Project OS Privacy Policy
Last Updated: 5 October 2026
Version: 2026-10-05
Project OS is operated by Arden Systems LLC.
This Privacy Policy explains how Arden Systems LLC doing business as Project OS (“Project OS,” “we,” “us,” or “our”) collects, uses, stores, shares, and protects information when you access or use Project OS, including our websites, web application, mobile or progressive web application, calculators, estimating tools, proposal tools, scheduling tools, project management tools, client portal features, email features, accounting and tax export tools, integrations, and related services (collectively, the “Service”).
This notice explains our data practices; it is not a request for blanket consent. Optional permissions and any legally required consent are obtained for the relevant activity. Acceptance of the Terms, acknowledgment of this notice and marketing or other optional consent have different purposes.
1. Information We Collect
We collect information you provide directly, information generated through your use of the Service, and information received from third-party services that help us operate the Service.
1.1 Account Information
When you create an account or sign in, we may collect:
- Name
- Email address
- Phone number
- Password or authentication credentials, handled by our authentication provider
- User ID
- Profile image, if provided
- Account settings
- Role, permission level, or team membership
- Login and authentication records
1.2 Business and Company Information
When you complete onboarding, company settings, proposals, invoices, exports, or account settings, we may collect:
- Business name
- Business address
- Business phone number
- Business email address
- Business logo
- License number
- Company slogan
- Tax or accounting preferences
- Labor rate settings
- Markup, overhead, profit, tax, and pricing preferences
- Subscription and plan information
- Team and employee information
1.3 Project and Client Information
When you create or manage projects, proposals, client records, schedules, or field records, we may collect:
- Project name
- Project address or jobsite location
- Project scope of work
- Project status and stage
- Client name
- Client company
- Client email address
- Client phone number
- Client address
- Project files and attachments
- RFIs, FARs, change orders, QC records, field notes, and daily report information
- Proposal records and proposal status
- Client portal or share-link information
- Project financial information
- Project schedule and activity information
- Team assignments and project access records
You are responsible for ensuring that you have the right to provide any client, employee, subcontractor, supplier, or third-party information you enter into the Service.
1.4 Estimating, Scheduling, and Calculation Data
The Service may collect and store construction-related data you enter, import, select, generate, or save, including:
- Measurements, dimensions, quantities, units, and calculation inputs
- Concrete calculator data
- Construction activities
- Work elements and production-rate selections
- Labor rates and labor cost snapshots
- Man-hours, durations, crew sizes, and hours per day
- Material, equipment, subcontractor, and indirect cost information, if entered
- Estimate type, estimate settings, markup, contingency, overhead, profit, and tax settings
- Schedule Preview data
- Logic Network relationships
- CPM calculations
- Level III Gantt data
- Crew demand data
- Project charts and reporting outputs
1.5 Proposal, Email, and Communication Data
When you send or manage proposals, invites, project communications, or transactional emails through the Service, we may collect:
- Recipient email addresses
- CC or BCC email addresses, if used
- Sender information
- Email subject
- Email template used
- Proposal link or public token
- Email delivery status
- Bounce, complaint, open, click, or delivery event information where supported
- Message metadata
- Date and time sent
- Related project or proposal ID
We use email service providers to send transactional emails. We do not guarantee delivery, inbox placement, open rates, or recipient action.
1.6 Payment and Subscription Information
If you subscribe to a paid plan, start a trial, upgrade, downgrade, cancel, or manage billing, we may collect or receive:
- Subscription plan
- Billing interval
- Subscription status
- Stripe customer ID
- Stripe subscription ID
- Stripe price ID
- Trial dates
- Current billing period dates
- Cancellation status
- Payment success or failure status
- Invoice and billing portal status
Payment card details are processed by our payment processor. We do not store full payment card numbers on our servers.
1.7 Accounting and Tax Export Information
If you use Accounting & Tax features, we may collect or process:
- Tax year
- Accounting method preferences
- Business entity preferences, if entered
- Revenue summaries
- Expense categories
- Project profit and loss summaries
- Labor, material, equipment, subcontractor, and indirect cost summaries
- Change order summaries
- Proposal and payment summaries
- Export history
- CPA workbook, CSV, PDF, ZIP, QuickBooks-related, or TurboTax helper export settings
Accounting and tax exports are user-controlled business record tools. They are not tax, legal, accounting, or financial advice.
1.8 Location and Weather Information
The Service may request location information to provide weather, placement, curing, or project risk features.
We may collect:
- Approximate location
- Precise location, if you grant permission
- Jobsite address
- Latitude and longitude
- Weather forecast or historical weather data related to your project
You may disable location permissions through your device or browser. Some weather or project condition features may not work without location data.
1.9 Device, Usage, and Diagnostic Information
We may automatically collect information about how you access and use the Service, including:
- IP address
- Browser type
- Device type
- Operating system
- App version
- Pages or features used
- Date and time of access
- Referring pages
- Error logs
- Crash reports
- Performance data
- Session data
- Security logs
- Feature usage events
This information helps us operate, secure, improve, and troubleshoot the Service.
1.10 Cookies and Similar Technologies
We may use cookies, local storage, session storage, pixels, SDKs, or similar technologies to:
- Keep you signed in
- Remember preferences
- Support security features
- Improve performance
- Understand usage
- Support analytics
- Support marketing or attribution, if enabled
You can manage cookies through your browser settings. Disabling cookies may affect Service functionality.
1.11 Information From Third Parties
We may receive information from third-party services, including:
- Authentication providers
- Payment processors
- Email providers
- Hosting providers
- Database providers
- Storage providers
- Analytics providers
- Accounting or QuickBooks-related integrations
- Client portal or share-link systems
- App stores or browser platforms
The information we receive depends on your settings, integrations, permissions, and use of those services.
Available apps and optional features can also involve recorded audio, transcripts, photos, precise coordinates, project geometry or model files, browser-stored drafts and synchronization data. Photo processing can retain or upload an original image when a report-copy conversion fails, and originals may contain camera, time or location metadata. Do not assume every uploaded photo has had its metadata removed. Record only people and places you are authorized to record.
2. How We Use Information
We use information to provide, operate, secure, support, and improve the Service.
We may use information to:
- Create and manage accounts
- Authenticate users
- Provide project dashboards
- Save project and client records
- Generate estimates and calculations
- Generate proposals and documents
- Send proposal emails, invites, notifications, and service messages
- Provide client portal and share-link functionality
- Generate schedules, CPM outputs, Gantt charts, crew demand, and charts
- Generate accounting, tax, CPA, CSV, PDF, Excel, ZIP, QuickBooks-related, and tax helper exports
- Process subscriptions, trials, billing, upgrades, cancellations, and payment status
- Provide customer support
- Troubleshoot errors
- Monitor security and prevent abuse
- Enforce terms, policies, and plan limits
- Improve features, performance, design, and reliability
- Analyze usage and product adoption
- Comply with legal obligations
- Protect our rights, users, and the public
Browser storage can hold authentication/session data, preferences, drafts and offline records. Shared devices require care: signing out or disconnecting an integration is not a guarantee that every previously downloaded file or locally stored draft has been removed. Use device and browser controls to manage local copies.
3. Legal Bases for Processing
Where required by applicable law, such as GDPR, we process personal information based on one or more legal bases, including:
- Performance of a contract, such as providing the Service you request
- Legitimate interests, such as securing and improving the Service
- Consent, such as location permissions or optional communications
- Legal obligations, such as tax, accounting, fraud prevention, or regulatory requirements
- Protection of rights, security, and legal claims
4. How We Share Information
We do not sell personal information in the traditional sense. We do not rent client lists, project records, or proposal data to third parties.
We may share information in the following ways.
4.1 Service Providers
We share information with vendors that help us operate the Service, such as:
- Database and authentication providers
- Hosting providers
- Storage providers
- Payment processors
- Email providers
- Analytics and diagnostics providers
- Customer support tools
- Accounting or integration providers
- Security and infrastructure providers
These providers may process information only as needed to provide services to us, subject to their own terms, privacy policies, and security obligations.
4.2 Payment Processors
Payment information is processed by third-party payment processors, such as Stripe. We receive payment and subscription status information but do not store full card numbers.
4.3 Email Providers
Transactional emails may be sent through third-party email providers. Email metadata, delivery status, bounce status, complaint status, open status, and click status may be processed where supported.
4.4 Integrations
If you connect third-party integrations, such as accounting platforms, export systems, or other tools, we may share information according to your authorization and the integration’s functionality.
You are responsible for reviewing the third-party provider’s terms and privacy policy before connecting an integration.
4.5 Team Members and Authorized Users
If you invite employees, clients, subcontractors, team members, or other users, information may be visible to those users according to their role, permission level, project access, or client portal access.
You are responsible for managing invited users and removing access when appropriate.
4.6 Client Portal and Shared Links
If you create public links, proposal links, client portal access, or shared project views, people with access to those links or invitations may view the information made available through them.
You are responsible for deciding what to share and with whom.
4.7 Legal, Safety, and Compliance
We may disclose information if we believe it is necessary to:
- Comply with law, subpoena, court order, or legal process
- Enforce our Terms of Service
- Protect our rights, property, users, or the public
- Prevent fraud, abuse, security incidents, or illegal activity
- Respond to lawful requests from public authorities
- Support audits, compliance, or dispute resolution
4.8 Business Transfers
If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or change of control, information may be transferred as part of that transaction.
Current infrastructure and optional content recipients include Supabase (authentication, database and storage), Netlify and Google Cloud (hosting and application operations), Stripe (billing and enabled customer-payment services), Resend (transactional email), and the configured document-scanning provider, including Cloudmersive where configured. Malware inspection can involve actual file bytes. Optional AI and transcription recipients are described in Section 16.
Customer-enabled integrations may disclose authorized files, metadata or events to Google Workspace, Microsoft or QuickBooks, and location or site information to mapping and weather providers such as Mapbox where that feature is enabled. Disconnecting a local connection stops its local use but does not necessarily revoke all provider permissions or delete files, messages or events already transmitted. Provider-side permission and deletion controls may also be needed.
5. Data Security
We use administrative, technical, and organizational safeguards designed to protect information against unauthorized access, loss, misuse, alteration, or disclosure.
These safeguards may include:
- TLS encryption in transit
- Access controls
- Authentication controls
- Role-based permissions
- Logging and monitoring
- Secure third-party infrastructure
- Limited access by authorized personnel
- Service provider security practices
- Backups and recovery processes
No method of transmission or storage is completely secure. We cannot guarantee absolute security.
You are responsible for maintaining the security of your account, devices, passwords, team access, and shared links.
6. Data Storage and Hosting
Information is stored or processed in the locations used by the enabled hosting, database, storage, email, payment and optional feature providers. These locations are not necessarily the United States. Authorized business operations and support may also occur from Thailand, where the owner currently manages Arden Systems LLC.
Our New Mexico address is a business mailing address, not a representation that all operations or data are located there. International processing is subject to applicable law and required safeguards. This notice does not claim a single U.S.-only data region or a particular transfer certification for every provider.
7. Data Retention
We retain information for documented service, security, legal and business purposes, considering the record type, account status and applicable law. Active company content, an individual login, Arden’s own billing or essential contract records, operational logs, backups and third-party copies can have different retention needs.
Cancellation or trial expiry does not itself submit a full company-erasure request. Contact support promptly if you need an export or deletion. Existing feature exports cover the records and formats they identify; no universal automatic export window or complete-account export is represented here.
Verified deletion requests are handled within applicable legal deadlines, subject to necessary and documented exceptions such as legal holds, disputes, fraud prevention and required business records. We do not retain every customer file merely because an Arden accounting record must be retained. Company-owned records may remain after an employee’s login is removed; personal references may be removed or de-identified where appropriate.
Recovery copies and provider-held copies can persist separately from active systems under their retention and deletion processes. We restrict retained recovery copies to appropriate recovery purposes. No fixed backup age-out period, instantaneous deletion from every provider or universal recovery guarantee is promised in this notice.
8. Your Choices
Depending on your location and applicable law, you may have choices regarding your information.
8.1 Account Information
You may review and update certain account, business, project, client, and proposal information in the Service.
8.2 Location Permissions
You can disable location access through your browser or device settings. Weather and placement-related features may not work properly without location access.
8.3 Emails and Notifications
You may receive transactional emails related to your account, proposals, projects, team invites, subscriptions, billing, security, or service activity.
You may opt out of marketing emails if we send them. You may not be able to opt out of essential transactional or security emails.
8.4 Cookies
You can manage cookies through your browser settings. Some features may not work if cookies or local storage are disabled.
8.5 Client Portal and Shared Links
You can manage certain client portal access, invitations, and shared links through the Service where available.
9. Privacy Rights
You may contact support@ardenprojectos.com to request access, correction, deletion and applicable portability of personal information. We provide a privacy-request contact process to U.S. users; particular statutory rights, exceptions, appeals and response deadlines depend on applicable law.
We verify the requester’s identity and, when company data is involved, their company-account authority before releasing, changing or deleting information. Do not send passwords, complete payment-card numbers or unnecessary sensitive identifiers. An authorized agent may contact us with evidence of authority where applicable law permits.
Self-service exports are available only for supported records and formats. Contact support for broader exports and verified full-account deletion. We will explain lawful omissions, retained necessary records and any legally permitted extension. A privacy request does not require consent to unrelated marketing or new data uses.
10. California Privacy Rights
If you are a California resident, California law may provide rights regarding personal information, including the right to know, access, correct, delete, and opt out of certain uses or disclosures.
We may collect the following categories of personal information:
- Identifiers, such as name, email, phone number, IP address, account ID, client information, and business contact information
- Customer records information, such as billing information, business contact details, project records, and client records
- Commercial information, such as subscriptions, proposals, invoices, project values, payments, or transaction history
- Internet or network activity, such as usage data, log data, device data, and diagnostics
- Geolocation data, such as jobsite location or device location if permission is granted
- Professional or employment-related information, such as company, role, team access, contractor data, or employee invite data
- Inferences or analytics, such as usage patterns, project status, or product engagement
- Sensitive personal information only if you choose to provide it or where necessary for specific features
We use these categories for the purposes described in this Privacy Policy.
We do not knowingly sell personal information. If we engage in activities that are considered “sharing” for cross-context behavioral advertising under applicable law, we will provide required notices and opt-out mechanisms.
We do not use sensitive personal information to infer characteristics about you.
California residents may submit requests using the contact information below.
11. GDPR, UK, and International Privacy Rights
If you are located in the European Economic Area, United Kingdom, Switzerland, or another jurisdiction with similar laws, you may have rights under applicable data protection laws.
These may include:
- Access
- Rectification
- Erasure
- Restriction of processing
- Objection
- Data portability
- Withdrawal of consent
- Complaint to a supervisory authority
Where we transfer personal information internationally, we rely on appropriate safeguards where required, such as contractual protections, service provider obligations, or other lawful transfer mechanisms.
If you are using the Service for business purposes and enter personal information about your clients, employees, subcontractors, or other third parties, you are responsible for ensuring you have a lawful basis and required notices or consents.
12. Children’s Privacy
The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13.
If you believe a child under 13 has provided personal information to us, contact us and we will take appropriate steps to delete it.
13. Business Customer Responsibilities
If you use the Service as a contractor, business, employer, or project manager, you may enter personal information about clients, employees, subcontractors, suppliers, inspectors, or other third parties.
You are responsible for:
- Providing any required privacy notices
- Obtaining any required consents
- Ensuring lawful collection and use
- Managing access permissions
- Avoiding unnecessary sensitive information
- Reviewing shared links and client portal access
- Deleting or correcting information when appropriate
- Complying with employment, privacy, consumer protection, contract, and industry-specific laws
14. Sensitive Information
Avoid uploading unnecessary sensitive or regulated information, including government identifiers, complete payment-card details, health information, passwords or private access keys. The Service is not represented as a dedicated regulated-data system. Payment-card entry should use the payment processor’s supported flow.
Voice, photos and precise location can contain sensitive information about workers, bystanders or clients. Device permission alone does not settle recording, workplace notice or other legal requirements. You must have the required authority, notices and permissions before collecting or sharing that information. Contact support if sensitive information has been submitted inadvertently.
15. Analytics and Product Improvement
We may use analytics and diagnostics to understand how the Service is used, improve features, identify errors, test performance, and prioritize development.
Analytics may include aggregated or de-identified information. We do not use private project data to publicly identify your business without permission.
Uploaded company names and logos may appear in the customer’s workspace and service documents. Arden marketing use of a customer name, logo or testimonial requires a separate explicit opt-in. Contact support to withdraw that permission; optional publicity permission is not a condition of ordinary service use.
16. Artificial Intelligence and Automated Features
Available AI-assisted features can process selected prompts, project context, notes or transcripts with OpenAI to provide requested text assistance. Available transcription features can send recorded audio to ElevenLabs and return a transcript. These are current optional feature paths, not hypothetical future providers; they depend on enabled features and configuration.
When you invoke those features, submitted content and the resulting output can be handled by the relevant provider under the applicable service terms, settings and privacy practices. Do not include information that you are not authorized to disclose. We do not represent every provider account as having zero retention, no training or a particular processing region solely because a request uses a storage-control flag.
Review generated text and transcripts for accuracy and suitability. They do not replace professional judgment. This disclosure does not authorize a new training use of previously collected customer data; any materially different use requiring permission must receive the appropriate notice and consent before introduction.
17. Accounting, Tax, and Export Records
Accounting and tax export tools may process business and financial data, including revenue, proposal values, project costs, tax categories, labor costs, expense categories, and export history.
These exports are intended to help you maintain business records. You are responsible for reviewing exports before providing them to CPAs, tax professionals, accounting software, tax software, clients, or government agencies.
We may retain export history and related metadata for business record, support, compliance, and audit purposes.
18. QuickBooks, TurboTax, and Third-Party Export Tools
If the Service provides QuickBooks-related exports, TurboTax helper exports, accounting software exports, or other third-party export tools, those features may require processing information in formats intended for third-party systems.
Use of third-party systems is subject to their own terms and privacy policies. We are not responsible for third-party acceptance, processing, storage, security, import errors, mapping issues, or changes to third-party platforms.
19. Public Proposal Links and Share Previews
The Service may allow public proposal links, share links, social previews, Open Graph previews, or client-access links.
Information included in shared links or previews may be visible to recipients or platforms that process the link. Do not create or share public links unless you are authorized to share the underlying information.
Some platforms may cache preview images, titles, descriptions, or metadata.
20. Data Deletion and Account Closure
For account closure, full deletion or comprehensive export requests, contact support@ardenprojectos.com. We verify identity and authority and distinguish an individual user’s login from the employer’s company account and company-owned records. Removing an employee login does not automatically erase the employer’s projects, accepted documents or necessary records.
Company-account erasure is an administrative fulfillment process, not a new public administration screen. Deletion, de-identification and lawful retention follow the purposes and exceptions in Section 7 and applicable law. We explain what was fulfilled and what necessary records remain. Copies already sent to recipients or independent services are not automatically recalled.
21. Data Accuracy
You are responsible for keeping your account, business, project, client, proposal, and billing information accurate and up to date.
We are not responsible for errors caused by inaccurate, incomplete, outdated, or improperly entered information.
22. Changes to This Privacy Policy
We identify updates with the published version and Last Updated date. Material changes receive clear notice as required by law. Material changes to contractual rights may require renewed Terms acceptance; acknowledgment of this Privacy Policy is separate from consent to new sensitive or materially different data uses.
We will obtain any required permission before introducing a new use that requires it. We do not treat continued use or acceptance of revised Terms as blanket, retroactive consent to expand the use of previously collected information. You may contact support to ask questions, exercise applicable rights, export supported records or cancel.
23. Contact Us
If you have questions about this Privacy Policy or want to exercise privacy rights, contact us at:
Arden Systems LLC
1209 MOUNTAIN ROAD PL NE
STE N
ALBUQUERQUE, NM 87110
USA
