Privacy Policy
Last updated: August 25, 2026 · Beta
Stratum is business software for outdoor construction companies. This policy explains what we store, why, and what happens when you want it gone. It’s written to be read.
What we store
- Your account: your email address, your company’s name, branding (logo, colors), and configuration such as pricing rules and build preferences.
- Your business records: the leads, customers, estimates, jobs, photos, documents, orders, and financial figures your team enters. This includes your customers’ contact details and addresses — you are responsible for having the right to enter them.
- Usage signals inside your account: for example, when a homeowner opens a quote link you sent them, we record the time of the open (no location, no device fingerprint) so you know your quote was seen.
- Billing: handled by Stripe. We never see or store card numbers.
What we don’t do
- We don’t sell your data or your customers’ data. To anyone. Ever.
- We don’t read your business records except inside a support window you grant (see below).
- We don’t use your data in cross-company statistics unless you’ve explicitly opted in to benchmarks — and then only anonymized and aggregated, never as your numbers.
Who can see your data — and how you’d know
Nobody at Stratum reads your identifiable records in the normal course of business. If you ask for help that requires us to look (say, a takeoff you think is wrong), an admin on your team grants a time-boxed support window from Settings → Data Access — and every read we make lands in an access log your whole team can see and nobody can edit. No window, no access; and the log’s default state, “nobody has ever accessed your records,” is checkable any time.
Isolation
Every company’s data is isolated at the database layer (row-level security). Your team’s roles control who inside your company sees money figures. Public links (quote pages, trade-partner forms, lead-intake forms) expose only what that page shows, are gated by long random tokens, and are rate-limited.
Who processes data for us
Stratum runs on a small set of infrastructure providers: Supabase (database and file storage), Vercel (hosting), Stripe (payments), Resend (transactional email such as quote delivery), Google Maps (address lookup, street imagery), Google’s AI models (the optional business analysis and photo/card reading), Intuit (only if you connect QuickBooks), and Sentry (error reports). Each receives only what its job requires.
Connecting QuickBooks
If you connect QuickBooks Online, Stratum reads your accounting data — customers, estimates, expenses, payments, sales receipts, deposits, and invoices — and copies it into your account so your customer list, estimates, and Finances page show real numbers. When you explicitly choose to send something, Stratum can also create a customer, estimate, or invoice in your QuickBooks file — only ever records you asked it to create, and never as a background process. Stratum never deletes anything from QuickBooks and never modifies QuickBooks records it didn’t create. The access keys Intuit gives us are encrypted before they are stored, are readable only by the server (never by your browser or by other companies on Stratum), and are deleted the moment you press Disconnect — which also stops all future syncing. Transactions already brought in stay in your books, because they are your records; you can delete them like anything else.
When you explicitly run a business analysis, Stratum sends an AI provider aggregated figures we calculated — totals, counts, averages, percentages — plus, at most, the number and title of a few of your oldest open estimates so a recommendation can point at something specific. Individual transactions, invoice lines, and the names of your vendors and counterparties are never sent, and nothing is sent at all unless you press the button.
Deletion
You can request account deletion from Settings → Account & privacy. We verify the request, protect companies shared with teammates (one person’s request never deletes a shared company), offer an export, and complete verified deletions within 7 days — including stored files, not just database rows.
Beta note
Stratum is in beta. We may contact you about your experience, and we look at aggregate activation metrics (like time-to-first-quote) to improve the product. The isolation and deletion promises above apply fully during beta.
Stratum · questions about this document: support@stratum.build