Privacy Policy
Last updated: October 4, 2026
Who We Are and What This Policy Covers
RolloutIQ Inc. ("RolloutIQ™", "we", "us") provides a store development and construction management platform for retailers. This policy explains what personal information we collect and how we handle it across three places: our website at www.rolloutiq.com, the RolloutIQ™ web platform (each customer's workspace and the admin tools our staff use to run it), and the RolloutIQ™ mobile apps for iOS and Android.
Most of the information in the platform belongs to our customers. A customer's workspace holds the projects, files, comments and contacts its people put there, and the customer decides what goes in and why. For that information we act on the customer's behalf as its service provider (a "processor" under laws such as the GDPR), and the customer's own privacy notice also applies. Website visitors' information, product analytics, diagnostics and support conversations are ours to decide on, which makes us the controller for them.
Information We Collect on Our Website
We collect information you provide directly to us, including your name, email address, company name, phone number, and any messages you send through our contact forms. Subscribing to our newsletter, The Rollout, gives us your email address and any details you add on the signup form. Your device and browser also send us information such as your IP address, browser type, operating system and the pages you visit.
Information We Collect in the RolloutIQ Platform
Our customers create the accounts in the platform. There is no public sign-up, so a workspace administrator either invites you or sets up single sign-on for your organization. Once you are in, we collect the following.
- Account and profile. Your name, email address, profile photo, language, time zone and display preferences, and whether your account is active or invited.
- Sign-in and security. A securely hashed password, or the name, email and account identifier your company's single sign-on provider (such as Google, Microsoft or Okta) shares with us when you sign in. We also keep session and access tokens, failed sign-in counts used to lock an account under attack, and the IP address and browser of your sessions.
- Work you put into the workspace. Projects, tasks, comments and @-mentions, meeting notes and attendees, RFIs, submittals, punch list items, approvals, out-of-office delegations, files and photos. Anything you or your colleagues write or upload is stored as part of the customer's workspace.
- People outside the workspace. Users can record vendors, contractors, landlords and other contacts, with names, titles, companies, phone numbers and email addresses. Our customer's users enter these details on the contacts' behalf.
- Change and download history. When a record changes we keep what changed, who changed it and when, along with the IP address, browser and page used. File downloads are logged the same way, with who, when, the IP address and browser, and, for downloads made through AI Access, which AI assistant made the request.
- Notifications and email. In-app notifications, your notification preferences, and a copy of each email the platform sends you, including its recipients, subject, body and delivery status, plus when an email was opened or a link in it was clicked.
- Exports. Spreadsheets and PDFs you export. Only the person who requested an export can open it.
- Consent records. When a workspace accepts a consent, such as the one required to turn on AI Access, we record, as proof of the agreement, who accepted or withdrew it, the exact wording and language, the time, and the IP address and browser used.
- Support. Chat messages and bug reports you send from the help menu, with your name, email and workspace. A bug report also includes a screen recording around the problem and a technical log, with passwords, tokens and sign-in requests removed before sending.
Information Collected by Our Mobile Apps
The RolloutIQ™ mobile apps are a companion to the web platform, and they sign in to the same workspace, so everything in the previous section applies to what you do in the app. The app also handles the following.
- Sign-in. Your workspace name, email address and password at sign-in. The password is sent once over an encrypted connection and never stored on the device. The app keeps your sign-in token in the iOS Keychain or Android Keystore and deletes it when you sign out.
- Device settings. Your time zone and app language are sent with each request so dates and text appear in your zone and language.
- Camera and photos. The app asks for camera or photo library access only when you first take or choose a photo, and asks again before saving an image to your photo library. On Android the system file and camera pickers grant access to just the item you pick, so the app holds no camera or storage permission.
- Device identifiers. Our crash reporting, analytics and support tools each generate a random installation identifier so they can group one device's events. The app does not read your phone's serial number, IMEI, Android ID, MAC address or advertising identifier.
- Data stored on your device. Your profile, unsent changes, unfinished punch item drafts and a cache of recently viewed photos and documents (kept up to 7 days). Signing out clears all of it except the workspace name, which stays so the next sign-in is quicker.
Photos and Location
Photos often carry hidden details from the camera, such as the date taken, the camera model and, if the camera recorded it, the GPS location. When you upload a photo, the original file is stored with those details intact, and our servers read the date, camera and location into the file's information so a site photo can be placed and dated. The previews and thumbnails we show in the product have these details removed.
The mobile apps do not read your device's location. A photo carries a location only if it already had one: a photo chosen from your library keeps whatever your phone recorded, and on Android a photo taken in the app keeps a location if your phone's camera adds one. Photos taken in the iOS app carry none. Pins you drop on a floor plan mark a spot on the drawing and carry no map coordinates. If a future version of the app offers to tag photos with your location, it will ask for your permission first.
How We Use Your Information
We use the information we collect to provide, maintain, and improve our services; respond to your requests and inquiries; send you technical notices, updates, and administrative messages; and communicate with you about products, services, and events offered by RolloutIQ™.
In the platform and the mobile apps we use your information to run the service our customer signed up for: signing you in, keeping accounts secure, showing your work to the colleagues it is shared with, sending you notifications, answering support requests, and finding and fixing problems. We use product analytics to understand which features get used so we can improve them. Platform and app data is never used for advertising or to track you across other companies' apps or websites, and we do not sell personal information.
Where the GDPR or similar laws apply, we rely on our contract with the customer to provide the service, on our legitimate interest in keeping the service secure and reliable and in improving it, and on consent where we ask for it, such as for marketing technologies on our website and for AI Access.
Diagnostics, Analytics, and Support Tools
We use outside tools for error and performance monitoring, product usage analytics and in-app support. We hold every one of them to the same rules, on the web platform and in the mobile apps:
- Identified by a random ID. Our error, analytics and performance tools know you only by a random user ID and your company's workspace name. They never receive your name or email address. The exception is our support tool, which needs your name and email so we can reply to you.
- No cookies or page contents. These tools never see cookies, sign-in headers, the contents of what you save or send, web address parameters or database values. Each platform also scrubs email addresses and other secrets from everything it sends, as a second safeguard.
- Masked screen recordings. Our analytics tool records how screens are used with every word, input, image and video hidden, and the error tool keeps the same kind of masked recording, limited to the moments around an error. A bug report you choose to send to support shows the screen as you saw it, because support needs to see the problem. In the mobile apps you see the report screenshot and can mark it up before you send it.
- Do Not Track. The web platform's product analytics stop if your browser sends a Do Not Track signal.
Service Providers
We do not sell, trade, or otherwise transfer your personal information to third parties without your consent, except as described in this policy. We share information with service providers who help us operate our website and services, under contracts that limit what they can do with it. They are:
- Amazon Web Services. Hosts the platform: servers, databases, file storage and logs.
- Railway. Our website host.
- Mailgun. Sends platform email such as invitations, password resets and notifications, and delivers contact form submissions to our team.
- Resend. Newsletter sending and the subscriber list.
- Pipedrive. Our CRM. It stores the details you send through our contact form and newsletter signup and runs the scheduler you can use afterward to book a demo. If you book a time, Pipedrive processes your booking details and sends the calendar invitation, under its own privacy policy.
- Sentry. Error reports, performance data and masked recordings around errors, from the web platform, our servers and the mobile apps.
- PostHog. Product analytics and masked session recordings in the web platform and the mobile apps. PostHog uses your IP address to estimate your general location.
- New Relic. Server and page performance monitoring, and search across our server logs, which are scrubbed of personal details first.
- Gleap. In-app support chat and bug reports, on web and mobile.
- Mapbox. Maps and address search in the platform. Mapbox receives the addresses you search for, the map locations being shown, and your IP address and browser or device details, and its software sends Mapbox anonymous usage statistics.
- Google reCAPTCHA, Plausible and lemlist. Spam protection, cookieless analytics and marketing measurement on our website, as described under Cookies and Tracking.
Single Sign-On, Integrations, and AI Access
Our customers set up some connections themselves, with companies they choose and contract with directly. When your organization uses single sign-on, your identity provider tells us your name and email at sign-in. A workspace that connects Smartsheet lets us read schedule data from the customer's own Smartsheet account.
AI Access lets you connect an AI assistant you choose, such as Claude or Cursor, to your workspace. A workspace administrator must accept a consent before it can be turned on. The connection is read-only and limited to what you can already see in RolloutIQ™, and data goes only to the AI provider you signed in to, under your agreement with that provider. RolloutIQ™ itself never sends your data to an AI provider.
Where We Store and Process Information
Platform data is hosted by Amazon Web Services in the United States (us-east-1, Northern Virginia). Each customer has its own separate database, and its files are stored apart from every other customer's. Most of our service providers process data in the United States, and some may process it in other countries, including in the European Union. If you are outside the United States, your information will be transferred to and processed in the United States.
How Long We Keep Information
We keep a customer's workspace data for as long as the customer's account is active. Deleting a record or file hides it from everyone in the workspace. The stored file is permanently erased 30 days after the last record that uses it is deleted, and earlier versions of a file are kept for up to 90 days after they are replaced. When a workspace administrator removes a user, that person can no longer sign in, but their name stays on the work they did so the project history remains accurate.
Change history, download history, consent records, notifications and copies of sent emails are kept for the life of the workspace, because they are the record of who did what. When a customer's agreement ends, we delete its workspace on the customer's request after the export period in our Terms of Service.
Signed-in sessions expire after 120 minutes of inactivity unless you choose to stay signed in, which lasts up to 30 days. Our own server logs are kept for 90 days, and database backups for 30 days, so deleted information can remain in a backup until it expires. Information held by our service providers is kept under each provider's retention settings.
Data Security
We implement industry-standard security measures to protect your personal information, including AES-256 encryption for data at rest and TLS 1.3 for data in transit, role-based access control, tenant-isolated databases, and append-only audit logs. We conduct regular security reviews.
Cookies and Tracking
We group cookies and similar technologies into categories. Strictly necessary items are required for the site to function and stay secure; these are always on and include remembering your privacy choices and Google reCAPTCHA, which protects our contact form from spam and abuse and is subject to Google's privacy policy and terms. The demo scheduler, which Pipedrive hosts, loads inside our page only after you submit the contact form, and it may set cookies it needs to work. Privacy-friendly, cookieless analytics that do not identify you may run without consent. Marketing technologies that recognize you or measure our outreach, including our marketing measurement provider lemlist, load only after you opt in. When you first visit, we ask for your choice and load nothing non-essential until you decide. You can change or withdraw your consent at any time using the Cookie Preferences link in the site footer. Depending on your location, you may also have the right to opt out of the sharing of your information for these purposes; contact us at privacy@rolloutiq.com to exercise that right.
The web platform uses its own cookies to keep you signed in (for up to 30 days if you tick "Remember me"), to protect forms against forgery, to route your requests, and to remember the workspace you last used. It also stores your language, theme and view preferences in your browser. Our analytics tool sets a cookie with a random visitor ID that lasts up to a year, and our error, performance, support and map tools keep small amounts of session and usage data in your browser.
Newsletter Polls
Our newsletter, The Rollout, sometimes includes a click-to-vote poll. When you cast a vote, we record the option you chose along with the date and time, your IP address, and your browser and device details. A vote is anonymous and is not linked to your name or email address. We use this information to prevent duplicate or automated voting and to protect the poll from abuse, and we store a cookie in your browser for the same purpose. We report only aggregate results, which may appear in a later issue of the newsletter. If you would like a vote associated with your IP address removed, contact us at privacy@rolloutiq.com.
Your Rights
You have the right to access, update, or delete your personal information. You may also opt out of marketing communications by following the unsubscribe instructions in any email we send. To exercise these rights, contact us at privacy@rolloutiq.com.
If you use the platform or the mobile apps through your employer, your organization controls your account and its data, so please send requests to your workspace administrator first. You can update your own profile and preferences in the app at any time. If you contact us directly about a workspace, we will work with the customer that owns it to respond.
Children
Our website, platform and apps are built for businesses and are not directed at children. We do not knowingly collect personal information from anyone under 16.
Changes to This Policy
We may update this privacy policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the 'last updated' date.
Contact Us
Send questions about this policy to privacy@rolloutiq.com, or write to RolloutIQ Inc., 2693 Sutter St, San Francisco, CA 94115.