Skip to policy content
Beacon

Beacon Work Privacy Policy

Effective date:

1. Scope of this policy

Beacon provides Beacon Work, a connected software suite consisting of the Beacon app, Command, and Estimator.

This Privacy Policy explains how Beacon (“Beacon,” “we,” “us,” or “our”) collects, uses, discloses, retains, and protects personal information in connection with Beacon Work.

This policy applies to Beacon Work services that link to it, including the Beacon app, Command, Estimator, and their related authentication, billing, Beacon Mail, file, API, and Model Context Protocol features.

Beacon Work is currently offered to United States business customers.

In this policy:

  • A “Customer” is a business or organization that creates or uses a Beacon Work workspace.
  • A “User” is a person authorized to access Beacon Work through a Customer.
  • “Customer Content” means information that a Customer or User submits, imports, sends, receives, or generates through workspace features. Customer Content does not include account, billing, security, or operational records that Beacon creates and maintains for the purposes described in this policy.

This policy also covers visitors to Beacon websites that link to this policy, workspace invitees, email correspondents, people who contact Beacon, and other individuals whose personal information Beacon handles.

For account, billing, support, security, and operational information, Beacon determines the purposes described in this policy. For Customer Content, the Customer determines what information is submitted and how it is used for the Customer’s business, while Beacon processes that information to provide, secure, maintain, and support Beacon Work, comply with applicable law, and follow the Customer’s instructions.

This policy does not govern a third party’s independent handling of information after a Customer or User chooses to connect, authorize, or visit that third party. This policy does govern Beacon’s collection and disclosure of information when enabling that connection.

2. Information Beacon collects and processes

The information Beacon collects and processes depends on which Beacon Work applications and features are used.

Beacon may receive information directly from Customers, Users, visitors, or people who contact Beacon; automatically from devices and services; from workspace administrators, invitees, email correspondents, and other people; and from providers or Customer-configured integrations.

Account and profile information

When a User creates or accesses a Beacon Work account, Beacon may collect:

  • Email address.
  • Display name.
  • Profile-image URL.
  • Authentication provider.
  • Authentication-provider account identifier.
  • Workspace memberships and roles.
  • Application access and permissions.
  • Last-selected workspace.
  • Account creation, update, access, and revocation timestamps.

Beacon uses Google and Microsoft for account authentication. Those providers authenticate the User and may provide information such as a verified email address, stable account identifier, display name, and profile-image URL.

Beacon does not receive or store the User’s Google or Microsoft password as part of authentication.

A profile image may be hosted outside Beacon. When an externally hosted profile image is displayed, its host may receive standard request information such as the requesting Internet Protocol address, browser information, and request time.

Workspace, membership, and invitation information

Customers and workspace administrators may provide:

  • Workspace name and identifier.
  • Workspace owner and administrators.
  • Member and invitee email addresses.
  • Roles and application access.
  • Invitation status and delivery information.
  • Seat assignments and subscription access.
  • Membership activity and administrative decisions.

A workspace administrator may provide another person’s email address when inviting that person to Beacon Work.

Command information

Through Command, Beacon may process Customer Content such as:

  • Contact and prospect names.
  • Primary and additional email addresses.
  • Telephone numbers.
  • Notes and custom fields.
  • Property and business addresses.
  • Structured address components and property coordinates.
  • Address-provider identifiers and related provider metadata.
  • Projects, tasks, assignments, reviewers, priorities, due dates, and status history.
  • Group and database records.
  • Descriptions, documents, revisions, and other work product.
  • External references and links.
  • Activity, inbox, search, and notification information.

Property coordinates describe a selected property or project location. Beacon does not use those coordinates to track a User’s device in real time.

Custom fields, notes, documents, and uploaded files can contain other information selected by the Customer.

Beacon Mail and communications

When Beacon Mail is used, Beacon and Postmark may process:

  • Sender and recipient names and email addresses.
  • To, CC, and BCC recipients.
  • Message subjects.
  • Plain-text and HTML message bodies.
  • Attachments.
  • Email headers and threading information.
  • Message and conversation identifiers.
  • Delivery, bounce, complaint, and failure information.
  • Drafts and response templates.
  • Related project or conversation metadata.

Inbound email may be sent by people who do not have Beacon Work accounts.

If Beacon cannot safely or reliably assign an inbound message, Beacon may store the message and its attachments in workspace quarantine for administrator review. Quarantine status does not itself delete the content. The message remains Customer Content subject to Customer action and applicable workspace-retention and deletion processes.

Beacon configures messages it sends through Postmark not to request open or link tracking. Beacon still processes operational events such as delivery, bounce, spam-complaint, and failure records.

Inbound HTML email may contain links or remote images controlled by the sender. The handling of remote email images is described in Section 4.

Estimator information

Through Estimator, Beacon may process information such as:

  • Customer or project name.
  • Lead, job, project, and session identifiers.
  • Property address.
  • Roof structures, dimensions, measurements, and adjustments.
  • Uploaded measurement reports.
  • Materials, quantities, labor, pricing, discounts, and estimate totals.
  • Product and supplier information.
  • Workflow notes and activity history.
  • Vendor quotes and material invoices.
  • Signed estimates and contracts.
  • Crew scopes of work.
  • Generated estimates, reports, production packets, and PDF documents.
  • Names of people who prepare, sign, or approve documents.

This information may describe a home, property, project, transaction, or Customer relationship even when the property owner does not personally use Beacon Work.

Files and documents

Through Beacon Work, Beacon may process:

  • Original and displayed filenames.
  • File types and sizes.
  • File checksums.
  • Creator and workspace associations.
  • Upload and generation timestamps.
  • Storage and cleanup status.
  • Uploaded or generated file contents.
  • Externally linked file locations.

Files may include PDFs, images, reports, contracts, invoices, email attachments, generated documents, and other Customer-selected materials.

Billing and subscription information

Beacon uses Stripe for checkout, subscriptions, billing management, and eligible transaction processing.

Payment-card details, billing addresses, tax information, and other payment information are entered into and processed by Stripe. Beacon does not receive or store complete payment-card numbers in its billing systems.

Beacon may receive and retain:

  • Billing contact email.
  • Stripe customer, checkout, subscription, price, and transaction identifiers.
  • Subscription plan, quantity, and status.
  • Amount and currency.
  • Billing and renewal dates.
  • Checkout and transaction status.
  • Refund and dispute information.
  • Operational records needed to reconcile billing activity.

Connected services and integrations

When a Customer or User enables a connected service, Beacon may receive information from or send information to that service according to the Customer’s settings and instructions.

This includes:

  • Google Places. When address search is used, Google may receive the address query, geographic search restriction, temporary search-session identifier, and selected place identifier. Beacon receives and may retain a structured address, property coordinates, the provider place identifier, and related provider metadata.
  • Customer-configured integrations and delivery endpoints. A Customer may configure Beacon Work to exchange information with an automation service, configured web endpoint, or connected product. Depending on the configuration, Beacon may receive or send workspace, project, job or session identifiers; status changes; external references; selected documents; job or folder identifiers; delivery results; and other fields or documents the Customer maps or selects.
  • Model Context Protocol clients. Model Context Protocol, or “MCP,” is a connection method that lets compatible applications—including AI-enabled applications—request authorized Beacon Work information or actions. A User may authorize an MCP-compatible application according to the User’s workspace access, the authorization granted, and any required confirmation.
  • External file and document destinations. Customers may store links to or deliver documents into systems they select, including Microsoft, Google, or other compatible services.

Estimator requires Customer-configured Lead-intake and document-delivery endpoints to use valid HTTPS URLs before Beacon will treat those endpoints as ready or transmit information to them.

HTTPS helps protect information while it is transmitted to the configured endpoint. It does not mean Beacon has reviewed, approved, or controls the endpoint’s security, privacy practices, or handling of information after receipt. The Customer selects and configures the external service or destination.

An external MCP client or other Customer-selected service handles information it receives under its own settings, terms, and privacy practices.

Technical, security, and operational information

When Beacon Work is accessed, Beacon and its providers may process technical information such as:

  • Internet Protocol address.
  • Request and connection metadata.
  • Application or service accessed.
  • Request time and response status.
  • Session identifiers and authentication state.
  • Workspace and User identifiers.
  • Security and rate-limiting information.
  • Action and activity records.
  • Error codes and diagnostic context.
  • Provider delivery and event identifiers.

Beacon hashes an IP-derived value used for certain rate-limiting purposes.

Operational logging is designed to redact common secrets and personal-information fields, but no automated redaction system can guarantee that unexpected information is never included in a log.

Information provided directly to Beacon

If you contact Beacon, Beacon collects your email address, the contents of your message, any attachments, and other information you choose to provide.

Beacon uses this information to respond to support, account, security, infrastructure, or privacy requests.

Messages sent directly to Beacon are routed and stored using email-routing and mailbox providers.

3. How Beacon uses information

Beacon uses personal information to:

  • Provide and operate Beacon Work.
  • Authenticate Users and maintain account sessions.
  • Create and administer workspaces, memberships, roles, and permissions.
  • Deliver invitations and account notices.
  • Provide projects, tasks, databases, contacts, email, files, estimates, and documents.
  • Process subscriptions, billing, refunds, and disputes.
  • Complete Customer-configured integrations and workflows.
  • Maintain activity history and workspace accountability.
  • Communicate about accounts, billing, support, security, and service changes.
  • Prevent spam, fraud, unauthorized access, and other abuse.
  • Enforce rate limits and security controls.
  • Troubleshoot errors and maintain service reliability.
  • Investigate security or operational incidents.
  • Respond to support, account, and privacy requests.
  • Enforce applicable agreements.
  • Comply with legal obligations and valid legal process.

4. How Beacon discloses information

Beacon may disclose personal information in the following circumstances.

Within a Customer workspace

Information may be available to the Customer and its authorized Users according to their roles, group memberships, application access, and content permissions.

Workspace owners and administrators may receive information needed to administer Users, memberships, licenses, security, and workspace access.

Messages and documents are disclosed to recipients selected by the User sending or delivering them.

Providers and integrated services

Beacon relies on infrastructure providers, operational service providers, and integrated services. Depending on the function, a provider may process information on Beacon’s behalf or independently under its own terms and privacy practices.

Current providers and functions include:

  • Railway for application hosting, databases, object storage, persistent application storage, networking, and platform logging.
  • Stripe for checkout, subscriptions, billing, tax and payment processing, disputes, and the billing portal.
  • Postmark for system notifications and Beacon Mail transport.
  • Google for authentication and Places address search.
  • Microsoft for authentication and account-profile lookup.
  • Email-routing and mailbox providers for messages sent directly to Beacon, including support, security, and privacy requests.

These providers receive information needed to perform the functions on which Beacon Work relies.

When a User interacts directly with a provider—such as during Google or Microsoft authentication or Stripe checkout—the provider may also process information independently under its own privacy notice.

Customer-directed recipients and integrations

Beacon may disclose information when a Customer or User instructs Beacon Work to interact with:

  • An email recipient.
  • An MCP-compatible client.
  • A Customer-configured automation or workflow.
  • A Customer-configured Estimator endpoint for Lead intake or document delivery.
  • An externally linked file service.
  • Another destination expressly configured by the Customer.

Information copied or delivered into a Customer-selected service may remain with that service according to its own retention and privacy practices.

Externally hosted content

Beacon Work may display profile images, links, or other content hosted outside Beacon. The external host may receive standard request information when that content is loaded or selected.

When Command displays an email containing a remote image, Beacon may retrieve the image through a server-side proxy. The remote host can observe that the image URL was requested. The proxy is designed to prevent the remote host from receiving the User’s Internet Protocol address or a Beacon Work page referrer directly.

Beacon does not control the independent collection or use performed by an external content host.

Legal, security, and safety purposes

Beacon may disclose information when reasonably necessary to:

  • Comply with applicable law, regulation, subpoena, court order, or other valid legal process.
  • Protect Beacon, Beacon Work, Customers, Users, or others from fraud, abuse, security threats, or unlawful activity.
  • Investigate or respond to a security incident.
  • Establish, exercise, or defend legal claims.
  • Enforce applicable agreements.

Business transactions

If all or part of Beacon’s operation of Beacon Work, an individual Beacon Work application, or related business assets is involved in a proposed or completed financing, merger, acquisition, reorganization, bankruptcy, sale, assignment, or other transfer, Beacon may disclose relevant personal information to advisers and prospective or actual transaction parties as reasonably necessary to evaluate or complete the transaction.

Beacon may transfer information associated with the affected operations or assets as part of a completed transaction.

Any completed transfer remains subject to applicable law and the privacy commitments applicable when the information was collected, unless those commitments are lawfully changed with any required notice or choice.

5. No sale or behavioral advertising

Beacon does not sell personal information.

Beacon does not disclose personal information for targeted advertising based on activity across unrelated businesses or services, sometimes called cross-context behavioral advertising.

Beacon does not integrate third-party advertising, behavioral-analytics, or session-replay tools into Beacon Work.

Beacon does not itself track Users across unrelated websites or services. Other parties may collect information about a User’s activities over time and across different websites or services when the User directly interacts with their features, follows an external link, loads externally hosted content, or connects a Customer-selected service, as described in Section 4.

Because Beacon does not sell personal information or use or disclose it for cross-site behavioral advertising, browser Do Not Track and Global Privacy Control signals do not change Beacon’s current processing.

Artificial intelligence training

Beacon does not use Customer Content to train artificial intelligence models for Beacon’s own purposes or disclose Customer Content to an artificial intelligence provider for Beacon-directed model training.

A Customer or User may choose to send Customer Content to an external AI-enabled application through MCP or another Customer-configured integration. That provider’s use of the information, including any model-training practices, is governed by its settings, terms, and privacy practices.

6. Cookies and local browser storage

Beacon uses cookies and local browser storage through Beacon Work for authentication, security, temporary workflows, and User preferences.

These technologies may be used to:

  • Maintain a signed-in session.
  • Preserve the selected workspace.
  • Complete authentication or connected-account authorization.
  • Protect account and destructive actions.
  • Complete billing-return flows.
  • Complete MCP review and confirmation flows.
  • Remember theme, navigation, layout, and pinned-item preferences.
  • Prevent duplicate submissions.
  • Recover certain unsaved work.

Beacon’s account sessions are time-limited. Cookie and browser-storage lifetimes vary according to their purpose.

Command may store an unsaved document-recovery copy in a User’s browser and make that copy available for recovery for up to 14 days. Command removes expired copies during a later browser-storage cleanup, so expired data may remain until that cleanup runs or the User clears browser storage.

The recovery copy is not saved as a Command document unless the User saves or submits the changes through Command.

Clearing browser storage may remove local preferences and recovery copies sooner.

Beacon does not use cookies for third-party advertising or behavioral analytics.

Google, Microsoft, Stripe, and other connected services may set their own cookies when a User visits or directly interacts with their websites.

7. Customer-controlled content

Customers and their Users determine what Customer Content they submit, receive, and generate through Beacon Work and can manage that content using the retention and deletion controls Beacon Work provides.

Customers are responsible for using Customer Content lawfully, including providing notices or obtaining permissions when required. Beacon remains responsible for its own processing described in this policy.

If your personal information appears in a Customer workspace but you do not have a Beacon Work account, you may contact that Customer or Beacon.

Because the Customer controls its workspace records, Beacon may coordinate the request with that Customer before disclosing, changing, exporting, or deleting the information.

Beacon does not design Beacon Work to request or require Social Security numbers, complete payment-card numbers, account passwords, medical records, or similarly sensitive information in Customer Content. Customers should avoid placing this information in Beacon Work. If a Customer does include it, Beacon processes it as Customer Content under this policy.

8. Retention and deletion

Beacon retains information according to the type of information, how it is used, the Customer’s instructions, and applicable operational or legal requirements.

Current retention behavior includes:

  • Active account and workspace information is generally retained while needed to provide the active account or workspace.
  • Command and Estimator items placed in Trash remain recoverable for 30 days and then become eligible for deletion from active systems. Deletion may take longer when cleanup is pending or related records must be handled together or preserved.
  • A deleted workspace remains recoverable for 60 days. After that recovery period, it becomes eligible for a coordinated purge across Beacon Work. Different categories of workspace information may be removed at different stages, and completion may wait for required billing, provider, email, file, or application cleanup.
  • Privacy-export download access expires after seven days. Each export link can be used once.
  • Account-erasure requests have a 24-hour cancellation hold. After that hold, Beacon may begin deleting or anonymizing eligible information from active systems, subject to the exceptions and backup lifecycle described below.
  • Certain Beacon application runtime records, such as error and service-event records, have retention schedules of up to 180 days.
  • Certain Beacon-controlled service-health records, such as availability checks, have retention schedules of up to 400 days.
  • Command browser-recovery copies have a 14-day recovery period; deletion occurs during a later browser-storage cleanup.

Some information may be retained longer, including:

  • Billing and transaction records.
  • Security and fraud-prevention records.
  • Activity and audit records.
  • Provider delivery records.
  • Support, security, and privacy-request correspondence.
  • Records establishing that a privacy, deletion, or administrative action was completed.
  • Limited workspace identifiers or Beacon Mail addresses retained to prevent them from being reassigned after deletion.
  • Information needed to enforce agreements, resolve disputes, satisfy legal obligations, or protect Beacon and Beacon Work.

Beacon retains these records only for as long as reasonably necessary for the applicable purpose, subject to operational and legal requirements.

Account erasure does not automatically delete records owned by an active Customer workspace. Beacon may instead remove or anonymize the former User’s identity and attribution while leaving the Customer’s business records under the Customer’s control.

Backup copies, when they exist, may remain until they are overwritten or deleted under Beacon’s or the provider’s normal recovery schedule. They are not used as active Customer records.

Information sent to Stripe, Postmark, Google, Microsoft, an email recipient, an MCP-compatible client, a Customer-configured endpoint, or another Customer-selected service may remain with that recipient subject to its own retention practices and applicable terms.

9. Choices and privacy requests

Users can review or change certain profile information through Beacon Work. Workspace owners and administrators can manage memberships, invitations, roles, and application access.

An account holder may ask Beacon to:

  • Confirm whether Beacon maintains information associated with their Beacon account.
  • Provide a copy of available account information.
  • Correct inaccurate account information.
  • Delete or anonymize eligible account information.
  • Revoke a connected MCP authorization.

A workspace export or workspace-level deletion may be requested only by a verified Customer representative authorized to act for that workspace.

If a person’s information appears only in Customer Content, that person should ordinarily direct the request to the Customer that controls the workspace. Beacon may forward or coordinate the request with that Customer.

Before fulfilling a privacy request involving Customer Content, Beacon will verify the requester’s identity and the requester’s authority to act for the relevant workspace.

To submit a request, email infrastructure@beacon.work. Using “Privacy Request” in the subject line will help Beacon route the request but is not required.

Beacon may need the requester to identify the relevant account, workspace, Customer, or email address.

Some information may not be deleted when retention is reasonably necessary for security, fraud prevention, billing, legal compliance, dispute resolution, enforcement, or protection of other people’s rights.

Beacon will review and respond to requests consistently with applicable law and the relationship among Beacon, the Customer, the User, and the person making the request.

10. Security

Beacon uses administrative, technical, and operational safeguards designed to protect personal information.

These safeguards include access controls, session-security controls, protections for data in transit, encryption for certain credentials and privacy-export archives, rate limiting, logging-redaction controls, abuse prevention, and service-health monitoring.

No online service, storage system, or transmission method can guarantee absolute security.

If a security incident triggers a legal notification obligation, Beacon will provide the notices required by applicable law.

11. Children

Beacon Work is business software and is not directed to children under 13.

Beacon does not knowingly permit children under 13 to create Beacon Work accounts. If you believe a child under 13 has created an account or provided personal information directly to Beacon, contact Beacon at infrastructure@beacon.work.

Customer Content may incidentally contain information about children, family members, or other individuals. The Customer controls that content under Section 7, and Beacon remains responsible for Beacon’s processing described in this policy.

12. Processing locations

Beacon and its providers may process information in the United States and in other locations where those providers operate.

Beacon does not currently offer location-specific data-residency commitments.

13. Changes to this policy

Beacon may update this Privacy Policy to reflect changes to Beacon Work, its providers, its data practices, or applicable requirements.

When Beacon updates this policy, Beacon will post the revised version and update its effective date.

If applicable law requires additional notice before a material change takes effect, Beacon will provide that notice by email, an in-product message, or another prominent method. Beacon may provide additional notice in other circumstances.

Beacon will obtain consent before applying a materially different use to information already collected when applicable law requires it.

14. Contact

For questions about this Privacy Policy or to submit a privacy request, contact:

BeaconEmail: infrastructure@beacon.workSuggested subject line: Privacy Request