← Back

Privacy Policy

Effective Date: April 14, 2026

This Privacy Policy describes how GC Commander ("Service") collects, uses, and protects your personal information.

1. Information We Collect

Account Information: Name, email address, company name, username, and password (stored as a bcrypt hash). Usage Data: Pages visited, features used, timestamps, IP addresses, browser type. Business Data: All data you enter into the platform (jobs, invoices, contractors, etc.) remains your property.

2. How We Use Your Information

We use your information to: (a) provide and maintain the Service; (b) authenticate your identity; (c) send transactional emails (verification, password reset, billing); (d) improve the Service through aggregate analytics; (e) comply with legal obligations.

3. Data Storage & Security

Your data is stored in encrypted databases with access controls. We use HTTPS encryption for all data in transit. Passwords are hashed using industry-standard algorithms. We perform regular security audits and backups.

4. Data Sharing

We do not sell, trade, or rent your personal information. We may share data with: (a) payment processors (Stripe) for billing; (b) law enforcement when legally required; (c) service providers under strict confidentiality agreements.

5. Your Rights (GDPR/CCPA)

You have the right to: (a) access your personal data; (b) rectify inaccurate data; (c) request deletion of your data; (d) export your data in a portable format; (e) withdraw consent at any time; (f) object to data processing. Exercise these rights via Settings → Privacy or by contacting support.

6. Cookies

We use essential cookies only for session management and authentication. We do not use tracking cookies, advertising cookies, or third-party analytics. You can disable cookies in your browser settings, but this may affect Service functionality.

7. Data Retention

Active account data is retained for the duration of your subscription. After account deletion, data is purged within 30 days. Backups containing your data are rotated and permanently deleted within 90 days. Audit logs are retained for 12 months for security purposes.

8. Children's Privacy

The Service is not intended for users under 16. We do not knowingly collect information from children.

9. Changes to This Policy

We will notify you of material changes via email or in-app notification at least 30 days in advance.