Data Processing & Security

Last updated: September 23, 2026

This document describes how Moore Build Co. processes, stores, and protects the data you entrust to the MooreBuild platform. It supplements our Privacy Policy and Terms of Service.

Data We Process

Business Data (Controller: You)

As a tenant on the platform, you act as the data controller for the business information you enter — employee records, payroll data, client information, project details, financial documents, and time entries. You determine what data to enter and how it is used. We act as your data processor, handling this data only to provide and operate the Service on your behalf.

Platform Data (Controller: Moore Build Co.)

We act as the data controller for account information (name, email), usage analytics, and billing data. This data is used to operate, secure, and improve the platform.

Data Storage and Encryption

  • In transit: All data is encrypted using TLS 1.2+ when transmitted between your device and our servers.
  • At rest: Databases and file storage are encrypted at rest using industry-standard encryption (AES-256).
  • File uploads: Documents, photos, and signatures are stored in access-controlled cloud storage with encrypted access tokens.
  • Payment data: Card information is processed exclusively by Stripe and never touches our servers. We store only the last four digits and card brand for display purposes.

Access Controls

  • Row-Level Security: Each tenant's data is isolated at the database level. Users can only access data belonging to their own tenant.
  • Role-based permissions: Access within a tenant is controlled by role (admin, manager, employee, client, partner) with configurable page-level permissions.
  • Authentication: Passwords are hashed using bcrypt. We support OAuth (Google) and session-based authentication with secure token management.
  • Internal access: Our engineering team has restricted, audited access to production systems. Access is granted on a least-privilege basis and logged.

Data Location

Data is stored in cloud infrastructure located in the United States. Backups are maintained in geographically separated regions within the US for disaster recovery.

Data Retention and Deletion

  • Active accounts: Data is retained for as long as your account is active.
  • Cancelled accounts: Data is retained for 30 days after cancellation, during which you can export it. After 30 days, data is permanently deleted unless legally required to be retained.
  • Deleted records: When you delete a record (e.g., a project or invoice), it is removed from your view immediately. Residual copies may persist in backups for up to 30 days before being purged.
  • Legal holds: We may retain data beyond standard periods if required by law, court order, or legal dispute.

Security Measures

  • Regular updates: Dependencies and infrastructure are kept current with security patches.
  • Vulnerability scanning: The platform undergoes automated security scanning.
  • Monitoring: Systems are monitored for suspicious activity, anomalies, and potential breaches.
  • Incident response: We maintain an incident response plan. In the event of a data breach, affected users will be notified within 72 hours per applicable law.
  • Employee training: Team members with system access receive security awareness training.

Third-Party Processors

We use the following categories of third-party services to operate the platform:

  • Payment processing: Stripe (PCI-DSS Level 1 certified)
  • Cloud hosting: Cloud infrastructure providers with SOC 2 Type II compliance
  • Email delivery: Transactional email services for notifications and receipts
  • Analytics: Usage analytics to improve the platform

Each processor is bound by data processing agreements and may only use data to provide services to us.

Your Security Responsibilities

  • Use strong, unique passwords and enable available security features.
  • Limit user access to only those who need it within your organization.
  • Remove access promptly when employees or partners leave your organization.
  • Do not share account credentials. Use the invitation system for new users.
  • Report suspected security incidents to us immediately.

Data Export

You can export your business data (projects, clients, invoices, time entries, employees) at any time using the export features on each page. If you need a full data export, contact support and we will provide it within 30 days.

Contact

For security questions or to report a security concern, contact security@moorebuild.com.

Legal Disclaimer: This document is provided as a general template for informational purposes only. It is not legal advice. We strongly recommend having a qualified attorney review and customize these documents to fit your specific business needs and jurisdiction before relying on them.