Privacy Policy

Last Updated: October 25, 2025

The Orange Corporation ("we", "our", or "us") operates a quotation application for heavy construction materials. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our application. Please read this privacy policy carefully.

1. Information We Collect

We collect several types of information to provide and improve our quotation services:

  • Personal Information: When you create an account or submit quotes, we collect your name, email address, phone number, and company information.
  • Customer Data: For quotation purposes, we collect customer names, email addresses, phone numbers, business addresses, GPS coordinates for delivery locations, payment terms, credit limits, and tax exemption status.
  • Business Information: Material specifications, pricing details, delivery locations, pickup locations, transport routes, and project-specific requirements.
  • Technical Data: IP addresses, browser type, device information, and usage patterns collected through our analytics services.
  • Communication Data: Contact form submissions, email correspondence, and support requests.
  • Location Data: GPS coordinates and addresses for delivery and pickup locations to calculate transportation costs and routes.

2. How We Use Your Information

We use the collected information for the following purposes:

  • Quotation Management: Creating, managing, and tracking construction material quotes.
  • Customer Relationship Management: Maintaining customer records, contact information, and business history.
  • Transportation Calculations: Using location data to calculate delivery routes, toll costs, and transportation fees.
  • Tax Calculations: Determining applicable taxes based on delivery locations and customer tax exemption status.
  • Communication: Sending quote confirmations, updates, and responding to inquiries via email.
  • Authentication & Security: Managing user accounts, roles, and permissions through our authentication system.
  • Analytics & Improvements: Understanding usage patterns to improve our services and user experience.
  • Legal Compliance: Maintaining records as required by law and for audit purposes.

3. Third-Party Services

We use trusted third-party services to operate our application:

  • Clerk: User authentication and account management
  • PostgreSQL & Upstash Redis: Data storage and caching
  • SendGrid & Resend: Email delivery for quotes and communications
  • PostHog: Analytics to understand application usage (anonymized data)
  • Google Maps API: Address validation and mapping services
  • TollGuru API: Toll calculation for transportation routes
  • TaxJar: Sales tax calculation and compliance
  • AWS S3 & Google Cloud Storage: Secure file storage for documents
  • Sentry: Error monitoring to improve application stability
  • Pusher: Real-time updates and notifications

These services are bound by their own privacy policies and we ensure they meet our security standards.

4. Data Storage and Security

We implement industry-standard security measures to protect your data:

  • Encryption: All data is encrypted in transit using HTTPS/TLS protocols.
  • Access Controls: Role-based permissions ensure only authorized personnel can access specific data.
  • Secure Infrastructure: We use secure cloud hosting providers with appropriate certifications.
  • Regular Monitoring: Continuous monitoring for security threats and anomalies.
  • Audit Trails: We maintain detailed logs of data access and modifications.
  • Data Backups: Regular backups ensure data availability and recovery capabilities.
  • Rate Limiting: Protection against abuse through request rate limiting.

5. Data Retention

We retain your information for as long as necessary to fulfill the purposes outlined in this policy:

  • Account Data: Retained while your account is active and for a reasonable period thereafter.
  • Quotation Records: Maintained for 7 years for business and tax compliance purposes.
  • Customer Data: Kept as long as there is an active business relationship.
  • Communication Records: Retained for 3 years for reference and compliance.
  • Technical Logs: Automatically deleted after 90 days.
  • Deleted Data: When you request deletion, we remove your data within 30 days, except where retention is required by law.

6. Your Data Rights

You have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Request corrections to inaccurate or incomplete data.
  • Deletion: Request deletion of your personal data (subject to legal obligations).
  • Portability: Receive your data in a structured, commonly used format.
  • Objection: Object to certain types of data processing.
  • Restriction: Request temporary restriction of data processing.

To exercise these rights, please contact us at privacy@theorange-corp.com. We will respond to your request within 30 days.

7. Cookies and Tracking

We use minimal tracking technologies:

  • Essential Cookies: Required for authentication and session management through Clerk.
  • Analytics: PostHog collects anonymized usage data to help us improve the application.
  • Local Storage: Used to store user preferences and temporary application state.

You can control cookies through your browser settings, but disabling essential cookies may affect application functionality.

8. Data Sharing and Disclosure

We do not sell your personal information. We may share your data only in these circumstances:

  • Service Providers: With third-party services necessary for application operation (as listed above).
  • Legal Requirements: When required by law, subpoena, or court order.
  • Business Protection: To protect our rights, property, or safety, or that of our users.
  • Business Transfers: In the event of a merger, acquisition, or sale of assets.
  • Consent: With your explicit consent for specific purposes.

All third parties are contractually obligated to protect your data.

9. International Data Transfers

Our services primarily operate in the United States. If you access our application from outside the US, please be aware that your data may be transferred to, stored, and processed in the US where our servers and third-party services are located. We ensure appropriate safeguards are in place for international data transfers.

10. Children's Privacy

Our services are not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If you become aware that a child has provided us with personal information, please contact us immediately.

11. Updates to This Policy

We may update this privacy policy from time to time to reflect changes in our practices or legal requirements. We will notify you of any material changes by posting the new privacy policy on this page and updating the "Last Updated" date. For significant changes, we may also notify you via email.

12. Contact Information

If you have questions, concerns, or requests regarding this privacy policy or our data practices, please contact us:

The Orange Corporation Email: privacy@theorange-corp.com Support: contact@theorange-corp.com

We are committed to addressing your concerns and will respond to all inquiries within 30 business days.

13. Contact Us

If you have any questions about this privacy policy or our data practices, please contact us at privacy@theorange-corp.com.

Privacy Policy | The Orange Corporation