← Back to Home

Privacy Policy

Effective: April 28, 2026

1. Introduction

Breche (“we,” “us,” or “our”) operates the construction management platform at breche.us. This Privacy Policy explains what personal information we collect, how we use it, and the choices you have. By using Breche, you agree to the practices described below.

2. Information We Collect

Account Information

When you create an account, we collect your first name, last name, email address, company name, and a password (stored as a cryptographic hash—we never store plaintext passwords). You also select a subscription plan at signup.

Business Data

You create and store business content within Breche, including contacts, leads, projects, estimates, proposals, invoices, expenses, work orders, service contracts, documents, photos, and notes. This data is stored in your company’s isolated tenant and is not shared with other companies.

Client Portal Data

When you share proposals or invoices with your clients through Breche’s portal, those clients access documents via unique token links. No account is created for portal viewers. We may collect their name and email address if you provide it for signing or communication purposes.

Payment Information

Subscription billing is handled by Stripe. Breche never receives, processes, or stores your credit card number or bank account details. Payment data is governed by Stripe’s Privacy Policy.

Usage Data

With your consent, we collect anonymous usage analytics (page views, feature usage) through Vercel Analytics and Vercel Speed Insights. These help us understand how the product is used and where to improve performance. You can opt out via our cookie consent banner.

Error & Performance Data

We use Sentry for error monitoring. When an error occurs, Sentry may capture technical information including the error message, stack trace, browser type, and breadcrumbs (recent user actions leading to the error). This data is used solely to diagnose and fix bugs. Session replays are only captured when an error occurs.

Technical Data

Our hosting infrastructure (Vercel) automatically collects standard server log information including IP addresses, browser type, device type, and referring URLs. This data is used for security, abuse prevention, and service operation.

Address Data

We use the Google Maps Platform for address autocomplete. When you type an address, your query is sent to Google to return suggestions. This is governed by Google’s Privacy Policy.

3. How We Use Your Information

  • Service Delivery — To operate, maintain, and improve Breche.
  • Authentication & Security — To verify your identity and protect your account.
  • Billing — To manage subscriptions and process payments through Stripe.
  • Transactional Email — To send proposals, invoices, notifications, and password resets via Resend.
  • Error Monitoring — To detect, diagnose, and fix bugs using Sentry.
  • Product Improvement — To understand usage patterns and improve features (with your consent for analytics).
  • Customer Support — To respond to your questions and requests.

4. Third-Party Services

We share data with the following third-party services solely to operate Breche. We do not sell your data to anyone.

ServicePurposeData Shared
SupabaseAuthentication, database, file storageAccount data, business data, uploaded files
StripePayment processingEmail, plan selection, billing events
ResendTransactional emailRecipient email, message content
VercelHosting, analytics, speed insightsAnonymous page view data (with consent)
SentryError monitoringError details, browser info, breadcrumbs
Google MapsAddress autocompleteAddress search queries

5. Cookies & Tracking

Essential Cookies

Supabase sets session cookies to keep you logged in. These are strictly necessary for the service to function and cannot be disabled.

Analytics Cookies

Vercel Analytics and Speed Insights collect anonymous performance data. These are only loaded after you give consent via the cookie banner that appears on your first visit. You can change your preference at any time by clearing your browser’s local storage for breche.us.

Error Monitoring

Sentry operates under our legitimate interest in maintaining a stable, bug-free service. It captures error data automatically to help us fix issues quickly. Sentry does not track you across websites and does not set marketing cookies.

6. Data Retention

  • Your data is retained for as long as your account is active.
  • If you cancel your subscription, your data is retained for 30 days to allow you to reactivate or export. After 30 days, data is permanently deleted.
  • You may request immediate deletion at any time (see “Your Rights” below).
  • Anonymized data (with all personal identifiers removed) may be retained for aggregate analytics.

7. Data Security

We protect your data with industry-standard security measures, including:

  • All data transmitted over HTTPS/TLS encryption
  • HTTP Strict Transport Security (HSTS) with a two-year max-age
  • Row-level security (RLS) ensuring each company can only access its own data
  • Passwords hashed using bcrypt via Supabase Auth
  • Optional multi-factor authentication (MFA/2FA) for all users
  • Security headers: X-Content-Type-Options, X-Frame-Options (DENY), strict Referrer-Policy, Permissions-Policy
  • Rate limiting on all authentication and public endpoints

While no method of transmission or storage is 100% secure, we continuously review and improve our security practices.

8. Your Rights

You have the right to:

  • Access — Request a copy of all personal data we hold about you.
  • Export — Download your data in a portable format. Company administrators can use the Privacy & Data Tools in Settings to export contact data.
  • Correction — Update or correct inaccurate personal information through your account settings.
  • Deletion — Request deletion of your personal data. Administrators can anonymize contact records using the Privacy & Data Tools. For full account deletion, contact us.
  • Withdraw Consent — Opt out of analytics cookies at any time by clearing your local storage or rejecting cookies when the banner reappears.

To exercise any of these rights, contact us at info@breche.us or use the built-in Privacy & Data Tools available to company administrators at Settings → Privacy & Data.

9. Client Portal Users

If you are a client accessing proposals, invoices, or contracts through a Breche portal link, please note:

  • You access documents via a unique, time-limited token link. No account or password is required.
  • Your name and email may be stored if the Breche user who sent you the document provided them.
  • Standard technical data (IP address, browser type) is collected by our hosting infrastructure.
  • If you sign a proposal or contract through the portal, your signature, name, email, and the signing timestamp are recorded.
  • To request access to or deletion of your data, contact the company that sent you the portal link or email us at info@breche.us.

10. Children’s Privacy

Breche is not directed at children under the age of 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us and we will promptly delete it.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the “Effective” date at the top of this page and, where appropriate, notify you via email or an in-app notice. Your continued use of Breche after changes are posted constitutes acceptance of the updated policy.

12. Mobile App

The Breche mobile app for iOS and Android collects everything described above plus a few mobile-specific data types, all used solely to deliver the field-worker features.

Location (GPS)

The app records GPS coordinates only when you clock in and clock out. We do not run continuous background location tracking. Each clock event stores latitude, longitude, accuracy, and a reverse-geocoded address so admins can verify on-site presence. The app never requests “Always” location access.

Camera & Photo Library

You can attach photos to projects, work orders, and bid requests. Photos go directly to your company’s Supabase storage bucket and are not shared with any third party. Photos are compressed before upload.

Push Notifications

On launch, after you grant notification permission, the app registers an Expo push token with the Breche backend so we can send notifications about messages, task assignments, invoice events, and dispatch alerts. Push delivery is performed through Expo’s push service, which forwards via Apple Push Notification Service and Firebase Cloud Messaging. Tokens are removed when you sign out.

Biometric Authentication

If you enable Face ID, Touch ID, or fingerprint login, the app uses your device’s secure enclave to gate access to the locally-stored Supabase session token. The biometric data itself never leaves your device — we don’t see it and it isn’t transmitted. Session tokens at rest are stored in iOS Keychain or Android Keystore.

Offline Queue

When you take an action without network, it is queued on-device and replayed when you reconnect. The queue is stored in app file storage and is wiped when you sign out. No third party can read it.

What the mobile app does NOT do

  • No continuous background location tracking
  • No collection of contacts, calendars, microphone, or motion data
  • No third-party advertising SDKs
  • No sale or sharing of data with advertisers or data brokers
  • No cross-app tracking (no IDFA / ATTrackingTransparency on iOS)

iOS permissions

NSLocationWhenInUseUsageDescription (clock in/out GPS verification), NSCameraUsageDescription (job site photos), NSPhotoLibraryUsageDescription (attach existing photos), NSFaceIDUsageDescription (quick, secure login).

Android permissions

ACCESS_FINE_LOCATION, ACCESS_COARSE_LOCATION (clock in/out GPS), CAMERA (job site photos), READ_EXTERNAL_STORAGE (attach existing photos), RECEIVE_BOOT_COMPLETED, FOREGROUND_SERVICE (push notification delivery).

Crash diagnostics

The mobile app uses Sentry, the same error-monitoring vendor as the web platform (see Section 4). When an error occurs, Sentry receives the error message, stack trace, OS version, app version, and breadcrumbs of recent user actions, used solely to diagnose and fix bugs.

13. Contact Us

If you have questions about this Privacy Policy or your data, contact us at:

Breche (La Breche Co LLC)
Email: info@breche.us

← Back to Home