Privacy Policy
Last updated: April 13, 2026
1. Introduction
ProBidCore ("we," "our," or "us") is committed to protecting the privacy of our users. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our construction bid management platform and Procore integration service.
2. Information We Collect
We collect information in the following ways:
- Account Information: When you create an account, we collect your name, email address, and authentication credentials managed through our authentication provider (Clerk).
- Project Data: Budget line items, WBS codes, cost types, quantities, unit costs, and other estimate data you enter into ProBidCore.
- Procore Integration Data: When you connect your Procore account via OAuth 2.0, we receive and store an access token and refresh token. We also retrieve your Procore user email, company name, and company ID to facilitate the integration. We do not store your Procore password.
- Usage Data: We collect information about how you interact with our service, including sync history, API usage patterns, and feature usage.
- Payment Information: Billing and subscription data is processed securely through Stripe. We do not store credit card numbers on our servers.
3. How We Use Your Information
- To provide, maintain, and improve our bid management and Procore sync services
- To process your transactions and manage your subscription
- To sync your budget line items to your Procore project budgets when you initiate a sync
- To send you service-related notifications (sync results, errors, account updates)
- To provide customer support and respond to your requests
- To detect, prevent, and address technical issues and security vulnerabilities
4. Procore Data Access
When you connect ProBidCore to your Procore account, we request the following OAuth scopes:
budgets:read— To check budget lock status before syncingbudgets:write— To push budget line items to your Procore projectprojects:read— To list and verify your Procore projects
We only access Procore data when you explicitly initiate an action (connecting, syncing, or disconnecting). We do not access your Procore data in the background or for any purpose other than the features you use. You can disconnect your Procore account at any time from the Settings page, which immediately revokes our access.
5. Data Storage & Security
- All data is stored in encrypted PostgreSQL databases hosted on secure infrastructure
- Procore OAuth tokens are stored server-side and never exposed to the browser
- OAuth state parameters are cryptographically signed using HMAC-SHA256 to prevent CSRF attacks
- All communication uses TLS/HTTPS encryption in transit
- Access to your data is scoped to your authenticated user account — no other user can access your projects or line items
6. Data Sharing
We do not sell, rent, or trade your personal information. We share data only in these circumstances:
- With Procore: When you initiate a sync, we send your budget line item data to Procore's API on your behalf
- Payment Processing: Stripe processes your billing information under their own privacy policy
- Legal Requirements: We may disclose information if required by law, regulation, or legal process
7. Data Retention
We retain your account data and project data for as long as your account is active. If you delete your account, we will delete your personal data within 30 days, except where we are required by law to retain it. Sync logs are retained for audit purposes for up to 12 months.
8. Your Rights
You have the right to:
- Access and download your project data at any time via CSV export
- Disconnect your Procore integration at any time
- Request deletion of your account and associated data
- Opt out of non-essential communications
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page with a revised "Last updated" date.
10. Contact Us
If you have questions about this Privacy Policy or our data practices, contact us at: