Privacy notice.
A launch-ready template describing the product’s data boundaries. Counsel approval and the final legal entity details are required before public production.
Last updated: August 9, 2026
Controller identity
The legal entity name, SPCSEAR DBA or assumed-name status, business address, and formal privacy notice address remain placeholders pending founder and counsel approval.
Information we process
SPCSEAR processes organization identity, user and role data, contractor verification evidence, project addresses and scope facts, uploaded documents, review and audit records, communication preferences, service usage, and provider references needed to operate the service.
How information is used
Information is used to authenticate users, verify contractor organizations, operate permit workflows, retain evidence, prevent fraud and abuse, support customers, bill for authorized services, and meet legal and security obligations.
What we do not collect
SPCSEAR does not store raw card numbers or CVC data. Product analytics prohibit names, emails, phone numbers, project addresses, document contents, credentials, exact geolocation, and unrestricted free text.
Service providers and authorities
Managed identity, payments, geocoding, hosting, storage, monitoring, and communication providers may process narrowly required information under contract. Project information is disclosed to a permitting authority only through an authorized service workflow.
Retention and rights
Retention depends on the record classification, contractual obligations, security needs, and applicable law. Requests for access, correction, deletion, or restriction are verified before action and may be limited where records must be retained.
Contact
Privacy requests should be sent to privacy@tradepermit.com.