Effective 24 July 2026

Privacy, in plain language.

Siteglass processes construction business records to provide quoting, document, tender and bookkeeping workflows. We do not sell personal information.

Information we process

This can include account and company details, team roles, customer contact details, job descriptions, images, documents, material and labour rates, quotes, approvals, audit records and support messages.

Connected services

When an administrator connects Xero, Google Workspace or Microsoft 365, Siteglass receives only the permissions approved in that provider's consent screen. Connector tokens are encrypted at rest. External actions remain subject to the workspace role and approval controls.

AI processing

Company evidence can be sent to the configured model provider to answer a company request. Siteglass does not use Google Workspace, Microsoft 365, Xero or other customer connector data to train or improve a shared model. Connector data is limited to the user-facing feature authorised by that company.

Google Workspace Limited Use

Siteglass's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell this information, use it for advertising or permit humans to read mailbox or Drive content except with documented permission for specific support, security or legal purposes.

Storage and security

Siteglass separates workspaces by tenant, applies role checks on protected routes, encrypts connector credentials, records sensitive actions and requires human approval before external connector calls. No internet service can guarantee absolute security.

Access, correction and deletion

Company administrators can update operational data and disconnect integrations. For an access, correction or deletion request, use the Siteglass contact page. We may retain records where required for security, legal or accounting obligations.

Retention, providers and international processing

We retain personal information only while it is needed for the enabled service, security, legal or accounting purpose. Siteglass uses contracted hosting, identity, model and connector providers; processing can occur outside the user's country. Applicable transfer safeguards and a current subprocessor list form part of the production customer agreement.

Security incidents

We assess suspected breaches, contain access, preserve evidence and notify affected customers and regulators when applicable law requires it. Security concerns can be sent through the Siteglass contact page.