Legal

Privacy Policy

Last updated: August 23, 2026

1. Overview

HazProof is a product of Opynbox LLC (“Opynbox,” “HazProof,” “we,” “us,” or “our”). HazProof provides construction safety-management software, including a web application at hazproof.com and an iOS field app for jobsite work (JHAs, meetings, inspections, and observations).

This Privacy Policy explains what information we collect, how we use it, who we share it with, and the choices you have.

Our two roles. When you create or accept an invitation to a HazProof account, we act as a data controller for your login and profile. When a contractor uses HazProof to run its safety program (employees, JHAs, incidents, photos, and similar records), that organization is the controller of that workplace data and HazProof acts as a processoron its behalf. If you are a worker whose information is in a customer’s workspace, please also contact your employer with privacy requests.

2. Information We Collect

We collect the following categories of information. Most of it is stored in our Supabase Postgres database and scoped to a single organization with row-level security.

Account information

AccountName, email address, and authentication credentials handled by our sign-in provider (Clerk). We do not store your password.
ProfileRole (for example field worker, supervisor, safety manager, or admin), organization membership, and optional profile details your employer stores.
InvitesHazProof is invite-only. We collect the email address an administrator invites and the status of that invitation.

Workplace & safety records (entered by your organization)

PeopleEmployee names, job titles, employee numbers, training and certification records, and related roster data.
Jobsite recordsProjects, JHAs, meetings, inspections, observations, incidents, action items, equipment, and signatures associated with that work.
Photos & filesCrew photos, inspection and observation evidence, and other files your organization uploads.
LocationOptional precise location when the iOS app stamps a field record or photo (When In Use only). You can deny location permission on the device.

iOS field app

DevicePush notification device tokens if you allow notifications, and technical diagnostics needed to deliver the app and over-the-air web updates.
Face IDIf you enable Face ID, biometric unlock stays on your device via the iOS Keychain. We do not receive or store Face ID templates.
Offline draftsThe field app may store catalogs and unsynced JHAs on the device until they can be sent to our servers.

Information collected automatically

When you use the product, we and our infrastructure providers may collect technical data such as IP address, device and browser type, log and diagnostic data, and essential cookies or session tokens used to keep you signed in. We do not use third-party advertising SDKs in the iOS app.

3. How We Use Information

We use the information described above to:

  • Provide, operate, and secure the HazProof web and iOS applications.
  • Authenticate users, enforce organization access, and send invite or security emails.
  • Store and display safety records your organization creates, including signatures and evidence photos.
  • Power optional AI features (for example JHA assist or insights) when an organization uses them.
  • Deliver over-the-air updates to the iOS field client (JavaScript and styling only).
  • Maintain security, prevent abuse, debug issues, and comply with legal obligations.
  • Send product or account communications. You can ask us to stop non-essential email by contacting us.

We do not sell personal information, and we do not use customer workplace data for advertising.

4. How We Share Information

We share information with service providers (subprocessors) that help us run the platform. Each is bound by contractual confidentiality and data-protection obligations and only receives the data needed to perform its function:

ClerkAuthentication, session management, and invite/sign-in emails.
SupabaseDatabase, file storage, and related backend services.
VercelApplication hosting and content delivery.
OpenAIOptional AI features (for example generating JHA assistance or embeddings). Prompt content needed for that request is sent to the provider. We use API settings intended to exclude your content from training the provider’s models where the provider offers that control.
Payment processorsIf you purchase a paid subscription, billing details are handled by our payment processor. We do not store full card numbers.

We may also disclose information to comply with the law, enforce our terms, protect our rights and safety, or in connection with a merger, acquisition, or sale of assets (with notice where required). Your organization’s administrators can access workplace records in that organization.

5. Data Retention

We retain account and organization data for as long as the organization’s HazProof workspace is active or as needed to provide the service. When a record is deleted by an authorized user, or when we complete a verified deletion request, we delete or anonymize the associated data within a reasonable period, except where we must retain it to comply with legal, accounting, safety, or security obligations (for example records an employer must keep under OSHA or similar law).

Offline copies on a phone are removed when the user signs out or the device storage is cleared, subject to ordinary device backups.

6. Security

Every data record is scoped to a single organization and protected by database row-level security, so customers can only access their own data. Data is encrypted in transit. Access to administrative tools is restricted. No method of transmission or storage is 100% secure, but we work to protect your information using industry-standard safeguards.

7. Your Rights & Choices

Depending on where you live, you may have rights to access, correct, export, or delete your personal information, and to object to or restrict certain processing. To exercise these rights:

  • Account holders: ask your organization administrator to deactivate or remove your user, or email us at privacy@hazproof.com. HazProof accounts are employer-provisioned; there is no public self-serve sign-up.
  • Workers whose data is in a customer workspace: contact your employer (the controller of that workplace data), or reach us and we will route your request to the organization.
  • iOS app:you can sign out, turn off Face ID, and deny camera, photos, location, or notification permissions in iOS Settings. Signing out does not delete your employer’s HazProof account.

We will respond to verified requests within the time required by applicable law.

8. Cookies

We use essential cookies and similar technologies to keep you signed in and to keep the product secure. We do not use third-party advertising cookies. You can control cookies through your browser settings, though disabling essential cookies may break sign-in.

9. Children's Privacy

HazProof is a workplace product for construction organizations and is not directed to children under 16 (or the minimum age required in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.

10. International Users

HazProof is operated by Opynbox LLC from the United States, and your information may be processed in the United States and other countries where our service providers operate. We take steps to ensure appropriate safeguards are in place for such transfers.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, provide additional notice.

12. Contact Us

Questions about this policy or your data? Email privacy@hazproof.com. Related terms are at hazproof.com/terms.

Opynbox LLC · HazProof