Legal
Privacy Policy
Effective April 28, 2026
Who we are
Footing is a membership portal for small construction company owners. We provide templates, SOPs, and operational tools through a subscription service. References to "Footing," "we," "us," or "our" refer to Footing and its operators.
Information we collect
We collect the following information when you use Footing:
- Account information:email address, password (stored as a hash), and optional company name and revenue band provided during onboarding.
- Payment information:Stripe handles all payment processing. We store your Stripe customer ID but never your raw card details.
- Usage data:which resources you download, when, and from which plan tier. Stored in our database and used to operate the service.
- Analytics:we use PostHog to track aggregate product usage (page views, download events, upgrade prompts). PostHog collects IP address and device information. You can opt out via your browser's Do Not Track setting.
How we use your information
- To operate your account and provide access to resources
- To process payments and manage your subscription via Stripe
- To send transactional emails (receipts, welcome emails, resource updates) via MailerLite
- To understand how members use the product and improve it
We do not sell your personal data to third parties.
Third-party services
Footing uses the following third-party services, each governed by their own privacy policy:
- Supabasedatabase and file storage (US-based)
- Stripepayment processing
- MailerLitetransactional and marketing email
- PostHogproduct analytics
- Vercelwebsite hosting
Data retention
We retain your account data for as long as your account is active. If you cancel your subscription, your data is retained for 12 months and then deleted, unless you request earlier deletion.
Your rights
You may request access to, correction of, or deletion of your personal data at any time by emailing support@footing.build. We will respond within 30 days.
Cookies
We use cookies to maintain your authentication session (via Supabase Auth) and to enable analytics (via PostHog). Authentication cookies are strictly necessary for the service to function. Analytics cookies are set only after consent is granted.
Security
All data is transmitted over HTTPS. Resource files are stored in a private Supabase Storage bucket and accessed only via short-lived signed URLs (5-minute expiry). We use Row Level Security on all database tables. The Supabase service role key is never exposed to the browser.
Changes to this policy
If we make material changes to this policy, we will notify members by email at least 14 days before the changes take effect.
Contact
Questions about this policy: support@footing.build