Legal

Privacy Policy

Last updated August 7, 2026

Oriel is construction software, not an advertising business. We collect what the service needs to run, we do not sell personal information, and we run no advertising or ad tracking of any kind. This policy says exactly what we collect, from whom, and why, in plain English.

SECTION 01Who we are

Oriel is operated by [ENTITY LEGAL NAME], with its principal place of business at [PRINCIPAL ADDRESS] (“Oriel,” “we,” “us”). Oriel is software for commercial construction teams: questions (RFIs) pinned to drawings, answered by outside parties through secure review links, kept in an append-only project record. This policy covers the websites at oriel.build and review.oriel.build and the Oriel service. For anything in this policy, contact [CONTACT EMAIL].

SECTION 02Who this policy covers

Four groups of people interact with Oriel, and we collect different things from each:

  • Site visitors: anyone browsing oriel.build.
  • Pilot applicants: people who submit the pilot request form.
  • Customer account users: people at a customer company who sign in and use the service.
  • External reviewers: architects, engineers, subcontractors, and others who respond to an RFI through a review link, without creating an account.

SECTION 03What we collect, and where it comes from

Site visitors

The marketing site runs no analytics, no advertising trackers, and no third-party tracking of any kind, and it sets no cookies for anonymous visitors. Our hosting infrastructure generates standard server logs (IP address, browser type, pages requested, timestamps) that we use to operate and secure the site.

Pilot applicants

The pilot request form collects your name, work email, company, role, and an optional one-line project description. The submission is delivered to us as an email; it is not written to a marketing database, and we do not add you to any automated mailing list. The submitting IP address is used briefly to rate-limit the form and is not kept.

Customer account users

When your company becomes a customer, we collect what the service needs: your name, email, and sign-in credentials (held by our authentication infrastructure; we never see your password); your organization membership and role; the project content you and your team create (drawings, RFIs, photos, comments, files); and an audit trail of material actions (who did what, when), which is a core feature of the product. Signing in sets essential cookies: an authentication session cookie and a cookie remembering which organization you are working in. We set no analytics or advertising cookies.

External reviewers

A review link opens a single record with no account and no password. If you submit a response, your name, email, response text, and any attachments are filed to the customer’s project record with a timestamp, exactly as the review page tells you before you submit. Downloads from a review page are logged to the project record. The link itself is scoped to one record, expires, and can be revoked by the customer.

SECTION 04How we use information

  • Operating the service: running projects, filing RFIs and responses, generating exports and reports, delivering notifications people asked for.
  • Communications: replying to pilot requests, sending service notifications (for example, that a response arrived), and supporting customers. We do not send marketing email to customer users or external reviewers.
  • Security: authenticating users, scoping every request to the right organization, scanning uploaded files for malware, keeping audit trails, and investigating abuse.
  • Improving the service: understanding failures and fixing them. We do this from operational logs, not from behavioral tracking.

SECTION 05Project records: who controls what

For the content inside a customer’s project records, Oriel processes information on the customer’s behalf. The customer owns the record. If your information appears inside a customer’s project records (for example, you answered an RFI as an external reviewer, or a colleague named you in one), the customer decides what happens to that record, and requests about it should go to that customer. We will refer such requests to the customer and support the customer in answering them. For information Oriel controls directly (pilot requests, account registration, this website), contact us at [CONTACT EMAIL].

SECTION 06Text messaging (SMS and MMS)

Oriel includes text messaging so field teams can send project communications (for example, a photo and a question that becomes a draft RFI) by SMS or MMS. This section governs that program wherever it is enabled for a project.

  • Program description: project communications for construction teams: messages to and from a project about RFIs, drawings, photos, and related project activity.
  • Consent: participants are enrolled by the customer during project onboarding, with written consent collected before any message is sent. We send messages only to people who have opted in.
  • Message frequency varies with project activity.
  • Message and data rates may apply.
  • Opt out at any time: reply STOP to cancel. Reply HELP for help, or contact [CONTACT EMAIL].
  • Carriers: supported carriers are not liable for delayed or undelivered messages.

No mobile information will be shared with third parties or affiliates for marketing or promotional purposes.

Text messaging originator opt-in data and consent will not be shared with any third parties.

SECTION 07Service providers

We use a small number of service providers to run Oriel, each processing information only to provide their function to us:

  • Hosting and database: the infrastructure the application and its data run on, in the United States. File storage is private; files are served only through signed, expiring links issued after authorization.
  • Email delivery: sending the service’s notification email.
  • File scanning: scanning uploaded files for malware before they are published to a project.
  • SMS delivery: transmitting text messages for the messaging program described above.
  • AI processing: where Oriel’s assistive features (drafting, flagging, search) use third-party AI providers, those providers process customer content solely to provide the service. Oriel does not permit customer content to be used to train third-party models.

Note for counselThe AI-training statement must be verified against the then-current terms of each AI provider actually in use before these features launch, and re-verified when providers change. As of this draft, no AI provider is integrated in the product; the features are on the public roadmap.

SECTION 08What we never do

  • We do not sell personal information, and we never have.
  • We do not run advertising and we do not share information with ad networks.
  • We do not use ad tracking, cross-site tracking, or analytics trackers.
  • We do not use customer project content for any purpose other than providing the service.

SECTION 09Retention

Project records are the point of Oriel: they are append-only, and the service is designed to preserve them. Records are retained per the customer’s instruction and plan; archived projects are read-only rather than purged. Customers can export their complete records at any time, and before a customer’s data is deleted, the customer gets the opportunity to export it. If records relevant to a dispute need to be preserved, contact us at [CONTACT EMAIL] and we will work with the customer to preserve them.

Pilot request emails are retained as ordinary business correspondence. Server logs rotate on our infrastructure providers’ standard schedules.

SECTION 10Security

Security claims here match what the product actually does, and nothing more. Files live in private storage and are never on a public URL; every file is served through a signed, expiring link issued server-side after authorization. Every organization’s data is isolated at the database and storage layer, deny-by-default. Material actions are written to an append-only, timestamped audit trail. Review links are scoped to a single record, expire, and are revocable. Uploaded files are scanned for malware. Traffic is encrypted in transit. No system is perfectly secure, and we do not promise otherwise; if we learn of a breach affecting your information, we will notify affected customers and individuals as required by law.

SECTION 11Children

Oriel is business software for construction professionals. It is not directed at anyone under 18, and we do not knowingly collect information from anyone under 18.

SECTION 12Where information is processed

Oriel is operated from the United States, and information is processed and stored in the United States. If you use the service from outside the United States, your information will be transferred there.

SECTION 13Your state privacy rights

Depending on where you live, state law (including the Texas Data Privacy and Security Act and similar laws such as the California Consumer Privacy Act) may give you rights over your personal information: to know what we hold about you, to get a copy, to correct it, to delete it, and to not be discriminated against for exercising those rights. Since we do not sell personal information or use it for targeted advertising, there is nothing to opt out of on that front.

To exercise these rights, email [CONTACT EMAIL]. We will verify your request and respond within the time the applicable law requires, and if we decline a request, we will say why and how to appeal. One routing note: for information inside a customer’s project records, the customer is the controller, and most requests about that content must go to the customer (see Section 05). We will tell you if that applies and refer your request.

SECTION 14Changes to this policy

When we change this policy, we will change the “Last updated” date above, and for material changes we will give customers reasonable advance notice through the service or by email. We will never quietly weaken what this policy promises about selling, advertising, or customer content.

SECTION 15Contact

[ENTITY LEGAL NAME], [PRINCIPAL ADDRESS]. Questions, requests, and complaints: [CONTACT EMAIL]. See also our Terms of Service.