Privacy Policy

Last updated: September 9, 2026

This policy explains what Radiant Toolkit (the "Service"), operated by Radiant Spaces ("we", "us"), collects, why, where it goes, and what you can do about it. It is written to match what the Service actually does.

What we collect

Account details. Your name, your email address, and a one-way hash of your password (we never store the password itself). We record when you signed up and when your address was confirmed.

Your company's data. Whatever you and your team put into the Service: company profile and header image, fixture library, estimates, proposals, job and as-built records, and photos. This often includes your clients' names, addresses, phone numbers and email addresses, which you are responsible for collecting lawfully.

Sign-in and security records. A session cookie so you stay signed in, the time of failed sign-in attempts (to lock an account after repeated failures), and single-use tokens for confirming an address, resetting a password, or accepting an invitation. Tokens are stored hashed and expire.

Error reports. When something goes wrong in the Service we record the error, which page or request it happened on, and your user and company identifiers, so we can fix it. We do not send request contents, cookies, or your data to the error service.

What we do not collect. The Service has no advertising, no analytics trackers, and no third-party scripts on its pages. We do not track you across other sites.

How we use it

We do not sell your data, and we do not share it with anyone except the service providers below, who process it only on our instructions.

Who handles it for us

How it is protected

All traffic to and from the Service is encrypted. Each company's data is isolated from every other company's at the database level, so a request from one company cannot read another's records. Passwords are hashed; tokens are hashed and single-use; photos are stored privately and served only to the company that owns them. The database is backed up every night and tested by being restored.

How long we keep it

Your data stays for as long as your company's account exists. When an administrator deletes the company, its data and the accounts that belonged only to it are removed immediately, and copies in backups age out within thirty days. Error reports are kept for ninety days. A confirmation or reset token that is never used expires on its own.

Your choices and rights

Cookies

The Service uses one cookie, to keep you signed in. It is marked so that scripts cannot read it and so that it travels only over encrypted connections. Your theme preference (light or dark) is stored in your browser and never sent to us. There are no advertising or tracking cookies.

Children

The Service is for businesses and is not directed at children under sixteen. We do not knowingly collect their data.

Changes

We may update this policy as the Service changes. If a change is material we will email the administrators of every company before it takes effect, and the date at the top will always tell you when it was last revised.

Contact

Radiant Spaces
Email: support@radiant-toolkit.com