Pine Canyon Analytics

Privacy Policy

How Pine Canyon Analytics collects, uses, stores, and protects information.

Privacy Policy

Last Updated: June 21, 2026

Pine Canyon Analytics, LLC (“Pine Canyon Analytics,” “we,” “us,” or “our”) provides business software for creating, managing, exporting, viewing, and signing quotes, proposals, job documents, and related project records.

This Privacy Policy explains how we collect, use, disclose, retain, and protect information when you use our websites, applications, public proposal links, electronic signature pages, portals, and related services (collectively, the “Services”).

This Privacy Policy is intended for users in the United States. The Services are not intended for children under 18.

For privacy questions or requests, contact us at:

logan@pinecanyonanalytics.com

1. How Our Services Work

Our Services are used by companies and their authorized users to manage quotes, proposals, projects, documents, and related customer records. Those companies may enter information about their customers, homeowners, businesses, projects, jobs, contacts, installers, project managers, sales representatives, and other people.

When a company uses the Services to enter, upload, generate, export, share, or sign documents, Pine Canyon Analytics generally processes that information on behalf of that company so we can provide the Services. If you are an end customer, homeowner, signer, or contact whose information was entered by a company using the Services, that company is usually the primary party responsible for the relationship with you and for deciding what information is entered into the Services.

2. Information We Collect

We collect information in several ways: information you provide directly, information entered by companies using the Services, information generated by the Services, information collected automatically for security and operation, and information received from service providers.

Account and Company Information

We may collect and store:

  • Company name
  • Owner name and email
  • Member names, emails, roles, permissions, positions, and phone numbers
  • Company settings, profiles, branding, colors, logos, addresses, proposal language, and other configuration settings
  • Login and authentication information
  • Subscription plan, billing status, Stripe customer IDs, Stripe subscription IDs, and related billing metadata

We do not store full payment card numbers. Payment processing is handled by Stripe.

Login and Authentication Information

We may collect and process:

  • Email address
  • Password authentication data
  • Password hashes
  • Password reset token hashes
  • Invite or access token hashes
  • Google account authentication information, such as Google account identifier, name, and email, when Google sign-in is used
  • Login status, account status, and role/permission data

Quote, Customer, Contact, and Job Information

Companies using the Services may enter or generate information such as:

  • Customer names
  • Business names
  • Customer emails and phone numbers
  • Job addresses and billing addresses
  • Quote and proposal data
  • Products, services, quantities, dimensions, prices, fees, taxes, discounts, notes, and totals
  • Lead source, sales representative, project manager, installer, and ordering information
  • Contact records and contact history
  • Job status, job records, checklists, installer actions, and project notes
  • Change orders and quote history

This information is controlled by the company using the Services.

Files, Uploads, and Generated Documents

The Services may store files and documents, including:

  • Company logos
  • Quote attachments
  • Imported PDFs
  • Generated proposal PDFs
  • Generated cut sheet PDFs
  • Signed proposal PDFs
  • Signed cut sheet PDFs
  • Change-order PDFs
  • Job files
  • Photos
  • Installer uploads
  • Project or supporting documents

Generated/exported PDFs are permanent records in the Services and cannot be deleted through the app.

Electronic Signature Information

When a proposal is signed electronically, we may collect and store evidence related to that signature, including:

  • Signer typed name
  • Drawn or electronic signature image
  • Signature date and time
  • Proposal option selected
  • Electronic signature consent text and consent version
  • Quote, proposal, and signed-document metadata
  • Document hashes and signature hashes
  • Frozen quote/proposal snapshots
  • Related signed PDF records
  • IP address or forwarded IP information
  • Browser, device, user-agent, language, origin, and referrer information
  • Audit and event metadata related to signing

The public signing form does not require the signer to provide an email address. However, the quote record may contain customer contact information entered by the company using the Services, and our backend may store optional signer contact details if provided through a workflow or record.

Electronic signature evidence may be retained permanently for business records, audit, legal, dispute, and document-integrity purposes.

Public Proposal and Document Link Information

Companies may create public-by-link proposal, signing, signed proposal, cut sheet, or attachment links. Anyone with a valid public-by-link document URL may be able to view or download the document or selected customer-facing attachments until access is revoked, removed, or otherwise disabled.

Public-by-link document pages are not intended to be indexed by search engines, and we use technical measures such as noindex headers and rate limiting on public document routes. However, noindex is not a security feature. Anyone with the link may still be able to access the document unless the link has been revoked or access has been removed.

We may log document views, signing events, access events, and related metadata for audit, support, security, and dispute-history purposes.

Automatically Collected Technical Information

We may automatically collect:

  • IP address
  • User agent
  • Browser and device information
  • Referrer and origin headers
  • Access times
  • Authentication/session status
  • Security and operational logs
  • API request metadata
  • Error, debugging, and diagnostic information
  • Rate-limit and abuse-prevention data

We use this information to operate, secure, troubleshoot, and improve the reliability of the Services.

Sensitive Information

We do not intentionally collect Social Security numbers, driver’s license numbers, dates of birth, health records, bank account numbers, payroll records, background checks, or similar highly sensitive personal information.

However, users may upload or enter files that contain sensitive project information, such as floor plans, building layouts, school or business security details, contracts, signatures, photos, faces, license plates, or similar information. Users should not upload highly sensitive information unless it is necessary, authorized, and appropriate for the project.

3. How We Use Information

We use information to:

  • Provide, operate, and maintain the Services
  • Create, save, export, and manage quotes, proposals, jobs, documents, and signed records
  • Authenticate users and manage accounts
  • Enforce company-level access controls, permissions, and seat limits
  • Process subscriptions and billing
  • Provide support and debugging
  • Investigate errors, security issues, abuse, fraud, or misuse
  • Maintain audit, contact, signing, and document-history records
  • Send transactional emails, such as account, billing, password reset, or service-related messages
  • Comply with legal, tax, accounting, billing, audit, dispute, and security obligations
  • Protect the rights, safety, property, and integrity of Pine Canyon Analytics, our users, our customers, and others

We do not use identifiable customer quote, job, contact, or signer data for product improvement, advertising, or marketing profiling.

We may use aggregated or de-identified information to understand usage, improve reliability, monitor product performance, and make business decisions, provided that the information does not identify a specific person or company.

4. Support Access and Manual Review

We do not casually browse customer data. We may manually access quotes, PDFs, files, logs, account records, or customer data only when necessary for support, debugging, security, legal, compliance, billing, service operation, or dispute-resolution purposes.

5. How We Share Information

We do not sell personal information.

We do not share personal information for cross-context behavioral advertising.

We do not use sensitive personal information to infer characteristics about people.

We may disclose information as described below.

Service Providers

We use service providers to operate the Services, including:

  • Microsoft Azure for hosting, servers, databases, file/blob storage, email infrastructure, and related cloud services
  • Stripe for billing, subscriptions, checkout, payment processing, invoices, and related billing services
  • Google for Google authentication/sign-in where enabled
  • Technical software libraries, infrastructure, and tools used to operate, secure, display, or maintain the Services

Some authenticated or internal file operations may use temporary Azure access URLs. Current public proposal and signed-document flows are intended to route document access through backend public document routes rather than exposing raw storage links as the primary public access method.

Companies and Authorized Users

Information entered by a company may be available to that company’s owner, admins, members, project managers, installers, salespeople, ordering users, or other authorized users according to the company’s permissions and configuration.

Public-by-Link Recipients

If a company creates or shares a public proposal, signing, signed proposal, cut sheet, or customer-facing attachment link, anyone with the link may be able to access the linked materials until access is revoked, removed, or otherwise disabled.

Legal, Safety, and Business Transfers

We may disclose information when we believe it is necessary to:

  • Comply with law, legal process, or government requests
  • Enforce our agreements
  • Protect the security or integrity of the Services
  • Prevent fraud, abuse, or misuse
  • Protect rights, property, safety, or legal interests
  • Resolve disputes
  • Support a merger, acquisition, financing, reorganization, sale of assets, or similar business transaction

6. Cookies, Browser Storage, and Tracking

We do not currently use marketing cookies, retargeting cookies, or behavioral advertising cookies.

The Services may use browser storage, tokens, or similar technical methods to keep users signed in, maintain app state, secure sessions, and operate the Services.

We do not currently use third-party analytics or advertising tracking tools.

7. Emails

We currently send transactional or service-related emails only. These may include account, password reset, billing, subscription, support, or service-operation messages.

We do not currently send marketing newsletters or promotional email campaigns.

8. Data Retention

We retain information for as long as reasonably necessary for the purposes described in this Privacy Policy, including providing the Services, maintaining records, complying with legal obligations, resolving disputes, enforcing agreements, protecting security, and preserving document integrity.

Different types of information are retained differently:

  • Account and company records may be retained while the account is active and after termination as needed for business, billing, legal, audit, dispute, security, and recordkeeping purposes.
  • Members removed from a company may be retained as inactive records and are not permitted to log in.
  • Draft quotes may be deleted where the app supports deletion.
  • Exported/generated PDFs cannot be deleted through the app. This includes proposal PDFs, cut sheet PDFs, signed proposal PDFs, signed cut sheets, change-order PDFs, public proposal documents, and related export records.
  • Electronic signature evidence may be retained permanently for business records, audit, legal, dispute, and document-integrity purposes.
  • Quote history, change-order history, contact logs, job logs, document logs, and audit records may be retained long-term or permanently where needed for business, legal, audit, security, billing, dispute, or document-integrity purposes.
  • Billing and Stripe-related records may be retained as needed for tax, accounting, billing, legal, and fraud-prevention purposes.
  • Job files, photos, quote attachments, and other uploaded supporting files may be removable where the app supports deletion, but deletion of supporting files does not delete exported/generated PDFs, signed records, signature evidence, or related audit records.
  • Security and operational logs may be retained as long as reasonably necessary for security, debugging, audit, abuse-prevention, legal, and business purposes.

We may also retain information in backups, archives, and system logs for a limited or extended period depending on technical, legal, security, and business needs.

9. Deletion Requests and Limitations

You may request deletion of personal information by contacting us at logan@pinecanyonanalytics.com.

Deletion may not be available or complete where information must be retained for legal, billing, tax, accounting, audit, security, fraud-prevention, dispute, backup, business-record, or document-integrity purposes.

Exported/generated PDFs, signed PDFs, signature records, quote history, signing evidence, document audit logs, and related records may be retained permanently and may not be deleted through the app.

If you are an end customer, homeowner, signer, or contact whose information was entered by a company using the Services, you should first contact the company that created the quote, proposal, job, or document. We may direct your request to that company or require that the company authorize deletion, correction, or access where the company controls the relevant data.

10. Your Privacy Choices and Rights

Depending on where you live and which privacy laws apply, you may have rights to:

  • Request access to personal information
  • Request correction of inaccurate personal information
  • Request deletion of personal information
  • Request a copy or export of personal information
  • Object to or restrict certain processing
  • Opt out of sale or sharing of personal information
  • Limit the use of sensitive personal information
  • Not be discriminated against for exercising privacy rights

We do not sell personal information. We do not share personal information for cross-context behavioral advertising.

To make a request, contact logan@pinecanyonanalytics.com. We may need to verify your identity and your authority to make the request. We will respond within the time required by applicable law.

Some requests may need to be submitted to the company that entered your information into the Services, especially where Pine Canyon Analytics acts as a service provider processing data on that company’s behalf.

11. Security

We use reasonable administrative, technical, and organizational safeguards designed to protect information. These safeguards may include HTTPS, Azure-hosted infrastructure, account authentication, password hashing, role-based permissions, company-level access controls, token hashing, public document rate limiting, noindex headers for public document routes, and other technical and operational controls.

No system is 100% secure. We cannot guarantee that information will never be accessed, disclosed, altered, lost, or destroyed.

You are responsible for keeping your login credentials secure, limiting access to authorized users, managing company permissions, and sharing public document links carefully.

12. Third-Party Services

The Services may link to or interact with third-party services, such as Stripe for billing and Google for authentication. Third-party services may process information under their own privacy policies and terms.

We are not responsible for the privacy practices of third-party websites, platforms, or services that we do not control.

13. International Use

The Services are intended for use in the United States. If you access the Services from outside the United States, you understand that information may be processed and stored in the United States or other locations where our service providers operate.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we update it, we will revise the “Last Updated” date above. Changes are effective when posted unless otherwise stated.

Your continued use of the Services after an updated Privacy Policy is posted means you acknowledge the updated policy.

15. Contact

For privacy questions or requests, contact:

Pine Canyon Analytics, LLC Email: logan@pinecanyonanalytics.com