USA construction estimating · Quantity takeoffs and cost estimates
Home › Privacy Policy

Privacy Policy

Last updated: 7 October 2026

Fast Estimating LLC collects information needed to respond to estimating requests, review drawings, manage client accounts, and deliver contracted estimating work.

Information you submit

  • Name, company, email, and optional phone number.
  • Project scope, location, deadlines, and other details you choose to include in your message, provide in later correspondence, or add to an authenticated project record.
  • Construction drawings and project files uploaded through the estimate request or authenticated client portal, plus any Dropbox shared link supplied with an inquiry.
  • Account security and service logs, including sign-in timestamps, IP address, and browser user-agent strings.

Use and retention

Information is used to review project requests, prepare and manage estimating services, communicate with clients, provide account access, and protect the service. Inquiries are retained in the application inbox up to its 500-record cap. Client files remain until removed by the owner or a deletion request is completed. Contact for access, correction, or deletion requests.

File storage and access

Uploaded drawings are encrypted with AES-256-GCM in the browser before upload. This site’s Vercel Blob store has a public provider access control list, so stored objects are ciphertext—not a private bucket. After an authenticated route checks account and project permissions, it issues a short-lived download URL and the decryption key for that specific file; the browser verifies and decrypts the file locally. A Blob URL alone does not reveal its contents. Provider-level private ACL protection is not configured.

Third-party services

The site uses Vercel for hosting and Blob storage. Dropbox URLs are stored as client-supplied shared links; the site does not connect to Dropbox or copy files through a Dropbox API. If the owner configures a Formspree form ID for inquiry alerts, contact/project metadata and any supplied Dropbox link (not drawing file bytes) may be sent to that email service. If server-side Resend settings are configured, one-time password-reset links are sent through Resend. Stripe checkout is not enabled unless the owner adds and verifies the required payment configuration.

Account security

Passwords are stored as scrypt hashes. Account changes require authenticated server-side routes and CSRF protection. Administrative access is limited by staff roles, rate-limited sign-in, and session controls. Clients can access only the project record linked to their authenticated account.

Confidentiality

Project information is used to respond to the request and provide estimating services. Do not upload payment-card details or government identification numbers. A signed NDA can be discussed before paid work begins.

Contact