This Privacy Policy explains what information Submittal Kit collects, why we collect it, and the choices you have. Submittal Kit is a business-to-business tool operated by Six Two Whiskey LLC, doing business as Submittal Kit ("we," "us," or "our"). It covers the website and application at submittalkit.com (the "Service").
The Service is used by control system integrators to manage PDF datasheets in a shared parts library and to compile O&M manuals, submittal packages, and as-built redline submittals for electrical control panels. This policy works alongside our Terms of Service. If you have questions, email us at [email protected].
01 Who We Are and Scope
Submittal Kit is a multi-tenant SaaS. Each customer company gets its own workspace, and all of that company's data is scoped to its workspace. In this policy, "you" means the person using the Service, and "your company" means the customer organization whose workspace you belong to.
This policy applies to the information we handle through the Service. Because Submittal Kit is a workplace tool, much of the information in it is provided by your company about its projects, its equipment, and its people. Where your company decides what to upload and why, your company is the party responsible for that content and for having the right to provide it to us.
02 Information You Provide
We collect information you and your company give us directly:
- Signing up. You can create a workspace by signing up with your name, work email, a password, and your company name. We store a pending signup record and email you a verification link; no account or workspace exists until you confirm your email address. Unverified signup records are deleted automatically after they expire. Confirming your email creates your company's workspace, your account, and starts your company's free trial. We notify the Submittal Kit team that a new workspace was created (see the Operator (Superadmin) Access section below).
- Account information. When your workspace is set up, we store your name, email, role, and a one-way salted hash of your password. We never store your password in plaintext. Your company's admins can also send single-use email invites to add members.
- Billing information. If your company purchases a paid plan, payments are handled by our payment processor, Stripe. Stripe collects your payment details directly — we never store your full payment card number. We keep limited billing records, such as the billing contact, plan, invoices, and payment status.
- Customer content. This is what you upload to or create in the Service, including manufacturer datasheets, product manuals, panel drawings, specifications, safety and policy documents, and returned review documents; bill-of-materials files (CSV, XLSX, or legacy XLS); company logos and branding assets; and project data such as projects, sites, panels, parts, catalog numbers, tags, annotations, highlights, and redline markups.
- Personnel information you enter about your employees. The Service lets your company build a personnel roster with names and certifications and store emergency contact information, which can be included in compiled submittals. This is personal information about your company's own employees. Your company is responsible for having the right to provide it to us and to include it in the documents it produces.
03 Information We Collect Automatically
When you use the Service, we automatically collect a limited amount of technical information:
- Server and infrastructure logs. Our systems record standard log data such as IP address, user agent, and request metadata. We use this for security, debugging, and operations. The application does not build behavioral profiles of you.
- Email engagement events. For emails we send, our email provider reports delivery and engagement events back to us, such as bounces, opens, and clicks. See the Service Providers and Subprocessors section below for details.
05 How We Use Information
We use the information described above to:
- Provide, maintain, and support the Service, including hosting your content and compiling the manuals, submittal packages, and redline submittals you request.
- Authenticate users, manage workspaces and membership, and enforce per-company isolation.
- Analyze datasheet content using the optional AI-assisted highlighting feature, when your company enables it, as described in the AI-Assisted Document Analysis section below.
- Process payments and manage billing for paid plans, through our payment processor.
- Send transactional emails such as sign-in links, invites, and security or account notices.
- Secure, debug, and operate the Service.
- Comply with our legal obligations and enforce our Terms of Service.
06 AI-Assisted Document Analysis
The Service offers an optional feature that uses AI to help locate and verify catalog-number highlights in uploaded datasheets. When this feature runs, relevant document content is transmitted to Anthropic's Claude API for analysis and the results are returned to the Service.
Anthropic does not use its API customers' data to train its models by default. This AI-assisted analysis is a convenience that can make mistakes; you and your company remain responsible for reviewing any highlighted or compiled output for accuracy before relying on it.
07 Service Providers and Subprocessors
We rely on a small set of service providers to run the Service. They process information only to provide their services to us:
- Anthropic — the Claude API used for the optional AI-assisted document analysis described above.
- Stripe — payment processing for paid plans. Stripe collects and processes your payment details under its own privacy policy; we do not store full payment card numbers.
- Resend — transactional email delivery, including magic sign-in links, invites, and account notices.
- Cloudflare R2 — object storage for uploaded documents, durable files, and database replicas.
- Cloud hosting providers — infrastructure with servers located in the United States.
Our pages load fonts and open-source scripts from third-party content-delivery networks — Google Fonts, the Tailwind CSS CDN, and the unpkg CDN. When your browser fetches those assets, it discloses its IP address and user agent to the CDN serving them. We do not use these CDNs to track you, and no analytics or advertising scripts are loaded anywhere on the Service.
08 No Sale of Personal Information and No Ad Tracking
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We do not run third-party advertising, and we do not use advertising or analytics cookies or load analytics or ad-tracking scripts. The information we collect is used to operate the Service, not to profile you or market to you across the web.
09 Operator (Superadmin) Access
Submittal Kit system administrators ("superadmins") can access company workspaces to provision them, provide support, and administer the Service. We limit this access to what is needed for those purposes.
10 Business Transfers
If we are involved in a merger, acquisition, financing, reorganization, or sale of some or all of our assets, information described in this policy may be transferred as part of that transaction. We will provide notice, by email and/or a notice on the Service, before your information becomes subject to a different privacy policy.
11 Data Retention
How long we keep information depends on what it is:
- Compiled working copies. A compiled submittal remains available while its source inputs are unchanged. When equipment, documents, recipe settings, or other inputs change, the previous working copy is invalidated and scheduled for deletion; the next compile produces a current copy.
- Revision snapshots. When a package is formally submitted, we mint an immutable revision snapshot of the exact compiled file and retain it as part of your company's submittal record. These snapshots persist — keeping the record of what was sent is a core purpose of the Service. Returned or marked-up review documents attached to revisions also persist. Because preserving what was actually submitted is a core purpose of the Service, revision snapshots and their attached review documents are retained even after your company's workspace is terminated. You may request deletion of a terminated workspace's snapshots by emailing [email protected], subject to any retention we need for legal or dispute-resolution purposes.
- Library documents. Uploaded library documents are stored content-addressed (by SHA-256 hash) and shared within your company workspace.
- Account and company data. We retain this while your workspace is active. On termination, we delete your data after a reasonable wind-down period, other than the revision snapshots described above and the billing records described below. On request during that period, we can provide a commercially reasonable window to export your data before deletion.
- Billing records. Invoices, payment status, and related billing records may be kept after termination for as long as we need them for tax, accounting, and other compliance purposes.
12 Security
We use reasonable administrative and technical safeguards to protect information in the Service, including:
- Passwords stored only as one-way hashes, with an enumeration-hardened login.
- HTTPS/TLS in production, with session cookies set HttpOnly, Secure, and SameSite=Lax.
- Per-company workspace isolation enforced in every query.
- Content-addressed storage with path-containment defenses on file serving.
No online service can be guaranteed to be perfectly secure, and we cannot promise absolute security.
13 Your Rights and Choices
You have choices about your information:
- Access and update. You can view and update your account information inside the app.
- Other requests. For access, correction, deletion, or export requests we cannot handle in the app, email us at [email protected]. Because the Service is a workplace tool, some requests may need to be coordinated with your company's admin.
- Employees of our customers. If you are an employee of one of our customers and have questions about personnel or emergency-contact information uploaded about you, please contact your employer directly — we hold that information on our customer's instructions and direct such requests back to them.
- Email preferences. We only send essential transactional emails, such as sign-in links, invites, and billing or security notices, while your account exists.
14 Children
The Service is a workplace tool for businesses and is not directed to children. No one under 18 may use the Service, and we do not knowingly collect personal information from children. If you believe a child has provided us information, contact us at [email protected] and we will address it.
15 United States Processing
We operate the Service from the United States, and the information we collect is processed and stored there. If you access the Service from outside the United States, you consent to processing your information in the United States.
16 Changes to This Policy
We may update this Privacy Policy as the Service evolves. When we make material changes, we will provide reasonable notice by email or in-app. The effective date at the top of this policy shows when the current version took effect, and your continued use of the Service after an update means you accept the revised policy.
17 Contact
If you have questions about this policy or your information, contact us at [email protected]. You can also review our Terms of Service.