CROWNFORGE Stone & Masonry LLC
Crownforge Privacy Standard / Release Draft

The property belongs to the client, not the platform.

Crownforge tools can handle home addresses, photographs, video, approximate location, design preferences, budgets, and construction evidence. This standard keeps collection visible, separates device and cloud storage, minimizes transmission, and gives the user direct controls.

Data Map

What each capability can touch.

No advertising pixels or behavioral-advertising SDKs are included in this release.

Permission based

Device sensors

  • Camera starts only after a user action and browser permission
  • Microphone starts only inside an explicit LiveSite action or System Check
  • Location is optional and can be omitted from the property twin
  • Motion and spatial interfaces are checked without claiming unavailable depth data
Local project vault

Saved project data

  • Design choices and lightweight records use browser local storage
  • Camera photos, scans, 3D packages, and build evidence use IndexedDB
  • Encrypted backups use AES-256-GCM with a password-derived key
  • Users can delete all recognized Crownforge records from Project Vault
Authenticated Crownforge Cloud

Protected project services

  • The private host forwards signed-in identity to the server; browser code never chooses another user's identity
  • D1 stores account, project membership, design metadata, AR sessions, and audit events
  • R2 stores only files the user explicitly uploads, with browser and server SHA-256 verification
  • Every project, file, AR, and audit request is authorized server-side and API responses are excluded from offline caches
Project inquiry services

Lead and consultation records

  • Contact details, project scope, requested meeting windows, consent, and source information are stored only after submission
  • Public attachment access uses a random lead-specific token; staff pipeline access requires an allowlisted signed-in account
  • Network rate limiting stores a salted connection hash rather than a raw IP address
  • Staff updates, protected downloads, consultation changes, and project conversion create an internal activity history
Accounts and memberships

Identity and billing records

  • Passwords are stored as salted, computationally derived hashes; Crownforge does not store readable passwords
  • Protected sessions, verification status, profile details, account roles, invitations, and acceptance versions are recorded for account operation and security
  • Stripe processes payment details; Crownforge stores provider customer, subscription, plan, and billing-status identifiers rather than card numbers
  • Resend delivers verification, recovery, and invitation email when configured
Launch diagnostics

Anonymous aggregate reliability metrics

  • Page views, browser errors, AR readiness events, and Core Web Vitals are counted in daily aggregates
  • No advertising cookies, visitor IDs, query strings, form contents, addresses, or raw IP addresses are stored
  • The hosting edge may set strictly necessary security cookies to detect abusive or automated traffic
  • A short-lived salted connection hash is used only to prevent diagnostic-event abuse
  • Global Privacy Control, Do Not Track, and the Project Vault diagnostics preference disable collection on the device
Control Standard

Collection, purpose, retention, and exit.

Last updated July 25, 2026
01

Collect only for the project

Contact and property information is used to respond to inquiries and organize design, consultation, estimating, construction coordination, closeout, and warranty conversations.

02

Ask before hardware access

Camera, microphone, location, and immersive spatial sessions require a visible user action and browser permission.

03

Separate local from cloud

The interface identifies device-only records, authenticated project records, and protected original-file storage without treating them as interchangeable.

04

Keep portability encrypted

Full-vault exports protect project media before download. The password is never stored by Crownforge and cannot be recovered.

05

Make deletion direct

Project Vault removes local records and media. Crownforge Cloud separately supports original-file deletion and project or lead archiving; final retention and hard-deletion policy still requires legal review.

06

Review before paid promotion

Broader operation still requires counsel review, service-provider agreements, a production retention schedule, consumer-request handling, and jurisdiction-specific disclosures.

Important Production Boundary

This page is an implementation standard, not final legal advice.

Before paid advertising or broader operation, Crownforge should have qualified privacy counsel review the final policy, California notice-at-collection language, consumer-request process, minor-user rules, retention schedule, subcontractor terms, cross-border access, account recovery, security incident process, and every connected CRM, payment, analytics, communications, AR, hosting, and AI provider.