without it), and legal obligation (retaining billing records). Section 6 describes how your data reaches the United States and the safeguards applied. To exercise any right, email hello@easytakeoffs.com.
11. Governing Law
This Privacy Policy is governed by the laws of the State of Florida, USA, without regard to conflict of law principles. Any disputes regarding privacy matters will be resolved in the state or federal courts located in Orange County, Florida. This does not affect the additional rights granted to you by mandatory data protection law in your jurisdiction (for example, CCPA, GDPR, or UK GDPR), which continue to apply.
12. Children's Privacy
Easy Takeoffs is a professional tool that is not directed at children under the age of 13, and we do not knowingly collect personal information from children under 13. If we become aware that we have collected personal information from a child under 13, we will delete that information promptly.
13. Changes to This Policy
We may update this Privacy Policy from time to time. When we make changes, we will update the “Last updated” date at the top of this page. For changes that materially affect how we collect or use your personal information, we will give you at least thirty (30) days advance notice by email and in-app notice before the change takes effect. Continued use of the service after changes are posted constitutes acceptance of the revised policy.
14. Contact Us
If you have questions about this Privacy Policy or how we handle your data, contact us at hello@easytakeoffs.com. We answer every privacy question and request within one month.