Privacy Policy
Last updated
⚠ Draft — pending legal review
This document was drafted in-house and has not yet been reviewed by an attorney. It is published so that it can be read and corrected. No customer is subscribed to the service, and these terms have not been presented to anyone for acceptance.
SC Connect is software that construction subcontractors use to run their business. It holds information about their crews, their customers and their jobs — including, for certified payroll, part of a worker’s Social Security number. This page says what is held, who can see it, where it goes and how long it stays.
1. Who is responsible for this data
SC Connect is operated by Netgician LLC.
For almost everything in the service, the subscribing company is the one that decides what is collected and why; we hold and process it on their instructions. If you are a crew member, a general contractor’s superintendent or a vendor’s contact and you want your information changed or removed, the company you dealt with is the right place to ask. We will help them do it.
For the subscription itself — the account we bill, the emails we send about it, the security records we keep — Netgician LLC decides, and this policy is our own.
[COUNSEL] Confirm the controller / processor split as stated, whether a written data processing addendum should be offered to customers as standard, and whether the service’s scale and the states it operates in bring it inside any of the state privacy statutes now in force.
2. Whose information is in here
Four groups, and only one of them ever signs in:
- The subscriber’s own people — owners, project managers, estimators, foremen, bookkeepers, warehouse staff and field crew. They have accounts.
- Workers on certified-payroll jobs, whose payroll figures and Social Security digits appear on federal form WH-347. Usually the same people as above.
- People at other companies — a general contractor’s superintendent, a supplier’s account manager, an architect, a city inspector. Their names and contact details are entered by the subscriber. They have no account.
- People who sign something — a superintendent signing a time-and-material ticket on a phone held out to them on site, or a vendor signing a lien waiver from an emailed link. They have no account either, and section 6 is about them specifically.
3. What is held
People with accounts
Name, employee code, optional email address, optional phone number, initials, trade classification, wage and fringe rates, roles, whether the account is active, and when it was last used. A password is stored only as a bcrypt hash. If two-factor authentication is enabled, its shared secret is stored.
We do not collect a date of birth, a home address, an emergency contact, bank or routing details, a driver’s licence, a passport, immigration status, or any tax identifier. There is no column for any of them.
Hours and pay
Timecards record who worked, on which job and date, how many regular, overtime and double-time hours, at what wage and fringe rate. For jobs that require certified payroll, weekly figures are also recorded: gross pay on the project, gross pay across all employment, itemised deductions, net pay, cheque number, and the last four digits of the worker’s Social Security number.
Contacts at other companies
Name, job title, email address and phone number, entered by the subscriber, plus their company’s name, postal address, phone and website.
Files
Jobsite photographs, drawings, delivery slips, certificates of insurance, licences, W-9 forms, signed lien waivers, and the PDFs the service generates — pay applications, proposals, certified payrolls and claim packages. Photographs carry the location and time they were taken, where the device provided them.
Activity records
An audit log records who did what and when, with the actor’s name, the record affected, and — where the deployment provides them — an IP address and browser user-agent string. There are no advertising cookies, no analytics, no tracking pixels and no third-party scripts anywhere in the product.
4. Social Security numbers, specifically
Federal form WH-347 asks for the last four digits of a worker’s Social Security number, so the service stores those four digits and nothing more. There is no field anywhere in the service for a full Social Security number, and the four digits are validated to be exactly four digits.
The four digits:
- are visible only to a company’s owner, administrator, project manager or bookkeeper — not to estimators, foremen, warehouse staff or field crew;
- appear masked, as (…1234), on the generated WH-347;
- are never sent to QuickBooks, to Stripe, or in any email;
- are stored in the database without field-level encryption (see section 8).
One route can bring a full number in, and you should know about it. A W-9 uploaded for a vendor who is a sole proprietor carries that person’s Social Security number as the taxpayer identification number. The service stores the file as uploaded; it never reads the number out of it, and there is no field holding it. Access to a W-9 is restricted to the same four roles above, separately from the rest of the compliance register — a foreman who may check whether a certificate of insurance is current cannot open a W-9.
[COUNSEL] The sharpest question in this document. Confirm what notice, consent, safeguarding and breach-notification obligations attach to holding SSN digits and to holding a full SSN inside an uploaded W-9; whether any state we operate in requires a written information security program covering it; and whether field-level encryption of the four digits should be treated as required rather than advisable.
5. What it is used for
To run the service the subscriber is paying for, and nothing else: showing them their jobs, calculating their costs, producing their documents, sending the emails they ask us to send, keeping a record of who did what, and keeping the whole thing secure and backed up.
We do not sell personal data. We do not share it for advertising. We do not use it to train machine-learning models. We do not profile anybody. We look at aggregate figures — how many workspaces exist, how much storage is in use — to operate and size the service.
6. If you signed something on a link
When a subcontractor needs a signature from someone at another company, the service emails a link. There is no account and no password: the link is the credential.
The link works for seven days by default and only opens one document. It is forwardable, which the email says explicitly — anyone holding it can sign. Because of that, access is logged by IP address and browser rather than by person; the service cannot know who actually opened a forwarded link.
When you sign, the service records, and keeps permanently:
- the name, job title and company you typed;
- your signature, stored as the shape you drew;
- the exact time in UTC;
- the location your device reported, if it reported one — you can decline, and the document still signs;
- the IP address the request came from, where the deployment records it.
That record cannot be changed or deleted afterwards, by us or by the subcontractor. The database refuses it. This is deliberate: a signed ticket, an approved change order and an executed lien waiver are legal instruments, and a record that could be edited after signature would be worth nothing to either side. It also means we cannot honour a request to erase one, and you should know that before you sign.
[COUNSEL] The most unusual disclosure in this policy. Confirm whether capturing a handwritten signature image, a precise location and an IP address from a person who has accepted no terms needs a consent or notice step at the point of signature; whether the signature vector counts as biometric data in any state we may operate in; and whether the permanent, irreversible nature of the record needs to be stated on the signing page itself rather than only here.
7. Who can see what
Each subscriber’s workspace is isolated in the database itself, not merely by the application asking politely — every query is filtered by company at the database level, so a bug in one screen cannot reach another company’s records.
Within a company, roles decide who sees what. In particular:
- Social Security digits, net pay, deductions and cheque numbers are visible to owners, administrators, project managers and bookkeepers only.
- Wage rates, contract values and margins are visible to those roles plus estimators. A foreman can run a job all day without learning what anyone is paid.
- Wage-compliance warnings reach foremen deliberately — the person entering the hours has to be told when an entry falls below a required floor — but the shortfall in dollars does not.
A small number of Netgician LLC operators can reach the platform administration tools, which show which companies exist, what plan they are on and their subscription state. Those tools deliberately have no route into a customer’s records, and that restriction is enforced by an automated check on every build rather than by convention.
8. How it is protected, and where it is not
We would rather tell you the limits than imply there are none.
- In transit, everything is encrypted with TLS, with strict transport security set for two years. Signing links are handed to a path-scoped, HTTP-only cookie immediately so the credential never sits in a URL, a browser history or a server log.
- Backups are encrypted with AES-256 on our own server, before they leave it, and only then sent to off-site storage. The storage provider holds ciphertext it cannot open. Backups run nightly, the credential that writes them cannot be used by the application, and restores are tested by actually performing one.
- Files — photographs, drawings, uploaded documents and generated PDFs — are private, never publicly addressable, and reachable only through a permission-checked link that expires in five minutes. They are not encrypted by us before upload; they rely on the storage provider’s own encryption at rest.
- Personal data in the database is not encrypted field by field. It is protected by the database being unreachable from any network outside the server, by per-company isolation enforced in the database itself, and by the access controls described above — not by encrypting individual columns. The server’s own disk is not encrypted at rest. The four Social Security digits are covered by that and no more.
- Photographs are not stripped of their embedded metadata. A photo uploaded from a phone may still carry the coordinates and time the camera recorded. Some upload paths re-encode large images and lose it as a side effect; most do not.
[COUNSEL] Confirm whether field-level encryption of the SSN digits, and encryption of stored files before upload, should be treated as required by any statute or by reasonable care given this data; and what breach-notification obligations would follow from exposure of the payroll table or the file store. Note specifically that the host’s disk is not encrypted at rest — an earlier draft of this page said it was, which was checked against the server and found untrue — so full-disk encryption is an open decision rather than an existing control.
10. How long it is kept
Honestly: indefinitely, unless somebody deletes it, and some of it cannot be deleted at all.
- Records are kept rather than erased, because that is what this kind of business needs. A departed worker’s timecards and signatures still have to resolve years later; certified payrolls are federal filings signed under penalty of perjury; lien deadlines and waivers matter long after a job closes. People are deactivated, not deleted.
- Signed documents and the audit log are permanent by design. The database refuses to modify or remove a signed ticket, an approved change order, an executed lien waiver, or any entry in the activity log. Neither we nor the subscriber can alter them through the software.
- Files stay until somebody deletes the record they hang from. There is no automatic expiry on stored photographs or documents.
- Backups roll over. Two full backups are kept plus the transaction log between them, so a deletion made in the live system works its way out of the backups within roughly two weeks.
After a subscription ends, the workspace is deactivated and its data is kept — see the Terms of Service for the export window.
[COUNSEL] This section and section 11 are where the product and the law are furthest apart today, and they need a decision rather than wording. There is currently no mechanism to delete a customer’s workspace or to erase an individual from it; parts of the data are deliberately immutable at the database level. Confirm what retention periods are actually required (federal certified payroll, state lien statutes, tax), what erasure rights apply notwithstanding them and to which categories, and what has to be built before the first customer — a bounded retention schedule, a tenant-deletion path, or both.
11. Your choices, and the limits on them
If you have an account, you can see and correct most of your own details in the product; your employer controls your roles and your pay rate. If you do not have an account, ask the company that entered your details.
You can ask us for a copy of what we hold about you, ask us to correct it, or ask us to delete it, by writing to the address in section 13. We will pass a request on to the subscriber whose workspace it concerns, and help them answer it.
Two limits, stated up front rather than discovered later. We cannot alter or remove a completed signature record or an entry in the activity log — the database refuses it, for the reasons in sections 6 and 10. And where a record is part of a certified payroll, a lien filing or another legal obligation of the subscriber, they may be required to keep it regardless of a request.
Depending on where you live you may have further rights, and we will honour them to the extent they apply.
[COUNSEL] Confirm which state privacy statutes reach this service given its size, sector and customers; what response deadlines and verification steps apply; and how to word the immutability limit above so that it is accurate without appearing to contract out of a right that cannot be contracted out of.
12. Children
The service is for businesses and is not directed at children. We do not knowingly collect information from anyone under 18. If a subscriber employs a minor as an apprentice, their records are handled exactly as any other worker’s.
13. Contact, and changes to this policy
Write to Netgician LLC at privacy@netgician.com.
If we change this policy we will update the date at the top of this page, and for a change that materially affects how personal data is handled we will tell subscribers by email before it takes effect.
[COUNSEL] Confirm the notice address and whether a named privacy contact or mailing address must be published.