Struct Technologies Privacy Policy
This Privacy Policy explains how Struct Technologies (“Struct”, “we”, “us” or “our”) collects, uses, stores and protects information across the Struct platform — the Android mobile application, the contractor web application, and the client web portal. All three connect to the same underlying organisation account and backend database; this policy applies to all of them, with product-specific detail called out in Sections 4–6 below.
1. Who this policy covers
Struct is a business platform provided to contracting companies and their authorised personnel (via the mobile app and contractor web application), and to those companies’ own clients, who can track their projects through a separate client web portal.
- Contractor users (company staff) — accounts are created and managed by Struct, the subscribing organisation, or an authorised company administrator. There is no public self-registration for contractor accounts.
- Client users — individuals or companies invited by a contractor to track their own project(s). Client users create their own account through the client web portal’s sign-up flow (see Section 6).
2. Data responsibility
Different parties are responsible for different information in the Struct platform:
- The subscribing contractor organisation generally controls the employee, client and project data it enters into Struct — what is recorded, who it’s shared with internally, and how long it’s needed for its own business purposes.
- Struct processes that data on the organisation’s behalf, to provide the platform’s project, workforce, procurement, document, reporting and other functions.
- Struct independently controls account, security, billing and platform-administration data — information about how the platform itself is used, secured and paid for, rather than the contractor’s own business records.
3. Information we collect
Depending on the product, the features enabled by an organisation, and the user’s permissions, Struct may process:
- Account and identity information: name, email address, phone number, user ID, organisation, role and access permissions.
- Business and operational records: project information, enquiries, estimates, quotations, purchase records, daily progress reports, attendance and manpower records, vendor or subcontractor records, finance-related business records, schedules and other information entered into the platform.
- User-provided content: notes, comments, descriptions and other content submitted by authorised users.
- Photos, files and documents: site photographs, progress evidence, drawings and documents selected or captured by a user for upload to Struct.
- Security and technical information: IP address, authentication events, timestamps and limited technical records reasonably required to operate, secure and troubleshoot the service.
Struct does not use any of its applications to collect precise or approximate device location, health or fitness information, the user’s device contact list, personal banking or card credentials, or advertising identifiers for targeted advertising. We do not sell personal information.
4. Mobile application (contractor field staff)
The Android mobile application displays and updates permitted information from a contractor’s shared organisation account; it does not maintain a separate customer database.
- Camera, photos and documents. When a user chooses to attach a site photo, progress image or document, Struct may request access to the device camera, photo library or file picker. This access is used only to let the user select, capture and upload the requested content — Struct does not continuously access the camera or photo library.
- Push notifications. Struct uses services such as Firebase Cloud Messaging and Expo notification services to deliver operational push notifications. These services may process an application installation identifier or push token. Users can control notification permission through their device settings, although disabling notifications may prevent timely workflow alerts.
5. Contractor web application
The contractor web application is the primary workspace for company staff — projects, procurement, finance, HR, scheduling and reporting. It shares the same account and permissions model as the mobile app. Access is via company-issued login credentials; there is no public self-registration.
6. Client web portal
The client web portal lets a contractor’s own clients track their project(s), review quotes, and view invoices, without needing a contractor account.
- Sign-up. A client creates their own account (as an individual or on behalf of a company) by providing a name, an email address and/or phone number, and a password.
- Verification. We verify the email address or phone number provided at sign-up using a one-time verification code sent to that email or phone.
- Linking to a project. A client’s account is linked to their project(s) by their contractor, after which the client can view project progress, quotes and invoices for the project(s) they’ve been linked to.
- Password reset. A client can reset their own password using a one-time verification code sent to their registered email address or phone number, without contractor involvement.
7. Cookies and local storage
The contractor web application and client web portal use essential cookies, authentication tokens and browser storage to keep users signed in, maintain security and remember necessary session information. Struct does not use these technologies for third-party targeted advertising.
8. How we use information
We use information to:
- authenticate users and manage organisation and client accounts and permissions;
- provide project, workforce, procurement, document, reporting and other platform functions;
- store and synchronise authorised records across the mobile app, contractor web application and client web portal;
- deliver operational notifications and workflow updates;
- maintain security, prevent misuse, investigate errors and support users;
- comply with applicable legal obligations and enforce our agreements.
We do not use personal information for third-party targeted advertising.
9. How information is disclosed
Information may be made available to:
- The relevant organisation: company administrators and other authorised users may access information according to their roles and permissions. Client project data may be accessed by authorised client users, authorised users of the contractor responsible for the project, and Struct or its service providers where reasonably necessary to operate, secure or support the platform.
- Service providers: hosting, storage, notification, email and SMS delivery, security and technical-service providers that process information on our behalf and subject to appropriate obligations — including providers that deliver account-verification and password-reset codes by email or SMS.
- Authorities or professional advisers: when reasonably necessary to comply with law, protect rights and security, or establish, exercise or defend legal claims.
- A successor organisation: in connection with a merger, acquisition, financing, restructuring or transfer of the service, subject to applicable law.
10. Data security
We use reasonable administrative, technical and organisational safeguards designed to protect information. Data transmitted between the Struct applications and our production services is encrypted in transit using HTTPS/TLS. Access is restricted through authentication and role-based permissions. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
11. Retention
We retain information for as long as necessary to provide the service, fulfil the purposes described in this policy, resolve disputes and meet contractual, security and legal obligations. Retention may vary according to the type of record and, for contractor organisations, that organisation’s own instructions. Deleted data may remain temporarily in restricted backups until those backups are overwritten under normal retention cycles.
12. Access, correction and deletion
Contractor users: because contractor accounts and business records are controlled at organisation level, an authorised company administrator may manage information and request deletion through the Struct web application. A company may also contact us using the email address below to request deletion of its account or data.
Client users: a client may request access, correction or deletion of their account by emailing us at the address below. Account deletion is currently handled by our team on request rather than as a self-service option in the portal. Deleting a client login account does not automatically delete invoices, contractual records or project records that the responsible contractor is required to retain for legitimate business, accounting or legal purposes.
13. International processing
Struct and its service providers may process information in countries other than the user’s location. Where required, we use appropriate contractual, organisational and technical measures for such transfers.
14. Children
Struct is a business application intended for users aged 18 and over. It is not directed to children, and we do not knowingly offer accounts directly to children.
15. Changes to this policy
We may update this Privacy Policy to reflect changes to Struct, our practices or applicable requirements. We will publish the revised policy on this page and update the effective date. Material changes may also be communicated through the platform or to subscribing organisations where appropriate.
16. Contact us
For privacy questions or requests, contact:
Struct Technologies
Email: structtech.app@gmail.com
Website: https://struct.ae