Privacy Policy
How we handle personal information
1. Who we are
Stralos is operated by Stralos Limited (company number 9442335, NZBN 9429053795076), a New Zealand company with its registered office at 105 Verona Place, RD 2, Ohoka 7692, New Zealand ("Stralos", "we", "us").
This policy explains how we collect, use, store, disclose and protect personal information when you visit our website (stralos.app and stralos.co.nz) or use the Stralos platform, our software service for estimating, scheduling and managing civil construction work (the "Service").
We comply with the New Zealand Privacy Act 2020 and its Information Privacy Principles (IPPs). We handle the personal information of everyone who uses Stralos, including people in Australia, in the same way, consistently with the New Zealand Privacy Act.
Our two roles
- For our own information (website visitors, people who register interest, account holders, billing contacts) we decide how the information is used and are responsible for it.
- For information our customers put into the Service (for example details of their staff, crew, clients, suppliers and subcontractors) we hold and process it on behalf of the customer. The customer organisation is responsible for having collected that information lawfully and for telling the people concerned. Under section 11 of the Privacy Act 2020, information we hold solely as our customer's agent is treated as held by the customer. If you are one of those people, please contact the organisation that uses Stralos first; we will help them respond.
2. What we collect
2.1 Website visitors and people who register interest
- Register-interest form: email address, and optionally your name, company, role, company size and whether you want beta access or updates.
- Collected automatically with the form: your country (derived by our hosting provider from your connection), your browser's user-agent string, and first-touch campaign details (UTM tags, ad click identifiers such as
gclid,fbclidormsclkid, landing page and referring site). The first-touch details are kept in your browser's local storage until you submit the form. - Analytics (only if you accept analytics cookies): pages viewed, clicks on buttons and links, sections scrolled into view, errors, and device and browser information. If you have accepted and then submit the form, your analytics profile is linked to your email address, name, company and role. If you decline, or have not yet chosen, no analytics are loaded or collected.
- Session recordings (only if you accept analytics cookies): we record how visitors interact with pages (mouse movement, clicks and scrolling) so we can improve the site. Everything you type into form fields is masked and is not captured in recordings.
- Bot protection: the form uses Cloudflare Turnstile, which processes device and browser signals to tell people from bots.
2.2 Account holders (users of the Service)
- Identity: name, email address, your role and permissions within your organisation, account status, and when you last signed in.
- Sign-in: your password (stored only as a one-way hash by our identity provider, never in readable form), one-time sign-in codes sent to your email, passkeys and authenticator-app settings if you enable them.
- Sessions: for each signed-in device we keep a session record containing a hashed session token and the browser and operating system type. We do not store your IP address or full user-agent string with your session.
- Usage and diagnostics: we use PostHog (EU cloud) in the app for product analytics (pages and features used, clicks, errors, and device and browser information), feature flags (to control which features are switched on for you), and session recordings. This is linked to your name and email so we can support you, fix problems and improve the Service. In app session recordings all text and form input is masked and network requests are not recorded.
- AI assistant conversations: the messages you type to the Stralos assistant, its replies, and a record of any actions it took or proposed on your behalf.
- Support: anything you tell us when you contact us.
2.3 Billing contacts
When your organisation subscribes we collect the billing email address, organisation name, country and billing address. Card details are entered directly into Stripe's hosted payment pages and are never received or stored by Stralos. We store the subscription status and the Stripe customer reference.
2.4 Information customers put into the Service
Customers use Stralos to run their construction business, so the Service holds information about people connected to that business, including:
- Client, supplier and subcontractor companies and their contacts: company and trading names, business numbers, websites, and contact names, roles, email addresses and phone numbers.
- Workforce and crew: first, last and preferred names, email and phone, employee number, role or title, employment type, working days, start and end dates, notes, driver licence classes and their expiry and verification dates, endorsements, competencies and certificates, and periods of unavailability with a reason and notes.
- Projects and sites: project names, job numbers, client references, addresses and map coordinates of project sites, office locations and supplier yards.
- Documents: drawings, specifications, schedules and other files uploaded or synchronised from Google Drive or Microsoft SharePoint, which may contain personal information.
Sensitive information. The Service is not designed to hold health, medical or other sensitive information. Customers should not record health details in free-text fields such as unavailability notes; record "leave" or "unavailable" instead.
3. How we use personal information
- to provide, operate, secure and support the Service, including signing you in and sending sign-in codes and invitations;
- to process subscriptions and payments and keep financial records;
- to respond to people who register interest, invite them to early access and send product updates they have asked for (you can unsubscribe at any time);
- to understand how the website and Service are used and to fix and improve them;
- to power AI features when you choose to use them (see section 5);
- to detect and prevent fraud, abuse, malware and security incidents; and
- to comply with our legal obligations.
We do not sell personal information, and we do not use customer data from the Service for advertising. We do not use customer data, whether identifiable, de-identified or aggregated, for benchmarking or to train or improve AI models.
4. Service providers and where your information goes
We use the following service providers (sub-processors) to run Stralos. They act on our instructions and are bound by contract to protect the information. Some are outside New Zealand; see section 6. This table is our current sub-processor list.
| Provider | What they do | Location of processing |
|---|---|---|
| Amazon Web Services | Hosting, databases, file storage, identity and sign-in (Amazon Cognito), email delivery (Amazon SES), document text extraction (Amazon Textract), malware scanning, logs and backups | Sydney, Australia (ap-southeast-2). Website/app delivery via the CloudFront global edge network. |
| Stripe | Subscription billing and card payments | United States and other countries |
| PostHog | Product analytics, feature flags and session recordings with all input masked (app; website only if you accept analytics cookies) | European Union |
| Cloudflare | Website hosting, register-interest database, bot protection (Turnstile), analytics proxy, network security | Global network. The register-interest database is located in Oceania. |
| Resend | Sending the email that confirms a register-interest submission, and the notification of it to our support team | United States |
| Google (Gemini API, paid tier) | AI model provider: generates assistant replies, summarises and classifies documents, reads rate sheets on import (see section 5) | United States and other countries |
| Google Maps Platform | Maps, address search, and travel distance and time between project sites and supplier yards inside the app | United States and other countries |
| Google Drive, Microsoft SharePoint | Only if your organisation connects them: synchronising project folders into Stralos | Per your organisation's own agreement with Google or Microsoft |
| Autodesk Platform Services (Design Automation) | Converting uploaded DWG and DXF drawings to PDF | United States |
We may also disclose information to our professional advisers, to a buyer or successor if our business is sold or restructured (subject to this policy), or where required or permitted by law, for example to a court or regulator.
We will give customers at least 30 days' notice, by email or in the app, before we add or replace a sub-processor, and update this list when we do.
5. AI features
Stralos includes AI features: the in-app assistant, automatic summaries and classification of uploaded documents, area take-off from drawings, and reading supplier rate sheets when you import them. When these features run, we send the model provider named in section 4:
- for the assistant: your messages, the earlier messages in the conversation, your role, and the Stralos data the assistant looks up to answer (for example project names, job numbers, client references, estimates, rates, schedules and office locations);
- for document features: text extracted from the document; and
- for rate imports: the contents of the rate workbook or PDF.
We remove sign-in tokens before anything is sent. We use AI providers under terms that do not allow them to train their models on your data. We use Google's paid Gemini API tier. Google does not use our prompts, files or responses to train or improve its products. Google retains prompts and responses for up to 55 days, solely to detect and prevent misuse of its service. We do not log model outputs.
AI output can be wrong. Check anything the assistant produces before relying on it. The assistant proposes changes as drafts for you to confirm.
Assistant conversations are kept for 12 months and the record of assistant actions for 24 months, then deleted by a scheduled deletion job that runs weekly.
6. Storage and overseas disclosure
The Service's data, including customer data, documents and backups, is stored in Amazon Web Services' Sydney, Australia region. Our website's register-interest data is held by Cloudflare in its Oceania location.
Some service providers in section 4 process information in the United States, the European Union or elsewhere. Those providers hold and process information only on our behalf, to provide the Service to us, and not for their own purposes. Under section 11 of the Privacy Act 2020 this is not a disclosure to them for the purposes of IPP 12 (cross-border disclosure): we remain responsible for the information, and we use contracts that require each provider to protect it.
7. Cookies and similar technologies
| Name / type | Where | Purpose |
|---|---|---|
Analytics choice (local storage, stralos-analytics-consent) | Website | Remembers whether you accepted or declined analytics cookies; strictly necessary |
PostHog cookie and local storage (ph_*) | Website (only if you accept analytics cookies) and app | Analytics identifier, feature flags and session recording |
| Campaign attribution (local storage) | Website | Remembers how you first found us until you register interest |
| Cloudflare Turnstile | Website form | Bot protection |
__Host-stralos-ceremony, __Host-stralos-security cookies | Sign-in | Security cookies used during sign-in; strictly necessary |
| Session tokens (local storage) | App | Keep you signed in; strictly necessary |
| Remembered email (local storage) | Sign-in page | Pre-fills the last email used on that device |
Your choice on our website. When you first visit, we ask whether you accept analytics cookies. PostHog is not loaded and nothing is captured unless you accept. You can change your choice at any time with (also in the footer of every page); if you withdraw, we remove PostHog's cookies and local storage from your browser.
You can also block or delete cookies in your browser settings. Blocking the strictly necessary items will stop you signing in.
8. How we protect information
- Data is encrypted in transit (HTTPS/TLS) and at rest (encrypted databases and file storage).
- Each customer's data is kept separate using database-level row security.
- Passwords are handled by Amazon Cognito and never stored by us in readable form; passkeys and authenticator-app multi-factor sign-in are available.
- Uploaded files are scanned for malware.
- Access to production systems is restricted to authorised staff and is logged.
Privacy breaches. If we have a privacy breach that it is reasonable to believe has caused or is likely to cause serious harm, we will notify the Office of the Privacy Commissioner and affected people as soon as practicable, as required by Part 6 of the Privacy Act 2020. Where the breach affects customer data we hold on a customer's behalf, we will tell the customer within 72 hours of becoming aware of it and help them meet their own obligations.
9. How long we keep information
| Information | Retention |
|---|---|
| Customer data in the Service | For the life of the subscription, then 90 days after it ends so the customer can export it, then deleted within 30 days after that |
| Database backups | 30 days on a rolling basis |
| Deleted old versions of uploaded files | 30 days |
| Sign-in sessions | Up to 30 days of inactivity (backup copies up to 35 days) |
| Application logs | 14 to 90 days depending on the system |
| AI assistant conversations / action records | 12 months / 24 months (see section 5) |
| Register-interest submissions | 24 months after our last contact with you, or sooner if you ask us to delete it |
| Billing and tax records | 7 years, as required by New Zealand tax law. A billing contact's name and email address remain on invoices already issued |
How deletion works
When a user deletes something in Stralos, it is first removed from view and kept so it can be restored and so project history stays accurate (for example, records referenced by a submitted estimate). Projects are archived rather than deleted. This means an in-app "delete" does not immediately erase the information.
If you ask us to erase personal information, or a customer asks us to erase its data when it leaves, we will permanently delete or de-identify it from our live systems within 30 days of confirming the request, except where we must keep it by law. Confirmed erasure requests are carried out by our team within 30 days. Scheduled deletion jobs run weekly to enforce the retention periods above. Copies in backups are overwritten as the 30-day backup cycle runs.
10. Your rights
You have the right to ask for access to the personal information we hold about you (IPP 6) and to ask us to correct it (IPP 7). You can also ask us to delete it or to stop sending you marketing. Email [email protected]. We will respond within 20 working days, as the Privacy Act requires. We may need to verify your identity. There is no charge for most requests.
If your information is held in a customer's Stralos account (for example you are an employee or a contact of one of our customers), please contact that organisation. If you contact us, we will pass your request to them and help them respond.
If you are not satisfied with our response, you can complain to the Office of the Privacy Commissioner (privacy.org.nz).
11. Children
Stralos is a business service and the website is not directed at children. We do not knowingly collect personal information from anyone under 16.
12. Changes to this policy
We may update this policy. We will post the new version here with a new effective date and, for material changes, tell account holders by email or in the app before the change takes effect.
13. Contact our Privacy Officer
Privacy Officer: Graeme Ainsworth, Director
Email: [email protected]
Post: Privacy Officer, Stralos Limited (company number 9442335, NZBN 9429053795076), 105 Verona Place, RD 2, Ohoka 7692, New Zealand
To report a security concern or suspected unauthorised access, email [email protected].