Trust Center
Security, privacy, and compliance.
This page is maintained by GridLine Operations LLC to answer common questions about how we protect your data, who we work with, and what your team is responsible for.
App-owner statement
This page is maintained by GridLine Operations LLC to answer common security, privacy, and compliance questions about the GridLine platform. It describes the controls and practices currently in place, and is not an independent certification or audit report.
Platform and hosting context
GridLine runs on managed cloud infrastructure provided by Lovable Cloud, which is built on Supabase's open-source platform. The application is served through a global edge network, and the database is hosted in a managed environment with automated backups, patching, and monitoring.
- •TLS encryption for all application traffic in transit
- •Database encryption at rest
- •Automated daily backups with point-in-time recovery
- •Geographic distribution via edge caching for performance
Authentication and access control
Users authenticate with email and password, Google sign-in, or phone SMS verification. Each company is isolated through row-level security policies, and role-based access controls limit what users can see and do based on their role.
- •Passwords are hashed and never stored in plain text
- •Optional phone-number verification via SMS OTP
- •Row-level security enforces company-level data isolation
- •Role-based permissions for owners, admins, supers, and field users
Data collection and use
GridLine collects the data needed to run construction operations: project details, daily reports, photos, task assignments, timecards, safety incidents, and user contact information. We use this data only to provide the service, send transactional notifications, and improve the product. We do not sell personal data.
- •Photos and documents are stored in private, company-scoped storage buckets
- •AI features process uploaded drawings and photos for analysis only
- •Email addresses are used for authentication, billing, and support
- •Usage data helps us prioritize features and monitor uptime
Subprocessors and integrations
GridLine uses the following service providers and subprocessors to deliver the platform. This list is current as of the date shown on this page and may be updated as services change.
- •Managed cloud platform — database, auth, storage, and serverless functions
- •Stripe — payment processing and subscription billing
- •Cloudflare — edge network, DNS, and DDoS protection
- •Google — sign-in authentication and optional analytics
- •React Email / Resend-compatible providers — transactional email delivery
Internal access controls
Access to production systems follows least privilege. Administrative access is limited to named accounts, protected by multi-factor authentication, and reviewed when roles change. Application code never accesses customer data with elevated privileges unless the operation is explicitly authorized server-side.
- •Multi-factor authentication required for all production administrative access
- •Least-privilege service credentials, scoped per function rather than shared globally
- •Service-role database credentials are never exposed to browser code
- •Privileged server operations verify the caller's role before executing
- •Access reviewed on role change and revoked promptly on offboarding
Vulnerability management and secure development
We run automated security scanning against the application and its database policies, plus dependency vulnerability checks, and remediate findings on a severity-based schedule. Row-level security policies are reviewed whenever the data model changes.
- •Automated platform and database policy scans run before each release
- •Dependency vulnerability scanning with prompt patching of high and critical issues
- •Critical findings targeted for remediation within 7 days; high within 30 days
- •All schema changes ship as reviewed migrations with explicit RLS policies and grants
- •Responsible disclosure welcomed at the security contact below
Data residency and resilience
Customer data is stored in a managed United States region. Static assets and application traffic are served through a global edge network for performance, but the primary datastore and file storage remain in-region. If a customer has a specific residency requirement, contact us before onboarding.
- •Primary database and object storage hosted in a US region
- •Edge network used for delivery and caching only, not for primary data storage
- •Automated daily backups with point-in-time recovery
- •Backups are encrypted at rest with the same controls as production data
Integration and API security
Where GridLine connects to third-party construction platforms, integrations use OAuth 2.0 in the installing user's permission context, or a scoped service account for unattended jobs. Tokens are encrypted at rest, refresh credentials rotate, and every sync attempt is written to an immutable audit log.
- •OAuth 2.0 authorization-code flow with PKCE for interactive installs
- •Third-party permissions remain the source of truth for what can be read or written
- •Tokens encrypted at rest; refresh credentials rotated and revocable per install
- •Per-company partitioning of credentials, rate budgets, and audit logs
- •Webhook receivers verify signatures before processing any payload
Retention and deletion
We retain your data for as long as your account is active. After account closure, project data is retained for a limited grace period to support recovery and billing reconciliation, then deleted. You can export or delete your data by contacting support.
- •Active accounts: data retained for the life of the subscription
- •Canceled accounts: a 90-day grace period before deletion
- •Admins can delete projects, photos, and documents from within the app
- •Full account deletion available by emailing support
Privacy requests and user rights
You can request access to, correction of, or deletion of your personal data by contacting the email below. We respond to verifiable requests within 30 days. California residents may exercise CCPA/CPRA rights; other jurisdictions may have similar rights under local law.
- •Access your data through the Settings and Company Profile pages
- •Request a full export by emailing support
- •Request deletion of your account and associated data
- •Update or correct profile information directly in the app
Incident response and security contact
If you discover a security issue or suspect unauthorized access, please report it to us immediately. We triage reports within one business day and work to resolve confirmed issues promptly.
- •Security contact: gridlineoperations@outlook.com
- •Please include a clear description and steps to reproduce, if applicable
- •We do not run a public bug-bounty program, but we do welcome responsible disclosure
Construction-specific disclaimers
GridLine Operations is a software platform, not a substitute for licensed engineering, architectural, legal, or safety advice. AI-generated insights, weather data, cost estimates, and schedule suggestions may contain errors. Always verify critical information before acting on it. See our Terms of Service for the full limitation of liability.
Questions or requests?
Contact us at gridlineoperations@outlook.com or read our Privacy Policy and Terms of Service.
Last updated: August 31, 2026.