Privacy policy
1. Who we are
costin is job management software for builders, made by site software Ltd, a company registered in England and Wales (company number 17471847), registered office 8 Mostyn Road, Bushey, Hertfordshire, WD23 3PN. In this policy, “we”, “us” and “our” mean site software Ltd.
We are registered with the Information Commissioner’s Office (ICO), registration number ZC263204.
For anything about your personal data, email privacy@costin.app.
2. Two different roles
We handle personal data in two different capacities, and it matters which one applies to you.
| Whose data | Our role |
|---|---|
| People who visit costin.app, register interest, or use costin as a named login at a building firm | Controller. We decide how and why this data is used. This policy explains it. |
| People whose details a building firm keeps in costin: its customers, employees, subcontractors, suppliers and contacts | Processor. The building firm is the controller and decides what is kept and why. We only store and process it on the firm’s instructions, under our terms of service. If you are one of those people, please contact the building firm first. We will pass any request we receive to them. |
3. What we collect, and why
If you register interest or email us
Your name, email address, company name and anything you choose to tell us. We use it to reply, to tell you when early access opens, and to understand what builders need. Lawful basis: our legitimate interest in answering enquiries and building the product, or your consent where we ask for it.
If you have a login to costin
- Account details: name, email address, the firm you work for and your role in it.
- Sign-in records: when you signed in and were last active, the type of device and browser, and the internet (IP) address used, so you and your firm can see where a login is in use and sign out a lost device. We also record failed sign-in attempts (the email address tried and the IP address) to protect accounts against guessing.
- Passwords are stored only as a one-way scrambled form (a “hash”). We cannot read them, and nobody at site software Ltd ever asks for your password.
- Support: anything you send us when asking for help, including, where your firm agrees, a copy of a document that wasn’t read correctly (see section 5).
Lawful basis: performing our contract with your firm, and our legitimate interest in keeping accounts secure.
If your firm pays for costin
The billing contact’s name, email and billing address, and records of invoices and payments. Card details and bank details for Direct Debit are handled by a payment provider and are never stored by us; we will name it here before we take any payment. Lawful basis: contract, and our legal duty to keep financial records.
4. Cookies
The costin.app website does not use cookies for advertising, tracking or analytics. The costin app itself sets one essential cookie that keeps you signed in. It is needed for the app to work, so no consent banner is required for it.
5. Who we share data with
We do not sell personal data, and we do not use it for advertising. We use a small number of suppliers to run costin:
| Supplier | What for | Where |
|---|---|---|
| Fly.io, Inc. | Hosting the app, its database, documents and backups | London, UK data centre. Fly.io is certified under the UK Extension to the EU–US Data Privacy Framework. |
| Cloudflare, Inc. | Domain name service for costin.app, hosting this website, and keeping an off-site copy of each nightly backup | Backups: the EU, locked (encrypted) on our servers before they are sent, so Cloudflare cannot read them. Otherwise its global network. |
| Microsoft (Microsoft 365) | Receiving and answering emails to costin.app addresses | UK data centres |
| Resend (Plus Five Five, Inc.) | Delivering the emails a builder sends from costin (invoices, quotes, orders, progress updates), with the attached PDF | Sent from Ireland (EU). Covered by Resend’s Data Processing Agreement. |
| Xero or Intuit (QuickBooks) | Only if your firm connects its accounting software: invoices, bills and the matching contacts are sent to that firm’s own accounts, and whether an invoice has been paid is read back | Under Xero’s or Intuit’s own terms |
Reading supplier invoices, making PDFs and making backups all happen on our own servers. The documents are not sent to any outside or AI service to do this.
A building firm can send its own customer a progress update from costin: the progress notes and photos from that job’s site diary, on a private link. Only what the firm marks for sharing is included, and the firm decides who receives the link.
If a firm chooses to send us a document that costin read incorrectly, so we can improve the reading, a copy is kept only until we have looked at it, and then deleted.
We may also share data where the law requires it, or to protect the rights and safety of our users, or as part of a sale or reorganisation of the business (in which case this policy would continue to apply).
6. Outside the UK
costin’s data is stored in the UK, with an encrypted off-site copy of the backups in the EU. Some of our suppliers are based in the United States and may access data from there, for example to provide technical support. Where that happens we rely on the safeguards the law requires, such as the UK International Data Transfer Addendum or the UK Extension to the EU–US Data Privacy Framework. Fly.io and Cloudflare are both certified under the UK Extension.
7. How long we keep it
- Register-interest emails: until you ask us to stop, or 12 months after we last contact you.
- Account details: while your firm uses costin. A sign-in record is removed when it expires, 30 days after the login was last used. Failed sign-in attempts are removed after an hour.
- Billing records: six years, as HMRC requires.
- Backups: each app is backed up nightly. Backups roll off automatically, within 30 days on the servers, within 60 days in our encrypted off-site copy, and within 8 weeks in our offline copy.
- When a firm leaves costin, its data is deleted as set out in our terms of service.
8. Keeping it safe
All connections use encryption (HTTPS). Each building firm has its own separate copy of the app and its own database, so one firm’s data is never stored alongside another’s. Logins have roles, so site staff don’t see prices or wages unless their firm allows it. Backups are checked when they are made. The off-site copy is encrypted before it leaves our servers, and offline copies are kept on encrypted equipment.
9. Your rights
You can ask us for a copy of your personal data, and ask us to correct it, delete it, restrict or object to how we use it, or to move it to another provider. Where we rely on consent, you can withdraw it at any time. Email privacy@costin.app. We will reply within one month.
If you are unhappy with how we have handled your data, you can complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113. We would appreciate the chance to put things right first.
10. Changes
We will update this page if how we handle personal data changes, and tell account holders by email about anything significant.
