Skip to content

Your data. Your business.

PRIVACY POLICY

We built Marapone around the principle that your data belongs to you. This policy explains what we collect when you visit this website or engage us as a client, and — importantly — what we do not collect and why.

Effective date: January 1, 2026  ·  Last updated: August 2026  ·  Marapone Contracting Inc. (Canada)

The core of our privacy model, stated plainly: the five programs — Blueprint Auditor, SpecChecker, the AI Estimator, the Bid Leveler and ScopeGuard — are a hosted service, so the documents you put into them are uploaded to Marapone-operated infrastructure in Canada or the EU to be read. What we promise is what happens to them there: they sit in a workspace scoped to your account, they are read by our own model rather than passed to OpenAI, Anthropic or Google, they are never used to train anything, and they are exported or deleted whenever you ask.

Two exceptions to be transparent about. First, the optional tools on this website — the live demo and the file-upload field on our contact form — do process the file you choose to send through cloud infrastructure (for hosting, malware scanning, and short-term quarantine) so we can run the demonstration or safely receive your attachment. These website tools are entirely optional, and exactly what happens to those files is described in sections 03 and 04 below.

Second, and more significant: the MaraponeAI mobile app is a hosted service. A phone cannot run these engines, so the work happens on our infrastructure and a document you process in the app is uploaded to us. It goes to our servers and no further — your own isolated workspace, our own model, no third-party AI vendor, and never used to train anything. That is a real difference from everything else we sell, so it has its own section 06 below rather than a line in a table. If nothing may leave your own infrastructure, a standard plan cannot meet that bar — deployment into your own cloud tenant is an enterprise arrangement, so ask before subscribing.

01 — Controller

WHO IS RESPONSIBLE FOR YOUR DATA

The data controller for personal information collected through this website and our services is:

Marapone Contracting Inc.

Canada & Italy  ·  Operating globally

general@marapone.com

info@marapone.com

support@marapone.com

invoices@marapone.com

If you are located in the European Union or the United Kingdom, your data is handled in accordance with GDPR and UK GDPR respectively. If you are located in Canada, your data is handled in accordance with PIPEDA (Personal Information Protection and Electronic Documents Act) and applicable provincial privacy legislation.

02 — Website Data

WHAT WE COLLECT WHEN YOU VISIT THIS SITE

When you browse this website, we collect minimal technical data to keep the site functioning:

  • Server logs: IP address, browser type, pages visited, and timestamps. These are standard logs kept by web servers. They are not tied to your identity and are retained for up to 30 days for security purposes only.
  • Cookies: We use a minimal number of functional cookies required for the site to operate correctly, plus Google Analytics cookies for aggregate traffic measurement. No advertising or behavioural tracking cookies are used. See our Cookie Policy for full details.
  • Bot & spam protection: Our demo and forms are protected by Cloudflare Turnstile, a privacy-focused alternative to CAPTCHA. To tell humans from bots, Cloudflare receives your IP address and basic browser signals. Turnstile does not use tracking cookies and is not used to profile or advertise to you.
  • Hosting & analytics: This site is hosted on Vercel, which also provides privacy-friendly, cookieless aggregate traffic analytics (Vercel Analytics). Standard hosting logs apply as described above.

We use Google Analytics (GA4) to measure aggregate site traffic — page views and visitor counts. Google Analytics cookies do not identify you personally and are not used for advertising or behavioural profiling. We do not use Facebook Pixel or any other advertising or surveillance tools. We do not build advertising profiles. We do not sell or share visitor data with any third party.

03 — Contact & Enquiry Data

WHEN YOU CONTACT US

When you submit the contact form, book a discovery call, or email us directly, we collect the information you provide, which typically includes:

  • Your name and business name
  • Your email address and phone number (if provided)
  • Your message or project description
  • Your industry and location (if you choose to share these)

Purpose: This information is used solely to respond to your enquiry and, if you engage us, to manage your project. We do not add you to marketing lists without your explicit consent.

Retention: Enquiry data from contacts who do not become clients is retained for up to 12 months and then securely deleted. Project-related communications with clients are retained for up to 3 years for contractual and legal compliance purposes.

If we arrange for you to send us a file: The contact form itself no longer accepts attachments — documents belong in your own workspace, which the free trial opens. Where we do agree to receive a file through the site, it is handled by a small number of processors before it reaches us:

  • Malware scanning (VirusTotal): The file is scanned for malware via VirusTotal before we open it. Be aware that files submitted to VirusTotal may be retained and shared within VirusTotal's security community — so please do not attach highly confidential documents through the website form. For sensitive material, we will arrange a private, locally-handled channel instead.
  • Short-term quarantine (Supabase): The file is stored in an access-controlled quarantine bucket (Supabase Storage) and made available to us via a private link that expires automatically after 7 days, after which it is removed from quarantine.
  • Spam filtering (Akismet): Discovery and enquiry submissions are checked for spam using Akismet, which receives the submitted text, email, and IP address for that check only.

Note: this website file handling is separate from how we treat documents during a paid client build. Client build materials are processed locally and are never sent to VirusTotal, Supabase, or any cloud AI service — see section 05.

04 — Live Demo Tool

WHEN YOU USE THE LIVE DEMO

The website offers an optional live demo — on the Blueprint Auditor page — where you can upload a sample document (PDF, CSV, TXT, or JSON, up to 5 MB) and our document-intelligence engine analyses it in real time. Here is exactly what happens to your data:

  • Your file is processed in memory only. It is sent to our serverless function, analysed deterministically, and discarded when the request ends. It is not stored, logged, or retained, and it is never sent to any external or third-party AI service.
  • Email (optional): To unlock the full results, you may enter an email address. We use it to notify our team of your interest (a sales lead) and to follow up. The notification records your email, which demo tool you used, the file name, and the summary risk score — not the file's contents. We do not add you to marketing lists without consent.
  • IP address & bot check: Your IP address is used temporarily to enforce rate limits (to prevent abuse), and a Cloudflare Turnstile check is performed before processing.

Because the demo runs on cloud infrastructure (unlike a delivered client build), please use sample or non-sensitive documents in the demo. The first finding is shown in full; the rest of the results are redacted server-side until you engage us for a private build.

05 — Client Project Data

YOUR BUSINESS DOCUMENTS & PROJECT MATERIALS

Documents you share with us for model training or a custom build are processed exclusively on Marapone's secure, locally-operated hardware. They are never uploaded to third-party cloud services, never passed through external AI APIs, and never stored beyond the duration of your project.

Specifically:

  • Your blueprints, RFI logs, daily reports, trade documents, and freight invoices are processed locally on our build hardware.
  • No document content is transmitted to OpenAI, Anthropic, Google, AWS, or any other cloud provider in the course of building your system.
  • Upon delivery of your project, all copies of your documents held by Marapone are permanently deleted from our systems.
  • The AI system we deliver to you runs on your own hardware. From that point forward, your data never touches Marapone's infrastructure.

If we engage an NDA prior to receiving your materials (which we recommend for sensitive projects), those obligations apply in addition to and independently of this Privacy Policy.

Software you buy off the shelf is different again: we never see your data at all.

The Blueprint Auditor, SpecChecker, the AI Estimator, the Bid Leveler and ScopeGuard are desktop applications for Windows, macOS and Linux. There is no Marapone account, no licence server and no telemetry. Everything they read and everything they produce — project manuals, drawing sets, subcontractor quotes, your award history, your rate tables and your own annotations — is written to a folder on your machine that you control, in open your own workspace, and stays there. They work with the network switched off, and uninstalling one does not delete your data.

This matters most for the commercially sensitive material these products handle. Subcontractor pricing and a contractor's working notes on the contract documents are among the most confidential records in a construction office, and nothing in these applications opens a socket.

The mobile app is the exception to this paragraph. The same eight tools reached from a phone run on our infrastructure, not on your device, and the same is true of the programs reached in a browser, so this section applies to both equally. Section 06 sets out what we hold there, for how long, and what we never do with it.

Data packs go one step further. A pack is a set of files — PDF, CSV and JSON — with no application attached, so there is nothing to run, nothing to register and nothing that could report anything back. Buying one gives us your name, email and the fact of the purchase, all of it collected by Stripe at checkout and used to deliver the files and honour the refund and upgrade-credit windows. We never see what you do with a pack afterwards, and there is no mechanism by which we could.

If you take a customised setup or an enterprise integration, you are sending us historical documents so we can tune the system to them — past estimates, awarded subcontracts, spec templates, quotes and change orders. Those are handled under exactly the terms set out above in this section: processed locally on our build hardware, never passed through an external AI API, and deleted on delivery.

06 — Mobile App Data

WHEN YOU USE THE MARAPONEAI MOBILE APP

The mobile app is the one product where we do hold your documents. It is a hosted service: the engines run on our infrastructure, so a drawing set you audit on the phone is uploaded to be audited. Everything else on this page describes software that sends us nothing. This section describes the exception, in full.

Why it works this way: the desktop suite needs a laptop's memory and a local model, and a phone has neither. The alternative to a server is an app that gives different answers on different handsets, so we chose the server and are telling you about it here rather than in a footnote.

What we hold, and why:

  • The documents you submit. Drawing sets, project manuals, subcontractor quotes and photographs of them. Stored so the engines can process them and so your projects still open tomorrow.
  • What the engines produce. Takeoffs, code findings, estimates, levelled bid comparisons, buyout findings and spec conflicts, plus the rate and jurisdiction settings you chose.
  • Account data. Your email address, your tier, the city and jurisdiction you selected, and — for a Firm account — the other seats in your team.
  • Operational logs. Which engine ran, when, how long it took, and whether it failed. Kept for up to 30 days to fix crashes and size the infrastructure. They record that a job ran, not what was in it.
  • Assistant conversations. Your questions and the answers, held against your own workspace so a conversation can continue.

What we do not do with it: your documents and their outputs are not used to train any model, ours or anyone else's; they are not shared with other customers or with any third party; they are not sold; and they are not sent to OpenAI, Anthropic, Google or any other AI provider. The language model behind the in-app assistant is our own open-weights model running on the same infrastructure as the engines. No third-party AI vendor is in the path of your tender documents.

Isolation: each account is processed in its own workspace, and the assistant is only ever given that workspace — so a question cannot reach another contractor's estimate. On a Firm account, the seats you add share one workspace by design; that is the feature, and it means your colleagues can see the projects in it.

Where it is processed: on infrastructure we operate in Canada, or in the EU for accounts that ask for EU residency. It is encrypted in transit and at rest.

Retention: your projects stay while your account is active. If a subscription lapses or is cancelled, they are kept for 90 days so that resubscribing restores them, and are deleted after that. You can export to PDF, Excel or CSV at any time while the account is active. Operational logs are deleted on their own 30-day cycle.

Deleting it yourself, immediately: you do not have to ask us, and there is no 30-day window to wait out. Your dashboard carries two buttons. Erase my documents deletes every drawing set, project and result we hold for you and leaves your login and plan running. Close my account does that and also cancels the subscription on the spot, then deletes your profile, your account number, your data-pack record and the login itself. Both run within the request — seconds, not a queue — and we email you a confirmation listing exactly what was removed. There is no charge, no exit interview and no condition attached.

What survives a deletion, and why: invoices for anything you paid for, held by Stripe. Tax and accounting law requires a seller to keep records of what it sold, so those are not ours to erase. They record what was bought and what it cost — never anything you uploaded. Everything else goes.

The stores: the subscription is billed by Apple or Google, so they hold your payment details, not us. We receive the fact of a subscription and its tier — never your card number. Apple and Google apply their own privacy policies to your App Store or Google Play account, which we do not control. The app contains no advertising SDK, no analytics SDK that profiles you, and it does not read your device's advertising identifier or contacts.

If any of this is a problem: tell us before you subscribe rather than after, and we will say plainly whether we can meet your requirement. If your obligation to an owner or architect is that tender documents never leave your premises, no plan can meet it — there is no offline or desktop version any more — and deployment into your own cloud tenant at the enterprise tier is the only arrangement we can offer. We would rather tell you here than after you have uploaded a set.

07 — Third Parties

WHO WE SHARE DATA WITH

We do not sell personal data. We do not share personal data with advertising networks, data brokers, or marketing platforms.

To operate this website and our services, we rely on a short list of reputable service providers (sub-processors), each handling only the data needed for its specific function:

Provider Purpose Data handled
VercelWebsite hosting & cookieless analyticsServer logs, IP, aggregate traffic
Google AnalyticsAggregate traffic measurementPseudonymous usage data, cookies
Cloudflare TurnstileBot/abuse protection on demo & formsIP, browser signals (no tracking cookies)
ResendTransactional & notification email deliveryName, email, message content
Supabase7-day quarantine of contact-form file uploadsUploaded file (temporary)
VirusTotalMalware scanning of uploaded filesUploaded file & its hash
AkismetSpam filtering of form submissionsSubmitted text, email, IP
Cal.comDiscovery-call scheduling (where offered)Name, email, booking details
StripeSoftware product and data pack checkout, and invoice paymentName, email and payment details, entered on Stripe's own page; we never see or store card data
Apple App StoreMobile app distribution and subscription billing (iOS)Your Apple account and payment details, held by Apple; we receive the subscription status and tier only
Google PlayMobile app distribution and subscription billing (Android)Your Google account and payment details, held by Google; we receive the subscription status and tier only

We may also disclose information to legal or regulatory authorities if required by law or court order, and will notify you to the extent permitted by law if such a request is received. Client build documents are not shared with any of the sub-processors above — they are processed locally as described in section 05. Nor are documents you process in the mobile app: Apple and Google bill the subscription and never receive your files, and the engines and the model that read them are our own, running on our own infrastructure, as described in section 06.

08 — Your Rights

YOUR DATA RIGHTS

Depending on your location, you may have the following rights regarding personal data we hold about you:

Right of access

Request a copy of the personal data we hold about you.

Right to rectification

Ask us to correct inaccurate data we hold about you.

Right to erasure

Delete your data yourself, whenever you like — two buttons on your dashboard, effective in seconds, with a confirmation email. No request to make. Subject only to invoices we are legally required to keep.

Right to object

Object to processing of your data for marketing purposes (we don't market to you without consent anyway).

Right to portability

Receive your personal data in a structured, machine-readable format.

Right to withdraw consent

Where processing is based on consent, withdraw it at any time without affecting prior processing.

To exercise any of these rights, email general@marapone.com. We will respond within 30 days. We do not charge a fee for reasonable requests.

09 — Security

HOW WE PROTECT YOUR DATA

We take reasonable and appropriate technical and organisational measures to protect personal data against unauthorised access, loss, destruction, or alteration. Our development hardware is physically secured, access-controlled, and not exposed to public networks during client builds.

No method of transmission or storage is 100% secure. If a data breach occurs that is likely to result in risk to your rights, we will notify you and relevant supervisory authorities within the timeframes required by applicable law.

10 — International Operations

CROSS-BORDER DATA HANDLING

Marapone operates from Canada and Italy. If you are located in the European Economic Area (EEA) or the United Kingdom and we process your personal data, that data may be transferred to and processed in Canada. Canada is recognised by the European Commission as providing an adequate level of data protection for commercial organisations under PIPEDA.

We do not transfer client document data internationally. Project documents are processed on local hardware in whichever office is managing your build, and deleted upon project delivery.

Mobile app data is processed on infrastructure we operate in Canada by default, or in the EU where an account requests EU residency. It is not moved between those regions in the course of ordinary processing. For EEA and UK customers on Canadian residency, the transfer relies on the European Commission's adequacy finding for Canada described above; tell us before you subscribe if your own obligations require EU residency and we will set the account up that way.

11 — Changes

UPDATES TO THIS POLICY

We may update this Privacy Policy as our services evolve or legal requirements change. The "Last updated" date at the top of this page reflects the most recent revision. Material changes will be communicated to active clients by email.

Privacy questions or requests

CONTACT US

For any privacy-related questions, data requests, or concerns, contact us directly. You will reach the people who actually run the company — not an automated system or third-party privacy service.

general@marapone.com

Marapone Contracting Inc.  ·  Canada & Italy  ·  Operating globally