Skip to content

REQ Suite

Privacy Notice

The short version

  • The public website works without an account. Browsing the marketing pages — including this one — sets no cookies, and we use no analytics, advertising trackers, or social-media pixels anywhere on the site or in the applications.
  • The “Request a Demo” link opens your own email application. There are no signup, contact, or marketing forms on the public site, and nothing is submitted in the background.
  • The applications require sign-in. They store the account information of authorized users and the company, project, and billing information a company’s users enter — that is the product.
  • We do not sell personal information, and we do not use it for advertising.

Information you provide

Email correspondence. If you write to demo@reqbuild.com, we receive your email address and whatever you choose to include, and we use it to respond to you.

Account information. Access to the applications is set up for each company; there is no public self-service signup. Authorized users have an account record including an email address, an optional display name, a role within their company, and account status.

Company and project information. The applications store the business information a company’s users enter: company name, project details (such as names, numbers, customer, and project address), and the contract, change-order, schedule-of-values, and payment-application information the workflow is for, including any files attached to those records.

Sign-in and session records

Signing in uses your email address and a one-time code sent to it; there is no password. To keep accounts secure, the service keeps sign-in session records — with session credentials stored only in one-way hashed form — along with limited technical metadata, and it limits repeated failed sign-in attempts. Sessions expire automatically, and signing out ends the session.

Usage and technical information

The applications keep an audit history as part of the product: certain account, membership, and billing-related actions are recorded with who performed them and when, so a company’s records can answer questions later.

Like essentially all web services, the cloud infrastructure that hosts REQ Suite generates standard server logs as part of operating and securing the service, which can include network information such as IP address, request time, and browser type. The application’s own error logging is designed to avoid recording personal data.

How information is used

  • To provide and operate the REQ Suite applications;
  • To sign users in and control what each role can see and do;
  • To maintain the audit history the product provides;
  • To respond when you contact us, including demo requests;
  • To secure the service and prevent abuse;
  • To communicate with customers about the service.

Service providers

REQ Suite runs on established cloud infrastructure and uses a small number of providers to operate the service on our behalf: a web hosting platform (Vercel), a managed PostgreSQL database (Neon), an authentication provider that issues the one-time sign-in code (WorkOS), and an email delivery provider that sends that code and any change-order proposal you choose to email from the applications (Resend).

Each of them receives only what its own function requires, which is:

  • The authentication provider receives your email address, together with the IP address and browser type of the sign-in request.
  • The email delivery provider receives the message it is asked to deliver — its recipients, its subject, and its text, which in a sign-in message contains the one-time code itself, and for a change-order proposal you send includes the note you wrote and the proposal document attached to it.
  • The hosting platform and the database service process the information described above in the course of running the service.

We do not share personal information with third parties for their own marketing, and no advertising or analytics companies receive data from the site or the applications.

Cookies

The applications use a small number of first-party cookies strictly for sign-in and session security. They are not used for advertising or cross-site tracking, and there are no third-party cookies. Browsing the public marketing pages sets no cookies and stores nothing in your browser.

Security

REQ Suite uses authentication and company-level access controls to protect application data: what someone can see and edit follows their role, and a company’s information belongs to that company’s account. Connections to the service are encrypted in transit (HTTPS), session credentials are stored only as one-way hashes, and access-affecting changes are recorded in an append-only audit history. No method of transmission or storage is perfectly secure, so we also design the service to collect little: the public site asks for nothing — no accounts, no forms, no cookies — beyond the standard server logs described above, and there is no payment-card collection anywhere in the service.

Retention

Account, company, and project records are kept while the account or company remains active, because they are the working records the product exists to hold. Audit history is kept as an append-only record of what happened. We have not published fixed retention schedules; if you have questions about specific records, contact us.

Your choices and requests

You can write to demo@reqbuild.com to ask what information we hold about you, ask us to correct it, or request deletion. We will respond honestly about what we can do — some records, such as the audit history that protects the integrity of a company’s billing records, may need to be preserved. Within a company, the company’s own administrators control who has access and in what role.

Children

REQ Suite is business software for construction companies. It is not directed to children, and we do not knowingly collect information from children.

Changes to this notice

If this notice changes, we will update the effective date at the top of this page, and material changes will be noted on the site. The current version is always at reqbuild.com/privacy.

Contact

Questions about this notice or about your information: demo@reqbuild.com.