Privacy Policy
Effective date: August 3, 2026
SyncFileBox ("we," "us," "our") provides a controlled file-exchange platform (a lightweight Common Data Environment) for design and construction project teams. This policy explains what data we collect, from whom, why, and how it's protected — covering project owners and admin users, the contractors/recipients who use tokenized portal links, and visitors to syncfilebox.com.
1. Who this applies to
- Account owners & admin users — people who sign in to the admin site to manage projects, files, RFIs, and settings.
- Contractors / portal users — people invited to a project who access it via a unique, tokenized portal link (no account or password required).
- Website visitors — anyone browsing syncfilebox.com.
2. Information we collect
From account owners & admin users
- Name, email address, and password (stored as a salted hash, never in plain text).
- Optional two-factor authentication (TOTP) secret, if you enable 2FA.
- Project data you create or upload: project names/codes, files and their metadata (filename, size, SHA-256 hash, revision/suitability/workflow status), RFIs, and project messages.
- Contractor contact details you add to a project (name, email).
- API keys you generate for integrations (e.g. FileMuster), and webhook endpoint URLs you configure.
From contractors / portal users
- Your name and email address, as registered against the project by the project owner (or provided by you when submitting via the portal or email intake).
- Files you upload or download through your portal link, and basic activity around that (timestamps, IP address) for the project's audit trail.
From everyone
- Standard web server logs (IP address, browser type, pages visited) for security and troubleshooting.
- Session cookies required to keep you signed in to the admin site, or to authenticate a portal link.
3. How we use this information
- To operate the platform: authenticate users, serve project files, maintain the transmittal register, RFI register, and message board.
- To send notifications you or your project has configured — instant email on new uploads/shares, RFI activity, or digest emails — and to run email-to-transmittal intake (matching inbound emails to a project by code and registered sender).
- To maintain the append-only audit trail (uploads, downloads, supersedes, sends, status changes) that is a core feature of the platform for project record-keeping.
- To secure the platform against abuse (e.g. verifying senders on email intake, rate-limiting, detecting anomalous activity).
We do not use project files, contractor details, or messages for advertising, and we do not sell any of this data.
4. Sharing
Within a project, the data you'd expect is visible to the people you've given access to: admin users see everything in their projects; contractors see only what's shared with them via their portal link. Beyond that, we share data only with:
- Our hosting and infrastructure providers, who process data on our behalf under confidentiality obligations.
- Integrations you explicitly authorize — e.g. an API key you create for FileMuster, or a webhook endpoint you configure — which then receive the specific data that integration is designed to exchange.
- Where required by law.
5. Data retention
Project data (files, transmittals, RFIs, messages, audit trail) is retained for as long as the project/account is active, since the audit trail's integrity is a core part of the service. Account owners can request deletion of their account and associated data by contacting us; some audit records may be retained where needed for legitimate record-keeping or legal obligations.
6. Security
- Passwords are stored as salted hashes, never in plain text.
- Every uploaded file is SHA-256 hashed to verify integrity and detect exact duplicates.
- Contractor access uses long, unguessable tokenized links rather than shared passwords.
- Optional TOTP two-factor authentication is available for admin users.
- Webhook payloads are signed so receivers can verify they genuinely came from SyncFileBox.
No method of transmission or storage is 100% secure, but we take these measures seriously as the platform's core value is trustworthy record-keeping.
7. Your rights
You can ask what data we hold about you, request corrections, or request deletion, by emailing us at the address below. For contractors, this may require your project's admin to confirm the request where data forms part of a shared project record.
8. Cookies
We use only the cookies necessary to keep you signed in (admin site) or to authenticate your portal link (contractors) — no third-party advertising or tracking cookies.
9. Changes to this policy
We may update this policy as the platform evolves; the effective date above reflects the latest revision.
10. Contact us
Questions about this policy, or a data request? Contact us at admin@syncfilebox.com.