Trust Center

Security, privacy, and compliance.

This page is maintained by GridLine Operations LLC to answer common questions about how we protect your data, who we work with, and what your team is responsible for.

App-owner statement

This page is maintained by GridLine Operations LLC to answer common security, privacy, and compliance questions about the GridLine platform. It describes the controls and practices currently in place, and is not an independent certification or audit report.

Platform and hosting context

GridLine runs on managed cloud infrastructure provided by Lovable Cloud, which is built on Supabase's open-source platform. The application is served through a global edge network, and the database is hosted in a managed environment with automated backups, patching, and monitoring.

  • TLS encryption for all application traffic in transit
  • Database encryption at rest
  • Automated daily backups with point-in-time recovery
  • Geographic distribution via edge caching for performance

Authentication and access control

Users authenticate with email and password, Google sign-in, or phone SMS verification. Each company is isolated through row-level security policies, and role-based access controls limit what users can see and do based on their role.

  • Passwords are hashed and never stored in plain text
  • Optional phone-number verification via SMS OTP
  • Row-level security enforces company-level data isolation
  • Role-based permissions for owners, admins, supers, and field users

Data collection and use

GridLine collects the data needed to run construction operations: project details, daily reports, photos, task assignments, timecards, safety incidents, and user contact information. We use this data only to provide the service, send transactional notifications, and improve the product. We do not sell personal data.

  • Photos and documents are stored in private, company-scoped storage buckets
  • AI features process uploaded drawings and photos for analysis only
  • Email addresses are used for authentication, billing, and support
  • Usage data helps us prioritize features and monitor uptime

Subprocessors and integrations

GridLine uses the following service providers and subprocessors to deliver the platform. This list is current as of the date shown on this page and may be updated as services change.

  • Managed cloud platform — database, auth, storage, and serverless functions
  • Stripe — payment processing and subscription billing
  • Cloudflare — edge network, DNS, and DDoS protection
  • Google — sign-in authentication and optional analytics
  • React Email / Resend-compatible providers — transactional email delivery

Internal access controls

Access to production systems follows least privilege. Administrative access is limited to named accounts, protected by multi-factor authentication, and reviewed when roles change. Application code never accesses customer data with elevated privileges unless the operation is explicitly authorized server-side.

  • Multi-factor authentication required for all production administrative access
  • Least-privilege service credentials, scoped per function rather than shared globally
  • Service-role database credentials are never exposed to browser code
  • Privileged server operations verify the caller's role before executing
  • Access reviewed on role change and revoked promptly on offboarding

Vulnerability management and secure development

We run automated security scanning against the application and its database policies, plus dependency vulnerability checks, and remediate findings on a severity-based schedule. Row-level security policies are reviewed whenever the data model changes.

  • Automated platform and database policy scans run before each release
  • Dependency vulnerability scanning with prompt patching of high and critical issues
  • Critical findings targeted for remediation within 7 days; high within 30 days
  • All schema changes ship as reviewed migrations with explicit RLS policies and grants
  • Responsible disclosure welcomed at the security contact below

Data residency and resilience

Customer data is stored in a managed United States region. Static assets and application traffic are served through a global edge network for performance, but the primary datastore and file storage remain in-region. If a customer has a specific residency requirement, contact us before onboarding.

  • Primary database and object storage hosted in a US region
  • Edge network used for delivery and caching only, not for primary data storage
  • Automated daily backups with point-in-time recovery
  • Backups are encrypted at rest with the same controls as production data

Integration and API security

Where GridLine connects to third-party construction platforms, integrations use OAuth 2.0 in the installing user's permission context, or a scoped service account for unattended jobs. Tokens are encrypted at rest, refresh credentials rotate, and every sync attempt is written to an immutable audit log.

  • OAuth 2.0 authorization-code flow with PKCE for interactive installs
  • Third-party permissions remain the source of truth for what can be read or written
  • Tokens encrypted at rest; refresh credentials rotated and revocable per install
  • Per-company partitioning of credentials, rate budgets, and audit logs
  • Webhook receivers verify signatures before processing any payload

Cookies and analytics

GridLine uses essential cookies for authentication and session management. Optional analytics cookies are gated behind a consent banner and only load after you accept. You can manage or withdraw consent at any time through the cookie banner.

  • Essential cookies are required for login and security
  • Google Analytics 4 is used only after consent is granted
  • No third-party advertising cookies are used

Retention and deletion

We retain your data for as long as your account is active. After account closure, project data is retained for a limited grace period to support recovery and billing reconciliation, then deleted. You can export or delete your data by contacting support.

  • Active accounts: data retained for the life of the subscription
  • Canceled accounts: a 90-day grace period before deletion
  • Admins can delete projects, photos, and documents from within the app
  • Full account deletion available by emailing support

Privacy requests and user rights

You can request access to, correction of, or deletion of your personal data by contacting the email below. We respond to verifiable requests within 30 days. California residents may exercise CCPA/CPRA rights; other jurisdictions may have similar rights under local law.

  • Access your data through the Settings and Company Profile pages
  • Request a full export by emailing support
  • Request deletion of your account and associated data
  • Update or correct profile information directly in the app

Incident response and security contact

If you discover a security issue or suspect unauthorized access, please report it to us immediately. We triage reports within one business day and work to resolve confirmed issues promptly.

  • Security contact: gridlineoperations@outlook.com
  • Please include a clear description and steps to reproduce, if applicable
  • We do not run a public bug-bounty program, but we do welcome responsible disclosure

Shared responsibility

Security and compliance are shared between GridLine Operations and our customers. We maintain the platform's infrastructure, access controls, and encryption. Customers are responsible for managing user accounts, assigning appropriate roles, and ensuring that field data collected through the platform is accurate and used in compliance with their own obligations.

  • GridLine is responsible for platform uptime, patching, and encryption
  • Customers are responsible for user provisioning and role assignment
  • Customers are responsible for the accuracy of field data they enter
  • Construction decisions should always be verified by qualified professionals

Construction-specific disclaimers

GridLine Operations is a software platform, not a substitute for licensed engineering, architectural, legal, or safety advice. AI-generated insights, weather data, cost estimates, and schedule suggestions may contain errors. Always verify critical information before acting on it. See our Terms of Service for the full limitation of liability.

Questions or requests?

Contact us at gridlineoperations@outlook.com or read our Privacy Policy and Terms of Service.

Last updated: August 31, 2026.