Legal
Privacy Policy
Last updated: September 11, 2026
CM360 (“Construction Manager 360”, “we”, “us”, or “our”) provides a construction management platform for businesses and teams. This Privacy Policy explains how we collect, use, store, and protect information when you use the CM360 website, web application, mobile applications, and related support services.
1. Introduction
CM360 helps authorized users manage construction-business records inside a company workspace, including:
- companies / workspaces
- projects
- clients
- vendors
- sub-contractors
- labour (site workers), attendance, and payroll
- temporary labour entries
- employees and salary payments
- project expenses and office expenses
- payments (client, contractor, labour, and related ledgers)
- personal “My Day” tasks
- reports and financial summaries
- team invitations, memberships, and role-based access
- subscription status for workspace access
CM360 is a business product for construction teams. It is not directed to children (see Section 14).
For privacy or data requests, contact Privacy and Support: support@cm360.site.
You may also use in-app Contact Support (email, and WhatsApp or phone when available).
2. Information We Collect
CM360 processes information that you (or your company administrators) provide, and technical information needed to operate accounts securely.
2.1 Account and profile information
When you create or use a CM360 account, we process:
- full name
- email address
- phone number (optional on profile)
- authentication credentials (your password is handled by our authentication provider and is not stored in readable form in CM360 business records)
- account and session identifiers needed to keep you signed in
Profile email is tied to authentication and is shown in My Profile. Name and phone can be updated in-app.
2.2 Company / workspace information
Company owners and authorized members may store:
- company name and optional legal name
- tax ID
- company phone, email, and address
- country and currency settings
- company image / logo
- subscription-related workspace status
2.3 Business contact and workforce records
Depending on modules your company uses, authorized users may enter:
| Category | Examples of data stored |
|---|---|
| Clients | name, phone, email, address, national ID / CNIC, notes, agreement files |
| Vendors | name, phone, email, address, national ID / CNIC, supply types, notes |
| Sub-contractors | name, phone, email, address, national ID / CNIC, notes, contract details, agreement files |
| Employees | name, phone, email, national ID / CNIC, designation, department, joining date, status, monthly salary, notes |
| Site labour | name, phone, national ID / CNIC, address, daily rate, status, notes |
| Temporary labour | worker counts, rates, totals, and notes (not individual worker identity records) |
2.4 Project, financial, and operational records
Authorized users may create and manage:
- projects (name, description, location, contract amounts, dates, status, cover image, agreements)
- attendance records (dates, status, overtime, rate snapshots, notes)
- expenses and office expenses (amounts, dates, methods, references, notes, verification details)
- payment records (amounts, dates, payment methods, reference numbers, notes, settlement periods where applicable)
- salary payment breakdowns (salary month/year, amounts, bonus, allowance, deduction, net paid)
- personal tasks (titles, due dates/times, optional reminders, notes, related record links)
- uploaded files such as receipts, bills, payment proofs, agreements, and images
Banking and payment content:
CM360 does not provide in-app card checkout for CM360 subscription billing. However, users may enter payment methods, reference numbers, and notes, and may upload payment proofs, receipts, or documents that include bank transfer screenshots, cheque images, or other payment details. Where that content is entered or uploaded, CM360 processes it as part of the company’s business records.
2.5 Invitations and team access
When inviting teammates, CM360 processes invitation emails, assigned roles, invitation status and expiry, and related invitation details needed to complete the invite.
2.6 Support communications
If you contact support (email, WhatsApp, or phone), we process the information you send. This may include your account email, company name, device or platform, and app version when those details are included to help resolve your request.
2.7 Technical and authentication data
To provide secure sign-in and operate the service, CM360 and its infrastructure providers process technical data such as:
- authentication session tokens
- account verification and password-recovery codes (one-time codes delivered by email)
- security and audit event records related to account and company activity
- standard hosting and security logs maintained by infrastructure providers
3. How We Use Information
We use information to:
- Create and authenticate accounts — sign-up, sign-in, email verification, password recovery, invitations, and session management.
- Provide construction-management features — store and display the business records your company enters.
- Calculate summaries and reports — generate dashboards, balances, payroll/attendance views, and similar operational calculations.
- Enforce roles and permissions — limit what each company member can see or change based on assigned roles (for example Owner, Accountant, Supervisor, Purchase Manager, or Viewer).
- Store and retrieve files — accept uploads of bills, proofs, agreements, and images and make them available to authorized users.
- Manage subscriptions — track plan status and manually recorded subscription payments so workspace access can be controlled.
- Provide support — respond to help, access, billing, and deletion requests.
- Protect the service — maintain audit history, investigate abuse or incidents, and operate necessary platform maintenance.
- Comply with legal obligations — retain limited records when required for security, disputes, accounting, or law.
We do not sell personal information.
4. Company Workspaces and Authorized Access
CM360 is organized around company workspaces.
- Data entered for a company belongs to that company’s workspace.
- Members of the same company can access information according to their assigned roles and permissions.
- Different customer companies cannot access each other’s workspaces through normal product use.
- Company Owners and administrators control invitations and membership for their workspace.
- A limited number of CM360 platform administrators may have elevated access for platform support, subscription management, security, and authorized deletion operations. This access is restricted and intended for operating the platform—not for routine browsing of customer business data.
Your company’s administrators are responsible for entering accurate records and for granting appropriate staff access.
5. Files and Documents
Authorized users may upload files such as:
- expense receipts and bills
- office-expense bills
- client, project, and contractor agreements
- payment proofs (client, contractor, salary, and similar)
- company and project images
These files are stored in private storage and made available to authorized users through authenticated, time-limited access. They are not published as open public links.
Uploaded documents may contain personal or financial details, including payment screenshots. Treat uploads as company business records and share access only with trusted team members.
6. Authentication and Security
Authentication
CM360 uses secure cloud authentication to protect accounts. Current sign-in options include:
- email and password registration and sign-in
- email one-time codes for signup verification
- email one-time codes for password recovery, followed by setting a new password
- invitation acceptance using email one-time codes, then joining the invited company
- signed-in sessions that remain active until you sign out or the session ends
Passwords are managed through our authentication provider. After a successful password reset, you are signed out so you can sign in again with your new password.
Security measures
We apply controls intended to protect accounts and company data, including:
- authenticated access requirements
- company isolation between workspaces
- role-based permissions inside a company
- private file storage with signed access
- encrypted transport (HTTPS) for app and website traffic
- audit logging of relevant security and administrative actions
No method of transmission or storage is completely secure. We work to protect information, but we cannot guarantee absolute security.
7. Subscriptions and Billing
CM360 subscription access is managed as a manual subscription record for each company, including:
- plan assignment and subscription status (for example trialing, active, inactive, and related statuses)
- subscription start/end or trial dates where applicable
- manually recorded subscription payment entries (amount, payment date, and optional note), typically verified outside the app
There is no in-app card checkout for CM360 subscriptions.
Ending or changing subscription access does not by itself delete your user account, memberships, or company business records. Account or company deletion must be requested separately. See Account and Company Deletion.
8. Service Providers
CM360 uses trusted service providers to host and operate the product. Providers that may process relevant information include:
| Provider / channel | Role |
|---|---|
| Supabase | Authentication, database, file storage, and related backend services used to run CM360 |
| Vercel | Hosting for the public website (cm360.site) |
| Transactional email service providers | Sending verification, invitation, password-recovery, and other service-related emails |
| Support channels (email, WhatsApp, phone) | Customer support communications when those channels are available |
These providers process information only as needed to deliver their services to CM360.
We do not use an in-app SaaS card payment processor for CM360 subscription checkout.
9. Data Retention
How long information is kept depends on whether a workspace is active, whether records have been removed inside an active workspace, and whether an account or company deletion request has been completed.
Active company data
While your company workspace is active, operational records you create generally remain available to authorized members so the business can continue using CM360.
Records removed inside an active workspace
Certain records removed from an active workspace may remain in a restricted or soft-deleted state while the workspace remains active, including where needed for record integrity, security, or business continuity. This is not the same as account or company deletion.
Account deletion and company closure
Specific timelines for account deletion and company operational purge are described in Account and Company Deletion, including the 14-day cancellation period and eligibility for permanent purge 7 days after company closure.
Audit and billing records
Limited audit history and subscription or billing records may be retained after account or company deletion for security, accounting, dispute, and integrity purposes. See Information We May Retain.
Backups
Deletion from CM360’s active system is separate from copies that may exist in infrastructure backups. Backup copies may remain until the normal backup-retention cycles of our infrastructure providers expire. We do not promise that backup copies are deleted within 7 days.
10. Account and Company Deletion
You can learn about deletion and start the process from:
- In-app: My Profile → Account → Delete Account
- Public help page: https://cm360.site/delete-account
If you cannot sign in, email support@cm360.site for assistance.
10.1 Normal company member (personal account deletion)
If you do not own a live company workspace, you can request deletion of your personal CM360 account.
After finalization:
- your CM360 login is removed
- your personal profile information is deleted or anonymized
- your company memberships and personal CM360 tasks are removed
- business records that belong to companies you worked with remain with those companies where appropriate
10.2 Company Owner (Delete Company & Account)
An Owner cannot delete only their personal account while leaving an ownerless live company.
An eligible Owner may request Delete Company & Account, which schedules deletion of:
- the Owner’s CM360 account, and
- the company workspace
If other members belong to that company, they lose access when the company is closed.
If an Owner currently owns more than one live company, self-serve deletion may be unavailable until ownership is resolved. Support can help.
10.3 14-day cancellation period
When you confirm a deletion request:
- the request remains pending for a 14-day cancellation period
- you can continue using CM360 during that period
- you can cancel the pending request from My Profile while it remains pending
After the request is finalized, CM360 does not provide a normal self-service restoration process.
10.4 What happens when company deletion is finalized
When an Owner’s company-and-account request is finalized:
- the company workspace is closed
- members lose access
- company files and operational data enter CM360’s deletion process
- the Owner’s login and profile are removed or anonymized as described above
10.5 Company operational purge (7 days after closure)
After the company is closed, remaining company operational data becomes eligible for permanent purge 7 days after closure.
CM360’s authorized deletion process permanently removes eligible operational data and associated files from the active system. When completed:
- a minimal anonymized company record may remain for audit, billing, and integrity purposes
- limited scrubbed audit and billing information may remain (see Section 11)
This additional period is an eligibility window for permanent removal. It is not a second customer cancellation period.
10.6 Subscription cancellation is not account deletion
Subscription cancellation is separate from account and company deletion. See Section 7, Subscriptions and Billing.
11. Information We May Retain
After account and/or company deletion is finalized and eligible operational data is purged, CM360 may retain limited information such as:
- anonymized profile or company records needed for integrity of historical references
- scrubbed audit records (with identifying detail removed or reduced where the deletion process applies)
- subscription and subscription-payment records needed for billing, accounting, or dispute handling
- other limited information required for security, fraud prevention, legal claims, or compliance
Where practical, identifying details are removed or anonymized. Retention of these limited records is not the same as keeping your full operational company workspace available in the product.
12. International Processing
CM360 uses cloud service providers that may process or store information in countries other than the country where you are located. If you access CM360 from another country, your information may be processed outside that country.
13. Your Rights and Choices
Depending on how you use CM360, you can:
- update profile details in My Profile (name and phone)
- reset your password using the forgot-password / email verification flow
- ask your company Owner or administrator to correct or remove business records they control inside the workspace
- request account deletion (and company deletion, if you are an eligible Owner) from My Profile → Account → Delete Account
- cancel a pending deletion request during the 14-day pending window
- contact Privacy and Support at support@cm360.site if you need help with access, correction, or deletion
14. Children's Privacy
CM360 is a business construction-management service and is not directed to children. We do not knowingly collect personal information from children for CM360 accounts. If you believe a child has created an account, contact us and we will take appropriate steps.
15. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date at the top of this page. Material changes may also be communicated through the website, app, or email where appropriate.
16. Contact Us
CM360 / Construction Manager 360
- Website: https://cm360.site
- App: https://app.cm360.site
- Account deletion help: https://cm360.site/delete-account
- Privacy and Support: support@cm360.site
You may also use in-app Contact Support (email, WhatsApp, or phone when available).