Legal
Privacy Policy
Effective August 15, 2026
1. Scope and our two roles
This policy explains how Ready To Inspect LLC, doing business as Ready-to-Inspect ("RTI", "we", "us"), handles personal information in connection with readytoinspect.io, our mobile applications, and the client portal (together, the "Service").
We handle personal information in two different capacities, and the difference matters:
As a controller — for information about the people who sign up for and administer accounts, for billing, and for security and support. We decide how this is used, and this policy governs it.
As a processor (service provider) — for the content our customers put into the Service: inspection records, photographs, observations, and signatures. A construction company is the controller of that content. We process it on their instructions. If your employer or a contractor you work with uses RTI and you have questions about photographs of you or records about your work, contact that company first. We will support them in responding.
Our processing on behalf of customers is governed by our Data Processing Addendum.
2. What we collect
Account and profile information
| Data | Source | Why |
|---|---|---|
| Full name, email address | You, at signup | Create and secure your account, send notifications |
| Password (hashed) or Google sign-in identifier | You | Authentication |
| Phone number, job title, trade, timezone, profile photo | Optional, entered by you | Display in the app so colleagues know who did what |
| Role and permissions | Your administrator | Access control |
| Company name, country, logo | Your administrator | Tenant setup and report branding |
Billing information
We use Stripe to process payments. We do not receive or store full payment card numbers. We store the Stripe customer and subscription identifiers, your plan, status, and billing period so we can show you what you are paying for.
Technical and security information
| Data | Why |
|---|---|
| IP address and browser user-agent, recorded with your session | Attribute actions in the audit trail, detect unauthorized access, verify new devices |
| A one-way hash of the IP address used to sign a record | Bind a signature to the network it came from without storing the address itself |
| Log and error data | Diagnose faults |
Inspection content (processed on our customers' behalf)
| Data | Notes |
|---|---|
| Checklist answers, written observations, notes | Entered by the person performing the inspection |
| Photographs | See Section 3 — these frequently contain identifiable people |
| Signatures | Drawn signature image or typed name, signer identity, timestamp, hashed IP |
| Project, location, and inspection-point names | May include site addresses |
| Activity log entries | Who did what, when — bound into a SHA-256 hash chain |
| Client contact name and email | Entered by our customer to grant portal access |
We do not collect Social Security numbers, government ID numbers, financial account numbers, precise health information, biometric identifiers, or information about children.
3. Photographs and location — read this part
This is the part of the Service most likely to affect an individual worker, so we state it plainly.
- Inspection photographs are taken on a jobsite and routinely capture people — the person doing the work, other trades, and sometimes members of the public.
- Where the device grants permission, the Service burns a timestamp and GPS coordinates directly into the image. Combined with the identity of the person who took the photo, this records where a specific individual was at a specific time.
- If location permission is denied, photographs are stamped without coordinates and the inspection still proceeds. Location is not required to use the Service.
- Photographs are stored in access-controlled storage and are visible to authorized people within the customer's workspace, and to any client the customer grants portal access to.
If you are a worker and photographs of you are in RTI: the company that employs or engaged you controls those records and decides who sees them. Contact them. If you cannot reach them, contact us at support@readytoinspect.io and we will help identify the right party.
4. How we use information
- Provide, operate, secure, and support the Service.
- Authenticate users and enforce access controls between and within customer workspaces.
- Maintain the integrity of the inspection record, including the tamper-evident activity log.
- Send transactional messages: account confirmations, password resets, inspection notifications, billing receipts, and service announcements.
- Bill you and manage your subscription.
- Detect, investigate, and prevent fraud, abuse, and security incidents.
- Comply with legal obligations and enforce our Terms.
- Improve the Service, including through aggregate statistics that do not identify any customer or individual.
We do not sell personal information. We do not share it for cross-context behavioral advertising. We do not use inspection content to train machine-learning models.
5. Legal bases (for individuals in the UK, EEA, or Switzerland)
Where GDPR or UK GDPR applies to our processing as a controller, we rely on:
- Contract — to provide the Service to the account holder.
- Legitimate interests — securing the Service, preventing abuse, and improving what we offer, balanced against your rights.
- Legal obligation — tax, accounting, and responses to lawful requests.
- Consent — where we ask for it, such as optional device location. You may withdraw consent at any time.
For inspection content, our customer determines the legal basis; we act on their instructions.
6. Service providers we rely on
We use the following providers. Each is bound by contract to process data only as needed to provide their service to us.
| Provider | What they do | Data involved | Location |
|---|---|---|---|
| Supabase (via Lovable Cloud) | Database, file storage, authentication | All account and inspection data, including photographs | United States |
| Stripe | Payment processing and subscription billing | Name, email, billing details, payment method (held by Stripe) | United States |
| Resend | Sending transactional email | Recipient name and email, message content | United States |
| Cloudflare | DNS, content delivery, video hosting | Network-level request data | Global edge network |
| Optional "Sign in with Google" | Email address and name, only if you choose this method | United States |
Optional integrations. If your administrator connects an optional integration such as Smartsheet, inspection data is transmitted to that provider at your organization's direction and under your organization's agreement with them.
A current list is maintained in Annex C of our Data Processing Addendum. We will give customers advance notice before adding a provider that processes inspection content.
7. When we disclose information
- To your organization. Everything you do in a workspace is visible to that workspace's administrators and QA/QC managers. This is the point of an audit trail. Do not use RTI for anything you would not want your employer to see.
- To Portal Users. Where your organization grants a client access to a project, that client can see the inspection records, photographs, and signatures for it.
- To service providers listed above.
- For legal reasons — to comply with law, valid legal process, or a government request; to enforce our Terms; or to protect the rights, safety, or property of RTI, our customers, or the public. Where we are permitted to notify the affected customer, we will.
- In a business transfer — if we are acquired or merge, information may transfer to the successor, subject to this policy. We will notify customers.
8. Retention
| Data | Retention |
|---|---|
| Inspection content and activity log | For the life of the account, then for the export window and deletion window in our Terms |
| Account and profile data | For the life of the account, then 90 days |
| Billing records | As required by tax and accounting law, typically 7 years |
| Session IP and user-agent records | 90 days, then deleted automatically |
| Backups | Overwritten on our normal backup cycle, typically within 30 days |
Activity log entries are append-only by design. Deleting individual entries would break the hash chain that makes the record tamper-evident, so we do not delete them selectively. When a workspace is deleted, its activity log is deleted with it as a whole.
9. Security
- Every row of customer data is scoped to a single workspace by database row-level security. Tenant isolation is enforced at the database, not only in application code.
- Data is encrypted in transit using TLS, and encrypted at rest by our infrastructure provider.
- Photographs and signature images are held in access-controlled storage and served through short-lived signed URLs, not public links.
- Passwords are hashed; we cannot read them.
- The activity log is chained with SHA-256 so that alteration of a historical record becomes detectable.
- We enforce password strength rules and offer new-device verification.
No system is perfectly secure. If we become aware of a breach affecting your personal information, we will notify you and, where we act as processor, the relevant customer, without undue delay and consistent with applicable law.
10. Your rights and choices
Everyone. You can view and update your profile in the app. You can ask us to correct or delete your account information by writing to support@readytoinspect.io.
Where we act as a processor for a customer, we will refer your request to that customer and assist them in responding, rather than acting on it ourselves.
U.S. state privacy laws (including California, Colorado, Connecticut, Utah, Virginia, and others as they take effect) may give you the right to know what personal information we hold, to obtain a copy, to correct it, to delete it, and to appeal a refusal. We do not sell personal information or use it for targeted advertising, so there is nothing to opt out of in those categories. We will not discriminate against you for exercising a right.
UK, EEA, Switzerland. You may have rights of access, rectification, erasure, restriction, portability, and objection, and the right to lodge a complaint with your supervisory authority.
How to exercise a right. Email support@readytoinspect.io with enough detail to locate your information. We will respond within the period required by applicable law, generally 45 days, and may need to verify your identity first.
11. International transfers
We operate in the United States and our providers are primarily U.S.-based. If you are outside the U.S., using the Service involves transferring your information to the U.S. Where required, we rely on Standard Contractual Clauses or another lawful transfer mechanism, as set out in our Data Processing Addendum.
12. Children
The Service is for business use by adults. We do not knowingly collect personal information from anyone under 18. If you believe a minor's information is in the Service, contact us and we will work with the relevant customer to remove it.
13. Cookies and similar technologies
We use cookies and local browser storage that are strictly necessary to run the Service: keeping you signed in, remembering your theme preference, and holding unfinished inspections on your device so a lost signal does not lose your work. We do not use advertising cookies or third-party tracking pixels on the signed-in application.
14. Changes to this policy
We may update this policy. For material changes we will notify account administrators by email at least 30 days before they take effect, and update the date at the top. Continuing to use the Service after the effective date means you accept the update.
15. Contact us
Ready To Inspect LLC Utah, United States support@readytoinspect.io
If you are in the EEA or UK and we are required to designate a representative, that designation will appear here.