Effective: April 28, 2026
Breche (“we,” “us,” or “our”) operates the construction management platform at breche.us. This Privacy Policy explains what personal information we collect, how we use it, and the choices you have. By using Breche, you agree to the practices described below.
When you create an account, we collect your first name, last name, email address, company name, and a password (stored as a cryptographic hash—we never store plaintext passwords). You also select a subscription plan at signup.
You create and store business content within Breche, including contacts, leads, projects, estimates, proposals, invoices, expenses, work orders, service contracts, documents, photos, and notes. This data is stored in your company’s isolated tenant and is not shared with other companies.
When you share proposals or invoices with your clients through Breche’s portal, those clients access documents via unique token links. No account is created for portal viewers. We may collect their name and email address if you provide it for signing or communication purposes.
Subscription billing is handled by Stripe. Breche never receives, processes, or stores your credit card number or bank account details. Payment data is governed by Stripe’s Privacy Policy.
With your consent, we collect anonymous usage analytics (page views, feature usage) through Vercel Analytics and Vercel Speed Insights. These help us understand how the product is used and where to improve performance. You can opt out via our cookie consent banner.
We use Sentry for error monitoring. When an error occurs, Sentry may capture technical information including the error message, stack trace, browser type, and breadcrumbs (recent user actions leading to the error). This data is used solely to diagnose and fix bugs. Session replays are only captured when an error occurs.
Our hosting infrastructure (Vercel) automatically collects standard server log information including IP addresses, browser type, device type, and referring URLs. This data is used for security, abuse prevention, and service operation.
We use the Google Maps Platform for address autocomplete. When you type an address, your query is sent to Google to return suggestions. This is governed by Google’s Privacy Policy.
We share data with the following third-party services solely to operate Breche. We do not sell your data to anyone.
| Service | Purpose | Data Shared |
|---|---|---|
| Supabase | Authentication, database, file storage | Account data, business data, uploaded files |
| Stripe | Payment processing | Email, plan selection, billing events |
| Resend | Transactional email | Recipient email, message content |
| Vercel | Hosting, analytics, speed insights | Anonymous page view data (with consent) |
| Sentry | Error monitoring | Error details, browser info, breadcrumbs |
| Google Maps | Address autocomplete | Address search queries |
Supabase sets session cookies to keep you logged in. These are strictly necessary for the service to function and cannot be disabled.
Vercel Analytics and Speed Insights collect anonymous performance data. These are only loaded after you give consent via the cookie banner that appears on your first visit. You can change your preference at any time by clearing your browser’s local storage for breche.us.
Sentry operates under our legitimate interest in maintaining a stable, bug-free service. It captures error data automatically to help us fix issues quickly. Sentry does not track you across websites and does not set marketing cookies.
We protect your data with industry-standard security measures, including:
While no method of transmission or storage is 100% secure, we continuously review and improve our security practices.
You have the right to:
To exercise any of these rights, contact us at info@breche.us or use the built-in Privacy & Data Tools available to company administrators at Settings → Privacy & Data.
If you are a client accessing proposals, invoices, or contracts through a Breche portal link, please note:
Breche is not directed at children under the age of 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us and we will promptly delete it.
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Effective” date at the top of this page and, where appropriate, notify you via email or an in-app notice. Your continued use of Breche after changes are posted constitutes acceptance of the updated policy.
The Breche mobile app for iOS and Android collects everything described above plus a few mobile-specific data types, all used solely to deliver the field-worker features.
The app records GPS coordinates only when you clock in and clock out. We do not run continuous background location tracking. Each clock event stores latitude, longitude, accuracy, and a reverse-geocoded address so admins can verify on-site presence. The app never requests “Always” location access.
You can attach photos to projects, work orders, and bid requests. Photos go directly to your company’s Supabase storage bucket and are not shared with any third party. Photos are compressed before upload.
On launch, after you grant notification permission, the app registers an Expo push token with the Breche backend so we can send notifications about messages, task assignments, invoice events, and dispatch alerts. Push delivery is performed through Expo’s push service, which forwards via Apple Push Notification Service and Firebase Cloud Messaging. Tokens are removed when you sign out.
If you enable Face ID, Touch ID, or fingerprint login, the app uses your device’s secure enclave to gate access to the locally-stored Supabase session token. The biometric data itself never leaves your device — we don’t see it and it isn’t transmitted. Session tokens at rest are stored in iOS Keychain or Android Keystore.
When you take an action without network, it is queued on-device and replayed when you reconnect. The queue is stored in app file storage and is wiped when you sign out. No third party can read it.
NSLocationWhenInUseUsageDescription (clock in/out GPS verification), NSCameraUsageDescription (job site photos), NSPhotoLibraryUsageDescription (attach existing photos), NSFaceIDUsageDescription (quick, secure login).
ACCESS_FINE_LOCATION, ACCESS_COARSE_LOCATION (clock in/out GPS), CAMERA (job site photos), READ_EXTERNAL_STORAGE (attach existing photos), RECEIVE_BOOT_COMPLETED, FOREGROUND_SERVICE (push notification delivery).
The mobile app uses Sentry, the same error-monitoring vendor as the web platform (see Section 4). When an error occurs, Sentry receives the error message, stack trace, OS version, app version, and breadcrumbs of recent user actions, used solely to diagnose and fix bugs.
If you have questions about this Privacy Policy or your data, contact us at:
Breche (La Breche Co LLC)
Email: info@breche.us