Privacy Policy
Effective date: June 13, 2026 · Last updated: June 13, 2026
This Privacy Policy explains how DMZ Technology Corp ("we") collects, uses, and shares information when you use ObraCraft (the "Service"). ObraCraft is a business tool; most data you provide is your company's business data.
1. Information we collect
- Account & company info: your email, organization name, and optional contact name, business address, phone, and logo.
- Content you upload or create ("Your Content"): supplier invoices and documents (PDFs and photos), the line items, item numbers, descriptions, prices, supplier names, job names, estimates, material lists, and any attachments you add.
- Payment information: handled by our payment processor, Stripe. We receive limited billing details (e.g., plan, status, last 4 digits) but do not store your full card number.
- Login & device records (security): to protect accounts and enforce that a subscription is used by a single business, we record login events (time, IP address, browser/device user-agent) and store a device identifier in a cookie. New-device sign-ins may trigger an email alert to the account owner.
- Email delivery receipts: emails that deliver billing documents on behalf of your company (e.g., payment applications) include a small open-receipt image and say so in their footer; when the recipient's mail client loads it, we record the open event so the sending company can confirm the document arrived.
- Usage & technical data: log data such as pages accessed, actions, timestamps, and error information.
2. How we use information
- To provide and operate the Service (store your catalog, generate estimates/PDFs, run searches and reconciliation).
- To read and structure the documents you upload. When you upload an invoice or photo, its contents are sent to a third-party document-processing provider (see Subprocessors) to extract the line items and fields. That provider processes the data to return results to us and, per its terms, does not use your data to train its models. You review and confirm the extracted data before it is saved.
- To authenticate you, secure accounts, detect/prevent abuse and credential sharing, and maintain audit/login history.
- To process subscriptions and payments (via Stripe).
- To communicate with you (login codes, security alerts, billing notices, support).
- To maintain, troubleshoot, and improve the Service, including using aggregated, de-identified data.
3. How we share information
- Service providers (subprocessors) who host, store, process payments, send email, and process documents on our behalf — see our Subprocessors page.
- Legal/safety: when required by law or to protect rights, safety, or the integrity of the Service.
- Business transfer: in connection with a merger, acquisition, or sale of assets, subject to this Policy.
- We do not sell your personal information, and we do not share one organization's data with another customer.
4. Google user data (optional Google Calendar sync)
ObraCraft offers an optional integration that lets you connect your own Google Account so your dated project tasks and company reminders appear on your Google Calendar. This feature is off by default; it operates only after you explicitly connect your Google Account and grant permission, and you can disconnect it at any time.
- What we access. When you connect, we request a single, narrow Google permission — the ability to
view and edit events on your calendars (
https://www.googleapis.com/auth/calendar.events), together with your basic Google profile email so we can show which account is connected. We do not request access to your Gmail, Google Drive, Contacts, photos, or any other Google data. - How we use it. We use this access solely to (a) create, update, and delete the calendar events that correspond to your ObraCraft tasks and reminders, and (b) read back changes you make to those same events (for example, moving an event to reschedule a task, or deleting it to mark a task complete) so your calendar and ObraCraft stay in sync. We read only the events created by ObraCraft, which we tag for this purpose; we do not read, collect, or store your other calendar events.
- Storage. To keep the sync working, we securely store the authorization token Google issues for your account, associated with your organization and isolated from other organizations. We never receive or store your Google password.
- Sharing. We do not sell this data, we do not use it for advertising, and we do not share it with other customers. One organization's Google data is never shared with another.
- Your control. You can revoke ObraCraft's access at any time from within ObraCraft (Company → Disconnect) or from your Google Account at myaccount.google.com/permissions. When you disconnect, we remove the calendar events ObraCraft created and delete the stored authorization token.
Limited Use. ObraCraft's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: we use Google Calendar data only to provide the calendar-sync features described above; we do not transfer it to others except to the service providers that host and operate ObraCraft as needed to provide these features, to comply with applicable law, or in connection with a merger or acquisition; we do not use it for advertising; we do not use it to develop, improve, or train generalized or non-personalized artificial-intelligence or machine-learning models; and we do not allow humans to read it except with your explicit consent, as needed for security or to fix a problem you report, or to comply with applicable law.
5. Data isolation & storage
Your Content is scoped to your organization within the Service. Uploaded files are stored with a cloud storage provider under keys namespaced to your organization. Data is stored in the United States.
6. Retention
We keep your information for as long as your account is active and as needed to provide the Service. After account termination we may retain data for a reasonable period for backup, legal, and accounting purposes, then delete or de-identify it. You may request deletion (see Your Rights).
When your subscription ends, your account follows a documented off-boarding schedule: for 30 days your account remains accessible in read-only mode so you can view everything, export your data, or reactivate. After that we automatically email you a complete archive of your data (an Excel workbook of your records plus every file you uploaded; the download link is valid for 30 days) and access is limited to the Billing page. Your data is stored for a further 30 days — reactivating during this time restores your account in full. If you do not reactivate, your organization's data is permanently deleted approximately 60 days after your subscription ends. Deleting your account in-app (Account Settings → Danger zone) deletes your data immediately instead.
7. Cookies
We use strictly-necessary cookies for login sessions and a device-identification cookie for security. Our payment and bot-protection providers may also set cookies. See our Cookie Notice.
8. Security
We use measures such as encrypted connections (HTTPS), email one-time-code login, single-active-session enforcement, new-device alerts, and per-organization data isolation. No method of transmission or storage is 100% secure, but we work to protect your information.
9. Your rights
- Access, correct, or delete your account information (much of it is editable in-app under Account settings).
- Delete your account and organization — and all associated data — at any time from within the app under Account Settings → Danger zone.
- Download a complete copy of your organization's data (data portability) at any time from Account Settings → Billing → Your data — we email the account administrator a download link containing an Excel workbook of your records and every uploaded file. You may also request a copy by contacting us.
- California (CCPA/CPRA): you have rights to know, delete, and correct personal information, and to not be discriminated against for exercising them. We do not sell or "share" personal information for cross-context behavioral advertising.
- If you are outside the U.S., note that your data is processed in the United States.
10. Children
The Service is for businesses and is not directed to anyone under 18. We do not knowingly collect data from children.
11. Changes
We may update this Policy; we will post changes here with a new effective date and notify you of material changes where appropriate.
12. Contact
DMZ Technology Corp · 3432 W 84 St #106, Hialeah, FL 33018 · Email: [email protected]