PRIVACY

PALM365 Privacy Policy

This policy explains the information PALM365 processes to provide construction project management, administration, collaboration, notifications, imports, exports, and professional networking features.

Last updated:

Controller and audience

PALM365 is operated by Adham Elbaroudi, Doha, Qatar. Privacy and support enquiries can be sent to info@palm365.org.

PALM365 is made and distributed as Adham Elbaroudi's personal activity and is not currently associated with a business entity. The current App Store Digital Services Act self-assessment is non-trader. Reassess promptly if PALM365 becomes connected to trade, business, craft, profession, monetization, or commercial services.

PALM365 is a business/workplace product and is not directed to children. A user must have legal capacity to accept these terms or use PALM365 through an organization that has lawfully authorized the user's access and assumes responsibility for it, subject to applicable law.

Information processed

PALM365 processes information you or an authorized organization provide, information created while teams use the service, and limited device information needed to operate the apps.

  • Account identity and authentication state, including email address, user ID, confirmation, recovery, and session information.
  • Professional profile and contact information, such as name, title, company, discipline, phone numbers, networking code, and business-card details.
  • Company, seat, role, capability, team, party, delegation, invitation, access-review, and audit records.
  • Project content including schedules, WBS, activities, risks, issues, changes, RFIs, letters, submittals, documents, drawings, files, procurement, daily reports, timesheets, comments, decisions, and approvals.
  • Imported XER, XML, XLS, XLSX, and CSV content, associated validation results, version history, and generated export artifacts.
  • Notification preferences, inbox state, push tokens, app variant, device platform/name, and delivery metadata.
  • Subject-scoped offline queues, selected projects, cached summaries, pinned projects, and onboarding state stored on your device.

Why information is used

Information is used to authenticate users, enforce organization and project access, operate requested workflows, preserve project and audit integrity, deliver notifications, support imports and exports, maintain security, and respond to support requests.

PALM365 does not include an advertising SDK, cross-app tracking SDK, or behavioral advertising integration in the reviewed application code.

Services that receive information

Supabase provides Auth, database, Storage, Realtime, and Edge Function paths. Expo, EAS, Expo Push, Apple and APNs may receive build, platform, push-routing, and delivery information when their relevant services are used. Netlify serves the public and web application surfaces. Production processing regions will be stated only after the deployed provider configuration is verified.

When you choose an Outlook compose action, recipient and message fields are handed to Microsoft in a user-directed compose URL. PALM365 does not send that message for you. Support email similarly opens a draft in your selected mail application.

Storage, security, and account separation

Hosted records are protected by database row-level security, organization/project capability checks, and service-only operations where required. Native authentication sessions use platform secure storage; browser sessions use origin-scoped browser storage.

Offline and cached account data is scoped to the authenticated user and is cleared during sign-out or successful account deletion. No system can guarantee absolute security, so users should protect their credentials and report suspected access promptly.

Retention and deletion

Following a valid account-deletion request, PALM365 deletes or disables the applicable Auth identity as the implemented lifecycle permits, revokes active sessions/access tokens, removes device push tokens, and deletes or de-identifies profile information when no longer required. For an ordinary company member, deletion offboards membership, removes the direct invitation identity link, and pseudonymizes retained access-audit linkage. Deletion remains blocked when the user is the last active subscription owner or owns files or business records that require safe transfer.

Project, file, approval, audit, security, offboarded membership, and other customer-controlled business records are retained or pseudonymized only as directed by the customer, required by contract, needed for security, or required by legal and documented construction-record duties; they are deleted or anonymized when no longer necessary. Accepted invitation contact fields are replaced with a non-deliverable alias, and retained membership/audit linkage uses a one-way subject fingerprint rather than the Auth user ID.

Active push tokens are removed promptly after valid deletion. Backup copies expire under the verified provider backup lifecycle; PALM365 does not promise a fixed 90-day maximum until the production backup architecture and regions are technically verified. Support communications and provider diagnostic records are kept only as long as needed for the request, security, legal duties, or the verified provider configuration.

Sale and tracking

PALM365 does not sell personal data and does not use personal data for behavioral advertising, cross-context advertising, or advertising tracking. This statement depends on the production app and business practice continuing to match the reviewed implementation and is rechecked before release attestations.

Your choices and contact

You can update profile and notification settings in the product, sign out to clear local account state, or start authenticated deletion from Settings. If you cannot sign in, use the public account-deletion page or email info@palm365.org.

Requests may require identity verification and may be routed to the organization responsible for the relevant project records.