GC Safety Consultant · Last updated September 16, 2026 · Effective September 16, 2026
This Privacy Policy explains what information the GC Safety Consultant application ("the App," "we," "us," "our") collects, how we use it, how we share it, and the choices and rights you have. By creating an account or using the App, you agree to this Policy. If you do not agree, please do not use the App.
If you use the App on behalf of a company or other organization (for example, a general contractor, employer, or client), this Policy applies to your use of the App. The organization that subscribes to or provides the App to you may act separately as a controller of, or have its own policies governing, the data you enter, and you should also review the organization's own policies.
We use your information to provide and operate the App, including to:
We collect only the information reasonably necessary for these purposes, and we do not use it for purposes that are not reasonably necessary to or compatible with these disclosed purposes without your consent.
We do not sell your personal information. We do not "share" your personal information for cross-context behavioral advertising, and we do not use it for targeted advertising.
We collect the categories of personal information described below, and we may have collected them during the 12 months before the "Last updated" date of this Policy. We collect this information directly from you (and, for photos and signatures, through your actions in the App) and automatically as you use the App.
| Category | Do we collect? | Used for | Sold or "shared"? |
|---|---|---|---|
| Identifiers (email, name, phone, address, username, account ID) | Yes | Account, support, billing | No |
| Personal information described in California Civil Code § 1798.80(e) (e.g., phone, address) | Yes | Account, jobsite records | No |
| Geolocation data (precise coordinates when you enable location) | Yes | Jobsite location, weather | No |
| Audio, electronic, visual, and similar information (photos, signatures) | Yes | Inspections, AI hazard analysis | No |
| Commercial information (subscription and transaction records) | Yes | Billing | No |
| Internet or other electronic network activity (usage logs, device data, AI scan counts, IP address) | Yes | Operations, security, plan limits | No |
| Professional or employment-related information | Only if you enter it | Records you create | No |
| Inferences (AI hazard suggestions) | Yes | Advisory hazard analysis | No |
Where state law treats precise geolocation or other information we collect as "sensitive" data, we obtain your consent before collecting or processing it where consent is required, and we process it only for the purposes described in this Policy.
We share information only as needed to run the App, with providers that act on our behalf and are contractually required to protect it:
We may add or change service providers over time; we will update this Policy so it remains accurate.
We may disclose your information where we believe in good faith that doing so is necessary to: (a) comply with a law, regulation, court order, subpoena, or other legal process; (b) respond to a government, regulatory (including OSHA or other occupational safety authorities), or law enforcement inquiry, investigation, or request; (c) establish, exercise, or defend legal rights, including in litigation, arbitration, or workers' compensation proceedings; (d) protect the rights, property, or safety of us, our users, or others; or (e) investigate or prevent fraud or security incidents. Inspection content, JHAs, and violation records may be relevant to regulatory or legal matters and may be produced as required by law.
If we are involved in a merger, acquisition, reorganization, or sale of all or substantially all of our assets, your information may be transferred as part of that transaction, subject to this Policy or a successor policy we provide to you.
We may use or share de-identified or aggregate information that cannot reasonably be used to identify you, for purposes such as analytics, security, and product improvement.
We do not sell your personal information to third parties.
When you request AI hazard analysis, the photo and related inspection context you submit are sent to our AI provider to generate hazard suggestions.
AI suggestions are advisory only. They may be incomplete, inaccurate, or wrong, and they are not a substitute for professional judgment, site inspection, or a compliance determination. You are responsible for verifying findings and for any decisions you make based on them.
We do not use your photos or inspection content to train AI models, and our AI provider is contractually limited from using your content to train its models and from retaining it longer than necessary (see Section 11).
Our AI analysis does not perform facial recognition or biometric identification, and we do not use photos to identify any individual. You remain responsible for obtaining any consents or authorizations required before you capture or upload photos or signatures that depict or identify other people, and for complying with any applicable workplace or biometric privacy laws.
The App uses only strictly necessary local storage and similar technologies: a sign-in session so you stay logged in, and on-device settings such as your remembered organization, in-progress inspection drafts, and preferences. We do not use advertising cookies, third-party tracking, or cross-site analytics. Because this storage is required for the App to function and is not used to track you, no separate cookie-consent banner is shown. Clearing your browser storage signs you out and removes local drafts. We may also use basic server logging and, if enabled in the future, analytics tools that collect usage information such as App version, device type, and error reports — in which case we will update this Policy and, where required, ask for your consent.
We currently do not respond to browser "Do Not Track" signals because the App does not track you across third-party websites for advertising or analytics not described in this Policy. If we enable analytics or other cross-site tracking in the future, we will update this Policy.
You can view and edit your profile at any time. You can export your data (via your inspection PDFs and JSON) and permanently delete your account and associated data from within the App (Profile → Delete account). Deleting your account removes your account and your inspections, violations, hazards, and related photos, and cancels any active subscription. Some records we are required to retain (such as proof of a signed agreement, or transaction records held by Stripe) may be kept as required by law.
You may also submit a request by emailing safety@gcsafetyconsultant.com. To protect your privacy, we will verify your identity before responding. Where applicable law allows, you may designate an authorized agent to make a request on your behalf. We will respond within the time required by applicable law (generally 45 days, and we may extend that period where permitted). If we deny a request, we will explain why and tell you how to appeal. We will not discriminate against you for exercising any privacy right, including by denying services, charging different prices, or providing a different level of service, except as permitted by law.
Depending on where you live, you may have additional rights under U.S. state privacy laws. These laws are in effect in many U.S. states and include (as applicable, and with each state's own scope and exemptions) California (the CCPA, as amended by the CPRA), Virginia, Colorado, Connecticut, Utah, and other states whose comprehensive privacy laws took effect in 2024, 2025, and 2026 (including but not limited to Montana, Oregon, Texas, Florida, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Indiana, Tennessee, Minnesota, Maryland, Kentucky, and Rhode Island, where such laws apply to us).
Depending on the law that applies to you, you may have the right to:
Because you can view, edit, export, and permanently delete most of your data directly in the App, you can exercise many of these rights yourself at any time. To make a formal request that is not available in the App, email safety@gcsafetyconsultant.com; we will verify your identity and respond as required by applicable law.
Under the California Consumer Privacy Act (CCPA), as amended, in addition to the rights described in Section 7 you may request that we disclose the categories and specific pieces of personal information we hold, correct inaccurate information, and delete your information. We do not sell your personal information, and we do not "share" it for cross-context behavioral advertising, so there is nothing to opt out of for those purposes; if that changes, we will update this Policy and provide the required notice. For California residents who wish to submit a "Do Not Sell or Share My Personal Information" request, you can do so at https://gcsafetyconsultant.com/, even though we currently do not sell or share your personal information.
California law treats certain categories as "sensitive personal information" (for example, precise geolocation). We collect precise geolocation only to provide the service you request — recording a jobsite and fetching local weather — which is a permitted service-based use. We do not use or disclose sensitive personal information for any purpose that would require us to provide a "Limit the Use of My Sensitive Personal Information" link; if our practices change, we will update this Policy and add that link. In the meantime, you may always decline or revoke location access through your device settings or the App.
California Civil Code § 1798.83 permits California residents to request, once per year, information about whether we have disclosed certain categories of personal information to third parties for their direct marketing purposes, and the names and addresses of those recipients. We do not share personal information with third parties for their direct marketing purposes, and we will honor any request you make under this law at safety@gcsafetyconsultant.com.
Where state law applies to us, we will honor the access, correction, deletion, portability, opt-out, appeal, and related rights described above. Some state laws exempt certain business-to-business, employment-related, or de-identified data; where an exemption applies, we may not be able to fulfill, or may not be required to fulfill, a particular request.
If you access the App through a company, employer, or client subscription, that organization may control, or have its own policies and legal obligations governing, the account and the records (including inspections, JHAs, and violation notices) associated with it. The organization may be able to view, export, or manage that content, and may be subject to its own regulatory or legal obligations relating to workplace safety records. You should consult your employer's or the organization's own policies regarding such records. We will honor your individual privacy requests to the extent required by applicable law.
The App is intended for users in the United States, and this Policy is intended to comply with the laws and regulations of the United States. The App and its service providers (Supabase, Vercel, Anthropic, Stripe, and weather providers) process and store data on servers in the United States. By using the App, you understand that your information will be processed and stored in the United States, even if you access the App from outside the United States. We do not direct the App to individuals located outside the United States, and users outside the United States use the App at their own discretion.
We keep your content while your account is active, and you may delete your account at any time. Records you delete are recoverable by you from the Recycle Bin for 30 days, then held in an access-restricted backup for five years so they can be restored at your organization's authorized request (a period aligned with occupational-safety recordkeeping requirements), after which they are permanently destroyed. Only GC Safety Consultant platform administrators can access backup copies, solely to restore them on request, and each access is logged; we do not use backup data for any other purpose. After you delete data or your account, copies may remain temporarily in our backups, logs, analytics, or fraud-prevention systems consistent with our operational and legal obligations, and will be deleted or anonymized in accordance with our retention practices. Service providers may retain limited data under their own policies and legal obligations: for example, Stripe retains transaction records as required for billing and tax purposes, and our AI provider retains API content only for the limited period needed for abuse monitoring (and not for model training) under our agreement. We retain other information only as long as necessary for the purposes described in this Policy or as required by law.
We use industry-standard administrative, technical, and physical measures to protect your information, including access controls and per-user data isolation. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. If we experience a data breach affecting your personal information, we will notify you and the relevant authorities as required by applicable law.
The App is intended for use by adults in a professional setting and is not directed to children under 16. We do not knowingly collect personal information from children, and we do not knowingly collect information from children under 13, consistent with the Children's Online Privacy Protection Act (COPPA). If we learn that we have collected personal information from a child under 13 (or under any applicable higher minimum), we will take steps to delete it promptly. If you believe a child has provided us personal information, contact us at safety@gcsafetyconsultant.com.
We may update this Policy from time to time. Material changes will be reflected by updating the "Last updated" date above and, where appropriate, by notice within the App or by other means. Your continued use of the App after the changes take effect constitutes your acceptance of the updated Policy.
If you have questions or requests about this Policy or your personal information, or to exercise any of your privacy rights, contact us at:
GC Safety Consultant
Website: https://gcsafetyconsultant.com/
Email: safety@gcsafetyconsultant.com
For California residents exercising rights under the CCPA, and for all other privacy rights requests, please use the contact information above. We will verify your identity and respond as required by applicable law.