Privacy Policy
Reconstro
Effective: 10 August 2026 · Last updated: 10 August 2026
1. Who we are
Reconstro is a construction-management platform: a web app at reconstro.com and mobile apps for iOS and Android. It is operated by RECONSTRO LIMITED, a company registered in England and Wales (company number 17363168), registered office Registered office address available on request from privacy@reconstro.com, and on the public register at Companies House (company 17363168)..
In this policy, "we", "us" and "Reconstro" mean RECONSTRO LIMITED. "You" means anyone who uses the app.
Contact for any privacy question or request: privacy@reconstro.com General support: support@reconstro.com
2. The two different roles we play — please read this first
Reconstro holds two very different kinds of personal data, and our responsibility differs for each.
(a) Data about you, because you use Reconstro. Your name, email, phone number, profile photo, what you tapped, which device you used. For this we are the data controller — we decide why and how it is used, and this policy governs it.
(b) Data a business puts into Reconstro about other people. When a contractor records a client's phone number, a staff member's salary, or a supplier's address, that data is about someone who may never have opened our app. For this the contractor is the data controller and we are only the data processor — we hold and process it on their instructions and do not decide what it is used for.
If you are a client, a staff member, or a supplier and want to know what a contractor holds about you, ask that contractor. If they cannot help, write to privacy@reconstro.com and we will point you to the right controller. Contractors who need our written processor terms can request the Data Processing Addendum from privacy@reconstro.com.
3. What we collect, and why
The "legal basis" column is the ground we rely on under UK and EU GDPR to process each kind of data.
Data you give us
| What | Examples | Why | Legal basis |
|---|---|---|---|
| Account details | Name, email address, phone number, password (stored only as a hash), profile photo | Create and secure your account, sign you in, show who you are to your team | Performance of a contract |
| Staff sign-in identifiers | The short "YouCode" a contractor issues to a staff member, and a generated first password | Let staff sign in without a personal email address | Performance of a contract |
| Business and project records | Projects, stages, tasks, reminders, budgets, cost estimates, transactions, notes, offices and zones | Deliver the service you signed up for | Performance of a contract. We act as processor where the record is about a third party — see §2b |
| People records | Client, staff and supplier names, phone numbers, addresses, roles, pay data | Deliver the service | Processor — the contractor is the controller |
| Files you upload | Receipt photos, activity photos, project documents, business logos, storefront photos | Attach evidence to records, and display your storefront | Performance of a contract |
| Public content | Showcase posts, product and work listings, comments, reviews, storefront details | Publish what you chose to publish | Performance of a contract, and legitimate interests |
| Messages | In-app chat with your staff, clients and suppliers, and business enquiries | Deliver the messaging feature | Performance of a contract |
| Reports you file | A report about a post or a review, and the reason you gave | Investigate and moderate, and keep the platform safe | Legitimate interests (platform safety), and legal obligation |
| Support correspondence | Emails you send us | Answer you | Legitimate interests |
Data collected automatically
| What | Examples | Why | Legal basis |
|---|---|---|---|
| Technical and device data | IP address, device type and OS version, app version, device language and region | Run and secure the service, detect abuse, and rate-limit | Legitimate interests |
| Approximate location from IP | Your approximate area, worked out from the IP address of the request by a geolocation provider | Decide which languages, currency and payment options to show | Legitimate interests |
| Push notification token | The notification token for your device, and its language | Send the notifications you enabled | Consent (you grant notification permission) |
| Diagnostic and request logs | Errors, HTTP status codes and route names, and the IP address and browser or device user-agent of each request | Fix faults, and detect abuse | Legitimate interests |
| Website analytics | On reconstro.com only: a cookieless daily-unique count of visits. No cross-site tracking, no advertising identifiers | Understand how many people visit | Legitimate interests |
About those logs, to be specific: an IP address is personal data, and we treat it as such. We do not log tokens, passwords or request bodies. Logs are kept on the server for 14 days and are then overwritten.
Device permissions the mobile app asks for
We ask only when the feature needs it, and the app works without them (that feature simply stops).
| Permission | Used for | If you refuse |
|---|---|---|
| Photos / media library | Choosing a profile photo, a receipt image, or a storefront photo | You cannot attach photos; nothing else changes |
| Precise / approximate location | Only while you have the map picker open, to centre the map on where you are when setting a project or business address | The map opens at a default position; type the address instead |
| Notifications | Push alerts for messages, reminders and payment events | No push notifications |
We do not track your location in the background, and we do not use location for advertising.
What we never collect
- Card numbers, CVV codes or bank credentials. Payments run entirely on our payment providers' own hosted pages. Card data never reaches our servers. We receive only a payment reference, the amount, the currency and a success/failure status.
- Advertising identifiers (IDFA / GAID). Reconstro shows no adverts and runs no ad SDKs.
- Special category data (health, religion, biometrics, political opinions) — we do not ask for it and no feature collects it. Please do not put it in free-text fields.
- Identity documents. We do not ask you to upload a passport, driving licence or national ID anywhere in the product.
4. Who we share data with
We do not sell personal data, and we do not share it for advertising. We use a small set of service providers ("sub-processors"), each contractually bound to protect it:
| Category of provider | What they handle |
|---|---|
| Hosting and infrastructure | Running the service and storing your data |
| Payment providers | Taking payment; card details go to them, never to us |
| App stores | Purchases made inside the mobile apps |
| Email delivery | Verification codes, password resets, receipts |
| Push notifications | Delivering alerts to your device |
| Maps and location | Showing a map and turning a picked point into an address |
| Sign-in providers | Only if you choose to sign in with an external account |
You can ask us at privacy@reconstro.com for the current list of named providers.
We also share data:
- With your own organisation. Your contractor and the colleagues they authorise can see your activity inside the workspace. A workspace is not private from its owner.
- Where you publish it. Anything you post to a Showcase storefront, a public listing, a comment or a review is public by design — see §5.
- When the law requires it, or to establish, exercise or defend legal claims.
- In a business sale or merger, to the acquirer, under equivalent protection.
5. Files, and what is public
Please read this before you upload anything.
Every file you upload — including receipt photos, activity photos and project documents — is served from a long, unguessable web address. Files are never listed or indexed unless you publish them yourself, but anyone who has the exact address can open the file without signing in.
So do not upload anything you would not be willing to share by sending someone a link.
We are describing what the system does today rather than what we would like it to do. If this changes — for example if the file store moves to signed, expiring links — this section will be updated and the change noted in §13.
6. Public content and moderation
Showcase posts, storefronts, comments and reviews are visible to anyone, including people with no Reconstro account, and may be indexed by search engines. A public post carries your business name and may carry your logo and photos.
You can delete or unpublish your own content at any time. Copies may persist briefly in CDN caches, and search engines may keep their own snapshots we do not control.
Content reported as breaching our acceptable-use rules — and the report itself — is reviewed by our moderation team. We keep records of reports and enforcement actions so we can apply rules consistently and evidence them if challenged.
7. Administrative access and "view as"
Our platform operators can, when investigating a fault or a safety report, view a workspace as that tenant would see it. This is restricted to a small number of staff and requires an elevated session that is separately authorised.
To be precise about what is recorded: administrative actions that change data are written to an audit log. Entering a workspace and reading it — projects, ledgers, messages — is not itself written to that audit log today. We are stating this plainly rather than claiming an audit trail that is wider than the one we keep. We use this access to support and protect the service, not to browse your data.
8. International transfers
We are based in the United Kingdom and serve customers worldwide, so some of the providers in §4 operate outside the UK and the EEA. Where personal data is transferred out of the UK or EEA, we rely on the UK International Data Transfer Addendum or the EU Standard Contractual Clauses, together with encryption in transit.
Ask us at privacy@reconstro.com for details of the safeguards in place.
If where your data is physically stored matters to your business, please read this section before you sign up rather than after.
9. How long we keep it
| Data | Retention |
|---|---|
| Account and profile | While your account is open. When you close it, the account is closed at once and the data is permanently erased 30 days later |
| Business and project records | While the workspace is active, then as instructed by the contractor who controls them |
| Financial and transaction records | Up to 7 years after the transaction, to meet UK tax and accounting law — this survives account deletion |
| Chat messages | While the conversation exists, or until deleted by a participant |
| Public Showcase content | Until you unpublish or delete it |
| Content reports and moderation decisions | 2 years after the decision |
| Diagnostic and request logs | 14 days on the server, then overwritten |
| Push notification tokens | Until the device unregisters or you sign out |
Deleted data can survive in encrypted backups for up to a further 90 days, until those backups age out on their normal cycle. To ask about deletion, write to privacy@reconstro.com.
10. Your rights
Under UK and EU data protection law you can ask us to:
- Access the personal data we hold about you, and get a copy.
- Correct anything inaccurate — most of it you can edit yourself in Settings.
- Delete your data ("right to be forgotten"). Some records must survive deletion because the law requires us to keep them — see §9 for what those are and for how long we hold them.
- Restrict or object to processing based on our legitimate interests.
- Port your data to another provider in a machine-readable format.
- Withdraw consent at any time, where consent was the basis — e.g. turn off notifications.
Write to privacy@reconstro.com. We reply within 30 days. There is no charge unless a request is manifestly unfounded or excessive.
Remember §2b: if the data is about you but was entered by a contractor, we must forward your request to them rather than act on it ourselves.
11. Security
We protect your data with: encryption in transit (HTTPS/TLS everywhere — the apps refuse plain HTTP), hashed passwords, short-lived access tokens held in the device keychain/keystore, a refresh token kept in an HttpOnly cookie the browser's scripts cannot read, strict tenant isolation enforced on the server for every request, role- and permission-based access control, rate limiting, audit logging of administrative actions that change data, and logs scrubbed of credentials, tokens and request bodies.
We do not claim blanket "encryption at rest" for the whole database, because we will not assert a control we have not verified end to end. Files on the CDN are covered by §5 above.
No system is perfectly secure. If a breach is likely to result in a risk to your rights, we will notify the ICO within 72 hours and tell you without undue delay.
12. Automated decision-making
We do not make decisions with legal or similarly significant effects about you by automated means, and we do not profile you for advertising.
13. Changes
We will update this policy as the product changes. The "Last updated" date at the top always reflects the current version. For material changes we will notify you in-app or by email before they take effect. Continuing to use Reconstro after that means you accept the updated policy.
14. Contact
RECONSTRO LIMITED Registered office address available on request from privacy@reconstro.com, and on the public register at Companies House (company 17363168). Registered in England and Wales · Company number 17363168
Privacy: privacy@reconstro.com · Support: support@reconstro.com · Web: reconstro.com