|

Privacy Notice

LAST UPDATED ON 8/14/2026

STACK Construction Technologies, Inc. and its affiliates and subsidiaries (collectively, “STACK”, “Company”, “Us”, “Our”, or “We”) are committed to protecting your privacy. This notice explains how we collect, use, and protect your personal information when you use our services.

This policy describes the types of information we collect from you or that you may provide when you (1) visit our websites, including https://www.stackct.com/, (2) any of our online applications or platforms, or (3) any other website or online application or platform that directly links to or provides this policy, or (4) any integration that allows a third-party artificial intelligence assistant or agent platform (an “AI Assistant”) to access our Services on your behalf, including our Model Context Protocol (“MCP”) server (collectively, the “Services”). This policy also covers information we may collect about you from third parties or when you contact us, such as via chat, email or by phone. This policy describes our practices for collecting, using, maintaining, protecting, and disclosing that information.

Please read this policy carefully to understand our policies and practices regarding your information and how we will treat it. This policy may change from time to time (see “Changes to This Notice”).

What information do we collect?

We may collect certain types of information from and about you, including:

Contact and other identifying information, such as when you place an order, subscribe to our newsletter or sign up for a free trial. When ordering or registering on our Services, as appropriate, you may be asked to enter your: name, e-mail address and phone number. We also may ask you to provide credit or other payment card information as necessary to process an order; that information does not come to our systems, and is processed by a trusted payment processing service provider and we do not receive that information from you.

Customer Content. When you use the Services, you and your colleagues create and upload the business records that make up your account. These include project records and their addresses, bid dates, statuses, notes, assigned users and custom fields; drawings and specifications; takeoffs and measurements; estimates, worksheets and pricing; company libraries; and tag and label vocabularies. We hold this content on your organization’s behalf. Customer Content may contain personal information where you choose to include it, including information about your colleagues, subcontractors, suppliers, and clients.

Information collected automatically. Our Services may use various technologies that may include cookies that collect certain online information, including, usage details, domain address, IP addresses, geolocation data, internet browser, operating system, your internet connection, the equipment you use to access our Website, and information collected through cookies. We, along with our third party service providers, may use the above technologies for a variety of purposes, including online analytics and enhancing your online experience and our product offerings. For more information, see the “Cookies” section below.

Service and request logs. We generate records when you, or an integration you have authorized, make a request to our Services. These records may include the date and time of the request, the IP address the request came from, the internal user and company identifiers associated with the request, an identifier for the client software making the request, a correlation identifier for the request itself, the capabilities you had granted, the operation that was requested, how long it took, and whether it succeeded or failed. We use these records to keep the Services secure and available, to enforce rate limits, to investigate and prevent abuse, to troubleshoot problems, and to meet our audit obligations. We do not use them to build advertising or behavioral profiles about you.

Information collected from third parties. We may receive information about you from third parties. For example, if you access our Services through a third-party connection or log-in (e.g., through Microsoft, Google), such third party may pass certain information about your use of its service to us. We may also receive information about you from third parties such as our business partners and service providers, including information generated at trade shows or seminars. We may also obtain other information about you such as change of address, contact information from commercially or publicly available sources.

Information we receive through AI Assistant integrations. If you connect our Services to an AI Assistant, we receive the parameters of each individual operation it asks us to perform on your behalf, together with the access credential we ourselves issued to it and the service and request log described above. We receive no sign-in or profile information about you from the AI Assistant itself, and we do not receive your conversation with it, or any part of that conversation you have not supplied as an input to a specific operation. See “AI Assistant integrations” below for what each type of operation accepts and returns.

How do we use your information?

Your personal information is primarily used by us to provide or facilitate your use of our Service. We may also use the information that we collect about you or that you provide to us for multiple purposes, including any of the following circumstances:

  • To process transactions, to communicate with you via email or otherwise, to improve our services, to enforce our terms of use and generally to enhance your experience with the Services.
  • To present our Services and its contents to you. We continually strive to improve our Services offerings based on the information and feedback we receive from you.
  • To provide you with information or services that you request from us.
  • The email address you provide for order processing, may be used to send you information and updates pertaining to your order, in addition to receiving occasional company news, updates, related product or service information, etc. Please note that you may unsubscribe from our promotional emails at any time using the unsubscribe link at the bottom of the email.
  • We may transfer your information in the event our business is sold, merged or otherwise acquired.
  • To notify you about changes to our Services or any products or services we offer or provide through the Services.
  • To allow you to participate in interactive features on or through the Services and to personalize your experience (your information helps us to better respond to your individual needs).
  • To authenticate a request made through an AI Assistant integration you have authorized, to confirm that you consented to the operation being requested, to carry out that operation, and to return the result to you.
  • To keep the Services secure and available, including to apply rate limits and to detect, investigate, and prevent unauthorized access, abuse, fraud, and activity that violates our Terms of Use.
  • To provide, support, and improve the artificial intelligence features of our Services, as described in “AI features and model training” below.
  • To share your information with the recipients, and for the purposes, described in “Who we share your information with” below.
  • We may share your information with service providers and other third parties that perform any services on our behalf, including order fulfillment, processing credit card payments, marketing research and analysis, communications, and customer success; however, these companies are prohibited from using your personal information for purposes other than those requested or authorized by us or required by law.
  • We may also disclose your information when we believe release is appropriate to comply with the law, enforce our site policies, or protect ours or others’ rights, property, or safety.
  • To comply with any legal obligations we are subject to or to detect instances of fraud or other illegal activities.
  • Except as described in this notice, your information will not otherwise be collected or used without your consent.

AI Assistant Integrations

Some customers use our Services through an AI Assistant rather than through our own web or mobile interface. To support that, we make available an MCP server that lets an AI Assistant you have authorized carry out a defined set of operations on your behalf. These integrations reach the data held in our Takeoff & Estimate solution, which we host in the United States, together with STACK’s own product reference documentation, which contains no information about you. This section explains how that works and what it means for your information, and applies in addition to the rest of this notice.

How the connection is established. We issue the credentials for this integration ourselves. The AI Assistant does not vouch for who you are, and we receive no identity assertion, profile, or sign-in information about you from it. Instead, you sign in to STACK with your own STACK credentials and existing session, you choose which specific operations the AI Assistant may perform, and we then issue an access credential to it. That credential identifies your internal STACK user and company identifiers, the AI Assistant, the permissions you granted, and the specific list of operations you consented to. It does not contain your email address. We never receive your STACK password, and we do not receive or ask for authentication codes, API keys, or other authentication secrets through the integration. We also receive registration details about the AI Assistant software itself, such as its name and the addresses of its own terms and policies; that information identifies the software, not you.

What each operation accepts. Each operation accepts only the inputs it needs to do its job. Those inputs are record identifiers, search and filter terms, and structured parameters defined in advance; no operation asks for general background or conversational context. Two inputs are free text: the words you search for, and the description of what you are looking for when searching our product reference documentation. As with free-text fields elsewhere in the Services, please do not put sensitive personal information there. Operations that report on estimate data are composed from a predefined query structure we control; an AI Assistant cannot supply its own database query. The operations available let you and an AI Assistant you authorize:

  • Find, look up, and search projects, takeoffs, and estimates, including takeoffs saved in your company’s library. Project results include the names of the users assigned to each project.
  • Read estimate and pricing information, and run predefined estimate reports.
  • Read company configuration options, tags, and labels.
  • Create and update projects, including the jobsite address fields for a project. An update replaces the project setup values it names.
  • Create new takeoffs on a project, and edit existing takeoffs, including replacing their current values.
  • Save copies of a project’s takeoffs to your company’s library, and import takeoffs from that library into a project.
  • Create tags in your company’s library, and assign tags to library takeoffs, which replaces any tags previously assigned to them.
  • Import your company’s labels for use on projects.
  • Search and read STACK’s own product reference documentation, which describes our Services and contains no information about you.
  • Return your own profile information when you ask for it, which consists of your display name, your email address, and your company.

What an AI Assistant can change. Some of these operations write to your account, and some replace information that is already there. An AI Assistant you have authorized can create projects, takeoffs, library entries, and tag vocabularies; copy takeoffs between a project and your company’s library; and overwrite existing records, including renaming projects and takeoffs, changing bid dates, statuses, privacy settings, notes, and addresses, and setting or clearing tag values. It can only carry out the specific operations you consented to when you authorized it, and only where you already hold the underlying permission in STACK.

What we return. A response returns the records and fields you asked for, drawn from the categories above. Some operations return a record as a whole rather than a selected set of fields, so a response may carry every field that record holds, including any label and tag groups your organization has defined on it. Where a response is drawn from a stored snapshot of an estimate that is no longer current, we also tell you that it is out of date. We do not include credentials, authentication secrets, or internal diagnostic metadata such as session, trace, or request identifiers in a response.

What we do not receive or collect. Our MCP server has no technical means to ask an AI Assistant for the contents of your conversation, and it does not do so. It sees only the parameters of the operation you invoked, and we make no attempt to obtain, reconstruct, or infer anything more. No operation accepts device location, GPS coordinates, or any other geolocation input; where an operation accepts a street address, that address describes the jobsite for a project and not you. We do receive the IP address your request comes from, as any web service does, and we use it to apply rate limits and to protect the Services rather than to determine where you are. No operation is designed to collect or return payment card data, protected health information, government identifiers such as social security numbers, or access credentials, and you should not enter that kind of information into free-text fields such as project names or labels.

How we log these requests. We deliberately do not write the contents of an operation’s parameters to our logs, because those parameters may contain personal information. We log the identifiers and outcome described under “Service and request logs” above instead. In one narrow case, where a request is rejected because it fails validation, the resulting error record may include a shortened excerpt of the value that was rejected.

Who receives it. The AI Assistant you authorized receives the response we return, because that is how the result reaches you. That includes any personal information the records you asked for happen to contain. Project results carry the names of the users assigned to each project; a request for your own profile returns your name, email address, and company; and free-text fields such as project notes carry whatever your organization recorded in them, which may include details of colleagues, subcontractors, suppliers, or clients. Some of those people will not have authorized the connection themselves. It handles that information under its own privacy policy and terms, which we do not control, and we encourage you to read them. Beyond that, information from these integrations is shared only with the categories of recipients described in “Who we share your information with” below. We do not sell information we receive through these integrations, we do not share it for advertising purposes, and we do not use it to build advertising or behavioral profiles.

Your controls. You choose which operations an AI Assistant may perform at the time you authorize it, and we record and enforce that choice. Your permissions are checked twice on every action: the AI Assistant can only attempt the operations you consented to, and we separately re-check that you still hold the underlying permission in STACK at the moment the action runs. If that permission is removed in STACK, access through the integration stops immediately rather than at the next credential renewal. You can review and revoke any connection at any time from the Connected Apps page in your STACK account, and the AI Assistant software can also revoke its own credential. Once you revoke a connection, requests for your data fail on the next attempt, and the credential itself expires in full within one hour. Your organization can also stop using these integrations at the company level, which prevents further access from being renewed. Revoking a connection does not by itself delete information we already hold; to ask us to delete it, see “How can I control my personal information?” below.

AI Features and Model Training

Some features of our Services use artificial intelligence. Our Terms of Use set out the rights you and your organization grant us in the content submitted to, and produced by, those features. In summary, and as described more fully in the Terms of Use:

  • We process the content you submit to an AI feature, and the output it returns, in order to provide that feature to you.
  • We may use that content and output, together with customer-created items, assemblies, and other customizations, to train, validate, test, and improve our AI features and our Services, and to generate recommendations of items, assemblies, features, products, and related content. Where we use this content for those purposes, we use it on an aggregated and de-identified basis, and we do not use it in a way that identifies your organization or you without prior written consent.
  • Information we receive through an AI Assistant integration is an exception. It is used to carry out and secure the request you made, and is not used to train or improve our AI features or models; our MCP server does not call a language model, and traffic from these integrations does not enter any training process of ours. This describes our own processing. The AI Assistant you choose to use may separately process or retain your conversation with it under its own terms, which we neither control nor administer.

Who We Share Your Information With

We share your personal information only in the circumstances described in this notice, and only with the following categories of recipients:

  • Cloud hosting and infrastructure providers that host our Services and store information on our behalf.
  • Service providers and subprocessors that perform functions on our behalf, including order fulfillment, payment processing, application and infrastructure monitoring, log management, security monitoring and detection, customer support and ticketing, email delivery, marketing research and analysis, product analytics, communications, customer success, and customer relationship management. These providers are required to protect the information we give them, and are prohibited from using it for purposes other than those we request or authorize, except where the law requires otherwise.
  • Third-party providers whose functionality is built into the Services, as identified in our Terms of Use.
  • AI Assistants that you have authorized to connect to the Services, as described above.
  • Professional advisors, including our auditors, legal counsel, and insurers, where they need the information to advise us and are obliged to keep it confidential.
  • An acquirer, in the event our business or part of it is sold, merged, or otherwise acquired.
  • Government authorities, courts, and other parties where we believe disclosure is necessary to comply with the law, respond to lawful requests or legal process, enforce our agreements and site policies, or protect the rights, property, or safety of STACK, our customers, or others.

We maintain a current list of the subprocessors we engage in our Trust Center at https://trust.stackct.com.

Data Security and Retention

We implement a variety of security measures including physical, organizational, contractual and technological in an effort to protect your personal information and reduce the risk of loss or theft, unauthorized access, disclosure, copying, misuse or modification of your personal information. These measures include restricting physical access to our offices and records, restricting access to your personal information to only those employees or agents who require access to fulfill their responsibilities, and restricting unauthorized access, disclosure, use and misuse of your personal information in our custody and control. We also periodically update and review such security measures which are audited annually by an independent third party.

Our goal is to prevent unauthorized access, loss, misuse, sharing or alteration of personal information in our possession. We also use these safeguards when we dispose of or destroy your personal information. For more details about our security practices please visit our Trust Center.

How long we keep your information

We keep personal information only for as long as we need it for the purposes described in this notice, and then delete it or de-identify it. How long that is depends on the type of information:

  • Content and records you create in the Services. Kept in accordance with the retention terms set out in our Terms of Use, including the post-termination retention period and the project retention limits described there. Where you use an AI Assistant integration to create or update a record, that record becomes ordinary customer content and is kept on the same basis as content you create directly in the Services.
  • Information handled by our MCP server. Our MCP server keeps no database of its own. The parameters of a request and the response we return are processed in memory in order to answer the request, and are not stored there. Rate-limiting counters retain only a shortened, one-way hash of a request key, never the contents of a request.
  • Service, request, security, MCP, and audit logs. Kept for no longer than 18 months, after which they are deleted.
  • Authorization and consent records. We keep a record of each connection you authorize, the operations you consented to, and each revocation, so that we hold an audit trail of who was granted access to what and when. Revoking a connection changes the status of these records rather than erasing them, and we retain them for as long as we need them for audit purposes.
  • Database Backups. Kept for up to 365 days, after which they are overwritten or destroyed.
  • Marketing preferences and unsubscribe records. Kept for as long as we need them to continue honoring the choices you have made.

Where we need to keep information for longer in order to investigate a security incident, comply with a legal obligation, resolve a dispute, or enforce our agreements, we keep it for that period and then delete or de-identify it.

How can I control my personal information?

We provide you the ability to exercise certain controls and choices regarding our collection, use and sharing of your information. In accordance with applicable law, your controls and choices may include:

  • Changing the relevant settings in your STACK account.
  • Requesting, via email or through the Services’ chat features, that we remove or de-identify your personal data. To email, please send an email request to privacy@stackct.com
  • Updating your collection and use preferences for certain data practices through our Cookies Settings. Please see the “Cookies” section below for more details. You can change your Cookie Preferences at https://www.stackct.com/cookie-notice/. If you are a California resident, you can also use these settings to exercise your right to opt out of the sale or sharing of your personal information.
  • Choosing which operations an AI Assistant integration may perform, and reviewing or revoking any such connection from the Connected Apps page in your STACK account.
  • Requesting a copy of the personal information we hold about you, or asking us to correct it if it is inaccurate or incomplete.
  • Withdrawing a consent you previously gave us.
  • Objecting to, or asking us to restrict, a particular use of your information, where applicable law gives you that right.

To make a request, email us at support@stackct.com. We will respond within the time applicable law allows. Before we act on a request, we may need to take reasonable steps to verify your identity. Where you use the Services through an account provided by your employer or another organization, that organization controls the account, and we may need to direct your request to them or act on their instructions. We will not discriminate against you for exercising any of these rights. If we decline a request, we will tell you why, and you may ask us to reconsider by replying to our response. Depending on where you live, you may also have the right to lodge a complaint with your local data protection or privacy authority.

Third party links

Occasionally, at our discretion, we may include or offer third party products or services on our Services through separate hyperlinks that will take you to third party sites. These third party sites have separate and independent privacy policies. We therefore have no responsibility or liability for the content and activities of these linked sites and we encourage you to read the privacy notices and disclosures upon visiting such third party sites.

Children’s Privacy

Our Services are built and made available for business professionals in the commercial construction and related industries. They are not directed to children. We do not knowingly collect personal information from anyone under 18 years of age, and our Terms of Use require that Authorized Users be at least 18 years old. Please contact us if you believe we may have collected information from a person under 18.

International Users

If you are accessing our Services from outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States. By using our Services, you consent to this transfer. Depending on which STACK solution your organization uses, we may host your information in Canada rather than in the United States.

Cookies

In order to make certain aspects of the Services work properly and provide relevant products and services to you, the Services uses certain cookies and other online tracking technologies. Please see our Cookie Notice, which provides you with information about these technologies and how to control them. You can review and change your Cookie preferences at any time at: https://www.stackct.com/cookie-notice/.

Changes to This Notice

We may update this privacy notice from time to time. When we make changes, we will update the “Last Updated” date at the top of this notice. We encourage you to review this notice periodically.

Contact Us

Shopping Basket

Which solution are you looking for?

Takeoff & Estimate
Calculate everything you need anytime, anywhere.
Build & Operate
Seamlessly link your data from the office to the field.

Need a more custom solution?  Talk to us

STACK Training Videos

Select which training library you would like to access: