Privacy Policy
Effective [confirm launch date]
This policy explains what personal information SiteHub collects, why, and what happens to it. It covers three different groups of people, because SiteHub is used differently by each:
- Customer Personnel - employees, supervisors and admins of a company that uses SiteHub to run its business.
- Customer's Clients - the contact people a SiteHub customer stores in their own client list (e.g. a property manager they do work for).
- Website Visitors - anyone who fills out the demo-request or info-pack form on our marketing site without becoming a user of the product itself.
Who operates SiteHub
SiteHub is built and operated by AkerHub ("we", "us")[confirm legal entity name and registered address]. Each SiteHub customer gets their own dedicated, separate deployment and database - your company's data is never mixed with another company's.
For Customer Personnel: what we collect, and why
If you're an employee, supervisor, inventory manager, project manager or admin at a company using SiteHub, your employer (not us) decides what information about you goes into the system. We process it on their behalf. That typically includes:
- Account details - name, email, job title, role, and (for admins) hourly pay rate.
- Time & attendance - clock-in and clock-out timestamps, which job they were tied to, and which device or kiosk code was used.
- Job-site content - photos uploaded from the field, daily notes, and any materials or receipts logged against a job.
- Employment documents, if your employer chooses to collect them through SiteHub - ID, licences, insurance certificates, or tax forms (e.g. a W-9).
- Payroll records - hours worked, calculated pay, and bonus amounts. SiteHub calculates and records payroll; it does not itself transfer money to anyone - actual payment stays your employer's responsibility, outside the platform.
- Vehicle assignment, if your employer uses it - which company vehicle (plate, VIN, make and model) is assigned to you.
- Security & access data - sign-in history, two-step verification status, and a permanent activity log of changes made to your account or by you.
Because your employer controls this data, they are the right first contact if you want to see, correct, or have it deleted. We act as a processor on their instructions, not as an independent decision-maker about your personal information.
For a customer's clients
A SiteHub customer may store contact details for their own clients - company name, contact person, email, phone and address - to track jobs and send estimates/invoices. This is the customer's data, collected and controlled by them; we only store and process it on their behalf.
For website visitors
If you fill out the "Request a demo" or "Get the info pack" form on our marketing site, we collect your name, company, email, phone (if given), team size and any message you write. We use this only to respond to your inquiry and send what you asked for - never for unrelated marketing, and never sold to anyone.
How we use this information
- To provide the features of SiteHub itself - job tracking, scheduling, time clock, payroll calculations, invoicing, inventory, and reporting.
- To secure accounts - two-step verification, automatic sign-out after inactivity, and a tamper-evident activity log.
- To communicate with a customer's admin about their account or support.
- We do not use Customer Personnel or Customer data to serve ads, and we do not sell personal information to anyone, ever.
Who we share it with
We use a small number of infrastructure providers (subprocessors) to run SiteHub. They can only access data as needed to provide their service to us, under their own confidentiality and security terms:
- Supabase - database, authentication, and private file storage.
- Vercel - application hosting.
We don't share personal data with anyone else, except where required by law (for example, a valid court order) or with your employer's explicit direction.
Data security
- Role-based access control enforced at the database level (Row Level Security) - not just hidden buttons - so, for example, a supervisor account genuinely cannot query payroll data even by trying the API directly.
- Optional two-step verification (2FA) for admin and management accounts.
- Automatic sign-out after a configurable period of inactivity.
- Job photos, receipts and employment documents are stored privately and only ever accessed through short-lived, signed links - never a public, guessable URL.
- All traffic is encrypted in transit (HTTPS/TLS).
- A permanent activity log records who changed what and when, and entries cannot be edited after the fact.
Where data is stored
Data is hosted with Supabase (built on cloud infrastructure) and Vercel. [Confirm the exact hosting region in your Supabase project settings - Project Settings → General - and state it here.]
How long we keep it
Data is retained for as long as a customer's account is active. If a customer stops using SiteHub, we will export their data to them on request and delete it from our systems within a reasonable period afterward [confirm exact number of days - e.g. 30 or 90]. A company's own activity log can only be cleared by their admin, and doing so is itself recorded as an event.
Your rights
If you're an employee of a SiteHub customer, start with your employer's admin - they control your account and can export, correct or delete your information directly. If you're a website visitor who submitted a form, you can ask us to delete your contact information at any time by emailing us. Depending on where you live, you may also have additional rights under local privacy law; contact us and we'll do our best to help regardless of where you're located.
Cookies
SiteHub uses only the functional cookies needed to keep you signed in. We don't run third-party advertising or analytics trackers on the product or the marketing site.
Children
SiteHub is a business tool and isn't directed at children. We don't knowingly collect personal information from anyone under 16.
Changes to this policy
If we make a material change to how we handle personal information, we'll update the date at the top of this page and, where appropriate, let customer admins know directly.
Contact
Questions about this policy, or a request related to your data: email florihoxha.al@gmail.com.
This document was drafted to accurately describe how SiteHub actually works today. It hasn't been reviewed by a lawyer yet - have one check it (particularly the bracketed items above) before relying on it as your binding policy.
