Privacy Policy
Last updated: 1 October 2026
Arqor is operated by Arqor Ltd, registered in England and Wales, company number 17380863
1. Introduction
This Privacy Policy explains how Arqor Ltd (“we”, “us”, “our”) collects, uses, stores, and protects your personal data when you use the Arqor platform and Arqor SiteRecord application (the “Service”). SiteRecord is a trading name of Arqor Ltd.
We are committed to protecting your privacy and complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
2. Data controller
The data controller responsible for your personal data is:
Arqor Ltd
Company number: 17380863
Registered office: 69 Empingham Road, Stamford, PE9 2SU
ICO registration: ZC223398
Email: hello@arqor.io
3. What data we collect
3.1 Account data
When you create an account, we collect your email address. If you provide additional information in your company profile (company name, logo, address), we collect that too.
3.2 Photo and job data
When you or your trades upload photos through the Service, we collect and store the photos themselves along with embedded metadata including GPS coordinates (latitude and longitude), date and time stamps, and device information extracted from EXIF data. We also store notes, phase tags, area descriptions, floor plan pin locations, and trade/worker names associated with each photo.
3.3 Trade user data
Trades who access the Service via QR code provide their name and trade type. This information is stored in the browser (localStorage) and associated with photos they upload. Trade users do not have accounts and we do not collect their email addresses.
3.4 Payment data
Payment processing is handled entirely by Stripe. We do not store your full card number, CVV, or other sensitive payment details. We receive and store your Stripe customer ID and subscription status.
3.5 Usage data
We collect basic usage data, such as pages visited and features used, through Vercel Analytics. When the website or the app hits an error, it sends us an error report: the error, the page, the browser or app version and, if you are signed in, your account, so we can fix it. Neither is used for advertising or sold to third parties.
3.6 The Arqor app
The Arqor app is for people who work for a company that uses Arqor. Your company sets you up and you sign in with your work email. Besides the error reports in 3.5, the app collects:
- Your location while you are clocked in — so your company has an accurate record of where and when you worked. Clocking out stops it.
- Your arrival at and departure from your company’s sites — only if your company turns on automatic clock-in and you agree to it in the app. Your phone then watches for you arriving at or leaving one of those sites, including while you are off the clock, and records the time and place of that arrival or departure so it can clock you in or out. It does not record where you go in between.
- Your location when you press and hold the Emergency button — sent to your company, and only when you press it.
- Photos, voice notes and recordings you make in the app — stored in your company’s account as site records. Photos carry the time and place they were taken (see 3.2); voice notes and recordings are turned into text by our transcription provider (see section 7).
- Your name and signature — when a site asks you to sign in to its register or to sign its safety documents.
What the app records is held in your company’s account: your company sees it, and we access it only to run and support the Service. It is never sold or used for advertising. You can turn off the app’s access to your location in your phone’s settings at any time.
3.7 Deleting your account
You can delete your Arqor account from the app: Profile & settings → Delete my account. Or email support@arqor.io from the address you sign in with. We confirm by email and delete it within 7 days: your sign-in, your profile and your access to every company you belong to. Photos, time records and other records you made for a company belong to that company, so they stay with it; ask the company if you want any of those removed.
4. Google user data (email client)
If you choose to connect a Gmail mailbox to Arqor, this section explains exactly what we access and what we do with it. Connecting a mailbox is entirely optional — the rest of the Service works without it — and you can disconnect at any time.
4.1 What we access, and why
We request only the permissions the email client genuinely needs. Where one permission already covers several narrower ones, we request the single permission rather than the list, so you are approving one thing rather than four that amount to the same access:
- gmail.modify — to display your mail in Arqor; to read supplier invoices and subcontractor quotes out of their attachments so they can be recorded against the right job; to send and reply from your own address when you choose to; and so that archiving, marking read or unread, starring, binning and filing into folders in Arqor takes effect in Gmail too. This permission does not allow permanent deletion — anything Arqor removes goes to your Bin.
- userinfo.email and userinfo.profile — to identify the connected mailbox and put the correct name on messages you send.
4.2 What we store
We store message headers, message bodies, and copies of attachments in our database so that your inbox, search, and the record of a supplier invoice remain available and fast. OAuth access and refresh tokens are encrypted at rest. We do not store your Google password; we never receive it.
4.3 Automated processing and AI
Some optional features send the content of a message or attachment to our AI provider (Anthropic) to perform a task you have asked for: sorting mail into tabs, summarising a thread, drafting a reply, translating a message, or reading the priced lines off a supplier invoice. That content is processed only to return your result.
Google Workspace API data is not used to develop, improve or train generalised or non-personalised AI or machine-learning models. Arqor does not use Google Workspace API data to train its own models, and our AI provider does not use that data to train its models.
4.4 What we never do
We do not sell Google user data. We do not transfer it to advertisers, data brokers, or for any resale purpose. We do not use it to build advertising profiles. Humans do not read your mail except where you specifically ask our support team to investigate a problem with your own account, or where we are required to by law.
4.5 Deletion
Disconnecting a mailbox in Arqor deletes the stored access and refresh tokens immediately, and deletes Arqor’s synced copy of your mail with them — the messages, their contents and the cached attachments all go. Nothing changes in Gmail itself; we only ever held a mirror.
One thing deliberately survives: a supplier invoice you have confirmed into a job’s costs. At that point it has stopped being a copy of an email and become a business record of money you spent, kept with the job like any other cost, under the retention rules in section 8. Everything not confirmed goes with the mailbox.
You can also revoke Arqor’s access at any time from your Google Account permissions page at myaccount.google.com/permissions. Deleting your Arqor account removes everything above with it, subject to the retention periods in section 8.
4.6 Limited Use
Arqor’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
4A. Microsoft user data (email client)
If you choose to connect an Outlook or Microsoft 365 mailbox to Arqor, this section explains what we access and what we do with it. It works the same way as a Gmail mailbox under section 4, and the same commitments apply. Connecting a mailbox is optional, and you can disconnect at any time.
4A.1 What we access, and why
Arqor acts only as you, on your own mailbox, using these Microsoft permissions:
- Mail.ReadWrite — to display your mail in Arqor; to read attachments so that drawings, supplier invoices and quotes can be recorded against the right job or project; and so that marking read or unread, flagging, archiving, deleting and filing into folders in Arqor takes effect in Outlook too. Deleting in Arqor moves an email to your Deleted Items. The one exception is a draft Arqor saved for you: saving it again replaces the earlier copy, and discarding it removes it.
- Mail.Send — to send and reply from your own address when you choose to. A copy is kept in your Sent Items, as if you had sent it from Outlook.
- User.Read — to identify the connected mailbox and put the correct name on messages you send. Nothing else from your profile is read.
- offline_access — to keep the connection working while you are not signed in, so your email keeps filing to your jobs and projects in the background.
An organisation’s Microsoft 365 administrator can approve Arqor once for everyone in the organisation. That approval does not give Arqor anyone’s mail: a mailbox is only read once the person it belongs to connects it.
4A.2 What we store, and what we never do
We store and protect Microsoft mail exactly as section 4.2 describes for Gmail: messages, their contents and copies of attachments, with access and refresh tokens encrypted at rest. We never receive your Microsoft password. Optional AI features process content only to return the result you asked for, as in section 4.3. Microsoft user data is not used to develop, improve or train AI or machine-learning models, by Arqor or by our AI provider. We do not sell it, pass it to advertisers or data brokers, or use it to build advertising profiles.
4A.3 Deletion
Disconnecting the mailbox in Arqor deletes the stored tokens and Arqor’s synced copy of your mail, with the one exception set out in section 4.5 for a supplier invoice you have confirmed into a job’s costs. Nothing changes in Outlook itself. You can also revoke Arqor’s access at any time: a work or school account at myapps.microsoft.com, and a personal Microsoft account at account.live.com/consent/Manage.
5. How we use your data
We use your personal data for the following purposes:
To provide the Service — storing and displaying your photos, generating share links and PDF reports, authenticating your account, and processing payments.
To communicate with you — sending magic link login emails, billing notifications, trial reminders, and service updates.
To improve the Service — analysing usage patterns to identify bugs, improve performance, and develop new features.
We do not use your data for advertising, profiling, or automated decision-making. We do not sell your data to third parties.
6. Legal basis for processing
We process your personal data on the following legal bases under UK GDPR:
Contract performance (Article 6(1)(b)) — processing necessary to provide the Service you have subscribed to.
Legitimate interests (Article 6(1)(f)) — improving the Service, preventing fraud, and ensuring security.
Legal obligation (Article 6(1)(c)) — where we are required to retain data for tax, accounting, or legal compliance.
7. Who we share data with
We share data with the following third-party processors who help us provide the Service:
Supabase (database, sign-in and file storage) — your data, photos and drawings are stored in London, on Amazon Web Services’ UK region.
Vercel (application hosting and analytics) — the application runs in London. Vercel’s network delivers pages from the location nearest each visitor, and Vercel may process hosting and analytics data in the US.
Stripe (payment processing) — PCI-DSS compliant payment processor.
Resend (email delivery) — sends the Service’s emails, such as sign-in codes and notifications, so it receives each recipient’s address and the message.
AssemblyAI (transcription) — when a voice note or a meeting is recorded, the audio is sent to AssemblyAI to be turned into text, with the job’s and company’s names so it spells them correctly.
Anthropic (AI processing) — where you choose to use an AI-powered feature, the relevant message, document or attachment content is sent to Anthropic’s API solely to perform the task you asked for and return your result. Google Workspace API data is not used to train or improve Anthropic’s models. If you do not use those features, no content is sent.
We also share data when you choose to — for example, when you generate a share link, the recipient can view job photos and associated metadata.
We will disclose personal data if required to do so by law or in response to a valid legal request from a public authority.
8. Data retention
We retain your account data and content for as long as your account is active. After account closure or subscription cancellation, we retain your data for 30 days to allow for reactivation, after which it is permanently deleted.
Payment records are retained for 7 years as required by HMRC for tax purposes.
Waitlist email addresses are retained until the individual subscribes or requests removal.
9. Data security
We implement appropriate technical and organisational measures to protect your personal data, including encryption in transit (TLS 1.2+), encryption at rest, access controls via Row Level Security in our database, and regular security reviews.
However, no method of transmission or storage is 100% secure. We cannot guarantee absolute security of your data.
10. Your rights
Under UK GDPR, you have the following rights:
Right of access — request a copy of your personal data.
Right to rectification — request correction of inaccurate data.
Right to erasure — request deletion of your data (subject to legal retention requirements).
Right to data portability — receive your data in a machine-readable format.
Right to restrict processing — request limitation of how we use your data.
Right to object — object to processing based on legitimate interests.
To exercise any of these rights, contact us at hello@arqor.io. We will respond within 30 days.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk if you believe we have not handled your data appropriately.
11. International transfers
Your data is stored in the UK: in London, with Supabase on Amazon Web Services, and the application runs in London too. Some processing may occur outside the UK: through Vercel (hosting and analytics), Stripe (payments), Resend (email) and AssemblyAI (transcription), and — where you use an AI-powered feature — through Anthropic, whose API may process the submitted content in the United States.
Each of these providers is engaged under a data processing agreement, and transfers outside the UK are made on the basis of the safeguards set out in those agreements. If you want the current detail of the transfer mechanism for a particular provider, contact us at hello@arqor.io and we will tell you.
12. Children
The Service is not intended for use by anyone under 18 years of age. We do not knowingly collect personal data from children.
13. Changes to this policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or through the Service. The date at the top of this policy indicates when it was last updated.
14. Contact
For privacy-related queries, contact:
Arqor Ltd
Company number: 17380863
Registered office: 69 Empingham Road, Stamford, PE9 2SU
ICO registration: ZC223398
Email: hello@arqor.io