Skip to main content

Privacy Policy

Effective August 5, 2026

This Privacy Policy explains how FL Permit Pay (“we,” “us”) collects, uses, shares, and protects information when you use flpermitpay.com and our construction software for Florida trade contractors (the “Service”). It applies to the contractors and teams who use FL Permit Pay.

1. Information we collect

We collect information you provide, information created as you use the Service, and information from services you choose to connect.

  • Account and organization data: your name, email, phone, company details, team members, roles, and license or credential records you enter.
  • Operational content: jobs, customers, leads, permits, compliance records, documents, job-site photos, estimates, proposals, pay applications, and related notes you create in the Service.
  • Payment information: when you or your clients make payments, payment details are collected and processed by our payment processor (Stripe). We do not store full card numbers on our systems.
  • Connected-service data: if you connect a third-party service such as QuickBooks Online, we access data from that service as described in Section 4, using tokens you authorize.
  • Usage and device data: log data, IP address, browser and device information, and actions taken in the Service, used to operate, secure, and improve it.

2. How we use information

We use information to:

  • provide, maintain, and secure the Service and your account;
  • process subscriptions and, where you enable it, facilitate payments between you and your clients;
  • sync records with services you connect, at your direction;
  • send transactional messages (for example, account, permit, renewal, or payment notifications) and, with the required consent, text messages;
  • provide support, prevent fraud and abuse, and meet legal obligations;
  • measure which of our ads bring contractors to us, as described in Section 9; and
  • improve reliability, performance, and features.

We do not sell your personal information, and we do not use the accounting, financial, or job data in your account to advertise to you.

3. QuickBooks Online and Intuit data

If you connect QuickBooks Online, you authorize FL Permit Pay to access your QuickBooks data through Intuit’s official APIs solely to perform the actions you request, such as syncing customers or exporting a certified pay application as an invoice. This may include company information, customers, items, and invoice or payment records.

  • We access QuickBooks data only as needed to provide the features you use, and only while your connection is active.
  • We do not sell your QuickBooks data, and we do not use it for advertising or for any purpose unrelated to the Service you requested.
  • We store the access and refresh tokens for your connection encrypted at rest, and you can disconnect at any time from your FL Permit Pay settings, which deletes those stored tokens.
  • Our use of Intuit data complies with the Intuit Developer terms and applicable data-handling requirements.

4. Payments and Stripe

Payment processing is provided by Stripe. When you or your clients pay, card and bank details are transmitted directly to Stripe and handled under Stripe’s terms and privacy policy; FL Permit Pay does not store full card numbers.

When you enable online payments to bill your own clients, we use Stripe Connect to help you set up and manage your own Stripe account. FL Permit Pay facilitates that connection but does not hold, control, or take custody of your funds; money moves through Stripe to your account. You and Stripe are responsible for the resulting transactions and records.

5. How we share information

We share information only as needed to run the Service, and with service providers (subprocessors) that process data on our behalf under contract:

  • Supabase — database, authentication, and file storage.
  • Amazon Web Services (AWS) — application hosting, storage (S3), content delivery, and transactional email (SES).
  • Stripe — payment processing and payout facilitation.
  • Intuit (QuickBooks Online) — accounting sync, only when you connect it.
  • Amazon Bedrock — Flory's AI service, when you use Flory.
  • Google — mapping and solar/roof-measurement APIs used in specific features.
  • CompanyCam and Roofr — only when you import data you have exported from those services.
  • Meta (Facebook and Instagram) — advertising measurement on our public marketing pages only, never inside the signed-in app. What we send, and how to stop it, is set out in Section 9.

We may also disclose information to comply with law, enforce our terms, protect rights and safety, or in connection with a business transfer. We do not sell your information. Apart from the ad measurement described in Section 9, we do not share it for advertising.

6. Data retention

We keep your records and files for as long as your account is open. We do not age out or delete your jobs, permits, documents, or photos while you are a customer — a permit photo from four years ago is still evidence, and we treat it that way.

Specific windows we hold ourselves to:

  • While your account is open: your records and files are retained indefinitely.
  • A file you delete: a recoverable copy is kept for 30 days, then permanently removed.
  • A data export you request: the download package is deleted 7 days after it is ready.
  • When you close your account: your records and every stored file are permanently deleted. Deletion is scheduled 7 days out so you can cancel; once it runs it cannot be undone and we cannot recover your data for you.

Some records may be retained longer where the law requires it, for example certified payroll and construction lien records that carry statutory retention periods. Where that applies, we keep only what the law requires and nothing more.

7. Security

We protect data with encryption in transit, encryption of sensitive credentials at rest, strict tenant isolation so one organization cannot access another’s data, least-privilege access controls, and audit logging. No method of storage or transmission is perfectly secure, but we work to protect your information and to promptly address issues.

Every file you upload is stored under a path unique to your organization, and access is checked against your organization on every request — separation is enforced by the system, not by convention.

We run on third-party cloud infrastructure providers located in the United States, under contractual terms that require them to protect your data and to process it only on our instructions. Your data is stored in the United States. We maintain a current list of the providers we use and will supply it on request to any customer who asks at support@flpermitpay.com.

8. Your choices and rights

You do not have to ask us for your data. An owner or admin can export it directly from Settings → Your datain the app: we build a file containing your organization’s records together with a list of every document and photo you have stored, including where to download each one. It is ready shortly after you request it and stays available for 7 days.

The same screen closes your account. Because closing it permanently destroys everything, we will not run a deletion while an export is still being prepared — export first, download it, then close.

You can also access and update most information directly in the Service, and disconnect third-party integrations at any time. For a correction you cannot make yourself, or any other request, contact us at support@flpermitpay.com. If your organization administers your account, some requests may be directed to that administrator.

9. Cookies and advertising measurement

We use cookies and similar technologies that are necessary to sign you in, keep the Service secure, and remember your preferences.

On our public marketing pages only, we also use the Meta advertising pixel (Facebook and Instagram) to measure which ads bring contractors to us. It records which marketing page you viewed. When you submit a form on one of those pages, we tell Meta that a form was submitted and include a one-way encrypted (hashed) version of your email address and phone number, so Meta can match the ad you clicked to the form you filled out. We do not send Meta your actual email address or phone number, and we do not send the contents of your message.

The pixel never reports a page inside the signed-in app.It is not started on any page under your account, and it is not started on the links you send to your own clients, such as a proposal, an invoice, or a shared file. No address of any of those pages is ever sent to Meta, so your jobs, customers, permits, documents, payroll, and payments are not reported to it. If you move from a public page straight into your account without a fresh page load, Meta's script can still be present in that browser tab until you reload, though it reports nothing further.

We report the same public-form submissions to Meta from our servers as well, because browsers increasingly block the pixel and we would otherwise have no way to tell which ads work. What we send is the same either way: the hashed email or phone, which marketing page it came from, your IP address, and your browser type. Each submission is sent with a single shared identifier so it is counted once, not twice.

If your browser sends a Global Privacy Control signal, we do not load the pixel and we do not report anything to Meta. Browser tracking blockers and ad blockers also stop it. Either way, nothing about your form or your account changes.

10. Children

The Service is intended for businesses and is not directed to children. We do not knowingly collect information from anyone under 18.

11. Changes to this policy

We may update this Privacy Policy from time to time. We will post the updated version here with a new effective date and, for material changes, provide additional notice where appropriate.

12. Contact us

Questions about this policy or your data? Email support@flpermitpay.com.