CoiLoop

Legal

Privacy Policy

Last updated: June 24, 2026

This Privacy Policy describes how CoiLoop("we," "us," or "our") collects, uses, and shares information when you use our website and software service at coiloop.com(the "Service"). By using the Service, you agree to this policy.

Who we serve

CoiLoop is a business tool for general contractors and their teams. Subcontractors may upload documents through magic links you send without creating a CoiLoop account.

Information we collect

Account and organization data

When you sign in and use the dashboard, we collect:

  • Email address and authentication identifiers (via magic-link sign-in)
  • Organization name, team membership, and role
  • Profile information you provide (such as display name or avatar)

Business data you enter

To operate COI tracking, we store data you and your team submit, including:

  • Subcontractor names, emails, trades, broker contacts, and notes
  • Project names and insurance requirement settings
  • Document metadata: type (COI, W-9, workers' comp exemption), status, expiration dates, and review notes
  • Activity related to invitations, uploads, approvals, and reminders

Documents and files

The Service stores files you or subcontractors upload - typically insurance certificates, endorsements, W-9s, and related PDFs. These may contain personal and business information about subcontractors, their insurers, and your projects. Treat uploaded content as confidential business records.

Subcontractor uploads without an account

When a subcontractor uses a magic upload link, we collect the files they submit and limited technical data (such as upload timestamps and token usage) needed to route documents to the correct general contractor account. We do not require subs to create a standing user account.

Payment information

If you subscribe to a paid plan, payment card and billing details are processed by Stripe. We do not store full card numbers on our servers. Stripe's handling of payment data is governed by Stripe's privacy policy.

Technical and usage data

We automatically collect standard log and device data when you use the Service - for example IP address, browser type, pages requested, and error logs - to secure the Service, debug issues, and improve reliability.

How we use information

We use collected information to:

  • Provide, maintain, and improve the Service
  • Authenticate users and enforce access controls
  • Store, organize, and display documents and compliance status for your organization
  • Send transactional messages (sign-in links, upload confirmations, expiration reminders)
  • Process subscriptions and billing when applicable
  • Detect abuse, fraud, and security incidents
  • Comply with law and enforce our Terms of Service

We do not sell your personal information.

How we share information

We share information only as needed to run the Service:

  • Infrastructure providers - hosting, database, authentication, and file storage (for example Supabase and Vercel)
  • Payment processor - Stripe, when you pay for a subscription
  • Email provider - to deliver transactional email (for example sign-in and reminder messages), when enabled
  • Within your organization- team members you authorize can see your organization's projects, subcontractors, and documents
  • Legal requirements - if required by law, regulation, legal process, or to protect rights, safety, and security

Service providers are permitted to use data only to perform services for us.

Data retention

We retain account and business data while your organization uses the Service and as needed to provide the Service, comply with law, resolve disputes, and enforce agreements. You may request deletion of your account and associated organization data by contacting us.

Your choices

  • Update organization and profile information in the dashboard where available
  • Control which team members have access through your account settings
  • Request access, correction, or deletion by emailing us (see Contact)

Security

We use reasonable administrative, technical, and organizational measures designed to protect information. No method of transmission or storage is completely secure; we cannot guarantee absolute security.

Children

The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13.

International users

The Service is operated from the United States. If you access the Service from outside the United States, you understand that information may be processed and stored in the United States and other countries where our providers operate.

Changes to this policy

We may update this Privacy Policy from time to time. We will post the updated policy on this page and update the "Last updated" date. Material changes may also be communicated by email or in-product notice where appropriate.

Contact

Questions or data requests: help@coiloop.com.