Privacy Policy

How SyteSense handles your data, simply explained.

Effective date:

Introduction

SyteSense (“SyteSense”, “we”, “us”, or “our”) is committed to protecting the privacy, confidentiality, and security of personal information entrusted to us.

This Privacy Policy describes how we collect, use, disclose, process, store, and safeguard personal data when you access or use:

  • The SyteSense web platform
  • Mobile applications
  • Construction workflow management tools
  • Field reporting and compliance tools
  • Subcontractor coordination systems
  • Project documentation and analytics services
  • Any related services (collectively, the “Services”)

SyteSense provides enterprise-grade construction management software to contractors, subcontractors, and infrastructure stakeholders globally.

This policy is written for users in New Zealand and Australia. If you are accessing the site from another jurisdiction, your local laws may grant you additional rights — please contact us if you have any questions about how we handle your data.

What information we collect

We only collect what we need to run our services and respond to your enquiries. This section covers the website. For the mobile app, see the SyteSense Mobile App section below.

Form submissions

When you fill out a form on our site, we collect the information you provide:

  • Your name
  • Your company name
  • Your email address
  • Your phone number
  • Any message or details you choose to share

Website analytics

We use Google Analytics 4 (provided by Google) to understand how visitors use our website so we can improve it. Google Analytics uses cookies and similar technologies. The data collected includes:

  • Pages visited and time spent on each page
  • How far you scroll down a page
  • Which calls-to-action and links you click
  • A randomly generated identifier (stored in a cookie) used to recognise return visits within Google Analytics
  • Approximate location derived from your IP address (typically city or region level), and device, browser, and operating system
  • Referring website or marketing campaign that brought you here

Some of this processing involves transfers to Google's servers outside New Zealand. For details on how Google handles analytics data, see Google's privacy policy.

What we do not do with this data

We have explicitly disabled all of Google's advertising- related consent signals (ad_storage, ad_user_data, and ad_personalization) at the code level. This means:

  • Your visit is never linked to a Google Ads click for conversion attribution
  • Google cannot use your activity on our site to build remarketing audiences
  • We do not run any advertising or personalisation campaigns based on this data
  • We do not sell or share your personal data with advertisers or data brokers
  • You can clear analytics cookies at any time via your browser's settings (see Cookies and tracking below)

How we use your information

We use the information we collect for straightforward purposes:

  • Form submissions: To respond to your enquiry, provide information about SyteSense, and follow up if you have asked us to
  • Analytics: To understand which pages and features interest visitors so we can improve the website

We never use your information for advertising, profiling, or selling to third parties.

Sharing and Disclosure

We may share personal data with:

  • Cloud hosting and infrastructure providers
  • Security and monitoring providers
  • Payment processors
  • Professional advisors (legal, audit, accounting)
  • Regulatory authorities where required

All vendors are contractually bound to confidentiality and data protection obligations.

How we protect your data

We take practical steps to keep your information safe:

  • HTTPS encryption on every connection. Your data is encrypted in transit
  • Hosted on Vercel – enterprise-grade infrastructure with SOC 2 compliance
  • No client-side storage of sensitive data. We do not store your details in browser storage
  • Server-side validation on all form submissions to prevent injection attacks
  • Rate limiting on form submissions to prevent abuse

How long we keep your data

  • Form submissions: Retained while needed to respond to your enquiry and follow up. You can request deletion at any time.
  • Analytics data: Stored by Google Analytics per our configured retention setting in Google Analytics 4. You can clear analytics cookies at any time via your browser's settings.

SyteSense Mobile App

The SyteSense mobile app collects additional information beyond what the website collects. This section explains what the app collects, why, and how it is handled.

Account and profile data

When you create an account and use the app, we store:

  • Your name, email address, and phone number
  • Your organisation name, role, and membership details
  • Projects you are assigned to and your role on each project
  • Your work schedule and crew assignments
  • Profile photo, timezone, and language preferences

Time tracking and work records

When you clock in or out, the app records:

  • Timestamps, duration, and any notes you add
  • Photos you capture as part of time entries (see below)
  • GPS coordinates at the moment of clock-in or clock-out (see below)
  • Tasks, site diaries, and form submissions linked to your work

Photos

When you take a photo through the app for time tracking, the photo is:

  • Saved on your device for offline access
  • Compressed and uploaded to our cloud storage (Supabase), organised by your organisation and project
  • EXIF metadata (including GPS coordinates, date, and time) is preserved in the uploaded photo

Location data

The app captures your GPS location only at specific moments: when you clock in, clock out, or take a photo. There is no ongoing or background location tracking. Location data is stored alongside your time entries on our servers.

Location data comes from one of three sources: the photo's EXIF metadata, your device's GPS, or manual entry. The app works without location permission. If you decline, location fields are simply left blank.

Financial data

If your organisation uses invoicing features, we store invoice details including subtotals, GST amounts, totals, and PDF documents. This data is scoped to your organisation and protected by role-based access controls.

Device permissions

The app requests the following permissions on your device. All are optional. The app will work with reduced functionality if you decline any of them.

  • Camera: To capture photos for time tracking entries
  • Location: To record GPS coordinates with your clock-in and clock-out entries
  • Notifications: To send you schedule reminders, sync updates, and important alerts
  • Photo library (iOS): To save time tracking photos to your device

Third-party services used by the app

The mobile app communicates with the following services. None of them use your data for their own advertising or marketing.

  • Supabase – database, authentication, and file storage (hosts your account data, time entries, and uploaded photos)
  • Firebase Cloud Messaging (Google) – delivers push notifications to your device
  • Firebase Crashlytics (Google) – collects crash reports to help us fix bugs. Reports include your device model, OS version, app version, and error details. No personal identifiers are attached to crash reports.
  • Firebase Analytics (Google) – collects anonymous usage data such as screen views, device type, and app version to help us understand how the app is used. No personal identifiers are collected.
  • Apple Push Notification Service – delivers push notifications on iOS devices
  • Resend – sends transactional emails such as notifications and invitations
  • Sentry – server-side error tracking for our backend services

Where your data is stored

The app stores data both on your device and in the cloud:

  • On-device: Photos, time entries, and app data are cached locally for offline access. This data stays on your device and syncs to the cloud when you have a connection.
  • Cloud: Your data is stored in Supabase, which uses enterprise-grade infrastructure with row-level security to ensure you can only access data within your own organisation and projects.

How long we keep mobile app data

  • Time entries, timesheets, and invoices: 7 years from the end of the relevant tax year, as required by New Zealand tax and employment law
  • Work site photos: 7 years after project completion, to support legal liability and insurance requirements common in the construction industry
  • GPS location data: Retained as part of time entry records for the same 7-year period
  • Crash reports: 30 days
  • Analytics data: 90 days
  • Push notification tokens: Deleted when your device unregisters or after 90 days of inactivity

After the applicable retention period, data is securely deleted. If you delete your account, we remove your personal information (name, email, profile) within 30 days. Anonymised business records such as timesheets and invoices are retained for the legally required period.

Your rights

Under the New Zealand Privacy Act 2020, you have the right to:

  • Access the personal information we hold about you
  • Request correction of any inaccurate information
  • Request deletion of your data

To exercise any of these rights, get in touch by email at support@sytesense.com or call us on +64 22 198 5603. We will respond within 20 working days, as required by the Privacy Act.

New Zealand Privacy Act 2020 Compliance

For individuals located in New Zealand, SyteSense complies with the Privacy Act 2020 (NZ) and the Information Privacy Principles (IPPs).

Under the NZ Privacy Act, individuals have the right to:

  • Request access to personal information
  • Request correction of personal information
  • Be informed of the purpose of collection
  • Expect reasonable safeguards to protect their data

We take reasonable steps to ensure personal information is:

  • Collected for lawful and necessary purposes
  • Not retained longer than required
  • Protected against loss, misuse, or unauthorized disclosure

If you believe we have breached the Privacy Act 2020, you may contact us directly or lodge a complaint with the Office of the Privacy Commissioner of New Zealand.

Cookies and tracking

We use cookies on our website. We show a brief notice on your first visit so you know they're in use; this notice is for transparency, not consent management. The cookies in use are limited to Google Analytics for measuring how the site is used. We do not use advertising or remarketing cookies.

Analytics cookies set by Google Analytics

  • _ga – distinguishes returning visitors. Expires after 2 years.
  • _ga_<container-id> – maintains session state for our specific Google Analytics property. Expires after 2 years.

Other browser storage

We store a small entry in your browser's local storage (ss_cookie_notice_dismissed_v1) to remember that you've dismissed the cookie notice, so we don't show it on every visit. This entry is not used for tracking and is not sent to any server.

Controlling cookies

You can clear or block cookies at any time via your browser's settings. Clearing analytics cookies for sytesense.com will reset your Google Analytics identifier — your next visit will appear as a new visitor in our reports.

We use Google's Consent Mode v2 with all advertising signals (ad_storage, ad_user_data, ad_personalization) hard-coded to denied at all times. Even if you have a Google account, your visit cannot be used to build remarketing audiences or for ad personalisation.

What we do not use

  • No advertising or remarketing pixels (Meta, LinkedIn, X, etc.)
  • No cross-site tracking or third-party identity graphs
  • No fingerprinting beyond the standard browser metadata Google Analytics collects

Children's privacy

SyteSense is a business tool for construction professionals. We do not knowingly collect personal information from anyone under the age of 16. If you believe a child has provided us with their information, please contact us and we will delete it promptly.

Changes to this policy

We may update this privacy policy from time to time. When we make changes, we will update the effective date at the top of this page. For material changes, we will add a notice on the website.

Contact us

If you have any questions about this privacy policy or how we handle your data, get in touch. We are happy to help.

Have questions about your data?

We are real people who will actually respond. Reach out anytime, no pressure, just answers.