Skip to content

Privacy Policy

Last updated: September 1, 2026

This Privacy Policy explains how Grup Holdings LLC ("Spec Sheet Builder," "we," "us," or "our") collects, uses, shares, and protects information when you use Spec Sheet Builder at specsheetbuilder.com and its related applications (the "Service").

By using the Service, you agree to the practices described here. If you do not agree, please do not use the Service.

1. Who this policy covers

Spec Sheet Builder is a tool for trade professionals (builders, general contractors, remodelers, and related trades) to create finish schedules and spec sheets and share them with clients. This policy covers:

  • Account information about you, the account holder; and
  • Project content you create in the Service, which may include information about your own clients and projects.

You are responsible for the information you enter about your clients. See Section 11.

2. Information we collect

Information you provide when you create and use an account

  • Your email address and password, used to authenticate you. Passwords are handled by our authentication provider and are stored only in hashed form; we never see or store your plaintext password.
  • Profile and branding details you choose to add, such as your company name and uploaded company logo.
  • Your in-app preferences, including AI feature settings.

Content you create in the Service

  • Projects, sections, line items, finish selections, manufacturers, models/SKUs, quantities, units, allowances, prices, statuses, dimensions, notes, and any images you upload to line items.
  • Client and project details you choose to enter, such as a client's name, email address, and project address.
  • Client and trade activity submitted through shared links, including comments, reactions, approvals, change-order signatures, trade acknowledgements, and delivery check-in notes and photos.
  • Some approval, signature, acknowledgement, and check-in records also include the submitter's name, consent, submission time, IP address, and user-agent information so the Service can maintain a security and activity record.

Payment information

When you subscribe to a paid plan, payment is processed by Stripe. We do not collect or store your full card number or card security details. We store a Stripe customer identifier and subscription status so we can manage your plan and entitlements.

Information collected automatically

Standard technical data generated when you use a web application, such as IP address, user-agent, browser and device information, request logs, and security or rate-limit events processed by us and our infrastructure providers for security, reliability, and abuse prevention. We do not use advertising trackers. Page-view analytics are described in Section 5 (Vercel) and Section 6.

3. How we use information

We use information to:

  • Provide, operate, and maintain the Service and your account;
  • Generate, store, and display your spec sheets and related documents;
  • Power optional AI features you choose to use (see Section 4);
  • Process subscriptions, billing, and plan entitlements through Stripe;
  • Send transactional emails you would expect, such as sign-in codes, password resets, and documents you send to your clients;
  • Secure the Service, prevent abuse, and troubleshoot problems; and
  • Comply with our legal obligations.

We do not sell your personal information, and we do not use it for third-party advertising.

4. AI features and the data sent to AI providers

Optional AI features use Google's Gemini models. Depending on the feature you start, Gemini may process:

  • Text you enter for AI chat, quick templates, product imports, search, or care-note drafting;
  • Limited snapshots of relevant project content, such as section titles, item names, product details, or recent conversation context;
  • Images you submit for product photo capture;
  • Documents or quote images you upload for quote reading; and
  • Product-page text and metadata extracted from a URL you ask us to import.

We send only the categories needed for the feature you requested. We do not send your account password or your stored payment information to Gemini.

AI providers process this data to return a result to you. We rely on these providers' commitments that data submitted through their business APIs is not used to train their models; their handling is governed by their own terms, and we encourage you to review them. AI output is generated automatically and may be inaccurate or incomplete. See our Terms of Service for the important disclaimer about relying on it.

5. How we share information

We share information only with service providers ("subprocessors") that help us run the Service, and only as needed for them to perform their function:

  • Supabasedatabase, authentication, and file storage.
  • Vercelapplication hosting and delivery, and page-view analytics. Analytics records page URL and path, referrer, filtered query string, country/region/city, device type, operating system, browser version, and a timestamp.
  • Stripepayment processing and subscription management.
  • Resendsending transactional email.
  • Sentryerror reports, which can include a stack trace, the request URL, and browser or server context. An opaque account identifier may be included. Email addresses, IP addresses, and request bodies are stripped before events are sent.
  • Cloudflare (R2)stores the nightly backup of the database dump and uploaded files, encrypted with age before upload. A small heartbeat record (outcome, hashes, and aggregate counts) is also stored. Residual copies remain for a limited period before they are overwritten.
  • GitHub (Actions)runs the nightly backup job. During the job, the database dump and uploaded-file bytes exist on the runner. The workflow does not upload those files as GitHub Actions artifacts. Encrypted archives go to Cloudflare R2.
  • Google (Gemini)AI features you initiate, including chat, the quick-template builder, product normalization and semantic matching, photo capture, quote reading, and care-note drafting.
  • Bright Dataretrieving a product page you asked us to import when the ordinary server fetch cannot access it.

When you paste a product link to import details, our servers first try to fetch it directly. If the page blocks that request, we may send the URL to Bright Data to retrieve the page. We extract product metadata (such as name, brand, model, price, images, and relevant page text) to pre-fill a line item, and may send the extracted material to Gemini for normalization.

We may also disclose information if required by law, to protect our rights or the safety of others, or in connection with a merger, acquisition, or sale of assets, in which case we will continue to protect your information consistent with this policy.

6. Cookies, local storage, and offline data

We use only the cookies and storage necessary to operate the Service:

  • Authentication cookies that keep you signed in.
  • Offline storage on your device (a service worker cache and a local database) so the app can work when your connection drops and sync your changes when you reconnect.

We do not use advertising cookies or cross-site tracking. Page-view analytics are described in Section 5 (Vercel).

7. Data retention and deletion

We keep your information for as long as your account is active or as needed to provide the Service. You can delete your account at any time. Deleting your account permanently removes your account and your associated data, including your projects, spec items, AI conversations, the files you uploaded (such as logos and item images), and generated PDF documents.

Client and trade submissions, including comments, reactions, approvals, signatures, acknowledgements, check-in notes and photos, and associated IP address and user-agent information, are retained with the related project until the project or account is deleted. An acknowledgement or check-in may remain after its individual trade package or item is removed so the project activity record stays intact, but it is removed when the related project or account is deleted.

Residual copies may remain in our encrypted backups for a limited period before they are overwritten. Service providers may retain data under their own policies and legal obligations. We may retain limited records where required for legal, tax, accounting, or fraud-prevention purposes.

8. How we protect information

We use industry-standard safeguards, including encryption in transit and at rest provided by our infrastructure providers, row-level database security that isolates each account's data, and hashing of sensitive tokens such as client share links. No system is perfectly secure, but we work to protect your information and to limit access to it.

9. Your choices and rights

  • Access and update the account and profile information available in the app at any time, and contact us using Section 14 to make a privacy request.
  • Edit project content while your current plan entitlement permits it. After paid access ends, project content becomes read-only, but you can still view and export it.
  • Export your project data in CSV or JSON format.
  • Delete your account and content as described in Section 7.
  • Manage email: transactional emails are part of the Service; we do not send marketing email by default.

Depending on where you live, you may have additional rights described below.

10. California privacy rights

If you are a California resident, you have the right to know what personal information we collect and how we use and share it (described in this policy), to request access to or deletion of your personal information, to correct inaccurate information, and not to be discriminated against for exercising these rights. We do not sell or "share" personal information for cross-context behavioral advertising. To make a request, contact us using Section 14.

11. Client and project information you provide

When you enter information about your own clients (such as their name, email, or project address) or share a spec sheet with them, you are responsible for that information: for having the right to provide it, for the accuracy of it, and for using the Service in a way that respects your clients' privacy. With respect to that client information, you act as the controller and we act as a processor handling it on your behalf to provide the Service.

Spec sheets you choose to share are made available through a read-only link secured by a unique token. You control whether to create or revoke a share link.

12. International users

The Service is operated from the United States, and your information is processed and stored in the United States. If you access the Service from outside the United States, you understand that your information will be transferred to and processed in the United States.

13. Children's privacy

The Service is intended for business use by individuals who are at least 18 years old. It is not directed to children, and we do not knowingly collect personal information from anyone under 18. If you believe a child has provided us information, contact us and we will delete it.

14. Contact us

Questions about this policy or your information? Contact us at:

Grup Holdings LLC — Spec Sheet Builder
info@specsheetbuilder.com

We reply within 2 business days.

15. Changes to this policy

We may update this policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify you. Your continued use of the Service after changes take effect means you accept the updated policy.