Privacy Policy

Last updated: August 25, 2026 · Beta

Stratum is business software for outdoor construction companies. This policy explains what we store, why, and what happens when you want it gone. It’s written to be read.

What we store

What we don’t do

Who can see your data — and how you’d know

Nobody at Stratum reads your identifiable records in the normal course of business. If you ask for help that requires us to look (say, a takeoff you think is wrong), an admin on your team grants a time-boxed support window from Settings → Data Access — and every read we make lands in an access log your whole team can see and nobody can edit. No window, no access; and the log’s default state, “nobody has ever accessed your records,” is checkable any time.

Isolation

Every company’s data is isolated at the database layer (row-level security). Your team’s roles control who inside your company sees money figures. Public links (quote pages, trade-partner forms, lead-intake forms) expose only what that page shows, are gated by long random tokens, and are rate-limited.

Who processes data for us

Stratum runs on a small set of infrastructure providers: Supabase (database and file storage), Vercel (hosting), Stripe (payments), Resend (transactional email such as quote delivery), Google Maps (address lookup, street imagery), Google’s AI models (the optional business analysis and photo/card reading), Intuit (only if you connect QuickBooks), and Sentry (error reports). Each receives only what its job requires.

Connecting QuickBooks

If you connect QuickBooks Online, Stratum reads your accounting data — customers, estimates, expenses, payments, sales receipts, deposits, and invoices — and copies it into your account so your customer list, estimates, and Finances page show real numbers. When you explicitly choose to send something, Stratum can also create a customer, estimate, or invoice in your QuickBooks file — only ever records you asked it to create, and never as a background process. Stratum never deletes anything from QuickBooks and never modifies QuickBooks records it didn’t create. The access keys Intuit gives us are encrypted before they are stored, are readable only by the server (never by your browser or by other companies on Stratum), and are deleted the moment you press Disconnect — which also stops all future syncing. Transactions already brought in stay in your books, because they are your records; you can delete them like anything else.

When you explicitly run a business analysis, Stratum sends an AI provider aggregated figures we calculated — totals, counts, averages, percentages — plus, at most, the number and title of a few of your oldest open estimates so a recommendation can point at something specific. Individual transactions, invoice lines, and the names of your vendors and counterparties are never sent, and nothing is sent at all unless you press the button.

Deletion

You can request account deletion from Settings → Account & privacy. We verify the request, protect companies shared with teammates (one person’s request never deletes a shared company), offer an export, and complete verified deletions within 7 days — including stored files, not just database rows.

Beta note

Stratum is in beta. We may contact you about your experience, and we look at aggregate activation metrics (like time-to-first-quote) to improve the product. The isolation and deletion promises above apply fully during beta.

Stratum · questions about this document: support@stratum.build