1. Introduction
- Mason Intelligence, Inc. (“Mason,” “we,” “us,” or “our”) provides project-management, communications, and artificial-intelligence-assisted services for construction and related projects (the “Services”). This Privacy Policy (“Policy”) explains how Mason collects, uses, discloses, retains, and deletes personal information when you visit Mason’s websites, including our public marketing and informational pages, use the Services, or connect a third-party account or service to Mason, including services such as Google Workspace, Gmail, or Zoom.
- This Policy applies to information processed by Mason as a business or controller. When Mason processes information on behalf of a customer organization, that organization may be the business or controller of that information, and its privacy notices, policies, and instructions may also apply.
- This Policy applies to Mason, and it governs any and all data collection and usage by us. Where applicable law requires a legal basis for processing personal information, Mason processes information as necessary to perform its contract with you or your organization, based on Mason’s legitimate interests, with your consent, and/or as necessary to comply with legal obligations. Where Mason relies on consent, you may withdraw that consent at any time, although withdrawal does not affect processing already completed and may prevent certain features of the Services from functioning.
2. Information We Collect
- Depending on how you use the Services, Mason may collect the following categories of information:
- Account and profile information: Name, email address, telephone number, organization, role, login credentials, profile image, account preferences, and similar account information.
- Project and contact information: Project names, addresses, schedules, budgets, scope details, stakeholders, vendors, project participants, and other project records that you or your organization provide.
- Communications: Emails, text messages, call and meeting information, message content, attachments, sender and recipient information, and related metadata that you send, receive, upload, or direct Mason to process through the Services.
- Files and recordings: Documents, photographs, images, audio or video recordings, transcripts, meeting summaries, and related metadata that you upload, create, or connect to the Services.
- Connected-account information: Account identifiers, authorization information and permissions, and information obtained from third-party services that you choose to connect to Mason, including Google Workspace, Gmail, and Zoom.
- Usage, device, and technical information: IP address, browser type, device type, operating system, application events, diagnostic logs, approximate location inferred from an IP address, and information regarding how you interact with the Services.
- Payment and transaction information: Subscription status, transaction identifiers, and limited billing information. Payment information is processed by Mason’s third-party payment processor, Stripe. Mason does not store complete payment-card numbers.
- Information from service providers and other sources: Information Mason receives from integrations, customer organizations, project participants, public sources, and vendors where permitted by law.
- You may choose not to provide certain information. However, if information is necessary to provide a particular feature or Service, Mason may be unable to provide that feature or Service without it.
3. How We Use Information
- Mason may use personal information to:
- provide, operate, maintain, and secure the Services;
- create and administer accounts, organizations, projects, contacts, roles, and permissions;
- enable users to send, receive, organize, and manage project-related communications;
- process communications, files, recordings, meetings, and other information at the direction of a user or customer organization;
- provide automation and artificial-intelligence-assisted features, including organizing information, transcription, translation, summaries, suggested content or responses, and project assistance;
- provide customer support and troubleshoot problems;
- prevent fraud, misuse, unauthorized access, and other security incidents;
- process payments and administer subscriptions;
- analyze and improve the performance, reliability, and functionality of the Services;
- comply with applicable laws and regulations;
- enforce Mason’s agreements and establish, exercise, or defend legal claims; and
- communicate with users about the Services, including account notices, security notices, product updates, and, where permitted by law and subject to any consent required by law, marketing communications.
- Mason retains personal information only for as long as reasonably necessary for the purposes described in this Policy, to provide the Services, and to satisfy applicable legal, accounting, contractual, security, and regulatory obligations. More specific retention and deletion practices are described below.
4. How We Disclose Information
- Mason may disclose personal information in the following circumstances:
- Customer organizations and authorized users. Mason may make information available to authorized users within the same customer organization or project according to configured roles, permissions, and project access.
- Service providers. Mason may provide information to third-party vendors that perform services on Mason's behalf, such as hosting, communications, artificial-intelligence processing, analytics, customer support, security, and payment processing. Such providers may process information only as necessary to provide services to Mason and subject to applicable contractual restrictions.
- At your direction. Mason may disclose information when you or your organization direct Mason to send a communication, share a file, connect an integration, invite a participant, save information to a project, or otherwise disclose information.
- Legal and safety reasons. Mason may disclose information when Mason reasonably believes disclosure is required by law or is necessary to protect Mason’s or another person’s rights, property, safety, or security; prevent fraud or abuse; respond to legal process; or enforce Mason’s agreements.
- Business transactions. Mason may disclose or transfer information in connection with a merger, financing, acquisition, reorganization, bankruptcy, sale of assets, or similar corporate transaction, subject to applicable notice, consent, and legal requirements. Google user data will be transferred in connection with a merger, acquisition, or sale of assets only in accordance with applicable Google Limited Use requirements, including obtaining explicit prior user consent where required by those requirements.
- Mason does not sell or rent personal information or customer lists. SMS consent and opt-in information will not be sold or shared with third parties for their own marketing purposes.
4A. Google Workspace and Gmail User Data
This section applies when a user chooses to connect a Google account to Mason. Mason accesses Google user data only after the user grants permission through Google’s OAuth authorization process. The permissions displayed during authorization determine what Mason is permitted to access.
4A.1 Information Mason May Access
- Depending on the permissions a user authorizes, Mason may access:
- Gmail metadata, such as email headers, sender and recipient information, subject lines, timestamps, labels, and conversation information;
- Gmail content, including message bodies and attachments, if the user separately authorizes read access;
- Gmail sending permissions, when authorized, to allow users to send messages and replies through Mason; and
- Google account connection information necessary to maintain the authorized connection.
- A metadata-only authorization does not permit Mason to read email message bodies.
- Mason does not modify or delete messages in a user’s Gmail mailbox unless the user separately authorizes a permission that allows Mason to do so.
4A.2 How Mason Uses and Shares Google User Data
- Mason uses Google user data only to provide and secure features requested or enabled by the user or the user’s organization, including sending and organizing communications, associating communications with relevant projects, and displaying relevant communications within the Services.
- Mason does not sell Google user data. Mason does not use Google user data for advertising, retargeting, determining creditworthiness, lending, or creating marketing profiles, and Mason does not transfer Google user data to data brokers or information resellers.
- Mason may provide limited Google user data to service providers, including artificial-intelligence service providers, when necessary to provide or secure features requested or enabled by the user. These providers may process Google user data only on Mason’s behalf and subject to applicable contractual and technical restrictions.
- Access to Google user data by Mason personnel is restricted. Mason personnel may access Google user data only with the user's explicit consent for a specific support purpose; where necessary for security, abuse prevention, or incident response; where required by law; or where the information has been appropriately aggregated and anonymized for permitted internal operations.
4A.3 Google Limited Use
Mason’s use and transfer of information received from Google Workspace APIs complies with applicable Google API Services User Data Policy, Google Workspace API user-data requirements, and applicable Limited Use requirements. Mason does not use, transfer, or permit Google Workspace user data to be used to create, train, or improve foundational or generalized artificial-intelligence or machine-learning models or for independent secondary purposes.
4B. Zoom User Data
This section applies when a user chooses to connect a Zoom account to Mason, including through a Mason application made available through Zoom. Mason accesses Zoom user data only after the user grants permission through Zoom’s OAuth authorization process. The permissions displayed during authorization determine what Mason can access.
4B.1 Information Mason May Access
- Depending on the permissions a user authorizes, Mason may access:
- Zoom account and profile information;
- cloud-recording information and related meeting metadata;
- recordings, transcripts, summaries, and related files; and
- account-connection information necessary to maintain the Zoom integration.
- Mason’s Zoom access is read-only. Mason does not modify or delete content in the user’s Zoom account and does not join or attend Zoom meetings.
4B.2 How Mason Uses and Shares Zoom User Data
- Mason uses Zoom user data to provide features requested or enabled by the user or the user’s organization, including organizing meeting information, associating meeting content with relevant projects, and displaying that information through the Services.
- Mason may provide limited Zoom user data to service providers, including artificial-intelligence service providers, when necessary to provide or secure these features. Mason requires such service providers to use Zoom user data only on Mason’s behalf and to provide the same or equivalent protection of that data as required under applicable Zoom developer requirements.
- Mason does not sell Zoom user data, use Zoom user data for advertising or the creation of marketing profiles, or transfer Zoom user data to data brokers or information resellers.
- Access to Zoom user data by Mason personnel is restricted to authorized support, security, incident-response, legal, or other permitted operational circumstances.
4C. Artificial Intelligence and Automated Processing
- Mason uses artificial intelligence and automated systems to provide user-facing features such as classification and organization of communications, information extraction, transcription, translation, summaries, suggested content, and project assistance.
- Mason may use third-party artificial-intelligence and transcription service providers to support these features. Mason limits information shared with these providers to information reasonably necessary to provide the applicable feature.
- Mason does not opt in to allowing its artificial-intelligence service providers to use Mason-provided user data to train generalized artificial-intelligence or machine-learning models.
- AI-generated outputs may be incomplete or inaccurate. Users should review AI-generated content before relying on it or sending it to others.
- Mason may retain user-visible AI outputs and related project records in accordance with the retention practices described in this Policy.
5. Cookies, Analytics, and Similar Technologies
- Mason and its service providers may use cookies, local storage, and similar technologies to keep users signed in, remember preferences, measure performance, diagnose errors, and protect the Services.
- Where required by applicable law, Mason will obtain consent before using non-essential cookies or similar technologies. Users may be able to block or delete cookies using browser or device settings, although doing so may cause some features of the Services not to function properly.
6. Data Retention and Deletion
- Mason retains personal information only for as long as necessary for the purposes described in this Policy, to provide the Services, and to meet applicable legal, accounting, contractual, security, and regulatory obligations.
- Connected-account information. Authorization information used to connect services such as Google or Zoom is retained while the applicable connection remains active and is deleted when the connection is revoked, disconnected, or otherwise expires.
- Project and customer content. Communications, recordings, transcripts, summaries, files, and other information saved to Mason may be retained while the applicable project, organization, or account remains active. Following deletion or a verified deletion request, Mason generally deletes or de-identifies applicable information from active systems within 30 days unless continued retention is legally required.
- Temporary processing information. Some information may be processed temporarily to provide features of the Services without being saved as part of a Mason project or account. Mason does not intentionally retain that information after the applicable processing is completed. Service providers may temporarily retain information in accordance with their applicable service and security-retention practices.
- Business and legal records. Mason may retain billing, transaction, audit, fraud-prevention, security, and legal records for the period reasonably necessary to satisfy applicable tax, accounting, contractual, security, regulatory, and legal obligations.
7. How to Disconnect Google and Delete Google User Data
- Users may stop Mason’s future access to Google or Gmail by disconnecting Google through available Mason account controls or by revoking Mason’s access through their Google Account.
- Disconnecting Google prevents future access through that authorization but does not automatically delete project-related information previously saved to Mason.
- To request deletion of stored Google user data or other personal information, contact Mason at info@mason.tech from the email address associated with the account and identify the information to be deleted. Mason may verify the request before acting on it and generally completes verified deletion requests within 30 days unless a shorter period is required by applicable law.
8. How to Disconnect Zoom and Delete Zoom User Data
- Users may stop Mason’s future access to Zoom by disconnecting the integration through available Mason account controls or by removing or deauthorizing Mason through Zoom.
- Disconnecting Zoom prevents future access through that authorization but does not automatically delete meeting information previously saved to Mason.
- To request deletion of stored Zoom user data or other personal information, contact Mason at info@mason.tech from the email address associated with the account and identify the information to be deleted. Mason may verify the request before acting on it and generally completes verified deletion requests within 30 days unless a shorter period is required by applicable law.
9. Children’s Privacy
- The Services are not directed to children under 13, and Mason does not knowingly collect personal information from children under 13.
- If Mason learns that it has collected such information without legally valid authorization, Mason will take reasonable steps to delete it.
- If a higher minimum age applies under the laws of the jurisdiction in which a user resides, Mason will comply with that requirement.
10. Your Choices and Privacy Rights
- Depending on where you reside and applicable law, you may have the right to request access to, correction of, deletion of, or a copy of your personal information; object to or restrict certain processing; withdraw consent; or appeal a decision relating to a privacy request.
- You may also:
- update certain account information and preferences through the Services;
- revoke a connected third-party service’s access through that provider’s account controls;
- unsubscribe from marketing emails using the unsubscribe link contained in the message or by contacting Mason; and
- contact Mason to exercise an applicable privacy right or ask a privacy-related question.
- Mason may verify your identity and authority before completing a privacy request. Authorized agents may submit requests where permitted by applicable law.
- Mason will not discriminate against a user for exercising a privacy right provided by applicable law.
11. Links to Other Websites
- The Services may contain links to or integrations with third-party websites, applications, and services. Except where a third-party processes information solely on Mason’s behalf as a service provider, the third party’s own privacy notice governs its collection and use of information.
- Mason encourages users to review the privacy practices of third-party services before providing information to them or enabling an integration.
12. International Data Transfers
- Mason is based in the United States. If you access or use the Services from another country, your information may be transferred to and processed in the United States and in other countries where Mason or its service providers operate.
- Where required by applicable law, Mason uses appropriate safeguards for international transfers of personal information.
13. Security
- Mason uses administrative, technical, and physical safeguards designed to protect information against unauthorized access, loss, misuse, alteration, and disclosure. Google and Zoom user data are protected using encryption in transit and at rest and are maintained in access-controlled systems. Access by Mason personnel is restricted according to job responsibilities and legitimate operational needs.
- No information system or method of electronic transmission is completely secure, and Mason cannot guarantee absolute security. If you believe that your Mason account or information has been compromised, please contact Mason promptly at info@mason.tech.
14. Changes to This Privacy Policy
- Mason may update this Privacy Policy from time to time to reflect changes in the Services, applicable law, or Mason’s data-processing practices.
- When Mason updates the Policy, Mason will post the revised version and update the effective date.
- If a change materially affects how Mason collects, uses, or discloses personal information, Mason will provide additional notice where required by applicable law and will obtain consent where consent is legally required.
15. How to Contact Us
For questions about this Privacy Policy, requests relating to personal information, or privacy-related complaints, contact:
Mason Intelligence, Inc.
2750 Market Street
San Francisco, CA 94114
United States
Email: info@mason.tech
Telephone: 415-815-4002