Privacy Policy
Effective: August 11, 2026
This policy explains how Struora collects, uses, discloses, and protects personal information when people visit our website, create an account, or use the Struora operations platform.
1. Scope and roles
This policy applies to Struora's public website, tenant subdomains, applications, support interactions, and related services. Struora acts as a controller for website, account, billing, security, and direct business-contact information. For customer-managed project, employee, technician, client, asset, document, and operational data, Struora generally acts as a processor or service provider on the customer's instructions.
2. Information we collect
Information you provide
- Account details such as name, email address, password credentials, role, and workspace.
- Business and tenant details, branding, configuration, billing contacts, and subscription information.
- Operational content such as projects, work orders, schedules, invoices, inventory, documents, photos, notes, forms, signatures, and communications.
- Support requests, feedback, invite details, and other communications.
Information collected automatically
- Authentication and security information, including session identifiers, timestamps, hostname, and tenant routing context.
- Basic device and request information made available by browsers and hosting infrastructure, such as IP address, browser type, and requested URL.
- Cookie and local-storage choices described in our Cookie Policy.
3. How we use information
- Provide, secure, maintain, and troubleshoot Struora.
- Authenticate users and enforce tenant isolation and permissions.
- Process subscriptions, invoices, payments, and account administration.
- Send service messages, invitations, security alerts, and support responses.
- Comply with law, enforce agreements, prevent fraud, and protect users and the platform.
- Improve accessibility, reliability, and product functionality using information permitted by your choices and applicable law.
Where applicable, our legal bases may include performing a contract, complying with legal obligations, protecting legitimate interests such as service security, and consent for optional technologies or communications.
4. How we disclose information
We may disclose information to the customer organization that controls the relevant workspace; authorized users selected by that customer; vendors that provide hosting, storage, email delivery, payments, content delivery, security, and support; professional advisers; and public authorities when legally required. Depending on enabled features, providers may include Vercel, Stripe, Resend, Google Fonts, and jsDelivr.
We do not sell personal information or share it for cross-context behavioral advertising. If this practice changes, we will update this policy and provide any legally required choices before beginning that use.
5. Tenant isolation
Each customer workspace is identified by its tenant context and protected through authentication and authorization controls. Users should access only the workspace and records authorized by their organization. Customers are responsible for configuring roles, invitations, and access appropriately.
6. Retention
We retain information for as long as needed to provide the service, maintain security and audit records, meet contractual and legal obligations, resolve disputes, and enforce agreements. Retention varies by data type and customer instructions. Account and workspace data may remain in active systems and limited backups for a reasonable period after deletion. Browser-storage retention is listed in the Cookie Policy.
7. Security
We use technical and organizational safeguards designed to protect information, including encrypted transport, secure authentication cookies, tenant-aware access checks, password hashing, permissions, and controlled backup processes. No system is completely secure, and users should protect their credentials and report suspected misuse promptly.
8. International processing
Struora and its providers may process information in countries other than where a user lives. Where required, we use contractual or other recognized safeguards for international transfers.
9. Your choices and rights
Depending on your location, you may have rights to access, correct, delete, restrict, object to, or obtain a copy of personal information, and to withdraw consent. You can revise browser-storage choices through Privacy choices. Requests involving customer workspace content should normally be directed to the customer organization first.
To submit a privacy request to Struora, email privacy@struora.com. We may need to verify the request and may retain information where permitted or required by law.
10. Children
Struora is a business operations service and is not directed to children. We do not knowingly collect personal information from children in violation of applicable law.
11. Changes
We may update this policy as our service or legal obligations change. We will post the revised version with a new effective date and provide additional notice when required.
12. Contact
Questions or privacy requests may be sent to privacy@struora.com.
