Privacy Policy
Last updated: July 24, 2026
TradeLog Site (“TradeLog Site,” “we,” “us”) is a construction time tracking and project management application built for field crews, foremen, and contractors. This Privacy Policy explains what information we collect, why we collect it, how we use it, and the choices you have.
1. Who we are
TradeLog Site is owned and operated by LionSync LLC, located in Nebraska, United States. For any privacy-related questions you can reach us at support@tradelogsite.com.
2. Information we collect
When you use TradeLog Site we may collect:
- Account information: name, email address, phone number, and password credentials.
- Company / dashboard information: company name, address, trade, role, and team membership.
- Project information: project names, addresses, scopes, schedules, status, and assignments.
- Field activity: time entries (clock in / clock out, manual entries), project notes, personal notes, tasks, punch list items, and calendar events.
- Access records: invitations, access requests, approvals, role changes, and removals.
- Payment and subscription metadata: subscription status, trial dates, plan, and billing identifiers returned by Paddle. Payment card data, billing details, and tax/VAT information are collected and processed directly by Paddle as the Merchant of Record. TradeLog Site does not receive or store full payment card numbers.
- Technical data: IP address, browser, device, and basic usage logs needed to run and secure the service.
3. Why we collect it
- To create and operate your account and dashboard.
- To deliver the core product: time tracking, projects, notes, tasks, calendar, and reporting.
- To authenticate users and enforce access controls inside a company.
- To process subscriptions and the 14-day free trial.
- To send transactional email (invitations, password resets, billing notices).
- To monitor security, prevent abuse, and improve the service.
4. How we use your data
We use the data above to provide and improve TradeLog Site, to support your team, to comply with legal obligations, and to enforce our Terms of Service. We do not sell your personal data.
4a. Legal basis for processing
Where data protection laws such as the EU/UK GDPR apply, we rely on the following legal bases to process your personal data:
- Performance of a contract — to create your account, operate your company dashboard, and deliver the core TradeLog Site features (time tracking, projects, notes, tasks, calendar, reporting).
- Legitimate interests — to secure the Service, prevent abuse, debug issues, and improve TradeLog Site, balanced against your rights and expectations.
- Legal obligation — to retain billing, tax, and accounting records and to respond to lawful requests.
- Consent — where required, for example for certain non-essential communications. You can withdraw consent at any time by contacting support@tradelogsite.com.
5. Who can access project and company data
TradeLog Site enforces role-based access at the database layer. Within a company dashboard:
- Owners and admins can see all projects, members, time, and billing for their company.
- Managers and foremen can see the projects they manage and the team members assigned to them.
- Employees and outside trades only see the projects they are assigned to and the permissions granted on that assignment.
- Personal notes are private to the author.
TradeLog Site staff may access account data only when strictly necessary to operate, secure, or support the service.
6. Third-party services and data processing roles
We rely on a small number of trusted providers to run TradeLog Site. For data-protection purposes:
- LionSync LLC (operator of TradeLog Site) is the data controller for the personal data you provide. We decide what data is collected, why it is processed, and how long it is kept.
- Supabase — acts as a data processor on our behalf. Supabase hosts the PostgreSQL database, handles authentication, and stores uploaded files. They process your data only to deliver the hosting and auth services we contract for, and they are bound by data-processing terms that restrict use to our instructions.
- Paddle — acts as the Merchant of Record and payment processor for TradeLog Site subscriptions. Paddle receives and processes payment card details, billing details, tax/VAT information, and transaction metadata required to process subscriptions, invoices, and applicable taxes. We receive only billing identifiers, subscription status, and transaction metadata from Paddle. Paddle’s privacy practices are governed by its own policies and data-processing agreements. Paddle may also set checkout cookies on its own domains as described in Section 6a.
- Resend — acts as a data processor for transactional email delivery (invitations, password resets, billing notices). Resend processes email addresses and message content solely to send the emails we request.
- Lovable — provides application hosting and deployment infrastructure. Lovable operates as a processor or subprocessor depending on the service layer, handling build artifacts, preview URLs, and edge-network delivery under our instruction.
Each provider only receives the data necessary to perform its function. We do not authorize any provider to use your personal data for its own independent purposes or to share it with unrelated third parties.
6a. Cookies and similar technologies
TradeLog Site currently uses only functional and necessary cookies to run the Service. We do not use advertising cookies, tracking pixels, tag managers, third-party analytics services, or session-replay tools, and we do not build behavioral profiles for cross-site advertising.
First-party, cookieless traffic measurement
To understand how our public marketing pages perform, we record a small, non-identifying event on our own servers when a public page is viewed. This measurement uses no cookies and no third-party service. Each event stores only: the time of the view, the public page path, the referring website’s domain, any campaign tags in the link, a broad device class (mobile, tablet, or desktop), and a random identifier held in sessionStorage that is discarded when you close the browser tab.
We also measure how long a page was actively visible during a single visit. Each of those measurements stores only: a safely normalized page or route (dynamic values such as project identifiers are replaced with a placeholder, and query strings and link fragments are removed before anything is recorded), how long that page was actively visible, a broad device class, the time of the visit, and a random identifier generated for that one page visit and never reused.
TradeLog Site does not write IP addresses, account identifiers, company identifiers, project identifiers, invitation tokens, authentication tokens, page content, or form entries to its analytics tables. A limited set of signed-in pages may be measured in the same anonymous way; in that case your sign-in is used only to authorize the measurement request, and your identity is never written to the analytics record. Pages that can carry sensitive values in the address bar — such as invitation links, password-reset links, and authentication callbacks — are never measured. Counts are best-effort and undercount visitors who block scripts. Raw events are automatically deleted after 400 days, and only aggregate totals are ever displayed.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
sidebar_state | TradeLog Site | Remembers whether an authenticated user’s navigation sidebar is open or closed; no PII. | 7 days |
tls-admin | TradeLog Site | Secure administrator authentication session; HttpOnly, Secure, SameSite=Lax. | Up to 12 hours |
| Paddle checkout cookies | Paddle | Loaded only when a user opens subscription checkout; used by Paddle for checkout operation, fraud prevention, payments, and regulatory compliance. | Set and retained by Paddle under its policy |
Browser storage (not cookies)
TradeLog Site also uses your browser’s built-in localStorage and sessionStorage. These are not cookies and are not transmitted with every request:
- Supabase authentication token is stored in
localStorageso that signed-in sessions persist between visits. It is removed or invalidated on sign-out, and you can clear it at any time using your browser’s site-data controls. - Theme preference and timesheet-calculator inputs may be stored in
localStorageso your choices persist across sessions on the same device. - Pending invitation and onboarding values may be held temporarily in
sessionStorageand are cleared after use or when the browser tab session ends.
None of these cookies or storage mechanisms are used for cross-site advertising or behavioral profiling. You can delete or block cookies and browser storage through your browser settings, but blocking necessary items may prevent sign-in, admin access, account signup completion, subscription checkout, or saved preferences from working correctly.
If we later add non-essential analytics or advertising technologies, we will update this policy and, where legally required, request your consent before enabling them.
7. Your rights
You may, at any time:
- Access the personal data we hold about you.
- Request corrections to inaccurate data.
- Request deletion of your account and associated personal data.
- Request a copy of your data in a portable format.
- Object to or restrict certain processing activities.
To exercise these rights, email us at support@tradelogsite.com.
8. Data retention
We keep different categories of data for different periods:
- Active dashboard data — account profiles, company dashboards, projects, time entries, notes, tasks, calendar events, and team assignments are retained for as long as your company dashboard remains active and you maintain a subscription (or trial).
- Cancelled or deleted accounts — if you cancel your subscription or delete your account, we begin a deletion process. Most personal data is removed or anonymized within 30 days. Some data may be retained longer (up to 7 years where required) for legal, tax, accounting, security, or backup-recovery obligations.
- Billing and transaction records — subscription invoices, payment metadata, and trial dates are retained for as long as required by applicable tax and accounting laws, typically 7 years.
- Security and audit logs — technical logs (IP addresses, access times, error traces) used for abuse prevention and security monitoring are retained for up to 90 days, after which they are deleted or aggregated into non-identifiable statistics.
- Email delivery logs — transactional email metadata (send status, bounces) are retained by Resend for up to 30 days as part of their delivery infrastructure.
When retention periods end, we securely delete or anonymize the data. If local law requires us to retain specific records beyond these periods, we will do so and limit use to that legal purpose.
9. Security practices
TradeLog Site uses HTTPS/TLS in transit, row-level security in the database, scoped access tokens, and least-privilege service roles. No service can guarantee absolute security, but we work continuously to protect your data.
10. Children and age restriction
TradeLog Site is intended for users who are 18 years of age or older. The Service is not intended for children or minors, and we do not knowingly collect personal data from anyone under 18. If we learn that we have collected personal data from a person under 18, we will take reasonable steps to delete it. TradeLog Site is owned and operated by LionSync LLC, located in Nebraska, United States.
11. Changes to this policy
We may update this policy from time to time. The “Last updated” date at the top reflects the most recent revision.
12. Contact
Questions about this policy? Email support@tradelogsite.com.
LionSync LLC
12020 Shamrock Plz Ste 201, Omaha, NE 68154-3537, PMB #491433
