Privacy Policy
Last updated: 13 September 2026
This Privacy Policy explains how ESTEPS, the company behind ProSite("we", "us"), collects, uses, discloses, and safeguards information when you visit https://prosites.app, use the ProSite mobile apps for iOS and Android, or use the ProSiteweb dashboard (together, the "Service").
1. Who we are & how the Service is structured
ProSiteis a multi-tenant operations platform for construction and other field teams. Each customer organisation has its own separate "workspace." Accounts are created by the organisation, on the web, by invitation: a workspace administrator invites a member, and the member sets a password on the ProSite website. There is no public sign-up, and accounts cannot be created in the mobile apps; the apps are for signing in to an existing account.
For the data your team enters into a workspace (projects, tasks, materials, schedules, shifts, and team records), your organisation is the data controller and ESTEPS acts as a data processor on its instructions. For our marketing site and for account administration, ESTEPS is the controller.
2. Information we collect
Information you or your organisation provide
- Account & profile: full name, work email address, optional phone number, optional profile photo, role, and language and appearance preferences. Passwords are handled by our authentication provider and are never stored in readable form.
- Workspace content: projects and project photos; tasks, status changes, progress notes, and progress photos; materials, material photos, stock movements, and damage reports; schedules; shift records (start and end times, breaks, materials checked out and returned, and linked tasks); custom fields; and reports and report branding.
- Field workers without a login: an administrator may add team members who do not use the apps (for example, by name) so their shifts can be recorded. That information is provided by the organisation.
- Enquiries: if you contact us, the information in your message. The contact form on our website opens a pre-filled email in your own email app; the form does not submit anything to our servers.
Information collected automatically
- Service logs: our hosting providers record technical request data (such as IP address, device or browser type, and timestamps). We use these logs to operate, secure, and troubleshoot the Service.
- Essential storage: cookies (web) and on-device storage (mobile) needed for sign-in sessions, your selected workspace, and your language and theme preferences.
We do not use advertising, advertising identifiers, third-party analytics, or cross-app tracking, and we do not sell or rent personal data.
3. The mobile apps (iOS & Android)
- Camera:used only when you choose "Take Photo" (for example, for a project, material, progress, or profile photo). The app does not access the camera in the background.
- Photos: selected through the system photo picker. The app receives only the photo you pick, not your whole library.
- Location, contacts, microphone: not accessed. Project locations are text addresses entered by your team, not device location.
- Notifications and tracking: the apps do not send push notifications, contain no ads, and do not track you across other apps or websites.
- Reports: when you open a report, the app shows the corresponding ProSite web page inside the app. It is subject to the same sign-in and permissions as the dashboard.
- Data on your device: the apps store your sign-in session, selected workspace, and preferences on the device, plus a temporary image cache. Signing out removes the session.
4. How we use information
- To provide, secure, and maintain the Service and your workspace.
- To authenticate users and enforce the roles and permissions your administrators configure.
- To send essential service emails, such as password resets.
- To respond to enquiries and provide customer support.
- To diagnose problems and improve reliability and performance.
- To comply with legal obligations and enforce our agreements.
5. Legal bases (EEA/UK)
Where applicable law (such as the GDPR) requires it, we rely on: performance of a contract with your organisation; legitimate interests (operating, securing, and improving the Service); and compliance with legal obligations. For workspace content, the organisation that controls it determines its legal basis.
6. How we share information
We do not sell personal data. We share it only with:
- Members of your own workspace, according to the roles and data scope your administrators configure. Workspaces are isolated from each other.
- Service providers (sub-processors) that host and run the Service for us under contract:
- Supabase, Inc.: database, authentication (including sign-in and password-reset emails), file storage, and server functions. Hosted in the AWS Tokyo region (Japan).
- Vercel, Inc.: hosting for the website and web dashboard.
- Cloudflare, Inc.: domain name (DNS) services.
- Authorities, where required by law.
- A successor entity in a merger, acquisition, or sale of assets, subject to this Policy.
Apple and Google distribute the mobile apps under their own privacy policies. We do not receive your app-store account details.
7. International transfers
Your information is stored in Japan and may be processed in other countries where our service providers operate, including the United States. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses or adequacy decisions) for these transfers.
8. Data security
All data is encrypted in transit (HTTPS/TLS). The platform isolates each workspace and enforces access at the database layer using row-level security, so users can only reach the data their role and scope permit. Photos you add to projects, materials, and task updates are stored at long, randomly generated links that cannot be guessed; anyone who has a photo's exact link can open it, so share those links with care. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
9. Data retention
We keep workspace content for as long as your organisation keeps an active workspace, and afterwards only as long as needed to meet legal obligations, resolve disputes, and enforce agreements. Service logs are kept for a limited period set by our hosting providers.
10. Deleting your account or data
To delete your ProSite account, email info@esteps.my from the email address on your account and include your workspace name. You can also ask your workspace administrator. We may contact you to confirm the request, and we will email you when your account has been deleted. To withdraw a request before it is completed, email info@esteps.my. If you are the owner of a workspace, we will contact you first about the workspace itself.
- What we delete, within 30 days of confirming your request: your sign-in credentials, your profile details (email, phone number, and profile photo), and your assignments to projects, tasks, and schedules. Your name is replaced with "Deleted user", so the records below no longer identify you.
- What may be kept:records that are part of your organisation's workspace, such as task updates, shift and time records, and material movements. Your organisation controls these business records and may retain them under its own obligations. Ask your organisation if you want them removed.
- Whole workspaces: a workspace owner can ask us to delete the entire workspace and all of its content.
11. Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict, or port your personal data, and to object to certain processing. You may also lodge a complaint with your local data protection authority. For workspace content, please contact your workspace administrator first, as your organisation controls that data. For anything else, contact us at info@esteps.my.
12. Children
The Service is intended for business use and is not directed to anyone under 16. We do not knowingly collect data from children.
13. Changes to this Policy
We may update this Policy from time to time. We will post the revised version on this page with a new "last updated" date and, where appropriate, give additional notice.
14. Contact us
Questions about this Policy or your data? Email info@esteps.my. See also our Terms of Service.