Scope and our role
This Privacy Policy applies to the Tiercord website, applications, support channels and related services (the Service). Tiercord is business software intended for construction-industry organizations and their authorized personnel, not for personal or family use.
Tiercord is responsible for personal information used to operate accounts, billing, security, support and direct communications. For project, contract, counterparty, document and other information entered by a customer organization, that organization normally decides why and how the information is handled. Tiercord processes that Customer Data on its instructions to provide the Service. If your information was entered by a Tiercord customer, contact that organization first; we will assist it with an appropriate request.
Information we collect
Depending on how the Service is used, we collect or process:
- Account and organization data: name, work email, password authentication records, Google account identifier and basic profile information, organization name, membership, role and preferences.
- Construction and business records: projects, contracts, counterparties, contacts, invoices, payments, holdbacks, notices, declarations, adjudication materials, deadlines, documents and related correspondence.
- Connected-service data: connection identifiers, account metadata, granted permissions, encrypted access credentials, synchronization records and information a user chooses to import, export or send.
- Billing data: plan, subscription, transaction and invoice metadata. Payment-card details are collected and handled by Stripe, not stored in Tiercord's application database.
- Security and use data: sign-in and account events, audit records, feature activity, delivery evidence, device and browser information, IP address, timestamps, diagnostics and error logs.
- Support and communications: messages, attachments, feedback and other information supplied when contacting Tiercord.
Where information comes from
We receive information directly from users and workspace administrators; automatically from use of the Service; from other authorized members of the same workspace; and from services a user deliberately connects, such as Google, Gmail, Microsoft, QuickBooks Online, Xero, Procore or an organization's identity provider. A customer may also enter information about employees, contractors, suppliers, owners or other project participants. Customers are responsible for having authority to provide that information to Tiercord.
Why we use information
We use personal information only for reasonable, disclosed purposes, including to:
- create and administer accounts, workspaces, memberships and permissions;
- provide project workflows, calculate deadlines, create documents, preserve audit records and deliver authorized emails and reminders;
- connect and synchronize services that a user or administrator enables;
- process subscriptions, maintain business records and provide support;
- authenticate users, protect the Service, investigate misuse, diagnose errors and recover from incidents;
- comply with law, enforce agreements and establish or defend legal claims; and
- understand and improve the Service using aggregated or de-identified information where practical.
We do not sell personal information. We do not use personal information for third-party behavioural advertising.
Google login and Gmail data
Google login. If you choose Sign in with Google, Google provides the identifier and basic profile information needed to authenticate you, such as your name and email address. Google login is separate from connecting Gmail for delivery.
Gmail sending. If an authorized user connects a Gmail account, Tiercord requests only openid, email and the Gmail gmail.send permission. This lets Tiercord confirm the connected address and send messages the user or an authorized workspace administrator chooses or configures through Tiercord. It does not give Tiercord permission to read, list or download the mailbox, messages, drafts, contacts, labels or settings.
Tiercord stores the connected address and Google subject identifier, granted permission, connection status and metadata, and encrypted OAuth credentials needed to send. Delivery records may include the sender, recipients, subject, delivery status, provider message identifier, timestamps and the Tiercord record that caused the send. These records form part of the customer's audit trail.
Google user data is used only to provide or improve the user-facing feature that caused the access. It is not sold, used for advertising or credit decisions, or used to train generalized artificial-intelligence models. It is shared only with infrastructure providers needed to operate the feature, for security or legal reasons, in a business transfer subject to appropriate safeguards, or with the user's explicit consent. Human access is limited to what is necessary for support with permission, security, legal compliance or internal operations where data is aggregated where feasible. Tiercord's handling of Google data is intended to comply with the Google API Services User Data Policy, including its Limited Use requirements.
A connected Gmail account can be disconnected in Tiercord. The user can also revoke Tiercord under Google Account permissions. Disconnection stops new sends through that connection, but Tiercord may retain past delivery and audit evidence where reasonably needed for customer records, security or legal obligations.
Optional artificial intelligence features
When a user deliberately runs an AI-assisted feature, Tiercord sends the prompt and the relevant workspace information needed for that request to Anthropic. Tiercord does not send workspace data to any AI provider except through the features described in this section. Most of those features stay off until someone in the workspace turns them on. Assisted document reading is the exception and is described immediately below. AI output and usage metadata are returned to Tiercord and may be retained with the relevant workspace record. Users should not include information that is unnecessary for the requested task and must review all output before relying on it.
There is one case where the sending is not a separate decision by the user, and it is described here rather than left to be inferred. When a user uploads an invoice or a notice and Tiercord cannot read it from the text of the file, because it is a scan, a photograph, or a layout Tiercord cannot parse, Tiercord sends that document to Anthropic to be read, as part of the upload the user asked for. It happens only on documents Tiercord could not otherwise read, only up to the size and page limits Tiercord applies, and never on documents Tiercord itself generated. Every value read this way is labelled on screen as having been read by AI, is recorded as such in the workspace audit trail, and still has to be confirmed by a person before Tiercord records anything from it. Workspaces that do not want documents sent this way can ask Tiercord to switch the feature off for their account, in which case those uploads still succeed and are filled in by hand.
Connecting Tiercord to an assistant. After a workspace administrator enables this feature, an eligible member can authorize a read-only connection to an assistant such as Claude, ChatGPT or Microsoft Copilot. The member chooses the access and projects to share within their current Tiercord permissions. The assistant can then request the authorized records, including projects, contracts, counterparties, invoices, payments, holdbacks, notices and computed deadlines, without a new consent screen for each request. Tiercord checks current access when the connection is used. The member can withdraw their own connection, an administrator can withdraw workspace connections, and loss of required access can also stop it. The connection cannot change, send or issue records, and some free-text fields are withheld entirely.
Tiercord records each authorized read attempt before reading and records the prepared response before returning workspace information. If either record cannot be confirmed, that information is not returned. These audit records describe the request and prepared output; they do not prove that a provider or person received it. Information returned through the connection goes to the provider account or agent used for that connection, which may be an individual or organizational account. If an agent uses shared connected credentials, other people using that agent may receive information within the authorized scope. The provider's handling and any further sharing depend on its terms, the applicable account agreement and settings. This Policy continues to describe Tiercord's own handling of the information.
When we disclose information
We disclose information only as reasonably needed for the purposes above, including to:
- Supabase for database, authentication and file-storage infrastructure;
- Vercel for application hosting, delivery and network services;
- Google for optional Google login and direct Gmail delivery;
- Microsoft for optional Microsoft sign-in and direct Outlook delivery;
- Stripe for optional subscription billing and payment processing;
- Anthropic when a user invokes an optional AI feature;
- Intuit QuickBooks, Xero and Procore when an authorized administrator connects those optional integrations;
- Sentry if optional external error monitoring is enabled; and
- professional advisers, insurers, auditors, law-enforcement bodies or other authorities when reasonably necessary or legally required.
Information may also be disclosed in a financing, reorganization, sale or transfer of all or part of the business, subject to confidentiality and applicable law. Messages sent from a connected Gmail account are delivered directly through Google's Gmail API.
Storage and processing locations
Tiercord's core customer database and file storage are configured in Supabase's Canada Central region. Hosting, network, support, security, payment, AI and optional integration providers may process information elsewhere in Canada or in other countries. Information processed outside your province or Canada may be subject to the laws and lawful access processes of that location. We use contractual, technical and organizational safeguards appropriate to the service and information involved.
Consent and choices
Where consent is required, it may be express or implied depending on the sensitivity of the information and the reasonable expectations surrounding the transaction. Optional integrations and AI features remain off until an authorized user activates them. You may withdraw consent on reasonable notice, subject to legal or contractual restrictions and reasonable notice. Withdrawal may prevent Tiercord from providing the affected feature or Service. Collection, use or disclosure may also occur without consent where applicable law permits or requires it.
Retention and deletion
We retain information only as long as reasonably needed for the purposes described here, customer instructions, dispute and audit requirements, security, backups and applicable legal obligations. The period depends on the type and sensitivity of the information, the customer's configuration, the active account relationship and legal limitation periods.
A deactivated individual account ordinarily has a 90-day reactivation period before permanent deletion is scheduled. Organization deletion removes active workspace records through the deletion workflow. Limited copies may remain temporarily in protected backups, security logs or legally required records and are isolated or deleted under the applicable retention cycle. Past email delivery and tamper-evident audit records may be retained where necessary to preserve a customer's compliance evidence or establish legal claims.
Safeguards and incidents
We use administrative, technical and physical safeguards appropriate to the sensitivity of the information, including encrypted network transport, access controls, tenant isolation, audit logging, backups and application-layer encryption for selected sensitive fields and integration credentials. No system is perfectly secure, and Tiercord cannot guarantee that an incident will never occur.
Customers are responsible for protecting credentials, using appropriate workspace roles, promptly removing access that is no longer authorized, and notifying Tiercord of suspected compromise. Report security or privacy concerns to the Privacy Officer using the contact below.
Service and marketing communications
We may send account, security, billing, support, deadline, backup and other operational messages needed to provide the Service. Where required, promotional messages are sent with consent and include an unsubscribe method. Opting out of marketing does not stop essential operational communications. Customer-generated emails and reminders are sent at the direction of the customer organization, which is responsible for its recipients, content and legal authority to send them.
Access, correction and complaints
Subject to applicable exceptions, you may request access to personal information under Tiercord's control, ask how it has been used and disclosed, and request correction. We may need to verify identity and may ask for details needed to locate the record. If another customer organization controls the information, we will direct the request to that organization or assist it in responding.
Send a request or complaint to the Privacy Officer at support@tiercord.ca. We will investigate and respond within the period required by applicable law. You may also contact the Office of the Information and Privacy Commissioner for British Columbia or, where applicable, the Office of the Privacy Commissioner of Canada.
Changes and contact
We may update this Policy as the Service, providers or law changes. We will post the new version here and change the effective date. If a change is material, we will provide additional notice where reasonably appropriate or legally required. The version in effect when information is handled governs that handling, subject to applicable law.
Privacy Officer, Tiercord Compliance
Email: support@tiercord.ca
General support: support@tiercord.ca
Related legal document
Read these documents together for the complete account terms.