AP
CommandAP
APCommandAP

Privacy Policy

Last updated September 17, 2026

1.Scope

This policy explains how CommandAP Inc. handles information when general contractors (“GCs”) and their subcontractors and vendors (“Subs”) use commandap.co, getcommandap.com, and the CommandAP service.

2.What we collect

From GCs: name, email, company details, team member details, jobs, budgets, bids, and the invoices and emails forwarded to your CommandAP inbox address.

About and from Subs: business name, contact details, address, license number, W-9 forms (which include a taxpayer identification number), certificates of insurance, signed agreements and lien waivers, and invoices.

Signing records: when a document is signed we record the signer’s stated name and title, the time, and the IP address and browser of the device used.

Payments: bank account and identity information for payments is collected and stored by Stripe, not by us. We keep identifiers, the last four digits of a connected account, and payment status and amounts.

Usage and device data: log data such as IP address, browser type, pages requested, and errors.

3.How we use it

To run the Service: read and route invoices, check compliance status, generate and deliver documents for signature, send requests, reminders, and receipts on a GC’s behalf, initiate and reconcile payments, detect duplicates and errors, maintain audit trails, secure the Service, provide support, and improve the product. We do not sell personal information and do not use it for third-party advertising.

4.Automated and AI processing

Invoices, certificates of insurance, and similar documents are processed with automated tools, including AI models provided by Anthropic, to extract fields such as vendor, amounts, dates, and coverage limits. Documents are sent to that provider only to perform the extraction.

5.Who we share it with

Between a GC and its Subs: what a Sub provides through a GC’s link is shared with that GC. A Sub’s information is not shared with other GCs unless the Sub provides it to them.

Service providers that process data for us: Supabase (database, authentication, file storage), Vercel (hosting), Stripe (payments and identity verification for payouts), Resend and Postmark (outbound and inbound email), Anthropic (document extraction), and Netlify (marketing site and its forms).

Legal and safety: when required by law, to enforce our Terms, or to protect users, Stripe, or CommandAP. Business transfers: as part of a merger, financing, or sale, subject to this policy.

6.Storage and security

Documents are stored in private storage and served through expiring signed links. Access to a company’s data is restricted to that company’s users by database-level access rules. No system is perfectly secure; tell us right away if you believe your account or documents have been exposed.

7.Retention

We keep data while an account is active. After an account closes we delete or de-identify it within a reasonable period, except signed documents, payment records, and audit trails that we or the GC must retain for legal, tax, or lien-related reasons.

8.Your choices

GCs can edit or remove most data in the Service and can ask us to export or delete their account data. Subs can ask the GC that invited them, or us, to correct or remove their information; some records must be retained as described above. Marketing emails include an unsubscribe link. Transactional messages about documents and payments are part of the Service.

9.Children

The Service is for businesses and is not directed to anyone under 18.

10.Changes and contact

We will post updates here and notify account holders of material changes. Questions or requests: devin@getcommandap.com.

Terms of ServicePrivacy Policydevin@getcommandap.com