Privacy Policy
Effective date: October 1, 2026. Last updated: October 1, 2026.
1. Introduction
Welcome to Groundflag. We respect your privacy and are committed to protecting your personal data. This Privacy Policy explains how Design Master Solutions LLC ("Groundflag", "we", "us" or "our") collects, uses, shares and protects information when you use our web application, mobile application and related services (together, the "Service").
1.1 Who we are
Design Master Solutions LLC
Yarmouth, MA 02664, United States
Privacy and general inquiries: hello@groundflag.com
1.2 Scope of this policy
This Privacy Policy applies to:
- The Groundflag web application and mobile apps
- Client, subcontractor and vendor portals
- API services and integrations
- Our websites and communications
1.3 Compliance
We comply with:
- CCPA/CPRA (California Consumer Privacy Act)
- GDPR (EU General Data Protection Regulation)
- LGPD (Brazil Lei Geral de Proteção de Dados)
- PCI DSS, through Stripe, for card payments
2. Information we collect
2.1 Information you provide directly
Account information: full name and business name, email address, phone number, business address, password (stored hashed) and tax identification number.
Business information: clients, jobs, estimates, change orders, invoices and bills, time cards, daily logs, photos and documents, notes and messages, and team member information.
Payment information: credit and debit card details are processed by Stripe and not stored by us; we keep the billing address, payment history and the payment status.
2.2 Information collected automatically
Usage data: pages and features accessed, actions taken, search queries and navigation patterns.
Device information: device type and model, operating system and version, app version, screen resolution and unique device identifiers.
Location data: IP-based approximate location (city or region). A team member's GPS location is collected only while that person is clocked in, and only if their company turns on the geofence for time cards. It is not collected outside clock in.
2.3 Information from third parties
Social login: Google (name, email, profile photo), Apple (name, email or masked email).
Payment processors: Stripe (payment status, last 4 card digits, transaction IDs).
Integration partners: QuickBooks (accounting data you sync), Google Calendar (events you create), CompanyCam (photos you choose to import).
2.4 Google Workspace APIs: Limited Use
Groundflag's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We request Google Calendar scopes for a single purpose: to show your own and shared calendars inside the app, and to create, reschedule and remove the events that mirror your Groundflag activities. We do not use, transfer or sell Google Workspace user data to develop, improve or train artificial intelligence or machine learning models, and our AI features have no access to Google Calendar data.
3. How we use your information
- Create and manage your account
- Authenticate identity and secure your account
- Store and sync data across devices
- Process payments and generate invoices
- Send transactional emails (password resets, receipts, documents you send to your clients)
- Generate AI drafts from the audio, photos and documents you send (see section 4)
- Provide customer support
- Understand feature usage and fix bugs
- Send product communications (with opt-out)
- Comply with legal obligations
- Detect and prevent fraud
4. AI processing
When you use an AI feature, the audio, photos or documents you send are processed by our AI providers to produce a draft (a daily log, a task, a change order, a bill) that a person reviews and confirms. We do not use your data to train AI models.
5. How we share your information
We never sell, rent or trade your personal data to third parties for their marketing purposes. We share data only with providers that run the Service:
- Cloud infrastructure: Railway (application and database, United States), AWS S3 (file storage, us-east-1), Cloudflare (CDN and web hosting)
- Payment processing: Stripe (PCI DSS compliant)
- Email: Resend
- AI processing: Anthropic and Google, only for the AI features you use
- Error tracking: Sentry
All service providers are contractually bound to use data only to provide their services, to implement appropriate security, and to comply with privacy laws.
5.1 Text messaging (SMS)
When you give consent in your client portal, Design Master Solutions LLC, the company behind Groundflag, sends transactional text messages about the jobs you have with contractors that use Groundflag; Design Master Solutions LLC is the sender: appointment reminders, job updates, estimate, invoice and payment notifications. Your mobile number and the consent record are stored on your client record and used only for that purpose.
Mobile information and SMS opt-in consent are never shared with third parties or affiliates for marketing or promotional purposes, and are never shared with any third party for any other purpose. Phone numbers are disclosed only to the messaging carrier and to our messaging provider, acting solely as our subprocessor to deliver the messages you asked for. Reply STOP to any message to opt out, or untick the consent box in your portal. See our SMS Terms and Conditions for the full program details.
6. Data security
- Encryption in transit (TLS)
- Role-based access control: each person sees what their role allows
- Card data handled by Stripe, never stored on our servers
- Daily database backups
In case of a data breach, we will notify you within 72 hours of discovery.
7. Data retention
- Active accounts: data retained while your account is active
- Canceled accounts: data retained for 90 days (for reactivation), then permanently deleted
- Usage logs: retained for 90 days
- Support tickets: retained for 3 years
- Backups: purged within 30 days of deletion
8. Your privacy rights
All users
- Access and export: export all of your data at any time from the app (CSV, JSON or PDF), or ask us for a copy
- Correction: update inaccurate information anytime
- Deletion: delete your account and all data
- Opt-out: unsubscribe from product communications at any time
CCPA/CPRA (California residents)
Right to know, delete, opt out of data sale (we do not sell data), correct, and limit use of sensitive data. No discrimination for exercising rights.
GDPR (European users)
Additional rights: restriction of processing, objection to processing, data portability, the right not to be subject to automated decisions, and the right to lodge complaints with authorities.
LGPD (Brazilian users)
Additional rights: anonymization, blocking, portability, explanation of processing, and consent withdrawal. Response within 15 days.
How to exercise your rights
Email hello@groundflag.com. Response time: 30 days (15 days for LGPD, 45 days for CCPA).
9. International data transfers
Data is stored in the United States. We use Standard Contractual Clauses (SCCs) for transfers from the EEA or Brazil.
10. Children's privacy
Groundflag is a B2B service for adults 18 and over. We do not knowingly collect data from children under 18. If discovered, such data will be deleted within 48 hours.
11. Cookies
Essential: authentication, security and performance (cannot be disabled).
Functional: language and theme preferences (can be disabled).
12. Changes to this policy
We will notify you of material changes by email and in-app notice at least 30 days before they take effect. Continued use constitutes acceptance.
13. Contact us
Privacy and support: hello@groundflag.com
Design Master Solutions LLC, Yarmouth, MA 02664, United States