CLIENTCAM · PRIVACY
Privacy Policy
In short: ClientCam uses account, job, photo, location and verification data to provide verified photographic evidence. Passwords are handled by Supabase Auth and are not available to ClientCam administrators or company owners.
1. Who we are
ClientCam is a verified photo-evidence service for builders, tradespeople and other business users. For privacy questions or requests, contact info@clientcam.co.uk.
For account and service administration, ClientCam acts as the data controller. Where a company or tradesperson uses ClientCam to record information about its own clients, workers, sites or jobs, that business is generally responsible for deciding why that information is collected and ClientCam processes it to provide the service.
2. Information we process
- Account data: email address, authentication identifiers, display/worker name, account status and sign-in/activity timestamps.
- Company and team data: company name, logo, business contact details, team membership, roles, permissions and invitations.
- Job and client data: client/job name, address, postcode, phone, email, references, work descriptions, private notes, job status, checklist information and site diary entries.
- Evidence data: photographs, imported files, annotations, evidence category, photo notes, capture source, image dimensions/file information, SHA-256 hashes, verification identifiers and server receipt timestamps.
- Location data: GPS coordinates and accuracy where the user grants location permission and location is available. Reverse-geocoded address information may be requested from the location.
- Completion and sharing data: customer sign-off/signature where used, public-share tokens, expiry/revocation status, generated reports and export metadata.
- Technical data: browser/device information needed for operation, security, camera compatibility, PWA/offline storage, service logs and error information.
- Correspondence and support: information you send to us by email or through the ClientCam support form, including your name, reply email, issue description and, where available, the ClientCam page/version, signed-in account identifier and basic browser/device information used to diagnose the problem.
3. Why we use this information
We process personal information to create and secure accounts; provide jobs, evidence capture, verification, reports and sharing; operate teams and permissions; synchronise data between devices; provide support; prevent misuse; maintain service security; and comply with legal obligations.
Our main lawful bases are performance of a contract or steps requested before entering one, legitimate interests in operating and securing ClientCam, and legal obligations where applicable. Where a device asks for camera or precise-location permission, you control that permission through your browser or operating system.
4. Photo verification and location
ClientCam records verification metadata so a stored evidence image can later be checked against the image hash and signed server record. Live capture and imported evidence are intentionally distinguished. GPS is recorded only when available and permitted.
Verification does not independently prove that the subject of a photograph is genuine, that a scene was not staged, or that GPS/device data is infallible. It records and verifies the evidence and metadata received by ClientCam.
5. Who we use to provide ClientCam
We use service providers that process limited information on our behalf or as part of delivering the website and app, including:
- Supabase for authentication, database, private storage and server-side Edge Functions.
- Cloudflare for website hosting, DNS, delivery and security.
- Purelymail for ClientCam business email, including delivery of support-form messages to ClientCam.
- OpenStreetMap / Nominatim for reverse-geocoding coordinates into a suggested address when that feature is used.
- Content-delivery providers used to load limited client-side software libraries needed by the app.
- Microsoft Clarity for optional analytics, heatmaps and session replay when a visitor grants analytics consent. ClientCam uses Clarity project
yerdr8vdkn.
We may also disclose information where required by law, to protect users or the service, or in connection with a lawful business transfer.
6. Public share and verification links
When a user creates a customer share link, the selected job/evidence information can be viewed by anyone who has that link until it expires or is revoked. Users should only share links with intended recipients. Individual verification pages may also be accessible using a verification identifier or QR code.
Private client notes are not intended to appear on customer-facing share pages or reports unless a feature expressly says otherwise.
7. Storage, analytics and session replay
ClientCam uses browser storage technologies such as local storage, session storage and IndexedDB for authentication state, preferences, PWA operation, active-job state, offline/pending evidence and remembering your analytics choice. These are used to provide requested app functionality or remember your privacy preference.
With your consent, ClientCam uses Microsoft Clarity to understand how people interact with the website and app. Clarity may record clicks, taps, scrolling, navigation, viewport information and a replay of visible page content, including signed-in ClientCam screens. Because ClientCam is configured for high-detail analytics, visible job, client, team, evidence, GPS and administrative information may appear in a Clarity recording when it is rendered on screen.
Clarity automatically masks the contents of form inputs, text areas and drop-down controls in all masking modes. ClientCam does not attempt to unmask passwords or form-control values. Clarity may use analytics cookies or similar identifiers after consent to join activity across pages and sessions.
You can choose Essential only or Allow analytics when ClientCam asks. You can change that decision later using the Analytics choices link. Withdrawing consent does not affect processing that occurred while consent was valid.
8. How long we keep information
We keep account, company, job and evidence information for as long as reasonably needed to provide ClientCam, maintain verification records, meet security or legal requirements, or until it is deleted through available controls or a valid deletion request. Some limited logs, backups or records may remain for a reasonable period where needed for security, recovery, legal obligations or dispute handling.
Share links may have their own expiry period and can be revoked by authorised users.
9. Security
ClientCam uses Supabase authentication, private evidence storage, server-side privileged operations and access controls. Service-role/private secrets are kept server-side. Company/team permissions are enforced for protected server actions as well as in the interface.
No online service can promise absolute security. Users should protect their account credentials and immediately contact us if they believe an account or share link has been compromised.
10. International processing
Some service providers may process information outside the United Kingdom depending on their infrastructure and your project/service configuration. Where required, transfers are handled using applicable legal safeguards provided by those service providers.
11. Your data-protection rights
Depending on the circumstances, UK data-protection law may give you rights to access, correct, erase, restrict or receive your personal information, and to object to certain processing. Where processing relies on consent, you can withdraw that consent without affecting earlier lawful processing.
To make a request, email info@clientcam.co.uk. We may need to verify your identity before acting on a request.
You can also complain to the UK Information Commissioner's Office (ICO) if you are unhappy with how your personal information has been handled: ico.org.uk.
12. Children
ClientCam is intended for business/trade use and is not intended for children. Users creating an account must be at least 18 years old or otherwise legally able and authorised to use the service for their organisation.
13. Changes to this policy
We may update this Privacy Policy as ClientCam develops. The current version will always be published on this page with its latest update date. Material changes will be communicated where reasonably appropriate.
14. Contact
Email: info@clientcam.co.uk
Website: clientcam.co.uk